1 / 31100%
264
STAKEHOLDER EXPECTATIONS
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 11
29.1 STAKEHOLDER OUTREACH:
Organizations will have various stakeholders, some of whom may indeed be
undesirable as far as the organization is concerned. For example, if a distribution company
wants to build an extension to its depot, the locals may oppose it. The locals are stakeholders
in the company's operations, even though the company owners may not want to acknowledge
that fact. ISO Guide 83 suggests that the term 'interested parties' is preferred, but stakeholders
is an acceptable alternative. ISO Guide 73 defines stakeholders as 'persons or groups who are
concerned with, affected by, or consider themselves affected by the organization'.
There will be various stakeholders in a typical organization that can be summarized as
CSFSRS, as follows:
•
Customer;
•
Staff;
•
financiers;
•
Suppliers;
•
regulator;
•
society.
Stakeholders may have contradictory expectations of the organization. For example, staff at a
sports club will seek the highest possible pay. This will conflict with the requirements of the
financiers, who want the club to be as profitable as possible. It is part of the management role
to balance the conflicting interests of different stakeholders and implement actions that
provide the best balance between conflicting stakeholder expectations. For organizations in
different sectors, the range of stakeholders will differ. For government agencies, the general
public will be the primary stakeholder. Certain groups within the general public will be
stakeholders in different agencies, depending on the objectives of each particular agency. For
organizations that have significant environmental interests or exposures, a range of different
stakeholders will need to be considered. For some energy companies, environmental pressure
265
groups are often unwanted stakeholders. There may be substantial conflict between mining
companies who want to extract minerals and local residents who do not want heavy industrial
activities to occur in the area.
Business process re-engineering (BPR) is a technique for ensuring that an organization
has the most effective and efficient processes and operations. The starting point for many BPR
exercises is identifying stakeholders and their expectations. The delivery of shared stakeholder
expectations is then carried out by the organization's core processes. Core processes are a
collection of high-level activities that are fundamentally important to the organization. For a
sports club, the core process of 'delivering success on the pitch' will be fundamental. These
processes will be important to many stakeholders, including supporters (or customers), players
(or staff) and sponsors (or financiers). The benefit of this approach is that the organization can
be defined by a small number of core processes that should include strategy, tactics,
operations and compliance. A corporate evaluation of these core processes and the risks that
may impact the core processes can be performed. By taking this approach, risk management
activities will be fully embedded in the organization.
Depending on the nature of the stakeholder, questions should be asked about
organizational risk awareness, activities designed to achieve risk improvement, and risk
governance arrangements within the organization. Relevant stakeholders are entitled to
receive information about the organization's risk profile. They are also entitled to information
about the arrangements for risk improvement and the metrics in place to monitor risk
performance. Finally, stakeholders are entitled to information about the organization's risk
appetite and arrangements for incorporating risk into strategy development. The box below
provides an example of how stakeholders will have different expectations from an
organization. Sometimes, these expectations will conflict. Even if they do not conflict, it is
helpful for one stakeholder group to have an understanding of the expectations of another
group.
Stakeholders in Theater:
Assume that a theater seeks to involve all stakeholders in its activities. This will
extend to consideration of the goals of performers in the theater, including artists and actors.
There needs to be a distinction between the goals of the performer and the needs of the
audience. For example, an established musician may want to promote a new album, but the
audience wants to hear well-known favorites from previous albums. Performers will have the
best chance of putting on a successful show if the starting point is an evaluation of audience
expectations, followed by an evaluation of theater expectations. The performer can then plan
266
the specific content of the show to be consistent with those expectations as well as taking into
account his or her professional and personal goals. Theatres can encourage this approach and
recognize the performer as a stakeholder, but encourage the performer to consider other
stakeholders and their expectations.
29.2 STAKEHOLDER DIALOG:
Dialogue with stakeholders should be based on a shared understanding of the
organization's purpose. The board is responsible for ensuring that the dialog is satisfactory.
While specific members of the organization may have day-to-day responsibility for
communication with specific stakeholder groups, the board will retain overall responsibility.
Table 29.1 provides a summary of the information that should be provided to the shareholders
of a company. This information will focus on providing accurate financial data.
The level and nature of dialogue with stakeholders will depend on the stakeholder's
particular interest in the organization's operations. Supporters of a sports club will require
different information than a bank that provides the necessary financial support to the club. To
get a full picture of the risks facing the organization, an analysis of stakeholders and their
expectations is necessary. Identification of stakeholder expectations is one of the outputs of
the external evaluation stage of the business cycle. Different stakeholders may have
conflicting or even mutually exclusive expectations in terms of the demands placed on the
organization. The importance of communication with stakeholders also extends to
whistleblowing and the text box below provides an illustration of how whistleblowing can be
valuable to the organization and should be encouraged.
Whistleblowing Policy:
Rank aims to maintain a culture of openness, honesty and opposition to fraud,
corruption and unethical business conduct. It is Rank's policy to implement and maintain
procedures that promote ethical business conduct and reduce the risk of fraud and other
irregularities, enabling early detection, investigation and reporting. Rank has a fraud and
business ethics violation policy that governs the ways in which employees can voice their
concerns about suspected fraud, corruption or unethical business conduct. During the period
under review, two frauds came to light in Grosvenor's retail casino business in circumstances
where it appeared that others not directly involved potentially had suspicions that they never
expressed. This led management and the committee to question whether the whistleblowing
policy was effective enough.
267
Although reports are made under the group's whistleblowing policy, the matters that
are the subject of reports are rarely related to fraud or unethical business conduct, and are
more often than not related to human resources issues. Managers in the business are being
consulted on how best to overcome the cultural resistance to using the whistleblowing policy
for the matters for which the policy is intended.
29.3 STAKEHOLDERS AND PROCESSES CORE:
Core processes deliver stakeholder expectations and are linked to the internal and
external context of the organization. Therefore, risks can be defined as events that have the
potential to impact the fulfillment of stakeholder expectations. This approach has the
advantage that internal and external stakeholders can be identified, along with their short-
term, medium-term, and long-term expectations. Figure 29.1 provides a graphical illustration
of the relationship between stakeholder expectations and the organization's core processes.
The figure illustrates that an organization's core processes can be strategic, tactical,
operational, or compliance (STOC). Figure 29.1 shows the compliance core process as a
separate process, although the compliance core process must also support and underpin other
types of core processes.
The classification of core processes as strategic, tactical and operational is recognized
in British Standard BS 31100 when discussing risk management perspectives. The strategic
perspective determines the future direction of the business; the tactical perspective is
concerned with turning strategy into action by achieving change; and the operational
perspective is related to the day-to-day operations of the organization, including people,
information security, health and safety, and business continuity. Again, compliance processes
are assumed to support other types of core processes.
An approach based on stakeholder expectations has many advantages. It facilitates a
full and thorough validation of the organization's core processes in relation to the expectations
that each stakeholder places on each core process. An important aspect of managing an
organization is balancing the various stakeholder expectations. There are inherent dangers in
achieving this balance, and a risk identification procedure based on stakeholder expectation
analysis is the most powerful way to ensure that these dangers are recognized, analyzed, and
minimized.
The analysis of stakeholder expectations is also one of the fundamental requirements
of the business process reengineering (BPR) approach. The stakeholders in the current and
future activities of the organization can be identified. The expectations of each stakeholder in
relation to each stated goal and the mission of the company can then be evaluated. Shared
268
expectations will emerge and the organization's core processes can then be defined (or refined)
specifically in terms of delivering these shared expectations. While stakeholder expectation
analysis can be one of the most powerful ways to identify risks, there are implications in terms
of the time and effort required for this approach to be successful. BPR can be a very time-
consuming exercise if done thoroughly. The benefits of taking a BPR or core process
approach include the ability to identify core processes that are most vulnerable to risk events.
This will enable the identification of stakeholders whose expectations are most likely to go
unmet because their expectations have not been met.
29.4 STAKEHOLDERS AND STRATEGY:
It has been clearly established and shown by research that incorrect risk management
decisions related to strategy can destroy more value for the organization than incorrect risk
management decisions related to operations or projects carried out by the organization.
Stakeholder expectations are delivered by the organization's core processes. Table 29.2
describes the range of stakeholder expectations for a typical sports club. The core processes
that deliver stakeholder expectations can be strategic, tactical, operational, or compliance
(STOC), which is shown in the bow-tie representation of the risk management process in
Figure 11.1. The strategic core process needs to be the most robust process in the
organization, and indeed this will be required by key stakeholder groups. Such stakeholders
include financiers and other shareholders who are interested in the long-term success of the
organization. Supporters' expectations include good stadium facilities, and a strategic core
process may need to be established to manage the construction of a new stadium. This will be
a significant investment that will require substantial support from financiers. To secure
support, the club needs to be aware of funder expectations. Funders and ensure that the new
stadium plan and the financial arrangements to be put in place meet the necessary stakeholder
expectations. The construction phase of acquiring a new stadium will be a significant project
for the club, with various stakeholders to consider.
29.5 STAKEHOLDERS AND TACTICS:
The tactical stakeholders of an organization may be very different from those
concerned with the operations of the organization. If an organization's tactics involve product
improvements, investments in new production techniques, responses to technological changes
or other developments that require projects, then finance is likely to be required. This means
that finance bodies are likely to be key stakeholders in projects and similar tactical changes.
Other stakeholders in the project may include building contractors and other specialist
269
professional support providers, such as architects. The importance of employees in the
implementation of tactics should not be underestimated. Staff will also have a stake in
operational issues and be key stakeholders in the operation of the organization. If changes to
working practices or product features are to be successfully incorporated into the
organization's operations, then staff support is critical and good communication with them is
essential.
It is important to consider the impact of changes, developments, projects, and tactics
on all stakeholders. By considering stakeholder interests in detail, many unexpected surprises
can be avoided. The impact of the project, both in execution and after project delivery, should
be considered in detail. This consideration should include internal and external stakeholders
for whom the changes that the project will bring may be significant. These changes can relate
to environmental factors during the construction project and after the work is completed, as
well as changes in working arrangements for staff. It may be a good idea to bring some people
who are not directly involved in the organization's activities into the project planning. This
will allow the organization to fully understand the impact of the work to be carried out. When
considering stakeholder management, the level of detail will often determine whether
engagement with stakeholders is successful. Even with successful projects, being able to
minimize negative impacts with early attention to key stakeholders and their expectations may
prove invaluable.
29.6 STAKEHOLDERS AND OPERATIONS :
There may be many stakeholder groups involved in the operational activities of the
organization. To continue with the sports club example, fans will be key stakeholders in a
large number of different aspects of the club's activities. One of the main concerns of the fans
will be good results on the pitch. They will also be interested in other operational aspects,
including ticketing arrangements, transportation and access arrangements, and the facilities
provided within the stadium.
Pharmaceutical companies are generally large organizations with very diverse
stakeholders. In particular, pharmaceutical companies that manufacture critical drugs have an
obligation to ensure the constant availability of such drugs to all their patients. Patients should
be seen by pharmaceutical companies as important stakeholders who have expectations
regarding the availability and effectiveness of the drugs they have been prescribed.
Stakeholder groups that have an interest in The operational activities of the organization are
likely to be customers, suppliers, and others who may be affected by disruptions to the
organization's normal efficient operations. For example, customers are likely to be affected if
270
the risk of harm materializes. Similarly, suppliers are stakeholders in the organization and
they will suffer if the organization is disrupted to the extent that their
supplies/products/components/services are no longer required.
Other stakeholder groups that may be affected by hazard risk will also have an interest
in the continuity of the organization's activities. For financial organizations such as banks,
customers will be directly affected if critical IT systems fail. The corporate governance model
requires adequate stakeholder involvement and stakeholder dialog. In some countries,
employees are recognized as stakeholders in the organization to the extent that employee
representation on the board may be mandatory. The box below considers the position in some
European countries.
Employee representation on the whiteboard:
Board-level employee representation involves employee representatives sitting on a
supervisory board, board of directors or similar structure in the company. These employee
representatives are either elected directly by the workforce, or appointed in some other way,
and can be employees of the company, officers of organizations that represent those
employees, or individuals who are perceived to represent employee interests in some way.
Board-level representation also differs from other types of indirect participation such as works
councils in that it seeks to provide employee input into overall company strategic decision-
making rather than focusing on information and consultation on day-to-day operational issues
in the workplace.
In most cases in Western Europe, employee representatives are a minority, and board-
level participation is associated with the acquisition of information and understanding
followed by the expression and exchange of opinions, views and arguments about company
strategy and direction. However, in some cases, when employee representatives are equal in
number to shareholders or other parties, issues of control, veto and real influence over
corporate strategy - sometimes known as 'co-determination' - come into play.
OPERATIONAL RISK MANAGEMENT
30.1 OPERATIONAL RISK:
The importance of managing operational risk has been well established for some time.
Operational risk can be thought of as the type of risk that will disrupt normal day-to-day
activities. In many ways, operational risk is closely related to infrastructure risk described in
271
the FIRM risk scorecard classification system. Operational risk is typically a hazard risk, and
historically this has been an area of strong risk transfer application through insurance.
However, operational risk now has a broader application and more specific definition,
especially in financial institutions. While addressing the same type of risk, operational risk in
financial institutions is distinguished by the fact that there is a need to measure this risk in
terms of potential financial loss.
Financial institutions are required to have sufficient capital reserves to meet actual and
potential financial losses and liabilities that the organization faces. This is a key requirement
of the regulatory framework set out for banks in the Basel II Accord and under the emerging
regulations for European insurance companies through the Solvency II European Directive.
Therefore, financial institutions need to measure the level of operational risk they face. A
major factor that contributed to the global financial crisis was that banks adopted high-risk
strategies that resulted in banks not having sufficient capital when such risks materialized.
Capital adequacy requirements based on Basel II require banks to
consider operational risk exposures in determining capital requirements. This operational risk
management framework should include identification, measurement and monitoring,
reporting, control and mitigation framework for operational risk. This capital needs
assessment is often called economic capital. In addition, regulations require that banks must
follow one of three specific quantitative methods to provide another measure of capital
requirements. This is called regulatory capital. Two methods are based on the financial
institution's earnings. The third method requires the assessment of all material operational risk
exposures with a high level of statistical quality. Under the Solvency II European Directive,
insurance companies in the EU must adopt a similar approach.
Basel II is the second Basel Accords that contains regulatory recommendations
banking legislation, as issued by the Basel Committee on Banking Supervision. The aim of
Basel II (2004) was to create an international standard that banking regulators could use when
making regulations on how much capital banks should set aside to guard against the types of
financial and operational risks they face. Basel III requirements have been developed,
although it is not anticipated that Basel III will be fully in effect until 2019.
30.2 DEFINITION OF RISK OPERATIONAL:
The operational risk faced by banks and other financial institutions essentially
represents the type of disruptive hazard risk faced by other organizations, although the
definition may be broader and the terminology slightly different. The specific point in the case
of operational risk for financial institutions is that the level of operational risk needs to be
272
measured, as the level of risk must be covered by the capital available within the institution.
This leads to the imperative for banks to reduce the level of operational risk to the lowest
cost-effective level.
Banks have long been concerned with market risk and credit risk (and insurance
companies with underwriting risk as well), but the advent of Basel II and Solvency II required
financial institutions to consider broader operational risk exposures. Operational risk was
originally defined as any form of risk that was not market risk or credit risk. This imprecise
definition was replaced by Basel II with a definition of operational risk as: 'the risk of loss
resulting from inadequate or failed internal processes, people and systems or from external
events'.
The Basel II definition includes legal risks, but excludes strategic and reputational
risks. The types of risks associated with the Basel II definition are as follows:
•
Internal fraud, including asset misappropriation, tax evasion and bribery;
•
External fraud includes theft, hacking, and forgery;
•
employment practices and workplace safety;
•
clients, projects and business practices;
•
damage to physical assets;
•
business interruptions and system failures;
•
execution, delivery and process management.
However, there is also recognition that operational risk is a term that has various meanings
and that certain financial institutions use different terms or broader definitions. The Basel II
definition identifies four types of risk categories: people, process, system and external risks.
People risks include failure to comply with procedures and lack of segregation of duties.
Process risks include process failures and inadequate controls. System risks include the failure
of application systems to meet user needs and the absence of built-in control measures.
Finally, external risks include actions by regulators (regulatory changes, but not including
enforcement or disciplinary actions), unsatisfactory performance by service providers and
fraud, both internal and external. External risks also include legal action by customers of
financial institutions related to negligence or fraud committed by staff.
The definitions of market risk and credit risk also need to be considered in relation to
financial institutions. Market risk is the risk that the value of an investment may decline over a
period, simply because of changes in the economy or other events that affect a large part of
the market. Credit risk is the risk that there will be a failure of a customer/client to repay the
principal and/or interest on a loan or other debt that have not been paid in a timely manner, or
273
not at all. Underwriting risk is also important for insurance companies; it is the client's risk
exposure through an insurance policy.
Operational risk management failure:
Operational risk management is at a crucial point in its development. Many
approaches have been developed in various industries, but many institutions struggle to make
it fully effective by actually incorporating it into their day-to-day business management. To
overcome this challenge, it is important to clearly define the relationship between operational
risk processes and the overall control environment.
Indeed, the effectiveness of operational risk management has been hampered by a
general failure to truly embed operational risk into overall risk management and control. The
group risk function should demonstrate to business unit staff the full potential of using the
operational risk process, developed under the group framework to manage actual risks in the
business.
As a result, operational risk governance involves more than just calculating annual
operational risk capital. As economic and financial conditions change over time, so do
operational risk exposures. This implies that a certain number of operational risk events may
become more likely, which in times of crisis require top management attention.
The losses associated with failing to manage operational risk can be substantial.
Losses suffered by so-called rogue traders are sometimes attributed to market risk. The
argument is that losses occur because market conditions change unexpectedly and significant
losses occur. From an operational risk perspective, this analysis is incorrect. It is more correct
to say that the losses occurred due to a failure to control the activities of the traders. If
operations had been controlled by adequate operational risk controls, the traders would not
have been in a position to put the bank's substantial assets at risk. Blaming the loss on market
risk when such a large amount of the bank's assets should not have been in the market is
simply not correct.
30.3 BASEL II AND BASEL III:
Basel II has been around for some time and, at the time of writing (2016), Basel III
requirements have been developed, but will probably not be introduced until 2019. The
revised requirements contained in Basel III will likely be consistent with what has gone
before. Similarly, the development of Solvency II that will determine capital requirements for
insurers has been completed and the full implementation date is currently expected to be no
later than 2019. The approach taken in Solvency II is consistent with the approach in Basel II
274
and Basel III. The ten 'Sound Practices' principles on operational risk put forward by the Basel
II committee are presented in Table 30.1. One of the key requirements, as set out in Principle
5, is that the processes necessary to assess operational risk should be established. The
objective of Basel II is to help protect the international financial system from the kinds of
problems that might arise if a large bank or series of banks collapses.
Basel II attempts to protect the international financial system by establishing strict risk
and capital management requirements designed to ensure that banks hold capital reserves
appropriate to the risks the bank faces through its lending and investment practices. These
rules mean that the greater the risk a bank faces, the greater the amount of capital required to
maintain solvency and overall economic stability. Basel II aims to ensure that capital
allocation is more risk sensitive, that operational risk is separated from credit risk (both must
be quantified) and that a global regulatory regime is in place.
The Basel II Accord describes comprehensive minimum standards for capital
adequacy that are being implemented by national supervisory authorities. In addition, Basel II
is intended to foster a more forward-looking approach to capital supervision that encourages
banks to identify the risks they face and improve their ability to manage those risks. As a
result, it is intended to be more flexible and better able to evolve with market advances and
risk management practices. There is much debate on the effectiveness of the Basel II (2004)
Accord in achieving its stated objectives. The effectiveness of the accord must be assessed
against the failure of the banking system in 2008. The role of that failure in the global
financial crisis has been the topic of a much more detailed evaluation.
30.4 OPERATIONAL RISK MEASUREMENT:
Operational risk has become a particular issue in financial institutions, due to the need
to quantify/measure the level of operational risk they face. The measurement of operational
risk can involve a number of methods and these are usually based on historical information,
simulated information or a combination of all. Table 30.2 presents examples of operational
risks faced by banks or financial institutions. Basel II offers three alternative approaches to
measuring operational risk for regulatory capital purposes, as outlined below. The first two
methods are proxies for operational risk management exposures; while research work is
undertaken to validate these methods, individual firms may differ substantially from the
assessment that these two methods would provide:
•
Basic indicator approach: calculates operational risk capital using one indicator for the
overall risk exposure.
•
Standardized approach: calculating the value of operational risk, using broad financial
275
indicators, multiplied by operational loss experience.
•
Advanced approach: using internal loss data and a combination of qualitative and
quantitative methods to calculate operational risk capital.
To quantify operational risks, financial institutions need to adopt a structured approach. Even
after risk identification, quantification is only possible if the amount of damage and the
probability of the risk are determined. Operational risks are difficult to quantify because loss
history is usually not available and some risks cannot be easily measured. Many banks have
undertaken a detailed evaluation and quantification of their operational risks. It is generally
recognized that the size of the bank (measured by the number of employees) affects the size of
the loss. This seems to indicate that larger banks tend to have larger clients. Another common
trend identified is that the amount of loss is strongly correlated with the number of clients
using the bank.
30.5 DIFFICULTY MEASUREMENT:
The growing interest in operational risk is based on the need to measure operational
risk in financial institutions. The challenges in measuring operational risk are considerable.
The expected level of loss can only be estimated, even if the probability of loss is known with
sufficient accuracy. Although statistical approaches have been adopted and developed, a
universally accepted approach is still not available. Expected losses can have both direct and
indirect costs. Indirect costs are often greater, and include the loss of customers. This loss can
be represented by the present value of that customer and all future profits from the customer
that relationship. Actions to be taken will include internal control measures as well as
evaluation by internal audit. Internal audit within a financial institution has the familiar, but
very important, responsibility of checking whether procedures are being followed in practice
and whether the procedures themselves may be effective in reducing the level of operational
risk.
Table 30.3 illustrates the different nature of operational risks faced by financial and
industrial enterprises. The table provides a comparison of the nature and impact of human
error in financial institutions, compared to industrial businesses. It is clear that controlling
staff behavior and actions is much more difficult in financial institutions than in
manufacturing facilities. It should be noted that quantification of operational risks is possible
for non-financial institutions, and transportation companies (for example) can investigate the
operational risks associated with their activities. Risks associated with operations include fuel
prices, tax liabilities and the financial impact of delivery errors. Operational risks can arise
from road traffic accidents or other delivery delays and changes by customers that have not
276
been properly incorporated into the delivery schedule.
Arguably the most important operational risks faced by transportation companies are
customer misdelivery and road traffic accidents. Quantification of the risk exposures
associated with different categories of operational risks will help transportation companies
focus on those risks with the greatest potential to cause disruption to normal efficient routine
operations, and then take appropriate control measures to reduce these operational risk
exposures.
30.6 OPERATIONAL RISK PROGRESSION:
Before considering the development of operational risk, it should be noted that
concerns about operational risk are universal across all organizations. While banks and other
financial institutions may have specific approaches to operational risk, the issues under
consideration are the same issues that affect all other types of organizations in the public,
private, and third sectors. (The third sector refers to not-for-profit organizations, including
charities, membership, and voluntary bodies.) Although the issues are the same, the
approaches at banks and other financial institutions can differ. In a non-financial institution,
questions related to operational risk might be: 'How much are my assets worth, how can they
be protected, and to what extent and what value (or indemnity limit) do I need to buy
insurance? ' In the financial sector, the question is more likely to be: 'What are the capital
requirements attached to my assets?' and 'Can I keep some (non-productive) capital in reserve,
or do I need to buy insurance and what is the value or indemnity limit?'
It is generally accepted that operational risk issues need to be an integral part of the
management of financial institutions. It is often the case that management trainees within
financial institutions spend some time in the risk management function, as their careers
progress in the general management side of the business. It is the intention that this
engagement with risk management will create greater awareness before individuals progress
into other roles. The measurement of operational risk in financial institutions remains a
challenge, especially during the global financial crisis, which showed that the level of
operational risk exposure was greater than most banks believed. Certain financial institutions
are seeking to adopt risk management standards, such as ISO 31000, IRM standards, and the
COSO framework. Basel II does not stipulate or require any particular framework for use with
operational risk management, except that the frameworks adopted are conceptually sound and
pay close attention to integrity issues.
There is another tension that arises with the development of operational risk within
financial institutions. In many cases, operational risk quantification is seen as a compliance
277
requirement rather than a business opportunity. Given that the quantification of operational
risk can be highly technical, there can be a tendency for management within an organization
to feel that the role of operational risk manager is responsible for this work. Responsibility for
risk management and the implementation of controls usually rests with line managers. If this
responsibility is not accepted, there is a danger that operational risk management will not be
fully integrated into the management of the financial institution, with disastrous
consequences.
The calculation of operational risk exposure is a Basel II requirement, and therefore
financial institutions must do this work. Financial institutions are driven by increasing
regulatory demands and other corporate governance pressures. Raising the level of operational
risk awareness by measuring risk levels and explaining the importance of risk management to
relevant staff members should be beneficial to the organization. This heightened awareness
will enable organizations to identify sources of operational risk and take appropriate cost-
effective actions to optimize operational risk exposure levels.
The U.S.-based Risk and Insurance Managers Society (RIMS) has conducted
evaluation of the causes of the global financial crisis. This evaluation considered the
contribution that enterprise risk management (ERM) can make and the reasons for failures in
the application of ERM tools and techniques. RIMS concluded that the global financial crisis
was not a failure of ERM, but was caused by the following failures:
•
There is an over-reliance on the use of financial models, with the false assumption that
'risk quantification' (used as a prediction) based solely on financial modeling is a
reliable and sufficient tool to justify the decision to take risks in the pursuit of profit.
•
There is an over-reliance on compliance and controls to protect assets, with the false
assumption that historical controls and monitoring of a few key metrics are enough to
change human behavior.
•
There is a failure to properly understand, define, articulate, communicate and monitor
risk tolerance, with the false assumption that everyone understands how much risk the
organization is willing to take.
•
There is a failure to embed enterprise risk management best practices from the top
down to the trading floor, with the false assumption that there is only one way to look
at a particular risk.
The text box below provides an example of how financial institutions report their operational
risks. This edited extract shows the scope of operational risk, but also illustrates that financial
institutions (FIs) face exactly the same range of operational risks as non-FIs. The key
difference is that FIs are required to quantify their operational risk, so that capital can be
278
allocated to fund this risk.
Scope of Operational Risk:
The group risk department defines and establishes insurance, market and operational
risk assessment processes for the business. It conducts second line reviews, including
reserving processes and capital modeling, and conducts regular reviews of all risks in
conjunction with management, with the results of these reviews recorded in the risk register.
Listed below are the key operational risks Admiral has identified through its ERM framework:
•
People risk:
o Failing to recruit, develop and retain suitable talent.
•
Process risk:
o Process failure or related control failure.
•
Technology risk:
o Failed to invest in, and successfully implement, appropriate technology.
•
Cyber risks:
o Financial loss, data loss, business interruption or reputational damage due to IT
system failure.
•
Customer yield risk:
o Failure of a product, process or service to meet customer and regulator
expectations.
PROJECT RISK MANAGEMENT
31.1 INTRODUCTION TO RISK MANAGEMENT PROJECT:
Projects will be undertaken by organizations for a number of reasons. When a change
in strategy is being planned, a project (work program) or series of projects will often be
required to implement the revised strategy. Also, improvements to core operational processes
will require changes to be implemented by undertaking a project. The selection of projects
and work programs determines the organization's tactics for strategy implementation. It is
important to distinguish between project risk management, which is about delivering projects
on time, within budget and quality, and the reason why projects are undertaken. Project risk
management is concerned about the risks embedded in project delivery. There are also project
279
risks and whether the project is properly allocated funds. Project risks can be identified by
asking whether: 1) the full benefits of the project will actually be delivered; and 2) this
particular project represents the best tactic for delivering the strategy.
The 2012 London Olympics is an example of a major project being delivered on time,
on budget and to quality. Whether staging the Olympic Games in London in 2012 was the
right decision and whether the legacy of the Olympic buildings and other infrastructure will
be handed over is a much broader issue. These questions can only be answered with reference
to the overall strategic plan for the City of London and the UK economy, and addressing the
question of whether staging the Olympic Games in London in 2012 was the right tactic to
deliver the overall strategy for the City of London.
Project risk management should be seen as an extension of conventional project
planning. A key requirement for any project is that it is delivered on time, within budget and
to specification or performance. Risk is often defined in terms of uncertainty or deviation
from expected/required outcomes. In relation to project risk management, the definition of
risk represented by uncertainty is the most relevant. In project management, variability of
outcomes is highly undesirable. Therefore, the focus of risk management in projects is often
on reducing outcome variability and managing control risks.
There will be uncertainties in every project related to events, conditions, and
circumstances. The requirement of project risk management is to identify events that may give
rise to uncertainty and respond to those events appropriately. The risk management style most
relevant to project risk management is control management. In addition to managing risks and
uncertainties in a project, project managers must also look for opportunities that may arise
when certain developments in the project are more favorable than expected. Project risk
management must take these positive developments into account and ensure that the structure
for managing risks in the project is flexible enough for opportunities to be recognized and
benefits to be reaped obtained. For example, consider a new road construction project where
one of the bridges can be completed ahead of schedule due to favorable ground conditions.
There may be opportunities to leverage this early completion into future project plans, so that
this advantage is not lost in the overall timescale for delivery of the final completed project.
For a project as large as the Olympic building, soil conditions and the level of soil
contamination are important variables that can have a major impact on time and cost.
31.2 RISK MANAGEMENT DEVELOPMENT PROJECT:
Project risk management is a type of control management. Projects may relate to the
delivery of a limited, specific or tactical, new development or process improvement:
280
•
Construction;
•
Products;
•
IT systems;
•
Technology;
•
Market.
Projects and upgrades are fundamentally important for organizations. Most projects are
undertaken to stay ahead of competitors or to catch up with them. In the context of risk
management, the project itself can be considered a risk reduction exercise designed to achieve
specific management objectives. The sole purpose in spending money on business
improvement projects is to achieve business benefits or value for money. Project risk
management is a well-developed discipline, with risk control and (especially) event
management as the most important risk management activities. Project risk management is
one of the more sophisticated and successful areas for the application of risk management
tools and techniques.
A requirement for all projects is that they are delivered within the parameters of
specified cost, time and quality. Quality is the relationship between specification and
performance. Some projects require results that conform to certain specifications, such as a
new floor in a restaurant that must be constructed of a certain material. Other projects may
require a desired level of performance, such as determining a floor's level of slip resistance.
Sometimes, both specification and performance will be required. Due to the nature of the
project, historical loss data is usually not available. Therefore, project risk management needs
to be forward-looking to anticipate issues before they arise.
Compliance risks, control risks and opportunities need to be considered as part of the
successful management of any project. There are risks associated with failing to obtain the
necessary permits and approvals (compliance risk). There are risks to the project that could
prevent it from being delivered on time and within budget (hazard risk). There are risks to the
project regarding the specification, performance, and quality of the end result (control risk).
Finally, there are risks that could improve project execution, such as earlier than expected
availability of materials (opportunity risks).
31.3 UNCERTAINTY IN PROJECTS:
To manage uncertainty in projects, organizations have a range of possible actions they
can take. Organizations may decide to respond in one of the following ways:
•
accept risk or uncertainty;
281
•
adapting activities and procedures;
•
adopt emergency plans and responses;
•
avoid risk or uncertainty.
For low exposure/low uncertainty risks, the organization (or project) will usually accept the
uncertainty inherent in each risk. For high exposure/low uncertainty risks, the organization
will adjust activities and procedures and introduce controls, including (when necessary)
insurance. For low exposure/high uncertainty risks, the organization will adopt appropriate
contingency plans and for high exposure/high uncertainty risks, the organization will avoid
the uncertainty inherent in the risk.
Figure 31.1 illustrates the use of a risk matrix to plot the various possible risks to the
project. The matrix plots possible time delays that could result in potential cost increases
associated with that event. This diagram will help the project manager identify whether the
risk fits into the comfort, caution, worry, or critical zones. The other variables shown in the
diagram are equal to the likelihood of each event occurring, and this is indicated by the size of
the bubble used to represent that risk.
The delivery of the Olympic Games in London in 2012 required the largest
construction project undertaken in London during the second half of the first decade of the
2000s. During construction, the global financial crisis emerged and the financial structure for
project delivery had to be renegotiated. Although this was a major concern, it was
successfully resolved. Figure 31.1 identifies adverse ground conditions as a possible cause for
concern in any construction project. In the case of the 2012 Olympics, the construction of the
Olympic village got a boost in terms of time and cost because the soil turned out to be less
contaminated than expected.
Figure 31.2 represents the risk management process in project management as a bow
tie. In this use of the bow tie, the sources of risk are shown as initiation, planning, execution
and closure. At the center of the bow-tie is the uncertainty associated with the project, as
uncertainty management is at the core of project risk management. The purpose of this bow-
tie representation is to illustrate that controls can be introduced to reduce uncertainty at the
center of the bow-tie, manage emerging uncertainty, and introduce further controls to limit the
impact of that uncertainty on quality, cost, time and compliance.
Project Risk Register:
A risk register or risk matrix should be populated and updated regularly throughout the
duration of the project. Risk management software tools can often be a cost-effective way to
282
maintain your risk register as they can reduce manual workload and help prioritize risk
management activities. Once risks are identified and a planto reduce themput in place, it is
very important to review them regularly. The internal and external project environment is
constantly changing. Some risks will disappear, others will emerge that were never envisioned
in the first place.
Therefore, the risk register should be kept up to date and reports generated on a
regular and periodic basis. Management reports should provide clear visibility of the risks
faced, enable prioritization of activities and facilitate decision-making.
31.4 PROJECT LIFE CYCLE:
Project risk management has become one of the most developed and respected
branches of risk management. This is not surprising given the dynamic and stressful
environment in which many projects are conducted. Projects can range from the
implementation of a new software package on a computer system to the construction and
commissioning of a substantial new sports stadium or the organization of the Olympic Games
in London (2012). Whatever the size of the project, a certain number of stages will always be
present. Figure 31.3 illustrates the key stages in the project life cycle. An important additional
feature of project risk assessment is that the client's requirements should always be the most
important. The client may be outside the organization, but is sometimes part of the same
organization.
Figure 31.3 sets out the project life cycle as having four stages. These are project
inception, project planning, project execution and project closure. The activities within each
of these four stages are listed in the figure. It is important to understand the stages in the
project life cycle, so that risk management inputs into each stage can be planned and executed,
and the necessary benefits obtained. The risk management process applied to project
management is similar to the standard risk management process discussed in Chapter 6.
However, the framework supporting the risk management process in each case may be very
different, due to the dynamic nature of projects. Each stage of the project lifecycle will have
significant risks and uncertainty issues embedded within it. The uncertainties embedded in
each project stage will include issues such as defining the project precisely, agreeing
timescales and budgets, and confirming performance/specifications. There will also need to be
arrangements for changes and developments in the project specification, as well as
arrangements for any deviations from the expected state.
283
Figure 31.4 illustrates how uncertainty reduces during the various stages of a project.
Uncertainty can be associated with cost, time and quality. The problem identified by Figure
31.4 is that as the project develops, the cost of making any changes increases. It is easier and
cheaper to change specifications before any work begins than in the later stages of the project.
The fact that Amendments and changes are more costly as the project progresses reinforcing
the need for risk management throughout the project, to increase the likelihood of the project
being delivered on time, on budget, and of quality.
Many organizations include a fourth variable in what is known as the project triangle.
This uncertainty may relate to the scope of the project, the effectiveness of the tactics that
gave rise to the project or the ability of the project to meet stakeholder expectations.
Stakeholders will almost certainly include regulators and compliance is often added as a
fourth output of the project that must be successfully delivered. Sustainability is also used by
some organizations as an alternative fourth output of a project. A simple approach is to
include compliance and sustainability as part of the third output of quality, specification or
performance.
Take for example renovating a block of flats. There will be many interested parties,
including architects and main contractors. External agencies will also need to be involved,
including planning, building regulation requirements, health and safety, environmental
protection and utilities. Successful management of this type of project will require the
following:
•
make risk management part of the project;
•
identify risks at the beginning of the project;
•
communicating about risk;
•
considering threats and opportunities;
•
clarify ownership issues;
•
prioritizing risks;
•
analyze risks;
•
plan and implement risk responses;
•
register project risks;
•
risk tracking and related tasks.
31.5 OPPORTUNITIES IN PROJECTS:
Projects are undertaken because they represent opportunities to be embraced or
284
challenges that need to be overcome. Often a number of projects need to be undertaken at the
same time. This kind of collection of projects is referred to as a program. Good project
planning requires arrangements to cope with unforeseen events or circumstances. These are
often referred to as contingencies in budgets or timescales. Contingencies may be for
additional time to complete tasks, or additional costs that may be incurred to ensure that the
end result of the project operates to the required specifications. As the project develops, any
perceived difficulties need to be addressed and opportunities to reduce the impact of these
difficulties explored. Very often, project specifications will change during the course of the
work. A good risk-managed project will take the opportunity to change the specification to
provide a level of risk mitigation greater customer satisfaction, as well as greater levels of
revenue for the organization implementing the project.
The main opportunity offered by the implementation of a project is that it is
It will prove to be the right tactic to deliver strategic objectives. In some organizations,
projects are only allowed if they reduce the risks that the organization faces. This is especially
true in energy companies, where the justification for undertaking a project is to increase
output, efficiency or quality of operations. This in turn reduces the risks associated with
reduced output, wasted resources and poor quality. In addition to achieving the opportunities
offered by undertaking projects, organizations also want to take advantage of the opportunities
offered in projects. These opportunities can reduce costs, reduce time and/or improve quality.
For example, if a construction project assumes a certain level of soil contamination but this
proves to be less than expected, there will be an opportunity for the project to be completed
ahead of schedule and at a lower cost. Some construction project contracts will include a
clause to share the benefits if circumstances arise.
In many established cities, there are archaeological remains that may have
considerable historical value, if discovered during the excavation phase of the project. When
carrying out construction work to replace buildings in old cities around the world, it is
possible that construction companies will come across such archaeological remains. A prudent
construction company will plan for this possibility and incorporate the consequences into the
project plan. Possible time delays caused by the discovery of archaeological remains can be
incorporated into the project schedule, and the increased costs associated with these delays
can be covered by archaeological insurance, if available at a cost-effective price.
31.6 RISK ANALYSIS AND MANAGEMENT PROJECT:
The Association for Project Management (APM) developed the Project Risk Analysis
and Management (PRAM) Guide in the mid-1990s. The key considerations supporting the
285
PRAM approach are presented in Table 31.1. Perhaps one of the most important points made
is that there is often no historical experience specific to a project that allows accurate
prediction of the impact of risk-based events. The PRAM Guide provides steps for project risk
management that are broadly consistent with the steps outlined above.
The PRAM approach represents an ongoing set of activities that can be initiated at
almost any stage in the life cycle of a project. There are five points in a project where certain
benefits can be achieved from using the PRAM model:
•
Feasibility: at this stage the project is most flexible, allowing changes to be made that
can reduce risk at a relatively low cost.
•
Sanctions: clients can view the risk exposures associated with the project and check
whether all steps to mitigate/manage the risks have been taken.
•
Tender: the contractor can ensure that all risks have been identified and that risk
contingencies or risk exposure limits have been set.
•
Post-tender: the client can ensure that all risks have been identified by the contractor
and assess the likelihood of the program being achieved.
•
During implementation: The likelihood of completing the project within the cost and
time scale will increase if all risks are properly identified and managed.
The text box below provides further comments and suggestions on the importance of risk
management in projects. Some important characteristics of risk management in projects, as
well as some ways to achieve success are discussed.
Risk Management Embedded in Projects:
Embedding risk management in project management leads some to consider that it is
just another project management technique or that its use is optional and only appropriate for
large, complex, or innovative projects. This attitude often results in risk management being
applied without full commitment or attention, and is often responsible for the failure of risk
management to deliver benefits. To be fully effective, risk management must be closely
integrated into the overall project management process. It should not be seen as optional, or
applied sporadically only on specific projects. Risk management should be built into project
management and not seen as a bolt-on. Built-in risk management has two main characteristics:
•
First, project management decisions are made with an understanding of the risks
involved. This understanding covers a wide range of project management activities,
including scope definition, pricing/budgeting, value management, scheduling,
resourcing, cost estimation, quality management, change control, and post-project
286
review.
•
Second, the risk management process must be integrated with other project
management processes. This process must not only use risk data, but there must also
be a seamless interface across process boundaries. This has implications for the project
approach and infrastructure, as well as project procedures.
SUPPLY CHAIN MANAGEMENT
32.1 THE IMPORTANCE OF THE SUPPLY CHAIN :
ISO 28000:2007 'Specification for Security Management Systems for Supply Chains'
provides the following definition of a supply chain:
A supply chain is a series of interconnected processes and resources that begin with the
sourcing of raw materials and end with the delivery of products and services to end users.
Supply chains can include manufacturers, suppliers, producers, distributors, wholesalers,
vendors, and logistics providers. They include facilities, factories, offices, warehouses, and
branches and can be internal or external to the organization.
Many organizations outsource a large portion of their operations and support services.
This can range from the use of contract cleaners to transportation, communication and
manufacturing outsourcing. Many leading suppliers of fashion goods design products and
supply finished goods through franchised retail stores. All manufacturing and distribution
activities are often outsourced to third-party providers in different parts of the world. Due to
these developments, supply chain management has become very important. Managing supply
chains in an increasingly globalized and competitive world can be very challenging.
Uncertainty in supply and demand, market globalization, shorter product life cycles, and rapid
technological change have led to higher risk exposure in the supply chain. The Japan
earthquake in March 2011 caused considerable disruption to the supply of components for
Toyota cars built in Japan.
Toyota has reportedly reviewed its supply chain management to ensure that it is
prepared for future incidents. A Toyota executive vice president commented:
We are conducting checks to see what needs to be done to enable recovery within two weeks
of the next earthquake coming.
287
All kinds of uncertainties can cause problems in the supply chain and this has
increased the importance of risk management. It is impossible to eliminate risk completely,
but adequate attention to risk management issues can reduce the likelihood and magnitude of
any disruption to supply. Due to trends As the demand for components and finished goods
continues to lead to greater use of overseas manufacturing facilities, corporate social
responsibility issues are also likely to increase.
Take for example a sports club that decides to outsource the procurement of
merchandise sold to fans of the club. Fans' expectations are that the merchandise will be
desirable, available, distinctive and of appropriate quality, and will represent value for money.
The club itself will require that the merchandise be of appropriate quality and high
availability, desirable, profitable, and ethically sourced. Risks associated with the supply
chain and risks of managing conflicting stakeholder expectations will need to be assessed.
Conflicting stakeholder requirements on value for money and profitability have led
clubs to take the decision that merchandise should be purchased from low-cost manufacturers,
perhaps based in countries with lower labor costs. However, the club may also have decided
that it will not purchase directly from the manufacturer, but will use a third-party procurement
agent. The requirements then placed on the procurement agent will include goods of
appropriate quality and obtained at the lowest cost available from ethical suppliers.
There are many risks associated with the actions that the club has decided to take.
There could be quality and availability issues that could cause dissatisfaction among fans and
result in a drop in sales. There is also the question of corporate social responsibility that needs
to be addressed. It is likely that the decision to use a third-party importer will mitigate these
issues, as the importer should be in a better position to set and monitor corporate social
responsibility standards.
The essence of the supply chain for many organizations is that they have moved from
a 'lowest risk at any cost' to a 'lowest cost at any risk' situation. In reality, both hazards and
opportunities need to be managed. In other words, the potential downsides of outsourcing
need to be identified and mitigated with the same level of diligence as the assumed benefits of
outsourcing.
32.2 SUPPLY CHAIN COVERAGE:
Due to the increasing use of outsourcing, there is an increasing interest in the risks
associated with dependence on third parties. Outsourcing of operations is usually done
because it is assumed that costs can be reduced and risks transferred. A careful evaluation of
the balance between risk and reward should be made before a supply chain outsourcing
288
decision is taken. Organizations should be aware of the fact that outsourcing means that the
organization must not only focus on its own risks but must also look at the risks associated
with other relationships in the supply chain. Supply chain management and risk management
are intertwined. Supply chain considerations are becoming more common, as well as much
more complex.
Outsourcing the various components of an organization's infrastructure is only part of
supply chain management. Successful supply chain management will depend on strategic
partnerships and may also extend to joint venture arrangements. Supply chain issues also
extend to simple outsourcing decisions, such as the appointment of cleaners and caterers.
There was a strong trend in the 1980s towards outsourcing various types of in-building
facilities management. In short, the scope of supply chain can extend to strategic partnerships,
joint ventures, support services and outsourcing of facility management activities. Many
organizations also choose to outsource the transportation component of their business. It is not
unusual for retail store chains to outsource the warehousing and delivery arrangements of
goods to their respective stores. The operation of the store itself can also be outsourced
through franchise agreements.
The box below is a summary of supply chain considerations that affected Nike in the
mid-2000s. The company took action to address the ethical sourcing issues that had been
raised. To protect its reputation, Nike took swift and decisive action in response to critical
reports.
Nike Supply Chain:
Nike has said that it has faced numerous issues with manufacturing in China, with
suppliers providing fake documents, underage labor and unpaid wages topping the list. The
sneaker and sportswear manufacturer, in what is believed to be the first country-specific
supply chain report, said that the company has been trying to get Chinese suppliers to follow
Chinese codes of conduct and laws. It is reported that the company's difficulties are a
reflection of the depth of some of the problems faced by the manufacturing business in China,
which is reportedly Nike's largest single supplying country, with about 180 manufacturers and
about 1,500 suppliers.
210,000 employees, at a time when prices are rising. and the legal environment is becoming
rigid.
The report, posted on Nike's website, said: "As China continues to evolve, we see
progress and best practices emerging. But like our partners in other countries, the factories we
contract with in China also continue to face challenges. According to the report, the company
289
faced several labor-related issues, including falsification of payroll records (particularly age
details), hiring practices and the absence of a proper grievance system for workers.
There are frequent references to the upstream supply chain and the downstream supply
chain. In general, upstream supply is the goods that are delivered to you and downstream
supply chain refers to the goods that you are subsequently delivered. This can be explained as
a timber grading company located by the river waiting for a shipment of timber from
upstream. The company grades the wood and then delivers the graded wood downstream to
the customer. However, this terminology is not universally used and can lead to confusion. It
may be better to think of the goods delivered to you by your suppliers as the supply chain and
the goods supplied or delivered by you to customers as the delivery chain. Whatever
terminology is used, most organizations receive goods and services from component suppliers
or outsourced service providers. Organizations need to assess the risks associated with their
various suppliers, and consider the risks arising from their position as suppliers of products
and services provided to their own customers and clients.
32.3 STRATEGIC PARTNERSHIPS:
When setting up arrangements to outsource parts of its operations, an organization
needs to consider very carefully the selection of each strategic partner. For example, the
production of an internal magazine will be outsourced by many organizations. Depending on
the importance of this magazine, an organization may want to establish a strategic partnership
with a publisher. Supply chain risk management becomes more important when production
activities are involved. When a supermarket makes arrangements for the supply of
manufactured goods, there are many considerations. The ability of the supply chain partner to
deliver the required goods on time and within agreed costs on an ongoing basis will be a key
consideration.
In order to secure exclusive supply, supermarkets may wish to establish strategic
partnerships with their suppliers. This strategic partnership will see the supermarket receive
priority treatment in the event of potential supply disruptions. The benefit to the supermarket
of this arrangement is that continuity of supply is assured and costs will be reduced. For the
supplier, the benefits are a secure market for its goods and long-term contracts. The
disadvantage for the supplier is that prices may be fixed, although the supplier may obtain
better prices on the open market over time. There is a further disadvantage that the supplier
may be dependent on orders from only one customer.
With an increased focus on cost and the use of 'just in time' delivery, a single supplier
arrangement can increase the risk of business interruption. While organizations want to limit
290
potential losses by purchasing insurance, traditional insurance is unlikely to adequately
protect the organization's reputation and market share under these circumstances. Therefore,
organizations need to look at business continuity strategies and develop strategic partnerships.
These issues explain why greater emphasis is being placed on organizational 'resilience' and
this emerging topic is discussed further in Chapter 9. Strategic partnerships are very useful
alliances formed for the benefit of stakeholders. They can sometimes involve two competitors
working together. A good example of this type of partnership is described in the text box
below.
The importance of strategic alliances:
When International SOS and Control Risks joined forces in 2008 to tackle some of the
biggest emergencies on the planet, they proved a centuries-old adage: 'two heads, indeed, are
better than one'. The partnership resulted in a joint risk mitigation service providing travel
security and medical assistance to clients worldwide. Specialist implementation unit offers
security training advanced, risk forecasting and emergency support worldwide; relief centers
and regional aviation units provide evacuation services in 150 countries.
Risk Control has a vision for medical safety as well as safety for the former
patriots, and we saw SOS as competition in our new territory. We had clients seeking
emergency medical support and estate planning from the same association, so we looked at
partnership options and approached SOS, who had clients seeking a similar combination of
services. We decided not to give it a separate name and identity: this is SOS Risk/Control
International.
32.4 JOINT ENTERPRISES:
Securing priority status from suppliers can be part of an organization's arrangement to
secure its supply chain. However, for highly critical components or support operations,
priority status may not be sufficient. Therefore, many organizations are exploring the
possibility of setting up joint ventures with their suppliers to ensure priority supply status.
Setting up a joint venture also allows the organization to have some management control over
the supplier's operations and eliminates the possibility that the supplier will ship goods to a
competitor in difficult market conditions. A joint venture arrangement can also be an
appropriate way to respond to competitor activity by denying competitors access to products
produced by joint venture partners. Joint ventures can also be a successful way to respond to
technological changes in the market, as the organization does not need to seek all the funds
necessary to embrace new technologies.
291
This kind of competition and technological change in the supply chain may be very
significant. In fact, it may be beyond the resources of existing organizations operating in the
market to respond to these changes. Joint-venture operations can ensure supply chain
continuity and also, if executed correctly, provide a competitive advantage. All of this can be
achieved while putting less capital at risk. An organization may have a strategic goal of
reducing its dependence on suppliers. Tactical options will be available, including taking over
the supplier or setting up a new organization together with your supplier as a separate joint
venture organization. Setting up a joint venture organization will put the organization into a
situation where more risks are under their direct control. Setting up such a joint venture may
be an appropriate tactical choice, as it will require less capital and/or fewer resources to be
allocated than would be the case if the supplier was purchased outright.
The advantage of a joint venture is that risks are shared. This is usually shared by
contractual agreement or by the establishment of a separate company with an agreed
allocation of capital to fund that company. Since the capital is shared, the risks involved with
the venture will be shared and, thus, the benefits and rewards will be shared. A joint venture is
a mechanism through which an organization can leverage benefits but with lower risk
exposure. This would be a suitable way for organizations that do not have the desire to fully
fund the venture.
32.5 OUTSOURCING OPERATIONS:
There are many benefits associated with outsourcing component manufacturing to
specialist sub-contractors. However, organizations that decide to outsource component
manufacturing need to be aware of the risks and introduce appropriate controls. Outsourcing
(or moving) component manufacturing does not completely transfer the risks associated with
the activity. As with risk transfer, appropriate contracts need to be developed and
implemented and these contracts should provide clarity on where risk is allocated within the
contract. Such contracts will likely include penalty clauses for failure to perform, but contracts
that also include provisions to reward outstanding performance provide a greater sense of
cooperation. Table 32.1 identifies examples of risks associated with outsourcing for an
automobile manufacturer.
Outsourcing non-core operations may also give rise to supply chain exposures. Table
32.2 sets out a list of considerations when contracting for the provision of outsourced support.
It is important that organizations consider the scope of the outsourcing arrangement and the
range of services to be provided. Various other features of the outsourcing agreement need to
be addressed.
292
In many countries, there are laws that cover employee protection when operations are
outsourced. For example, if an organization decides to transfer catering or cleaning services to
an outsourcing company, the employment rights of staff previously employed by the
organization may be protected. This can be a significant barrier to outsourcing certain facility
management and other activities and thus obtaining the cost reductions that would result.
Outsourcing operations is usually considered as a mechanism to have non-core activities
performed by contractors. For example, an office-based business may decide to outsource
cleaning and catering, as well as other facility management operations. The benefits will
usually focus on cost reduction while, at the same time, receiving a greater level of expertise
from the outsourcing contract.
The box below considers some of the benefits of outsourcing. Outsourcing is often
done to save costs, but it can also be done so that work can be done by specialist companies.
For example, mortgage lenders may outsource property surveys to companies with greater
resources and more expertise.
Benefits of outsourcing:
Most businesses outsource certain functions, but it is a big decision and the benefits
may be difficult to determine. Outsourcing can cut costs by reducing overheads and having
professionals perform operations. Although these benefits can be achieved, it should not be
the only reason a company decides to outsource.
The benefits of outsourcing can be divided into two types. First, there are the direct
benefits of having a specialist company perform the outsourced activities. Then, there are the
indirect benefits of providing greater focus on the core activities that remain in-house. The
direct benefits of outsourcing are reduced costs, decreased cycle times and improved customer
perception and satisfaction, including:
•
focus on core competencies;
•
reduction in manufacturing costs and logistics services;
•
reduction in the number of worker heads and hourly management;
•
improved accuracy;
•
flexibility and a wider range of services;
•
access to global networks and superior technology;
•
service and quality improvement;
•
capital investment decreases and cash flow increases.
293
32.6 RISK AND CONTRACT :
Risk management is definitely an important component when creating a supply chain
contract or deciding to outsource certain activities. The need for a detailed contract between
the organization and the outsourced service supplier is clear from the factors of considered in
Table 32.2. The nature and complexity of the contract will depend on at least the following
factors:
•
the level of risk associated with the contracted services;
•
contract value for the provision of goods or services;
•
duration and scope of the contract;
•
the level of skill required in delivering the contracted service;
•
critical nature of the contracted goods or services.
The desire to achieve greater value for money and reduce costs has resulted in complex supply
chains that are much more fragmented than was previously the case. Many organizations will
contract out key parts of their activities, so that money can be saved and higher levels of
specialist expertise are available from outsourcing companies. Outsourcing also allows
organizations to focus on their own operations and core competencies. However, this has
resulted in complex global supply chains that are more vulnerable to potential disruptions
through external sources such as terrorism, pandemics and natural disasters. Organizations
need to conduct a thorough risk assessment of their supply chains and outsourcing
arrangements to ensure that the risks associated with these contracted services are adequately
managed. Remember that contracting out the supply of goods or services does not transfer all
risks. The scope of factors to consider are discussed in the text box on the next page.
Outsourcing arrangements should be introduced only if they offer a cost-effective and
efficient way of doing business. Outsourcing decisions based on the belief that risks are fully
transferred to a third party may prove to be incorrect. Reputational damage may still be
suffered if the outsourced manufacturing activity produces substandard goods or is revealed
as carrying out unethical business practices. For example, an organization that decides to
undertake manufacturing in a lower cost region may find that the goods produced do not fully
meet safety requirements. There are examples of toys manufactured in one part of the world
that are illegal in the country where they are sold because they use lead-based paint.
It is possible that the cost of supply will be reduced, but the risk is actually
may increase. When contracting out services and supplies, an organization needs to be assured
that the risks associated with these transfers are within its risk appetite and consistent with the
organization's risk attitude, as well as within its risk capacity. Finally, an evaluation should be
294
conducted to determine the actual risk exposure associated with increasingly complex supply
chain arrangements. Insurance may be available for incidents occurring at supplier sites.
However, the arrangements are usually such that physical damage such as fire, flood or
earthquake must occur at the supplier's location. In these circumstances, policy extensions
may be available for property damage insurance purchased by the organization. Incidents such
as poor component quality, late delivery or supplier bankruptcy are generally not insurable.
Motor Industry Supply Chain:
The automotive supply chain is as complex as it gets. There are about 20,000 parts in a
car, and if just one of those parts is not available, the finished product cannot be shipped.
Automotive manufacturers need to re-evaluate risk mitigation strategies to deal with
large-scale disruptions to their supply chains. There are a number of avenues open to them,
including:
•
challenge suppliers to develop disaster plans so that they can make provisions to move
to alternative production sites, if they are unable to manufacture products at their main
factory;
•
eliminate single-source suppliers and develop additional enterprise capabilities; having
one supplier may be too few, but having five suppliers is too many in terms of
achieving economies of scale;
•
analyze supplier locations and limit the number of critical component suppliers
geographically located in risk areas;
•
review insurance policies and consider whether to take out contingent business
interruption insurance that protects against losses relating to a supplier's inability to
deliver.
Students also viewed