1 / 27100%
26
SCOPE OF RISK MANAGEMENT
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 2
4.1 ORIGINS OF RISK MANAGEMENT :
Risk management has various origins and is practiced by various professionals. One of
the early developments in risk management emerged in the United States from the insurance
management function. The practice of risk management became more widespread and better
coordinated as the cost of insurance in the 1950s became prohibitive and the scope of
coverage limited. Organizations realized that buying insurance was not enough if there was
not adequate attention to the protection of property and people. Therefore, insurance buyers
became concerned with the quality of property protection, health and safety standards, product
liability issues, and other risk control issues.
This combined approach to risk financing and risk control was developed in Europe
during the 1970s and the concept of total cost of risk became important. As this approach
became established, it also became clear that there were many risks facing organizations that
were not insurable. Risk management tools and techniques were then applied to other
disciplines, as discussed later in this chapter.
Taking Calculated Risks:
Risk management is not about controlling/reducing existing risks. If the business is to
run, management must learn to take more risks and accept failure. To perform better than
others, you must take greater risks, but they must be calculated risks (accepted risks are
known, as are their likelihood and impact). It is not acceptable to take risks unwittingly - the
past practice of a silo-based approach to managing pockets of risk, led to unclear
responsibilities and lack of visibility, thus exposing the organization to unnecessary risks.
The maturity of the risk management discipline is now such that the link with
insurance has become less strong. Insurance is now seen as one risk control technique, but it
only applies to a subset of hazard risks. Risks associated with financial, commercial, market
and reputational issues are recognized as being of great importance, but outside the historical
scope of insurance. The range of different approaches to risk management is illustrated by the
definitions of risk management as listed in Table 4.1.
27
Risk management is a set of activities within an organization undertaken to
deliver the most profitable outcomes and reduce the volatility or variability of
those outcomes.
Providing an appropriate definition of risk management is as difficult as providing an
appropriate and universally accepted definition of risk. Since it is generally accepted that risk
management should address hazards, uncertainties and opportunities, descriptions and
definitions are needed that reflect the broad scope of risk management activities. The
following definitions are offered by the authors:
The growing importance of risk management can be explained by the list of issues
presented in Table 4.2. Many of these issues indicate that the application of risk management
has moved far from its origins in the insurance world. Nevertheless, the insurance origins of
risk management remain very important and are still part of the hazard management approach.
This chapter considers the nature of risk management and the defined stages that make up the
risk management process. Historically, the term risk management has been used to describe
an approach applied only to hazard risk. The discipline is now evolving in a way that allows
risk management to contribute to the improved management of control risks and opportunity
risks.
4.2 RISK MANAGEMENT DEVELOPMENT:
Risk management as a formal discipline has been around for at least 100 years. It has
early origins in the activities of insurance specialists, who can trace its history back over
several centuries. As insurance became more formalized and structured, the need for risk
control standards increased, particularly in relation to the insurance of cargo transported by
ships around the world. Perhaps one of the earliest developments in this area was the
introduction of the 'Plimsoll Line' to indicate the level of cargo that a ship could safely carry
without dangerous overloading.
As risk management grew, educational programs emerged to support the development
of risk management as a profession. It was at this time that risk management regulations
related to corporate governance began to evolve and various regulators were given more
authority related to specific hazards (such as health and safety), and also related to specific
business sectors (such as health and safety financial institutions). The development of risk
management qualifications became increasingly formalized during the 1980s.
Development of risk management education and qualifications, as well as approaches
28
More structured regulators led to the emergence of risk management standards. The AS/NZS
4360:1995 risk management standard is one of the early examples of a comprehensive
approach to risk management. In addition to generic risk management standards that apply to
all industries, specialized risk management approaches have also emerged in certain sectors,
including the financial sector. The emergence of regulated capital requirements for banks and
insurance companies indicates the higher level of risk management maturity required of
financial institutions.
The role of enterprise risk management in the United States during the 1950s became
an extension of insurance purchasing decisions. During the 1960s, contingency planning
became more important to organizations. There is also an emphasis beyond risk financing on
loss prevention and safety management. During the 1970s, self-insurance and risk retention
practices were developed in organizations. Captive insurance companies also began to
develop. Contingency plans then evolved into business continuity planning and disaster
recovery plans.
At the same time during the 1960s and 1970s, there were many developments in risk
management approaches adopted by occupational health and safety practitioners. During the
1980s, the application of risk management techniques to project management expanded
substantially. Financial institutions continued to develop the application of risk management
tools and techniques for market risk and credit risk during the 1980s. During the 1990s,
financial institutions further expanded their risk management initiatives to include structured
consideration of operational risk.
Also, during the 1980s, treasury departments began to develop a financial approach to
risk management. There was recognition from finance directors that insurance risk
management and financial risk management policies should be better coordinated. During the
1990s, risk financing products emerged that combined insurance with derivatives. At the same
time, corporate governance and listing requirements prompted directors to place more
emphasis on enterprise risk management (ERM) and the first appointment of a chief risk
officer (CRO) occurred at that time.
During the 2000s, financial services companies have been encouraged to develop
internal risk management systems and capital models. There has been rapid growth of CRO
positions in energy companies, banks, and insurance companies. Boards are now investing
more time in ERM due to the Sarbanes-Oxley Act of 2002 in the United States. More detailed
risk reporting and other corporate governance requirements have also been introduced.
However, the financial crisis of 2008 called into question the contribution that risk
management can make to corporate success, especially in financial institutions. There is no
29
doubt that the application of risk management tools and techniques failed to prevent the global
financial crisis. This failure was a failure to properly implement risk management processes
and procedures, not an inherent flaw in the risk management approach.
4.3 SPECIALIST FIELD OF MANAGEMENT RISK:
Risk management is a constantly evolving and growing discipline. As well as
originating in the insurance industry and other branches of hazard management, risk
management has strong links with credit and treasury functions. Many functions within large
organizations will have a significant risk management component to their activities, such as
tax, treasury, human resources, procurement and logistics. However, it is unlikely that
specialists in those areas will consider their activities as simply a branch of the risk
management discipline.
Perhaps one of the most well-known and specialized areas of risk management is
workplace health and safety. Other specialist areas are disaster recovery planning and
business continuity planning. Also, there is no doubt that quality management is a very well-
developed branch of risk management, given the high profile attached to quality management
systems, such as ISO 9000. In addition, other specialist areas of risk management have
developed over the past few decades, including:
Project risk management;
Clinical/medical risk management;
Energy risk management;
Financial risk management;
IT risk management.
All of the above specialist areas of risk management have made major contributions to the
development and application of risk management tools and techniques. Project risk
management is an area where the application of risk management tools and techniques is
particularly well developed. As discussed earlier, project risk management has an emphasis on
managing uncertainty or control risks.
Clinical risk management has been evolving for some time. This area of risk
management is mainly concerned with patient care, especially during surgical operations. The
cost of medical malpractice claims and the inevitable delays in making insurance payments
have resulted in the introduction of risk management systems. A particular aspect of clinical
risk management includes greater attention to making patients aware of the risks that may be
associated with the procedures they are about to undergo.
30
It is also important that surgeons report incidents that occur during surgery.
Considerable emphasis has been placed in clinical risk management on the need to report,
accurately and in a timely manner, details of any incidents that occur in the operating room.
There are many publications available on clinical risk management, and much work has been
done to establish the systems and procedures required to cover this specialist area of risk
management. In addition to project and clinical risk management, risk management tools and
techniques have also been applied across a range of specialist industries. In particular, risk
management techniques have been applied in the financial and energy sectors. Risk
management in the financial sector focuses on operational risk, as well as market, credit and
other types of financial risk. In the financial sector, the title of Chief Risk Officer was first
developed.
The energy sector is also experiencing increased attention being paid to risk
management tools and techniques. For some organizations in the energy sector, risk
management is primarily concerned with future energy prices and with exploration risks. The
approach to risk management is therefore similar to the activities of the treasury function,
where hedging and other sophisticated financial techniques form the basis of risk management
efforts. Financial risk management has gained a high profile in recent times, and Chapter 30
considers the importance of operational risk management within the financial sector.
However, risk management in the financial sector is broader than just operational risk. Banks
and other financial institutions will be concerned with credit risk and market risk, as well as
operational risk. Finance and insurance are highly regulated business sectors, governed by
international standards such as Basel III and Solvency II.
IT risk management is another well-developed and specific branch of risk
management. The growing importance of information to organizations, in terms of data
management and security, has resulted in the development of specific standards that apply to
IT risk management. Among the most established of these risk management standards is
COBIT, which is similar in many ways to the COSO standard discussed in Chapter 6.
4.4 A SIMPLE REPRESENTATION OF RISK MANAGEMENT :
Risk management has well-established stages that make up the risk management
process, as described in Table 4.3. These stages build valuable risk management activities,
each of which makes an important contribution. There are many ways to represent the risk
management process, and each of the standards mentioned in Chapter 6 provides a slightly
different description.
Figure 4.1 provides a simple diagrammatic representation of the risk management
31
process. This basic description of the risk management process is referred to as the 8Rs and
4Ts of hazard risk management. The activities associated with risk management are as
follows:
risk recognition;
risk rating;
ranking against risk criteria;
respond to significant risks;
resource control;
reaction (and event) planning;
risk performance reporting;
review the risk management system.
Risk management can improve the management of an organization's core processes by
ensuring that key dependencies are analyzed, monitored, and reviewed. Risk management
tools and techniques will assist in the management of hazard risks, control risks, and
opportunity risks that may affect these key dependencies.
Organizations should ensure that the risk management process is repeated as often as
necessary, to overcome the difficulty of static snapshots of the status of risks facing the
organization. This will ensure that risk management remains a dynamic activity.
4.5 RISK MANAGEMENT COMPANY:
Another area where the risk management discipline has evolved in recent times is the
approach referred to as enterprise-wide risk management (ERM). This approach to risk
management is discussed in more detail in Chapter 8. The key feature that distinguishes ERM
from what might be considered more traditional risk management is the more integrated or
holistic approach taken in ERM. In many ways, this can be considered a unifying philosophy
that brings together the management of all types of risk, rather than a new or different
approach. When an organization considers all the risks it faces and how these risks may affect
its strategies, projects, and operations, it embarks on an enterprise risk management approach.
The US risk management association, Risk and Insurance Managers Society (RIMS) defines
enterprise risk management as follows:
32
Enterprise Risk Management ('ERM') is a strategic business discipline that
supports the achievement of an organization's objectives by addressing its full
spectrum of risks and managing the combined impact of those risks as a portfolio
of interrelated risks.
ERM in the Pharmaceutical Industry
A good example of the ERM approach is the pharmaceutical industry. If someone is
dependent on a certain drug, then it is very important that it is always available. From the
pharmaceutical company's point of view, this means that the core process of the organization
should be a process of 'constant availability of medicine'. If a pharmaceutical company takes
this approach, it will look at risks that could affect this core process or the expectations of
stakeholders across the company. This will involve supply chain analysis, evaluation of
manufacturing activities and analysis of delivery arrangements. The overall question that
needs to be answered is what could prevent a continuous supply of drugs. Risks to continuous
supply will include unavailability of materials, disruption to manufacturing activities, product
contamination, disruption in supply transportation arrangements, and disruption to
distribution.
An enterprise-wide approach has considerable advantages, as it analyzes potential
disruptions to overall stakeholder expectations. Health and safety, for example, is then seen as
a component in ensuring that staff are always available so that the overall core operational
processes will not be disrupted, rather than (or perhaps even) a separate hazard management
issue.
4.6 RISK MANAGEMENT SOPHISTICATION LEVEL:
This chapter describes the various styles of risk management currently practiced. More
professions and disciplines are now involved in risk management than in previous years. This
adds diversity to the development of the risk management discipline. An organization not only
needs to be sophisticated in its risk management approaches and expectations, but also mature
in how it conducts risk management activities. The importance of risk maturity is considered
in Chapter 24. Initially, an organization may not be aware of the legal and contractual
obligations it faces. In this case, it is necessary to inform the organization of its obligations
with respect to risk. As the level of sophistication develops, the organization will realize the
need to comply with obligations and the more general need for better risk management.
After realizing the obligation, there will be a need for the organization to reform in
response to the risk of harm. As the organization responds to risks, it will seek to conform to
33
appropriate risk control standards.
After this stage, the organization may realize that there are benefits to be gained from
the risk. The organization will then have the ability to perform and view the risk as an
opportunity risk, as illustrated in Figure 4.2. As a simple example, a publisher may realize that
it is not fully compliant with equal opportunity legislation, as there is no ethnic minority
representation in the workforce. The company will identify the necessary actions to reform its
procedures, so that they comply with legal requirements. Upon achieving compliance, the
issuer should recognize that a significant portion of the workforce comes from diverse ethnic
backgrounds. The company should see this diversity in its workforce as a benefit that will
enable it to perform better in the market by exploring opportunities to produce and publish
new magazines that appeal to a more ethnically diverse readership.
The stage of reform to match performance is the level of sophistication of risk
management. However, risks or risk management practices need not evolve from hazard to
control to opportunity. In fact, risks can regress under certain circumstances. At any one time,
a particular risk will be a particular type in an organization. Benefits can be derived from the
successful management of that risk at whatever level of sophistication is appropriate at the
time. In short, risk management only needs to be as sophisticated as the organization needs it
to be to bring benefits. Although the four levels of risk management sophistication illustrated
in Figure 4.2 represent an enhanced approach to risk management, there is a danger that
organizations will become obsessed with risk management to the point that important
decisions are not taken.
At this point, it can be said that too much care and concern about risk and risk
management will cause the organization to change its form of operation. To summarize:
unaware of obligations - INFORM;
awareness of non-compliance - REFORM;
actions to ensure compliance - CONFORM;
achieve business opportunities - PERFORM;
inactivity caused by obsession - DEFORM.
Most countries in the world have a wide variety of voluntary and charitable organizations. It is
understandable and very appropriate that directors or trustees of these organizations should
have a high level of care and awareness when it comes to risk management. However, it is
often reported that trustees are more concerned with risk management and proper governance
than raising funds for the charities they support. Allowing this concern with risk management
to cripple the activities of the organization would be detrimental to the good cause that the
34
charity supports.
As the level of sophistication increases and risk management professionals become
aware of alternative approaches to risk management, they should appreciate the contributions
that other approaches can make. The development of risk management approaches can be
summarized as follows:
Compliance management should not be fragmented, even if excellent compliance
standards have been achieved.
Hazard management specialists may find that there is a trend towards wanting to retain
more insurable risks (and buy less insurance) as a result of a more holistic approach to
risk management.
Control management specialists should not squeeze entrepreneurial spirit and effort
out of the organization.
Strategic planners should recognize that risk management tools and techniques can
contribute to better strategic decisions and successful exploitation of business
opportunities.
The approach to improving risk management sophistication described in this section is also
considered in Chapter 24 using the 4Ns. An alternative approach to increasing the level of risk
management sophistication or risk management maturity is the fragmented, organized,
influential, leading (FOIL) approach which is also discussed in more detail in Chapter 24.
PRINCIPLES AND OBJECTIVES OF RISK MANAGEMENT
5.1 RISK MANAGEMENT PRINCIPLES:
The main principle of risk management is to provide value to the organization. In
other words, risk management activities are designed to achieve the best possible outcomes
and reduce the volatility or uncertainty of outcomes. However, risk management operates on a
broader set of principles, and there have been several attempts to define these principles. ISO
31000 includes a detailed list of suggested risk management principles.
Many of the lists of principles outline descriptions of what risk management activities
should be and what should be achieved. It is important to distinguish between the risk
management initiatives that have been set out to achieve and the nature of the risk
management framework to be implemented. It is suggested that successful risk management
initiatives (and frameworks) are:
proportional to the level of risk in the organization;
35
aligned with other business activities;
comprehensive, systematic and structured;
embedded in business procedures and protocols;
dynamic, iterative and responsive to change.
It provides the acronym PACED and provides an excellent set of principles that are the
foundation of a successful approach to risk management in any organization. A more detailed
description of the PACED principles of risk management is presented in Table 5.1. The risk
management approach is based on the idea that risk is something that can be identified and
controlled.
The above statement of principles relates to the essential features of risk management.
These principles describe what risk management should look like in practice. Some lists of
principles also include information on what risk management should do or deliver. It is
important to separate risk management principles into two different lists: what should
characterize risk management, as listed above; and what should be delivered, as listed below:
obligations must be placed on the organization;
assurance regarding the management of significant risks;
decisions that take full account of risk considerations;
effective and efficient core process.
If organizations are to gain maximum benefit from their risk management activities,
the above principles should be applied when risk management initiatives are planned and risk
management frameworks are developed. In many ways, the starting point for all risk
management activities is deciding what the organization wants to achieve. Table 5.2 sets out
possible objectives or motivations for risk management initiatives as liability, assurance,
decision-making and effective and efficient core processes (MADE2). Core processes
represent organizational activities and can be strategic, tactical, operational or compliance
(STOC).
The objectives for risk management provide the acronym MADE2 and this asserts that
the output of risk management will lead to less disruption to normal efficient operations,
reduced uncertainty in relation to tactics and better decisions in relation to the evaluation and
selection of alternative strategies. In other words, an important part of risk management is the
improvement of organizational decision-making. The resources available to manage risk are
limited so the aim is to achieve an optimal response to risk, prioritized according to the risk
evaluation. Risks are unavoidable and every organization needs to take action to manage them
in a justifiable manner to an acceptable level. The appropriate range of responses will depend
36
on the nature, size and complexity of the organization and the risks it faces.
5.2 THE IMPORTANCE OF RISK MANAGEMENT :
Table 4.2 provides a number of examples that illustrate the importance of risk
management. Risk management has taken on an increasingly high profile in recent times, due
to the global financial crisis and the number of high-profile corporate failures around the
world that preceded it. In addition, risk management has become more important due to rising
stakeholder expectations and the increasing ease of communication. In addition to aiding
better decision-making and increased efficiency, risk management can also contribute to the
provision of greater assurance to stakeholders. This assurance has two important components.
The director of any organization must be confident that risks have been identified and
appropriate steps have been taken to manage the risks to an appropriate level.
Also, there is a greater emphasis on accurate information reporting by organizations,
including risk information. Stakeholders require detailed information on company
performance, including risk awareness. The Sarbanes-Oxley Act of 2002 (SOX) in the United
States has financial reporting accuracy as its main requirement. It brings the issue of accurate
reporting of results to a higher priority (section 404), while also requiring complete and
accurate disclosure of all information about the organization (section 302). Although SOX is a
specialized law that only applies in certain circumstances, the principles it contains are
essential for all risk management practitioners. Therefore, Chapters 35 and 36 consider risk
assurance and accurate reporting as integral components of the overall risk management
process.
When deciding on the importance of risk management in the organization, the design
of risk management initiatives and risk management frameworks should reflect the rationale
for risk management in the organization, in relation to MADE2. This decision needs to be
made with an eye on the risk management drivers for the particular organization. Drivers may
relate to specific considerations within MADE2, such as the effectiveness and efficiency of
core operational processes. Some organizations have appointed loss control managers with
specific responsibility for reducing the frequency and cost of accidents to people and damage
to plant and equipment. Sometimes, initiatives will be based on a desire to enhance the
organization's reputation by improving compliance with applicable rules and regulations, or
the ability to demonstrate more ethical behaviour - including in the supply chain.
5.3 RISK MANAGEMENT ACTIVITIES:
Risk management is a process that can be divided into stages. The IRM Risk
37
Management Standard provides one representation of the stages involved in the risk
management process. Alternative illustrations of the risk management process can be found in
the ISO 31000 International Standard and other publications. These standards are discussed in
Figure 4.1 illustrates the stages in the (hazard) risk management process. The terminology
used to describe the stages in the risk management process is deliberately chosen, so that the
process can be represented as the 8Rs and 4Ts of hazard risk management. Table 4.3 provides
more information about each of the stages illustrated in Figure 4.1.
ISO Guide 73 and British Standard BS 31100 describe the risk management process as
the systematic application of management policies, procedures, and practices to the tasks of
communicating, consulting, setting the context, identifying, analyzing, evaluating, treating,
monitoring, and reviewing risks. However, it could be argued that the establishment of
policies, procedures, and practices, along with the tasks of communicating, consulting, and
establishing that context, are actually part of the risk management framework, rather than the
risk management process itself. In this book, the risk management process is considered a
narrow set of activities, described above as identifying, analyzing, evaluating, addressing,
monitoring, and reviewing risks. This provides a clear distinction between the risk
management process and the framework that implements and supports this process. A
description of the risk management process along with the risk management framework is
required to produce a comprehensive risk management standard.
There has been much discussion about whether a single risk management process
and/or diagram can be used to describe the management of compliance risk, hazard risk,
control risk, and opportunity risk. This book uses different terminology to describe the four
types of risk and, therefore, Figure 4.1 and Table 4.3 are used to illustrate the stages in the
hazard risk management process only. There are a number of options when responding to
hazard risks. These are often represented as the 4Ts of hazard risk management, and these risk
response options are considered in more detail in Chapter 15.
In short, the options for responding to hazard risk are:
tolerate;
treat;
removal;
end.
5.4 EFFECTIVE AND EFFICIENT CORE PROCESSES :
Insurable risks or hazards can have a direct impact on operations. Therefore, the initial
38
application of risk management principles was to ensure efficient continuity of normal
operations. As risk management has evolved, emphasis has been placed on project
management and program delivery to deliver improvements to core business processes.
Processes must be effective because they deliver the required results, as well as efficient. For
example, there is limited value in having an efficient software program if it does not deliver
the full range of required functions. Strategic decisions are the most important that
organizations have to make. Risk management provides better information so that strategic
decisions can be made with more confidence. The strategy decided by an organization must
be able to deliver the required results. There are many examples of organizations that chose
the wrong strategy or failed to implement the chosen strategy successfully. Many of these
organizations experienced corporate failure. Strategic decisions are often most difficult when
changes in technology or customer expectations arise, as is often the case with grocery stores.
The box below provides an example of an adult grocery business that attempted to introduce a
new strategy that failed; the company was taken over shortly thereafter.
Strategies should be designed to capitalize on opportunities. For example, a sports
club may identify the possibility of selling more products to its existing customer base. Some
clubs will set up travel agencies for club fans traveling abroad, along with the provision of
related travel insurance. Also, there is the possibility of creating a club credit card that would
be managed by a new financial subsidiary. Having identified these possibilities, clubs need to
look at the risks associated with these potential investment opportunities and devise a suitable
project program to implement the chosen strategy. Ensuring that adequate account is taken of
the risks during all these activities will increase the chances of choosing the right strategy,
designing the right tactics and, ultimately, ensuring efficient and profitable operations. It
should be noted that projects and work programs represent the tactics with which strategies
are implemented.
Organizations that have effective and efficient tactics, operations, and compliance, but
the wrong overall strategy will fail. This will happen, no matter how good the risk
management activities are at the operational and project levels. The wrong strategy has
resulted in more corporate failures than ineffective or inefficient operations and tactics.
Nevertheless, the importance of compliance activities cannot be overemphasized, as
demonstrated by the text box below from The Rank Group Plc's Annual Report and Financial
Statements.
Importance of Compliance:
The loss of a license could adversely affect our business and profitability and prevent
39
us from providing gambling services. Rank's gaming license is critical to its operations. In the
UK part of the business, there is a requirement to hold an operator's license from the UK
Gambling Commission (the body responsible for regulating commercial gambling in Great
Britain) in respect of each licensed activity carried out. In addition, it is necessary to hold a
premises license from the relevant local authority where each premises is located, one for
gambling activities and one for the sale of alcohol. Rank has a dedicated compliance function
independent of operations and a separate internal audit function independent of both
operations and the compliance function. Rank maintains strong and open relationships with
the UK Gambling Commission and other relevant regulatory bodies in all jurisdictions in
which we operate.
5.5 IMPLEMENTING RISK MANAGEMENT :
In a rapidly evolving discipline like risk management, there is room for different
practitioners to be intolerant of the approaches adopted by others. Internal control specialists
who believe that risk management is about managing uncertainty and achieving corporate
objectives should not become intolerant of more traditional insurance risk management
approaches. There is no value in one group of specialists ignoring the approaches adopted by
others and being unwilling to utilize the expertise available in other groups.
After all, no one risk management style or risk management approach offers all the
answers. Clearly, the various styles that can be adopted should operate as complementary
approaches within an organization. An integrative approach to risk management accepts that
organizations must tolerate certain risks of harm and must have an appropriate appetite for
investment in risks of opportunity. Risk management tools and techniques should be used to
achieve the following:
compliance management provides risk governance;
hazard management makes the results less negative;
control management reduces the range of possible outcomes;
opportunity management makes the outcome more positive.
Hazard management will make the outcome of any hazard event less negative. In the context
of hazard management, insurance is a mechanism to limit the financial cost of losses when
risks materialize. Risk control and loss management techniques will reduce expected losses
and should ensure that overall costs are contained. The combination of insurance and risk
control/loss management will reduce the actual cost of hazard losses and this should (and
does) cause the organization's hazard tolerance to decrease. More organizational risk capacity
40
will be available for opportunity investment.
Control management reduces the range of possible outcomes of any event. Control
management is based on established internal financial control techniques, such as those
performed by internal auditors. The main objective is to reduce the losses associated with
inadequate control management at the same time as reducing the range of possible outcomes.
It is the contribution that internal control should make to the overall approach to risk
management within an organization. Opportunity management seeks to make positive
outcomes more likely and more substantial. As part of the opportunity management approach,
organizations should also look at the possibility of increasing revenue from products or
services. In non-profit organizations, opportunity management should facilitate the delivery of
better value for money.
5.6 REACH BENEFITS:
Options for increasing these rewards could be discussed at strategy meetings and
several options could be adopted, including the introduction of bonus and incentive schemes
for staff and management. Obviously, taking lessons from the global financial crisis, these
incentive schemes can be should be balanced and should not reward excessive risk-taking.
This chapter has considered risk management principles that explain what risk management
should be and what it should deliver. Although organizations may recognize that there are
benefits from implementing risk management, successful implementation should be
undertaken as an initiative or project. Appendix C sets out a detailed consideration of the
stages involved in successful enterprise-wide risk management.
The most important point to make is that support from senior management and
(ideally) sponsorship from board members is essential. Also, an implementation plan to
address employee and other stakeholder concerns is required. Although risk management is
critical to the success of an organization, many managers may need to be convinced that the
suggested implementation approach is correct. It is important to note that not all activities and
functions performed by managers should be claimed by risk managers as being performed on
behalf of risk management. Not all activities in an organization will be driven by risk
management, even if all decisions, processes, procedures and activities have risk embedded in
them.
Risk Management is Not Just Brakes:
There is a popular question among risk managers: 'why do cars have brakes?' The
answer offered is that brakes allow cars to go faster. This implies that risk management
41
should be seen as a brake on an organization's activities. This is a completely negative view
that presents risk management in an unfavorable light.
Risk management is also the driver of operations, tactics, and strategy. Therefore, it is
worth revisiting the question above. To continue the metaphor, risk management should, in
fact, be seen as all three pedals in a car. Risk management as a brake reduces operational
hazards and helps organizations avoid distractions, thereby improving operational efficiency.
The clutch pedal relates to changing gears in a car in the same way that projects
implement tactics in an organization. Therefore, risk management is also a clutch pedal as it
helps aid the successful management of tactical change and the reduction of associated
uncertainty, so that the organization can achieve successful change. Finally, the accelerator
helps the car go faster and risk management fulfills this function by helping organizations
embrace strategic opportunities and seek rewards - thereby ensuring that organizations design
and successfully implement strategies that deliver what is needed.
A large part of this book deals with risk management inputs in operations.
It is likely that operations will be affected by hazard risks and therefore the focus of risk
management in relation to operations is on hazard management. To achieve maximum benefit
from risk management input in operations, organizations need to focus on loss control. Loss
control is a combination of loss prevention, damage limitation and cost control. Projects must
be completed on time, within budget and specification, performance or quality. Inevitably,
there will be a large amount of uncertainty associated with all projects. The contribution of
risk management is to minimize this uncertainty. Risk management in projects is a
management style of control.
Risk management's input into strategy focuses on assessing the risks of the various
strategic options available to an organization. Risk management's contribution to a successful
strategy is, therefore, focused on decision-making activities. Figure 15.2 illustrates the 4Es of
opportunity management and plots risk exposure against potential rewards. Organizations that
conduct strategic risk management will complete a careful review of viable new business
prospects and conduct detailed risk assessments before making strategic decisions.
The overall benefits of risk management can be summarized in several ways. By
undertaking risk management initiatives, less disruption to operations, successful project
delivery, and better strategic decisions are the expectations. Also underlying risk management
initiatives is the desire for adequate risk assurance. These components - mandatory, assurance,
effective and efficient decision-making and core processes - provide the acronym MADE2.
By using the FIRM risk scorecard structure, the organization will be able to
demonstrate the benefits it derives from its risk management initiatives. It is possible that the
42
following benefits have been delivered to theaters that have been pursuing a structured
proactive enterprise risk management approach for about three years:
financial benefits arising from better allocation of funds, monitoring of expenses and
reduced exposure to fraud;
infrastructure benefits that include fewer IT system failures and reduced staff
absenteeism;
reputational benefits from ethical sourcing policies and the use of organic food in
restaurants, as well as successful niche productions in theaters;
market benefits resulted in an occupancy rate of 89 percent, up from 83 percent three
years ago, as well as increased in-theater spending by customers.
The theater will continue to develop its risk management initiatives and continue to acquire
Benefits. Risk management activities are now embedded in the management culture of the
organization.
MANAGEMENT APPROACH
Learning Outcomes Part Two:
Describe the key stages in the risk management process and the main components of
the risk management framework;
State the main features of the most established standards, including iso 31000, coso
erm cube, and irm standard;
Explains the scope and importance of establishing context as the first stage in the risk
management process;
Explain the importance of the relationship between external context, internal context
and risk management context;
Discuss key considerations when designing a risk register and the benefits associated
with using a well-designed risk register and provide examples;
Describes the features of an enterprise-wide approach to risk management and the
various erm definitions available;
Outline the steps required to achieve successful implementation of enterprise risk
management initiatives;
Considering the changing face of risk management and the growing importance of
managing emerging risks.
43
Case Study:
United Utilities: Our risk management framework
We have developed a sophisticated approach to risk assessment, management and
reporting, with processes aligned to ISO 31000:2009 and established governance structures
for the group board to review the nature and extent of risks facing the group and for the audit
committee to review the effectiveness of processes.
Our current risk profile describes around 200 event-based risks. All event types
(strategic, financial, operational, compliance and hazard) are considered in the context of our
strategic themes (best service to customers; lowest sustainable cost; and responsible manner).
For internal or external drivers, each event is assessed for the likelihood of occurrence and the
negative financial or reputational impact on the company and its objectives, should the event
occur.
Responsibility for risk assessment and management (including monitoring and
updating) is assigned to appropriate individual managers who are also responsible for
reporting on assessment, management and control/mitigation at least twice a year, in line with
reporting to the group board at full and half year statutory accounting reporting periods. By
their nature, event-based risks in the context of our strategic themes will include all
combinations of high to low likelihood and high to low impact. Heat maps are typically used
in various reports managerial and group either as a method to collectively evaluate the extent
of all risks within a given profile or to illustrate the effectiveness of mitigation for a single risk
by plotting the gross, current (net of existing controls) and selected target positions within
individual risk statements.
Birmingham City Council: Oversight, accountability and risk management:
The board has had a risk management strategy in place since July 2002, and this is
updated regularly. Leadership is provided for the risk management process by the director of
legal and democratic services, who is a corporate governance champion and the deputy leader
who is designated as a member corporate governance champion.
The Board has approached embedding risk management in accordance with best
practice guidance as a 'top-down' process, with the corporate risk register supported by
directorate and divisional risk registers. Birmingham Audit continues to deliver presentations,
provide training, facilitate workshops and provide guidance through the publication of risk
management toolkits that have been produced to give managers at all levels a better
understanding of how to implement risk management in their areas of responsibility and have
some understanding of the City Council's top down process.
44
The toolkit provides a step-by-step approach to implementing risk management using
the Board's methodology. The high-level risk management methodology has been reviewed to
provide more focus to members and senior risk management officers. The Council's
whistleblowing policy was introduced in the late 1990s and is well publicized throughout the
workforce. The City Council has a strong internal audit function (Birmingham Audit) and
established protocols for working with external audit. The Council's external auditors have a
responsibility under the Code of Audit Practice to review compliance with policies,
procedures, laws and regulations within their remit.
Tsogo Sun: Risk management process:
The Tsogo Sun board recognizes that business risk management is critical to our
continued growth and success and this can only be achieved if all three elements of risk -
threats, uncertainties and opportunities - are recognized and managed in an integrated manner.
The audit and risk committee is mandated by the board to establish, coordinate and drive risk
processes across the group. It has overseen the establishment of a comprehensive risk
management system to identify and manage significant risks across operational divisions,
business units and subsidiaries.
The system of internal control is designed to manage rather than eliminate risk, and
provides reasonable but not absolute assurance of the integrity and reliability of financial
statements, compliance with laws and regulations, and to safeguard and maintain
accountability of the group's assets. In addition to the risk management processes embedded
within the group, the group executive committee identifies, quantifies and evaluates the
group's risks twice a year using facilitated risk assessment workshops. Risk severity is
measured qualitatively as well as quantitatively, guided by the board's risk tolerance and risk
appetite measures.
The risk profile, with risk responses, is reviewed by the audit and risk committee at
least once every six months. In addition to group risk assessments, risk matrices are prepared
and presented to the audit and risk committees for each operating division. This methodology
ensures that risks and opportunities are prioritized and cost-effective responses are designed
and implemented to counter the effects of risks and capitalize on opportunities.
45
RISK MANAGEMENT STANDARD
6.1 SCOPE OF RISK MANAGEMENT STANDARD
There are a number of established risk management standards and frameworks. The
first was developed by a standards body in Australia in 1995, and has been followed by those
developed in Canada, Japan, the United Kingdom and the United States. Standards have also
been developed by other national standards bodies, as well as by government departments
around the world. The overall approach of each of these standards is similar. The standard that
had the widest recognition was Australian Standard AS 4360 (2004), but this was withdrawn
in 2009 in favor of ISO 31000. The ERM version of the COSO standard is also widely applied
in many organizations. British Standard BS 31100:2011 'Risk Management: Code of Practice
and Guidance for the Implementation of BS ISO 31000' was published in 2011. Further
guidance to the ISO standard was published in 2013 as ISO/TR 31004:2013 'Risk
Management - Guidance for the Implementation of ISO 31000'.
The international standard ISO 31000 (2009), 'Risk Management: Principles and
Guidelines', was published in late 2009. Although some standards are better known than
others, organizations should choose the approach that is most relevant to their particular
circumstances. It is important to distinguish between risk management standards and risk
management frameworks. Risk management standards set out an overall approach to
successful risk management, including a description of the risk management process, along
with a suggested framework that supports that process. In simple terms, a risk management
standard is a combination of a description of the risk management process, along with a
recommended framework. The key features of a risk management framework are described
later in this chapter. Table 6.1 provides a summary of the most widely used risk management
standards and frameworks.
One of the most established and most widely used risk management standards was
produced by IRM in 2002 in collaboration with Airmic and Alarm. The IRM standards are a
high-level approach aimed at non-risk management specialists and have been translated into
many languages. The Australian standards and COSO standards/frameworks are designed to
be used primarily by specialist risk management practitioners. The IRM Standards are
available as a free download from the IRM website, and the risk management process used in
them is reproduced in Figure 6.1.
For organizations listed on the New York Stock Exchange, the approach outlined in
the COSO Internal Control framework originally published in 1992 and updated in 2013 is
recognized by the Sarbanes-Oxley Act of 2002 (SOX). SOX requirements also apply to
46
subsidiaries of US-listed companies around the world. Therefore, the COSO approach is
internationally recognized and, in many circumstances, mandated. It should be noted that
SOX requires the approach described in the COSO Internal Control framework (2013). (This
is not the same as the COSO ERM (2004) framework, although the COSO ERM framework
contains all the elements of the recently revised version of Internal Control.)
For many stock exchanges, the greater emphasis in the listing requirements and
associated corporate governance codes is on internal control, rather than risk management.
This emphasis was retained in the 2010 version of the Combined Code, which has now been
renamed the UK Corporate Governance Code, although the 2010 version includes some
enhanced specific risk management requirements. Sections of the 2010 version of the UK
Corporate Governance Code have been updated and the latest version of the UK Corporate
Governance Code is dated April 2016. The COSO Internal Control Framework has become
the most widely used internal control framework in the United States and has been adapted
and/or adopted by many countries and businesses around the world. The enterprise risk
management (ERM) version of the COSO framework was produced in 2004 and this has both
risk management and internal control in its scope.
In addition to the UK, ISO and COSO standards, a number of other standards are also
well regarded and widely used. The Financial Reporting Council's (FRC) UK risk guidance
was updated in 2014 and is considered by the Securities and Exchange Commission (SEC) in
the United States as an acceptable alternative to the COSO Internal Control framework for
Sarbanes-Oxley compliance. The updated risk guide can be found as a free download from the
UK-based FRC website.
In addition to established standards and frameworks, a large amount of guidance on
risk management has been published by various government departments. HM Treasury in the
UK has published the highly regarded Orange Book, which contains a large amount of useful
information on risk management tools and techniques. Many of the ideas and concepts
presented in the Orange Book are referenced throughout this volume.
Some of the available standards were developed by risk management professionals,
while others were developed by accountants or auditors. There are three different approaches
followed in the various standards:
The 'Risk Management' approach, followed by ISO 31000, British Standard BS 31100
and the IRM Standard;
The 'Internal Control' Approach, Developed By The COSO Internal Control
Framework And By The FRC Risk Guide;
The 'Risk-Aware Culture' Approach, Developed By Canadian Institute Of
47
Chartered Accountants, Known as the Coco Framework.
6.2 RISK MANAGEMENT PROCESS:
A simple representation of the risk management process is provided by Fig.
4.1 and similar processes are contained in all established risk management standards. Many
standards distinguish between risk management processes and the frameworks that implement
and support those processes. However, this distinction is not always clear in many established
risk management standards/frameworks. The best approaches to risk management are the IRM
Standard, ISO 31000, BS 31100, and the COSO ERM framework. All four provide
descriptions of risk management frameworks, but more emphasis is placed on risk
management processes in the IRM Standard, ISO 31000 and BS 31100. The COSO approach
does not provide the same clear distinction between the framework and the risk management
process itself and is mainly concerned with framework considerations.
Some countries have developed their own internal control and risk management
standards as part of their requirements to be listed on a stock exchange. Typically, these are
frameworks that are similar to COSO Internal Control in approach, and this is certainly the
case with the current FRC risk guidance requirements that exist in the UK. While there are
many ways to represent the risk management process, the basic steps are all similar. There
may be difficulties with the terminology used to describe the various steps, and Appendix B
provides definitions of basic terms, as well as cross-referencing the various terminology that
can be used. Appendix C describes the stages involved in achieving successful risk
management and this is organized in a plan-implement-measure-learn (PIML) format. This is
very similar to the plan-do-check-act format followed in some international standards and is
often referred to as PDCA. PIML is meant to show a more structured and analytical approach.
6.3 RISK MANAGEMENT CONTEXT:
There are many risk management standards and risk management frameworks that
have been produced by various organizations. It is generally recognized that standards are
documents that generate information about risk management processes and risk management
frameworks. In many risk management standards it is stated that risk management activities
should be carried out in the context of the business environment, the organization, and the
risks facing the organization. In order for the context to be described and defined, a
framework is needed to implement and support the risk management process. ISO 31000
places special emphasis on context and states that consideration should be given to the internal
48
context, external context and risk management context when performing risk management
activities.
All established risk management standards refer to the risk management framework,
although this is represented in different ways. To provide a simple explanation of the scope of
the risk management framework, the acronym risk, architecture, strategy and protocol (RASP)
has been developed. Figure 6.2 illustrates the key features of a risk management framework
that builds on and supports the risk management process. The RASP approach is fully
consistent with the concept of a risk management context or risk management framework
described in ISO 31000.
Part Five of this book describes the risk architecture, strategy and protocol (RASP) in
more detail. It is these elements that define the framework within which the risk management
process takes place. These three components of risk architecture, strategy and protocol are
necessary for successful risk management activities. There needs to be a clear understanding
of the risk management process, followed by a clear definition of the framework that supports
the process. As the framework is the structure that supports, it is shown in Figure 6.2 as a
series of components built around and supporting the risk management process.
In order to implement and support the risk management process, a framework of
Risk management work needs to facilitate communication and the flow of risk information.
The risk management framework has two separate considerations. First, it must support the
risk management process and, second, it must ensure that the outputs of the process are
communicated to the organization and achieve the expected benefits for the organization. If an
organization decides to follow the structure of the IRM Risk Management Standard, then it
must establish a framework that includes the components of risk management structure,
responsibility, administration, reporting and communication. All these procedures will then be
recorded in the risk management manual.
6.4 COSO ERM CUBE:
The Enterprise Risk Management (ERM) version of the COSO framework was
produced in 2004 and this has both risk management and internal control in its scope. Details
of the COSO ERM framework are provided on the COSO website and there is a free
download of the COSO ERM executive summary. The COSO ERM approach suggests that
enterprise risk management is not strictly a series of sets of activities, where one component
only affects the next. It is considered an iterative and multi-directional process where almost
any component can and does affect all other components. In the COSO ERM framework,
there is a direct relationship between the objectives, which an entity is trying to achieve, and
49
the enterprise risk management components, which represent what is required to achieve
them. The relationship is depicted in a three-dimensional matrix, in the form of a cube, and
this is reproduced as Figure 6.3.
The COSO ERM cube is a highly influential risk management framework and consists
of eight interrelated components. It is derived from the way management runs the company
and is integrated with management processes. A brief description of the COSO ERM
components is presented in Table 6.2. COSO ERM describes the framework by stating: 'in the
context of the organization's defined mission or vision, management sets strategic objectives,
selects strategies and establishes aligned goals that flow through the enterprise.'
The company's risk management framework is geared towards achieving the
company's objectives, which are defined in four risk categories:
strategic: high-level goals, aligned with and supporting its mission;
operations: effective and efficient use of its resources;
reporting: reliability of reporting;
Compliance: compliance with applicable laws and regulations.
6.5 RM STANDARD FEATURES:
The main risk management standards that have been developed are the IRM Standard,
ISO 31000, British Standard BS 31100 and the COSO ERM framework. British Standard BS
31100:2011, entitled 'Risk Management: Code of Practice and Guidance for the
Implementation of BS ISO 31000', was published in 2011. It emphasizes the requirement for a
risk management framework to support the risk management processes described separately.
Specifically, British Standard BS 31100 states that the risk management process should
provide a systematic, effective and efficient means by which risks can be managed at different
levels throughout the organization.
The risk management framework is described in the British Standard in detail.
In fact, most of the standard consists of a description of the risk management framework,
along with a detailed section on how to develop risk management activities. Part of the reason
for updating the original BS 31100:2008 was to align it more closely with ISO 31000.
Therefore, the diagrams used in BS 31100:2011 are very similar, and in some cases identical,
to those used in ISO 31000.
The International Standards Organization (ISO) published ISO 31000 entitled 'Risk
Management: Principles and Guidelines' in the latter part of 2009. The diagram used to
illustrate the risk management process in ISO 31000 is reproduced in Figure 6.4. It can be said
50
that Figure 6.4 contains the elements of the risk management framework, as well as the key
stages of the risk management process. In addition to developing ISO 31000 and the risk
management terminology guide, Guide 73, work has also been completed on the risk
assessment techniques guide. ISO/IEC 31010 'Risk Management: Risk Assessment
Techniques' is a very comprehensive publication and reflects current good practice in the
selection and utilization of risk assessment techniques.
Standards bodies around the world have a requirement to review standards on a
regular basis, typically every four years. Therefore, existing standards, as well as additional
standards under development, will be reviewed periodically. This will ensure that the advice
and guidance provided in the various standards will remain current and in line with current
practice. In addition to the risk management standards, there are also a number of internal
control standards. These internal control frameworks have a different emphasis and are
beyond the scope of this book, with the exception of the Criteria of Control (CoCo)
framework produced by the Canadian Institute of Chartered Accountants. The approach in the
CoCo standard is discussed briefly below and evaluated in more detail later in this book. The
approach in CoCo is based on evaluating an organization's internal control culture or
environment.
6.6 UPDATE EXISTING STANDARDS:
There is an ongoing desire to keep risk management standards and corporate
governance codes, relevant and up-to-date. Regulators around the world continue to learn
from company failures and from each other. There is also a growing trend for standards
organizations to develop management standards relevant to a wide range of topics risk
management, including business continuity, information security, corporate governance and
compliance management.
The ISO 31000 risk management standard was first published in 2009 and is an
update and refinement of the previous AS/NZS 4360 standard. AS/NZS 4360 was first
published in 1995, and updated in 1999 and 2004. The current ISO 31000 (November 2016) is
undergoing a substantial review and update. Various other standards have also been published
over the past 20 years, including the Project Management Association Project Risk Analysis
and Management (PRAM) and the UK Office of Government Commerce (OGC) Management
of Risk (MoR) guidance.
There is an established format for ISO management standard specifications and this is
51
described in Chapter 9. This format is used for standards that can be used for certification of
organizations, and the most established ISO management standard specification is ISO 9001
on quality management. In general, established risk management standards, including ISO
31000, the IRM standard and the COSO ERM cube, do not adopt the ISO format. Part of the
reason is that the ISO technical committee responsible for ISO 31000 has taken the position
that risk management activities are not suitable for external certification.
The challenge for standards organizations is to ensure that the risk management
standards they publish are relevant to the future success of the organization. As can be seen
from the text box below, COSO has taken the approach, in updating the COSO ERM
framework, that greater consideration should be given to stakeholder expectations and the
relationship between risk and strategy. Specifically, the COSO consultation document
suggests that organizations that integrate enterprise risk management into strategic planning
can gain a range of benefits including:
increase the range of opportunities by considering both positive and negative risk
aspects;
improve performance by identifying and managing risks across the entity;
reduce negative surprises, increaseprofits and profits from favorable developments;
reduce performance variability by taking measures to minimize disturbances;
improve resource deployment and achieve improved resource allocation.
While there are considerable benefits in adopting established risk management standards,
there is no doubt that organizations need to change and adapt the detailed requirements of
existing standards to their particular circumstances and/or external, internal and risk
management contexts. Greater acceptance of the risk management approach within an
organization will be achieved when the approach has been tailored specifically for the
organization by the organization itself. One of the key features of the development of
approaches to risk management is that the plan-implement-measure- learn (PIML) approach is
increasingly being adopted. This is often referred to as plan-do-check-act (PDCA). and is the
basis of the US standard ASIS SPC.1-2009 Organizational Resilience: Security, Preparedness,
and Continuous Management Systems.
COSO seeks public comment:
'Enterprise risk management has evolved significantly since 2004 and stands on the
verge of delivering significant value as organizations pursue value in a complex and uncertain
environment', said Dennis Chesley, PwC's global risk consulting leader and lead partner for
the COSO ERM effort. 'This update more clearly connects enterprise risk management to
52
many stakeholder expectations, establishes the link between risk and strategy, positions risk in
the context of organizational performance, and helps organizations anticipate so they can get
ahead of risk and embrace a resilience mindset.'
Students also viewed