1 / 27100%
53
SETTING THE CONTEXT
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 3
7.1 SCOPE OF CONTEXT:
ISO 31000 states that the first stage in the risk management process is
to establish context. The previous Australian standard AS 4360 refers to
context as having three components, in addition to the risk management
process. These components are risk management context, internal context and
external context. The relationship between the three contexts is illustrated in
Figure 7.1.
The three components of context can be considered as follows:
The risk management context has been described as the risk
architecture, strategy and protocols or risk management framework
within the organization. This framework must fulfill two functions:
1) provide support for the risk management process within the
organization; and 2) ensure that the outputs of the risk
management process are communicated to internal and external
stakeholders.
The internal context refers to the organization itself, the activities it
undertakes, the range of skills and capabilities available within the
organization, and how it is structured. Internal stakeholders and their
expectations are part of the internal context. These can be thought of
as strengths and weaknesses within the organization.
The external context is the environment in which the organization
finds itself. This environment will include consideration of the
business sector in which the organization operates, external
stakeholders and their expectations and the external financial
environment. These can be thought of as the opportunities and threats
facing the organization.
54
The nature and extent of the risk management process is a key consideration
when setting the context for risk management. The key question is what the
risk management process is expected to achieve or the answer to the question
of why the organization has a risk management activity. The context for risk
management also includes considering who will be responsible and
identifying the resources that will be needed to fulfill the risk management
activity.
Another important consideration in the context of risk management is
the establishment of risk appetite or risk criteria. This will help the
organization decide what controls to implement and whether the residual or
current level of risk is acceptable. The risk management context should also
provide a means to establish the overall total risk exposure so that this can be
compared to the organization's risk appetite and the organization's capacity to
withstand risk.
The internal context is about the culture of the organization, the
resources available, receiving outputs from the risk management process and
ensuring that these influence behavior, and supporting and providing risk
governance and risk management. Context Internal context concerns the
organization's goals, capacities and capabilities, and core business processes.
An important consideration regarding the internal context is how the
organization makes decisions. The external context is about stakeholder
expectations, industry regulations and regulators, competitor behavior and the
general economic environment in which the organization operates. The
external context also considers drivers and trends that may affect the success
of the organization and its ability to achieve goals.
7.2 EXTERNAL CONTEXT:
The ISO 31000 risk management standard identifies 'setting the
context' as the first stage in the risk management process. Establishing context
is an important fundamental aspect of successful risk management, and is also
identified by other international standards as an important early stage in
implementing management system standards. For example, the ISO
9001:2015 quality standard also identifies context as part of the strategic
planning that organizations must undertake.
There are three components to setting the context for risk management
55
activities, and these relate to the external context, internal context, and risk
management context. Setting the external context must take into account the
expectations of external stakeholders. The importance of stakeholder
expectations is discussed in more detail in Chapter 29. For many
organizations, the most important external stakeholder group is the customer.
The external context for an organization will be significantly influenced by
the nature of the customers and the products or services offered to them.
Consideration of customers and customer offerings is an important part of the
model. The business case for the organization and the relevance of the
business model to risk management are considered in more detail in Chapter
20.
After identifying the expectations of external stakeholders, including
consideration of customers and the services and products offered to
customers, the organization can then look in more detail at the factors that
influence the external context for the organization. The FIRM risk scorecard
provides a structure for carrying out a detailed evaluation of the organization's
context. The reputation and market components of the FIRM risk scorecard
are primarily related to the external context and the finance and infrastructure
components are primarily related to the internal context.
Table 14.2 provides a detailed list of questions relating to the
development of a risk index based on the FIRM risk scorecard structure. In
summary, the reputation component of the external context for an
organization defines the external perception of the organization and the
customer's desire to trade with the organization and the level of customer
retention. Specifically, when evaluating the reputation component of the
external context, the following issues should be addressed:
public perception of the industry sector in which the organization operates;
corporate social responsibility standards achieved by the organization;
governance standards and whether the sector is highly regulated;
product or service quality and/or after-sales service standards.
Another component of the FIRM risk scorecard that is relevant to the external
environment is the market and the organization's level of presence within the
market. This will impact the level of customer trading or spending. In
particular, when evaluating the market component of the external
56
environment, the following issues should be addressed:
level of income in the market and return on investment;
presence of aggressive competitors and/or high customer expectations;
level of economic stability, including exposure to interest rates and
foreign exchange rates;
supply chain complexity and raw material cost volatility;
exposure to international disruptions due to political risks, war and
terrorism.
The FIRM risk scorecard offers one mechanism for evaluating an
organization's external context, but other structures can be used, such as a
strengths, weaknesses, opportunities and threats (SWOT) analysis or the use
of one of the risk classification systems discussed in Chapter 11. The overall
goal of the external context evaluation is to determine the level of risk
associated with the external environment in which the organization operates.
This will allow the organization to validate the existing business model and
develop strategies for the future, along with tactics to implement those
strategies.
External stakeholders:
Good stewardship by the board should not inhibit sensible risk-taking
that is essential for growth. However, risk assessment as part of the normal
business planning process should support better decision-making, ensure that
the board and management respond promptly to risks when they arise, and
ensure that shareholders and stakeholders are aware of the risks. Other
interests are well informed about key risks and prospects of the company. The
board's responsibility for organizational culture is critical to the manner in
which risks are considered and addressed within the organization and with
external stakeholders.
7.3 INTERNAL CONTEXT:
Establishing the internal context of the organization must take into
account the expectations of internal stakeholders. There will be a variety of
internal stakeholders, but the most important group is the people who are
directly dependent on the organization. This will include staff members and
people who provide services on an outsourced, contracted and/or supplier
57
basis. Having identified the expectations of internal stakeholders, including
the identification of their importance to the organization's operations and
compliance, it is then possible to look in more detail at the factors that
influence the internal context. The FIRM risk scorecard provides a structure
for carrying out a detailed evaluation of the organizational context. The
financial and infrastructure components of the FIRM risk scorecard are
primarily related to the internal context and the reputation and market
components are primarily related to the external context.
Table 14.2 provides a detailed list of questions related to the
development of a risk index based on the FIRM risk scorecard structure. In
summary, the financial component of an organization's internal context
defines financial procedures and the manner in which money is managed and
profitability is achieved. Specifically, when evaluating the financial
component of the internal context, the following issues should be addressed:
availability of adequate funds to fulfill the strategic plan;
there is a robust procedure for the correct allocation of funds for investment;
the nature of the internal financial control environment to prevent fraud;
availability of funds to meet historical and anticipated future
obligations.
Other components of the FIRM risk scorecard relevant to the internal context are
infrastructure, as this affects the nature of the processes performed within the
organization. Infrastructure risks determine the degree of inefficiency and
dysfunction that may arise during internal processes. In particular, when
evaluating infrastructure components from an internal context, the following
issues must be addressed:
senior management structure and the nature of the risk culture;
availability of adequate human resources and human skills, including
intellectual property;
availability of adequate physical assets to support operational activities;
adequate information technology infrastructure to achieve resilience
and protect data;
business continuity plan to ensure continuity of activities after a major
disruption;
arrangements for the provision of services and/or reliable
58
transportation and communication infrastructure.
The FIRM risk scorecard offers one mechanism to evaluate the internal context
organizations, but other approaches can be used, including SWOT analysis.
Many organizations use the political, economic, social, technological, legal
and environmental/ethical (PESTLE) risk classification system. The PESTLE
risk classification system is discussed in more detail in Chapter 2.
11. Some components of the PESTLE risk classification system are related to
the external context, some are related to the internal context and others are
relevant to both the external and internal contexts.
There are many checklists available that will enable an organization to
identify the nature of the external and internal context in which it operates.
Which classification system or list of questions is used is less important than
the need to identify the various risk issues faced by the organization. This will
enable the organization to validate the existing business model, the resources
required to deliver the business model, as well as the level of resilience in the
existing business model.
7.4 RISK MANAGEMENT CONTEXT:
Chapter 21 considers the risk management context in detail, in terms
of the risk architecture, strategies and protocols (RASP) developed by the
organization. The organization's RASP defines the structure of the risk
management context and how the components of that context are implemented
to achieve the desired benefits of enterprise risk management initiatives. It is
important that the risk management context of an organization is able to
provide the necessary risk management strategies and develop the necessary
risk-aware culture. The components of a satisfactory risk-aware culture are
leadership, engagement, learning, accountability, and communication
(LILAC), as discussed in more detail in Chapter 24.
An important component of the risk management context is the
mandate given by senior management that provides the scope and level of
authority to perform risk management activities within the organization. The
mandate given to the risk manager, head of internal audit and others involved
in risk management initiatives should be established in the risk management
policy for the organization. The organization's risk attitude and risk appetite,
as defined by the risk criteria for different types of risks, help define the
59
organization's risk management context and provide the basis for conducting
risk assessments and recording the results in the risk register. The nature and
extent of communication of the information contained in the risk register
across the organization's risk architecture also helps define the risk
management context.
Perhaps the most important feature of the risk management context
that will determine the success of enterprise risk management initiatives
relates to how they are implemented. Appendix C provides an outline of
implementation guidance for enterprise risk management initiatives in terms
of planning, implementing, measuring and learning (PIML). The risk
management context should contribute to the success of the organization and
support the delivery of stakeholder expectations, both external and internal.
The context requirement of risk management is that it must identify emerging
risks and support responses to changes in the external and internal context of
the organization. The nature of emerging risks can be complex and, by
definition, highly unpredictable.
In helping the organization identify the nature of emerging risks, the
risk management context should provide mechanisms to provide early
warning. This has been described as the organization's 'risk radar' and should
include timely review and evaluation of information relating to emerging
risks. To comprehensively determine the specific impacts and consequences
for the organization, the mechanism for identifying emerging risks should also
include provisions for identifying opportunities that can be leveraged in the
future.
In short, organizations are required to identify any specific external,
internal and risk management context issues that may impact the organization,
acquire and evaluate timely knowledge and information about them, evaluate
the risks and opportunities presented by these context factors and take
appropriate actions to mitigate risks and embrace opportunities. All this
should be documented within the scope of the risk architecture, strategies and
protocols (RASP).
7.5 DESIGNING THE RISK REGISTER:
The use of risk registers has become an established practice for many
risk managers. There are disadvantages associated with the use of risk
60
registers, including the danger that the information recorded in risk registers
will not be used dynamically. A risk register can be a static record of risk
status, rather than a risk action plan for the organization. A risk register is
defined in ISO Guide 73 as 'a document used to record the risk management
process for identified risks'. The guide adds that the purpose of the risk
register is to facilitate ownership and management of each risk. Typically, a
risk register will include the significant risks facing an organization or project.
It will record the results of the risk assessment associated with the process,
operation, location, business unit or project under consideration.
When risk assessments are conducted from a strategic option, they are
more commonly used as part of decision-making activities. Typically, this
information will not be recorded in a risk register format, but will be
presented to the decision maker as part of the range of information available
to make that strategic decision. The purpose of the risk register is to form an
agreed record of the significant risks that have been identified. Also, the risk
register will serve as a record of control activities being undertaken. It will
also be a record of additional actions proposed to improve the control of a
particular risk.
Other information about the risk will also be included in the risk
register. While there is no fixed format for this document, Table 7.1 outlines a
basic format for a risk register. It may not be necessary to include all of the
risk description information that is set out in tables in the risk register, as this
can make it a complicated and clunky document. Risk registers can be
compiled in several formats, depending on the type of risk assessment being
recorded. Table 7.2 provides an example of a partially completed risk register
for a sports club and Table 7.3 provides an example of a risk register for a
hospital.
At its simplest, a risk register can be kept as a document stored on a
computer. However, there are many more sophisticated forms of risk registers,
including records of significant risks stored on a database. Where exposure
quantification is required, then a simple risk register kept as a document is
unlikely to be sufficient. This applies to operational risk recording systems,
where quantification of risk exposure is required.
7.6 USING THE RISK REGISTER:
61
A well-constructed and dynamic risk register is at the core of a
successful risk management initiative. However, there is a danger that a risk
register can become a static document that records the status of risk
management activities at any given moment. The practical implication of this
is that senior management may consider that attending risk assessment
workshops and creating risk registers fulfills their risk management
obligations and no ongoing action is required.
It is better to think of the risk register as a risk action plan that records
the status of the organization with respect to risk management, but also
provides a record of the critical controls in place, along with details of any
additional controls that need to be introduced. In producing such a risk action
plan, responsibility for carrying out the identified actions will be clearly
established.
Chapter 26 considers options for the use of a risk management
information system (RMIS) to record the information stored in the risk
register. Also, the information stored in the risk register may be available on
the organization's intranet, and this will help with risk understanding and
communication. In some organizations, the risk register is granted controlled
document status for use by internal audit as one of the key reference
documents for conducting audits of risk management activities.
Even if this is not the case, the information set out in the risk register
should be considered and constructed with great care. For example, the risks
set out in the register need to be precisely defined so that the cause, source,
event, magnitude and impact of each risk event can be clearly identified. In
addition, existing control activities, along with proposed additional controls,
should be described in precise terms and accurately recorded. Risk control
activities must be described in sufficient detail for the control to be auditable.
This is especially important when the risk register relates to routine operations
performed by the organization. Risk registers should also be created for
projects and to support strategic decisions.
The project risk register should be a very dynamic document. An
example of a project risk register is presented in Table 7.4. Details of the risks
facing the project, as recorded in the risk register, should be discussed at each
project review meeting. In addition to the risk register being relevant to the
project, they should also support business decisions. In this case, the exact
62
format of the risk register may be less formal. When strategic decisions are to
be taken at board level, a risk assessment of that strategy should be attached to
the proposal. This risk assessment may include the risks of implementing the
strategy and an analysis of the risks associated with not undertaking the
proposed strategy.
Finally, the risk register should be attached to the business plan as a
record of risks that may impact the achievement of the plan. Table 7.5 shows
a simple, partially completed risk register in a format that can be attached to
the business plan. A simple example of a risk that could result in the business
plan not being achieved is presented in this illustration.
For example, a sports club may wish to record reputational risks in the risk
register. There may be specific concerns regarding the club's reputation, so the
board will require a detailed evaluation of the reputational risks associated
with:
success in the field;
legal compliance;
ethical supply of goods at reasonable prices.
When considering reputational issues, the level of control required will be
evaluated, along with the responsibility for managing the brand. The club will
also ensure that existing controls and additional controls are described in a
way that will ensure that the implementation of controls can be fully audited.
The board may wish to look at the risk register at least quarterly, and more
frequently if significant changes occur. This will ensure that the risk register
remains a dynamic document and is kept fully up to date. It will also ensure
the necessary actions are taken and reported to the board.
ENTERPRISE RISK MANAGEMENT
8.1 COMPANY-WIDE APPROACH
In recent years, there have been important developments in the practice of risk
management. First, specialist branches of risk management have developed, including project,
energy, financial, operational risk and clinical risk management. Second, organizations have
embraced the desire to take a broader approach to risk management practices. Various terms
have been used to describe this broader approach, including holistic, integrated, strategic and
63
enterprise-wide risk management. It is the term enterprise or enterprise-wide risk management
(ERM) that is now the most widely used and generally accepted terminology for this broader
approach. The fundamental idea behind the ERM approach is to move away from practicing
risk management as separate, individual risk management. ERM takes a unifying, broader and
more integrated approach. The ERM approach means that an organization looks at all the
risks it faces across all the operations it performs. ERM is concerned with managing risks that
may impact the organization's objectives, key dependencies, or core processes. Also, ERM is
concerned with managing opportunities, as well as managing control and hazard risks.
There is also consideration of the fact that many risks are interrelated and that
traditional risk management fails to address the relationships between risks. With the ERM
approach, the relationships between risks are identified by the fact that two or more risks can
impact the same activity or objective. The ERM approach is based on looking at an objective,
key dependency or core process and evaluating all risks that could impact the evaluated item.
Organizations practice risk management in several different ways. However, there are
many features common to most of these approaches. Table 8.1 provides an overview of
enterprise risk management features in comparison to silo-based approaches where risk
management tools and techniques are applied to different types of risks independently.
Enterprise risk management has become an established means of conducting risk management
activities in most organizations. It allows the organization to gain an overview of all the risks
it faces so that it can take coordinated action to manage those risks. However, specialist risk
management functions, such as health and safety and business continuity continue to make a
valuable contribution.
An example of an ERM approach is to consider a sports club where the core process is
to maximize attendance at games. This process consists of several activities, including
marketing, advertising, ticket allocation and sales as well as logistical arrangements to ensure
that the gaming experience is as good as possible. Part of maximizing match attendance is to
ensure there are adequate parking and transportation arrangements, along with appropriate
catering and other welfare arrangements at the ground.
By identifying the key activities that deliver the selected core processes, the club can
identify risks that may affect these activities and the core processes. Targets can then be set
for improved attendance at future matches, and responsibility for the success of these core
processes allocated to the club's commercial director. Consideration of opportunities to
improve match attendance can also be included in this broader approach.
8.2 ERM DEFINITION
64
Table 8.2 presents a number of suggested definitions of enterprise risk management.
There are three necessary components in a comprehensive definition of the ERM process.
These are: 1) a description of the processes underlying enterprise risk management; 2)
identification of the outputs of those processes; and 3) the impacts (or benefits) arising from
those outputs. Many definitions concentrate on the process by describing the activities that
make up the ERM approach. This is a good starting point, but the outputs of the ERM process
are not the same of the process is more important than the process itself. Some definitions do
include reference to the output of the process, such as being able to manage risk within the
organization's risk appetite and provide reasonable assurance regarding the achievement of
objectives.
However, to be comprehensive, the definition should also consider the expected
impact of those outputs. In summary, the expected outputs of ERM are that better decisions
will be taken, improved core processes will be identified and introduced, possibly through
tactics that include projects or work programs, and operations will be effective, efficient, and
free from unplanned interruptions. . This list of outputs from enterprise risk management can
be described as mandatory obligations are met, assurance is obtained, decision-making is
improved and effective and efficient core processes are introduced (MADE2).
The following is offered by the author as a comprehensive definition of ERM:
ERM involves the identification and evaluation of significant risks, assignment of
ownership, implementation and monitoring of actions to manage these risks within the
organization's risk appetite.
The output is the provision of information to management to improve business
decisions, reduce uncertainty and provide reasonable assurance regarding the
achievement of organizational objectives.
The impact of ERM is to improve efficiency and service delivery, improve resource
(capital) allocation for business improvement, create shareholder value and improve
risk reporting to stakeholders.
8.3 ERM IN PRACTICE
The evolving role of the risk manager is discussed in Chapter 22. It states that the
seniority of the risk manager should be proportional to the risks the organization faces. For
many organizations, including those in finance and energy, a board-level risk director is often
appropriate. Where appropriate and proportionate, the board-level risk manager is often
referred to as the chief risk officer (CRO). To date, this designation has been almost
65
exclusively in the energy and finance sectors, although this may change as ERM becomes
more clearly established across a wider range of organizations.
CRO seniority is just one example of how ERM should be achieved in practice. The
risk management principles defined as PACED are fully applicable to enterprise risk
management practices. The principles of risk management are that it should be proportionate,
aligned, comprehensive, embedded and dynamic (PACED). By taking a comprehensive
approach to enterprise risk management, various benefits can be provided and these are
presented in Table 8.3. It is for each organization to decide how the enterprise risk
management initiative will be structured and how these benefits will be achieved.
A key feature of ERM is that the various significant risks facing the organization are
evaluated. The linkages between risks must be identified, so that the total risk exposure of the
organization can be compiled. After measuring the organization's total risk exposure, the level
of that risk exposure can then be compared to the board's risk appetite and the organization's
own risk capacity.
8.4 ERM AND BUSINESS CONTINUITY:
There is an important relationship between enterprise risk management (ERM) and
business continuity management (BCM). The risk assessment required as part of the risk
management process and the business impact analysis that forms the basis of business
continuity planning (BCP) are closely linked. This can be seen in Table 8.1, which describes
the features of an enterprise-wide approach.
The normal approach to risk management is to evaluate objectives and identify
individual risks that may affect these objectives. The output of the business impact analysis is
the identification of critical activities that must be maintained for the organization to continue
functioning.
Based on the above definition of ERM and the fact that it must be applied to the
evaluation of core processes, it can be seen that the ERM approach and the business impact
analysis approach are very similar, as both approaches are based on the identification of key
dependencies and functions that must be in place for business continuity and success. The
subsequent activities differ between ERM and BCP, as the former is concerned with the
management of risks that may impact core processes, while business continuity is concerned
with the actions to be taken to maintain the continuity of individual activities. Therefore, the
business continuity approach has a very specific function of identifying the actions to be taken
after a risk has materialized to minimize its impact. BCP deals with damage limitation and
loss control components, as described in Chapter 13.
66
8.5 ERM IN ENERGY AND FINANCE
Risk management in the energy and financial sectors has become a well-developed
discipline. In the financial sector, the goal of ERM initiatives is to increase shareholder value
by:
Improve capital and efficiency by providing an objective basis for allocating resources
and exploiting natural hedges and portfolio effects;
Support financial decision-making by considering areas with high potential adverse
impacts and by capitalizing on areas with risk-based benefits;
Build investor confidence by stabilizing yields and protecting them from disruption
and thereby demonstrating proactive risk management.
ERM in the energy sector often relies on the treasury function and the expertise of specialists
hedging against the price of a barrel of oil. This area of financial risk management has
become well established, with very large departments established in many energy companies.
However, ERM practices in energy companies are still very closely related to treasury risk
management.
One of the drivers of risk management in the financial sector is the regulatory
environment. Banks have been subject to Basel II for some time, and are preparing for the
implementation of Basel III requirements in 2019. The insurance sector in Europe will be
subject to similar requirements, set out in the Solvency II Directive. This creates an obligation
for financial institutions to measure their exposure to operational risk.
The output of operational risk management (ORM) activities in financial institutions is
the ability to calculate the capital that should be held in reserve to cover the consequences of
identified risks that materialize. The impact of these ORM activities is that risks will be better
identified and managed, resulting in lower capital required to meet the consequences of
realized risks. ORM in financial institutions can be seen as a specialized application of the
ERM approach. The failure of the world banking system calls into question the effectiveness
of risk management activities in banks and, in particular, the effectiveness of operational risk
management. One of the consequences of the world financial crisis is that news reports now
routinely state that: 1) risk is bad; and 2) risk management failed. In fact, taking risks is
critical to organizational success.
The assertion that risk management has failed in banks is harder to refute. However,
the reality is that it was not the failure of risk management principles that caused the banking
crisis. It was the failure to apply those principles properly. Many banks made two
simultaneous mistakes:
An accurate risk and reward analysis was not conducted, so the bank made decisions
67
based on the available rewards, rather than taking a more balanced view of the risks
involved in seeking those higher rewards.
Quantification of the level of risk involved is inaccurate, as the bank takes such an
aggressive approach to risk that certain events are considered so unlikely that they can
be ignored.
A detailed analysis of the 2008 banking crisis is beyond the scope of this text. However, it
appears that the crisis was caused by the failure of two different sets of risk analysis models.
First, banks assumed that repackaged debt, including subprime mortgages, would continue to
be a tradable commodity in the market, but this was not the case. Second, banks assumed that
short-term loans in the wholesale money market would continue to be available. This short-
term money was used by banks so that they could continue to lend money in the long term, at
more favorable rates. The collapse of the wholesale money market was not anticipated by the
credit model used by most banks.
8.6 FUTURE DEVELOPMENT OF ERM:
The COSO ERM cube represents a framework for performing enterprise risk
management, although there is not enough description in the COSO model of the risk
management process itself. However, the COSO approach is becoming more widespread as
the recently updated COSO Internal Control framework (2013) is the preferred approach for
meeting the requirements of the Sarbanes-Oxley Act. US companies that have subsidiaries
around the world often require their subsidiaries to adopt the COSO approach.
Another important development in risk management was the publication of British
Standard BS 31100 in 2008 and the publication in 2009 of the ISO risk management standard,
ISO 31000. ISO 31000 was adopted by Standards Australia to replace the previously available
and established Australian Standard AS. 4360 (2004), which was first published in 1995. BS
31100 was revised and updated in 2011 to provide greater compatibility with ISO 31000.
Future developments in ERM practices will likely be focused on two key areas: first,
ensuring risk management activities are fully embedded in an organization's core business
processes; and second, demonstrating quantifiable financial benefits associated with
implementing enterprise risk management initiatives. Embedding ERM in the organization is
achieved through leadership, engagement, learning, accountability, and communication
(LILAC). Developments in operational risk management practices may lead in the
measurement of an organization's total risk exposure.
While considering the ongoing development of enterprise risk management, it is also
68
worth commenting on the emergence of strong resilience as an organizational requirement for
the 2010s. The ISO 22300 series of standards will cover business continuity, crisis
management, and broader requirements relating to the resilience of society in general, and
organizations in particular. ISO 22301 on business continuity is discussed in Chapter 18 and
the importance of the other standards in the ISO 22300 series is discussed in Chapter 9. In
summary, the discipline of enterprise risk management has become established and is here to
stay, but it must be able to demonstrate significant and measurable financial benefits. These
financial benefits need to be demonstrated in the form of increased profits in private sector
organizations and in the form of improved efficiency and/or delivery of value-for-money
services in the public sector. The box below shows the keys to success in ERM.
Successful Implementation of Erm:
Risk managers have the responsibility to sell the value added by risk management to
the organization and its stakeholders, but this is not an easy task. How can risk managers sell
the value they generate when that value can only be realized when an unexpected event
occurs, or if a new control system is successful, when the risk never occurs?
Risk managers need to remember that the actual implementation of the ERM program
generates value itself. Often risk managers are so focused on successfully managing the
program that they do not have time to clearly communicate this value to the organization. The
greatest value derived from developing an enterprise risk management program into an ERM
system is the development of physical, financial and cultural resilience within the business as
a whole, while remaining focused on achieving overall business objectives. Risk managers
can be their own worst enemy as one of the key elements of a successful practitioner is the
passion to successfully customize, implement and maintain an ERM program.
Correspondingly, this passion is a weakness as practitioners need to remember that others do
not always have that passion.
One of the main challenges facing ERM programs is the development of an 'ivory
tower' mentality. In this scenario, all risk knowledge and activities are based in one
department. Risk managers need to design systems that encourage the migration of risk
management methodologies and tools into the organization. There is also a balancing act
required. Practitioners should not force the use of risk management processes in operational
areas that are of little value. It is critical to the success of an ERM program that it has a system
that is flexible enough to work with the organization to capture and manage critical risks
successfully without adding unnecessary work in managing lower level risks.
69
ALTERNATIVE APPROACHES
9.1 CHANGING THE FACE OF RISK MANAGEMENT :
As with any management initiative that is embedded in the way an organization
operates, successful risk initiatives will inevitably evolve and become more sophisticated.
Developments in the discipline of risk management, especially over the past 10 years, have
been dramatic. Also, the degree to which risk management requirements have become
embedded in corporate governance has been extensive. Many new developments in risk
management have emerged during this time. In the 1990s, risk management practitioners used
to talk about integrated or holistic risk management, but now the universally accepted
terminology for the broad application of risk management across an organization is enterprise
risk management (ERM). Similarly, operational risk management (ORM) has been
established and developed substantially over a shorter period of time, perhaps five years.
In many ways, the fact that the risk management discipline is constantly evolving and
adapting to changing circumstances can be seen as beneficial. However, there is a danger that
risk management practitioners will be seen to be delivering an ever-changing and therefore
inconsistent message. That is not to say that risk management should be a static discipline, but
it is important to remember that changing the basis on which risk management analysis and
advice is offered and seemingly changing the nature of the risk management process, will lead
to confusion and a lack of interest among senior board members.
Any review of the changing face of risk management must recognize the crisis
global finance and the role that risk management played in the development of this situation.
As the global financial crisis developed, newspaper and television reports constantly repeated
two messages: 'risk is bad' and 'risk management has failed'. Neither of these statements is
true. It is important that organizations take appropriate risks, and the failures that led to the
global financial crisis were failures in the application of risk management, not failures of risk
management itself.
There is no doubt that taking too many risks may be inappropriate and may result in
the failure of the entire organization. However, the experience of many organizations is that
they almost always get away with it, or (at the very least) manage to survive. A detailed
understanding of the level of risk embedded in the organization is not meant to stop all bold
strategic decisions. Risk awareness should not prevent organizations from embarking on high-
risk strategies, but decisions will be taken with full awareness of the risks involved.
Organizations should continue to look for opportunities and, from time to time,
70
acknowledge that there are good opportunities that look very risky. The organization may still
have the desire to embark on such risky strategies, but the next stage of discussion should be
about how to manage risk so that it remains within the organization's risk capacity, and how to
measure risk so that the board remains aware of its true risk exposure. The global financial
crisis does not reflect a failure of risk management. It represents a failure to fully and properly
implement risk management procedures and protocols. Figure 25.3 illustrates the risk appetite
of a risk-aggressive organization. When an organization is risk aggressive, it limits the range
of risks that the board will consider, as there is limited scope to identify risks as high
likelihood/high impact. In other words, the universe of risk for that organization is highly
constrained and will exclude risks that should receive board attention.
If the organization is risk aggressive and operates with a model that fits Figure 25.3,
then very few significant prioritized risks will be identified. This will result in the
organization creating a 'closed risk universe' for the board that potentially limits wider
discussion and analysis. However, there is nothing inherently wrong about an organization
being risk aggressive. If an organization is risk aggressive, there is an increasing need to
revisit risk assessments, challenge the scope and outcomes of risk analysis activities, and
ensure that a highly dynamic approach to risk management is maintained at all times and at all
levels within the organization. In addition to the concerns about risk management raised by
the global financial crisis, there are several other challenging issues for risk management. The
concepts of risk appetite and risk upside are useful ideas, but further development is needed
before successful definition and application of the concepts can deliver guaranteed benefits.
9.2 MANAGING RISKS THAT ARISE:
All organizations notice changes in the external and internal context that pose new
challenges, uncertainties and opportunities. These changes can be considered as emerging
risks facing the organization. However, consideration of emerging risks can be difficult unless
the organization clearly understands the nature of the emerging risks it faces. Emerging risks
can be divided into three categories, as follows:
New risks that arise in the external environment, but are related to the organization's
existing strategy - new risks in a known context;
Existing risks that the organization already knows about, but have evolved or changed
circumstances have triggered known risks in a new context;
Risks not previously faced by the organization, as they relate to changing core
processes - new risks in a new context.
71
Several business developments have increased the level of risk faced by organizations in
recent times, including moving into new markets, embracing new technologies and
developing increasingly complex supply chains. Generally, these increased risks will be under
the control of the organization itself. In addition, there are many emerging or evolving risks
that are not within the control of individual organizations, including:
Climate change;
National debt;
National security;
Changing demographics.
When attempting to manage these emerging risks, the organization must evaluate whether
they are treated as hazards, control risks, or opportunities. Depending on the activities of the
organization, many of these emerging risks may simply be a threat to the organization or
represent an opportunity for future development. In some cases, emerging risks will simply
represent additional uncertainty that needs to be managed. An important consideration when
thinking about emerging risks is the speed at which they can become significant. Some risk
management practitioners refer to the speed at which risks develop and change as risk
velocity.
A good example of an emerging risk is nanotechnology. Nanotechnology
is used extensively in the medical and, to some extent, cosmetic industries to improve the
effectiveness of cosmetic treatments of skin conditions. Whether long-term risks will arise
from the use of nanotechnology has not been fully established. Another good example is that
related to the use of cell phones. Cell phones have become commonplace, but the technology
has evolved greatly over the past 25 years. Cell phone signals were much stronger 25 years
ago. Therefore, if health allegations start to arise against cell phone use, these health effects
are likely to be related to technology that is no longer in use. This would represent a
significant challenge in deciding whether health hazards no longer exist because the
technology has changed, or whether health hazards are just as significant and would prove to
be just as related to current technology.
Nanotechnology Risks:
As nanotechnology is an emerging field, there is great debate over the extent to which
it will benefit or pose risks to human health. The health impacts of nanotechnology can be
divided into two aspects: potential medical applications to cure diseases, and potential health
hazards posed by exposure to nanomaterials.
72
The extremely small size of nanomaterials means that they are more easily absorbed
by the human body than larger-sized particles. How these nanoparticles behave inside the
organism is one of the big problems that needs to be solved. The behavior of nanoparticles is
a function of their size, shape, and surface reactivity with the surrounding tissue. Regardless
of what happens when nanoparticles that are not can degrade or slowly accumulate in organs,
another concern is their potential interaction with biological processes in the body: due to
their large surface, nanoparticles exposed to tissues and fluids will be immediately absorbed
into their surface by some of the macro-molecules they encounter.
The large number of variables affecting toxicity means that it is difficult to generalize
about the health risks associated with exposure to nanomaterials; each new nanomaterial must
be assessed individually and all properties of the material must be taken into account. Health
and environmental issues merge in the workplaces of companies engaged in the production or
use of nanomaterials and in laboratories involved in nano-science and nanotechnology
research. It is safe to say that current workplace dust exposure standards cannot be applied
directly to nanoparticle dust.
9.3 INCREASING THE IMPORTANCE OF RESILIENCE:
In recent years, there has been an increased interest in the topic of resilience. Perhaps,
the trend started with governments and local or municipal authorities. There was a recognition
during the 1990s and 2000s that society in general, and communities in particular, had to
become more resilient. This growing awareness initially emerged in relation to civil
emergencies, as well as natural disasters, such as earthquakes, and extreme weather events.
While the initial concern with resilience may have begun with considerations of how to
respond to events over a wide area, broader concerns have developed in recent times.
Increased awareness and concern related to resilience is clearly demonstrated
by the fact that the replacement for British Standard BS 25999:2006 Part 1 'Code of Practice -
Business Continuity Management' is ISO 22301:2012 'Social Security - Business Continuity
Management Systems - Requirements'. A number of other standards in the ISO 22300 series
are being developed and there are moves to develop resilience standards in other countries.
One of the best established resilience standards is the Organizational Resilience Standard
(ASIS SPC.1-2009) published by the American National Standards Institute.
This ASIS standard takes an enterprise-wide view of risk management, enabling
organizations to develop comprehensive strategies to prevent when possible, prepare for,
mitigate, respond to, and recover from disruptive incidents. It allows integration with ISO
31000. It is also compatible with existing ISO management system standards (such as ISO
73
9001, ISO 14001, ISO 27001 and ISO 28000). The overall approach is that a resilient
organization needs to 'prevent, protect and prepare' in relation to resources and assets and at
the same time be able to 'respond, recover and review' when a crisis occurs. When seeking to
make an organization more resilient, it is important to have a definition of the desired state of
resilience that is being sought. ISO 22300:2012 'Societal Security - Terminology' defines
resilience as 'the adaptive capacity of an organization in a complex and changing
environment'. This is a useful definition, but resilience is often associated with crisis
management, and this definition does not explicitly address organizational behavior during a
crisis. Perhaps a better definition is 'the capacity of an organization to consistently achieve a
desired state after a change in circumstances'. This definition better encompasses crisis
management, as well as the ability to successfully respond to less dramatic or disruptive
events.
The rise of resilience is an opportunity for risk management and business continuity
specialists to work together to ensure a more coordinated approach to enterprise risk
management, business continuity and crisis management. There are three behaviors that an
organization must achieve if it is to achieve increased resilience:
awareness of changes in the external environment, internal, and risk management, so
that constant attention to resilience is ensured;
'prevent, protect and prepare' relates to all types of resources, including assets,
networks, relationships and intellectual property;
'respond, recover and review' relates to disruptive events, including the ability to
respond quickly, review lessons learned and adapt.
Finally, it should be noted that another trend in the structure of risk management and
resilience standards seems to be emerging. Some standards are moving towards a 'plan-do-
check- act' (PDCA) structure. This approach is fully consistent with the plan, implement,
measure, learn (PIML) approach to implementing risk management initiatives set out in
Annex C. The ASIS standard explicitly follows the PDCA format. PIML is preferred over
PDCA because it is a more comprehensive and analytical approach. In fact, both the risk
management framework and process described in ISO 31000 align with the PIML approach,
once the 'mandate and commitment' for the framework and 'setting the context' for the process
stages (respectively) have been completed.
As the growing importance of resilience is recognized, advice for achieving resilience
is becoming more widespread. For example, the box below summarizes advice given to
organizations by the UK government's Cabinet Office.
Increase the importance of resilience
74
Embedding organizational resilience into governance mechanisms should ensure that
the management of risks to critical infrastructure posed by natural hazards, major accidents
and other malicious damage are considered by the board. The resilience needs of the
organization will thus inform strategic investment and procurement decisions, risk
management and discussions with supply chain partners. This will enable infrastructure
owners and operators to improve their understanding of the resilience of their infrastructure,
periodically measure the success of the strategy, and make necessary amendments to secure
delivery or match changing organizational priorities.
9.4 DIFFERENT APPROACHES:
The approach adopted by the Canadian Criteria of Control (CoCo) (1995) framework
produced by the Canadian Institute of Chartered Accountants is based on the idea that the risk
culture of the organization is the most important consideration. If the risk culture is right, then
successful risk management should follow. The CoCo framework states that:
A person performs a task, guided by an understanding of its purpose (goals to be achieved)
and supported by capabilities (information, resources, equipment and skills). The person will
need a sense of commitment to perform the task well over time. The person will monitor his or
her performance and the external environment to learn about how to do the task better and
about changes that should be made. The same applies to any team or work group. In any
organization of people, the core of control is purpose, commitment, capability and monitoring
and learning.
The COSO ERM framework refers to the control environment as the internal
environment. This is equivalent to the control environment considered in the CoCo
framework. CoCo provides a structured means of analyzing the control environment that
enables a quantitative assessment of the control environment, so that features for
improvement can be identified.
The CoCo framework is discussed in more detail in Chapter 33. While there are
different versions of the CoCo questions, the following are the headings typically used to
evaluate the risk-aware culture in an organization using the CoCo approach:
goals, vision and mission;
commitment to integrity and ethical values;
ability, authority and responsibility;
75
learning and competency development.
In addition to the CoCo approach, there are many other risk management and internal control
standards available around the world. The scope and intended purpose of the standards vary.
For example, the Orange Book produced by HM Treasury in the UK is intended as guidance
for central government departments on risk management.
An important development in standards is the emergence of the concept of
Governance Risk and Compliance (GRC) and this is discussed in more detail in Chapter 35.
The approach underlying the principle is related to the concept of three lines of defense where
different risk management and internal control responsibilities are allocated to senior
management, specialist risk functions and internal audit. The overall approach to GRC is
based on the separation of functions. Senior management is responsible for governance within
the organization, specialist risk functions are responsible for risk management activities and
adequate compliance assurance is provided by internal audit.
In South Africa, the highly influential and detailed King III corporate governance code
was published in 2009. Risk management remains important in the updated code and more
detailed guidance is provided on how to achieve it. The board is responsible for risk
governance and disclosure and management is responsible for the risk management design,
implementation and monitoring of the risk management plan.
Detailed responsibilities for risk management are set out in King III in relation to
corporate board responsibilities. These are summarized in Table 9.1. In addition to risk
management standards and corporate governance requirements, there are a number of
specialist standards that apply to risk management. In particular, the IT sector has produced a
number of well-regarded and widely used standards. Perhaps the best-known standard is
Control Objectives for Information and Related Technology (COBIT). COBIT provides good
practice across domains and process frameworks and presents activities in a manageable and
logical structure. The COBIT approach is described in more detail in the box below.
Control Objectives for Information and Related Technologies (COBIT)
The good practices described in COBIT represent the consensus of experts. They focus
heavily on control, less on execution. These practices will help optimize IT-enabled
investments, ensure service delivery, and provide measures to assess when things go wrong.
For IT to be successful in meeting business requirements, management must implement an
internal control system or framework. The COBIT control framework contributes to this need
by:
create links to business requirements;
76
organize IT activities into generally accepted process models;
identify key IT resources to be utilized;
determine the management control objectives to be considered.
COBIT's business orientation consists of linking business objectives with IT objectives,
providing metrics and maturity models to measure their achievement, and identifying the
associated responsibilities of business and IT process owners.
9.5 STANDARD STRUCTURE MANAGEMENT:
ISO has produced guidance on the required structure of management system standards.
This guidance is referred to as Annex SL and a number of existing standards have been
converted to this format, including ISO 14001:2004 'Environmental Management Systems -
Requirements with Guidance for Use'. Also, ISO 22301:2012 'Social Security - Business
Continuity Management', which is discussed in more detail in Chapter 18, has been moved to
this new structure. The main clause numbers and titles of all management system standards
will become identical, once Annex SL is adopted for the standards. Following the introduction
section, the management system standards corresponding to Annex SL will be structured with
the following clauses:
1. Scope
2. Normative reference
3. Terms and definitions
4. Organizational context
5. Leadership
6. Planning
7. Support
8. Operation
9. Performance evaluation
10. Improved
It is interesting to note that the structure does not explicitly describe the framework and
processes as separate items, as presented in ISO 31000. Perhaps this is part of the reason that
currently (November 2016) there are no plans to convert ISO 31000 into the Annex SL
format. Nevertheless, the structure of Annex SL allows organizations developing their own
approach to enterprise risk management to design an approach that is compatible with other
ISO standards applied within the organization, including the most popular ISO standard - ISO
77
9001 on quality management. Many of the titles used in Appendix SL will be familiar to risk
professionals, including Clause 4: Organizational Context. Clause 4 is intended to identify
why the organization exists. As part of answering this question, the organization needs to
identify external and internal issues that could impact the desired outcome, as well as all
stakeholders and their requirements. Clause 5: Leadership and Clause 7: Support work
together and can be considered equivalent to risk architecture, strategy and protocol (RASP)
in relation to Clause 5, and the embedded risk management component as leadership,
engagement, learning, accountability and communication (LILAC) in relation to Clause 7.
Clause 6: Planning, Clause 8: Operations, Clause 9: Performance evaluation and
Clause 10: Improvement are exactly the same as the plan-implement-measure-learn (PIML)
approach described in this book. The PIML approach is similar to the plan-do-check-act
(PDCA) terminology used by some organizations. An important aspect of Annex SL is that
the planning stage described in Clause 6 specifies two sub-clauses:
actions to address risks and opportunities;
management system, objectives and plans to achieve them.
This means that the requirement to plan and implement actions to address risks and
opportunities is now embedded in ISO 9001 on quality management and will become
embedded in other standards as the Annex SL format is gradually introduced. An important
lesson for risk professionals, as more and more management system standards are migrated to
the Annex SL format, is to ensure that a company's risk management initiatives are fully
aligned with the Annex SL approach. This should ensure greater acceptance of enterprise risk
management initiatives within the organization. One further important point to note is that
Clause 8: Operations is described as having most of the management system requirements,
including the overall process and management which will include adequate criteria to control
the process.
Under Clause 8 in the new format that familiar steps of the risk management process
will be included for organizations that decide to adopt the Annex SL structure when
implementing enterprise risk management initiatives.
9.6 THE FUTURE OF RISK MANAGEMENT :
Emerging trends in risk management have been mentioned throughout this book. The
development of the international risk management standard ISO 31000 is undoubtedly an
important step forward for risk management practitioners. The advent of enhanced corporate
governance codes has also added to the profile of risk management practices in many
78
countries. The effects of the global financial crisis are still being felt and questions are still
being asked about risk management and why it did not contribute more to avoiding this crisis.
Other important trends include the development of enhanced reporting requirements
placed on all types of organizations. This is especially true for organizations listed on stock
exchanges around the world. Risk management information systems are becoming more
developed and sophisticated and can offer significant benefits to organizations that use it.
Despite all these developments and the undoubted increase in professionalism and
competence of risk management practitioners, there is still room to ask questions about the
future development of risk management.
The emergence of 'governance, risk and compliance' (GRC) has already been
mentioned and it represents a major step forward in the structure of risk management
activities. The advent of GRC, along with a better understanding of the benefits of the three
lines of defense, has put organizations in a better position to practice risk management. Risk
management practitioners realize that their discipline makes a major contribution and they
also realize that risk management activities must be integrated with other management
activities. In some cases, there is a danger that risk management activities will be integrated
with audit activities, and the three lines of defense then become two lines of defense.
There is a need for organizations to integrate risk activities across their organization,
rather than treating risk management activities as a separate management role that requires
separate management information. Perhaps this is one of the major drawbacks of using risk
registers in many organizations. Risk registers are a snapshot of risk management activities
within an organization, but the risk is that they are not reviewed on an ongoing basis. The risk
register is often a static document that adds little benefit to the management of the
organization. Perhaps the time of the risk register has passed, and organizations must now
integrate risk assessment, risk recording, and risk action plans in the management information
used for day-to-day management of the organization.
In summary, the challenge for risk managers and risk management is to keep risk
management activities proportionate, aligned, comprehensive, embedded and dynamic
(PACED). However, the challenge of doing this becomes greater as the board, executive
management, managers and staff become more familiar with the theory and application of risk
management. The challenge is to ensure integration of these activities, without them
becoming so routine that the importance of risk management is lost. Risk management
activities need to be linked to discussions on strategy, tactics and operations, as well as linked
to discussions on business delivery, budgets and business development models.
The publication of ISO 31000 in 2009 opened the possibility of international
79
standardization of risk management standards in due course. British Standard BS 31100 was
originally published in 2008, but was updated in 2011 to provide better alignment with ISO
31000. BS 31100 provides greater detail on risk management frameworks than ISO 31000
and is a useful addition to existing risk management standards and frameworks.
Management initiatives often come and go. Certain approaches become fashionable
for a while and then fade away. This is unlikely to be the case with risk management, as the
requirement to have risk management procedures in place has become mandatory in many
sectors. In addition, the global financial crisis has resulted in the analysis detail the benefits
that risk management can provide and how this can be achieved. The brief comments below
illustrate how risk management is valued around the world and why it is here to stay.
Risk Management is Here to Stay:
Every day, managers and employees practice risk management by making decisions
about what to do, and how and when to do it. Decisions should be based on factors such as
whether the organization has the capacity, whether the organization sets aside funds and will
impact other business units. ERM is not just a passing trend. It is here to stay and is driven by
both governance issues and societal demands. Companies, charities, and public sector
organizations have successfully embraced ERM.
Risk management does not have to be complex or a heavy user of resources. It can be
tailored to meet the needs of the organization at an early stage and modified as the level of
sophistication and comfort with the process grows. It is a systematic and proactive approach
to managing risk. This means that high-risk exposure areas are understood, managed, and
controlled to acceptable exposure levels so that the organization is well protected to minimize
negative consequences. It allows the organization to focus on what is important to control
versus what is easy to control.
Students also viewed