1 / 28100%
80
DUTIES AT RISK
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 4
Learning Outcomes Part Three:
•
Explain the importance of risk assessment as a very important stage in the risk
management process;
•
Summarizes the most common risk assessment techniques, plus the advantages and
disadvantages of each, including swot;
•
Explains the importance of the organization's long-term attitude towards risk and how
it affects risk perception;
•
Describe options for classifying risks according to the nature, source, timescale,
impact and consequences of the risk;
•
Explain the importance of risk classification systems and describe the features of
existing systems, including pestle, firm, and 4p;
•
Describe the attributes of each characteristic and illustrate through a risk matrix the
nature and attributes of the risk in terms of likelihood and magnitude;
•
Illustrate, using a risk matrix, the risk attitude of an organization and the importance
of the 'risk universe' concept;
•
Provided examples of using the risk matrix, including using it to show the dominant
risk responses in each quadrant (4t);
•
Explain the main components of loss control as loss prevention, damage limitation and
cost control, and provide practical examples;
•
Summarize alternative approaches to defining the upside of risk and the application of
these approaches to core processes.
Case Study:
AA: Risk governance
Group-wide risk assessment requires business units to formally review business risks
81
every quarter. This approach to risk identification, analysis and assessment ensures
responsibility so that such risks are managed, controlled and monitored. A broad spectrum of
risks are considered through this process including those relating to strategy, operational
performance, finance, product engineering and technology, business reputation, human
resources, health and safety and the environment. The causes and consequences of each risk
are considered and, where appropriate, linked to strategic and operational objectives.
Management controls designed to monitor and mitigate risk
documented. A risk owner is assigned to each risk. Risk responses are based on an assessment
of potential risk exposure and accepted tolerance levels. The response reflects whether we
accept the risk based on the assessed level of exposure and the mitigating controls currently in
place, where possible, or reduce the risk through additional mitigations to match the required
tolerance level. The duties of the risk committee include advising the board on the group's
overall risk appetite, tolerance and strategy. The risk committee and the board have reviewed
and approved the revised risk appetite since we became a public listed company.
As with any business, we face risks and uncertainties every day. It is this effective
management that puts us in a better position to be able to achieve our strategic objectives and
to embrace emerging opportunities. The board has carefully considered the nature and extent
of the significant risks it is willing to take in achieving the group's strategic objectives and
delivering satisfactory returns for shareholders.
British Land: Our risk assessment is the cornerstone:
Internally we have undertaken several significant change projects to improve the
effectiveness and efficiency of our business operations. While this inevitably presents a level
of operational risk, we believe we have the right people in place to manage the changes
effectively. In the year, we recognized the increased risk of terrorist activity at our assets and
have tested our crisis response plans to ensure they are robust.
At British Land, we take the view that our risk assessment is the cornerstone of our
strategy and our embedded risk management is fundamental to its delivery. Our integrated
approach combines a top-down strategic view with complementary bottom-up operational
processes. The top-down approach involves a review of the external environment in which we
operate. This guides the assessment of the risks we feel comfortable taking in pursuit of our
performance objectives - this is our risk appetite. This evaluation guides the actions we take in
executing our strategy. Key risk indicators (KRIs) have been identified for each of our key
risks and are used to monitor our risk exposure. KRIs are reviewed quarterly by the risk
committee to ensure that business activities remain in line with our risk appetite.
82
The bottom-up approach involves identifying, managing and monitoring risks in every area of
our business. In this way, risk management is embedded in our day-to-day operations. Control
of this process is done through the maintenance of risk registers in each area. These risk
registers are compiled and reviewed by the risk committee, with significant and emerging
risks escalated for board consideration as appropriate.
NSW/ACT Guide Dogs: List of key remaining risks
A (partial) list of the key residual risks identified in the NSW/ACT Guide Dog risk
management plan and an update on actions taken to mitigate these risks follows:
1. There were insufficient guide dogs to meet the demand. This breeding program
resulted in 140 puppies and 51 guide dogs graduating. We will continue to increase the
number of dogs graduating each year, and further reduce the waiting time.
2. Insufficient instructors to meet the growing demand, due to cutbacks have reduced our
instructor numbers. Ten orientation and mobility instructor students will be recruited
to begin studies in 2016.
3. Ongoing funding of the Eye Health Center. Guide Dogs NSW/ACT invests significant
effort to attract funding partners and donors and works with international fundraisers.
4. The potential for client injury while utilizing mobility skills taught by the instructor. A
review of the risks involved in delivering different types of client service programs has
been completed and programs with unacceptably high risks have been eliminated from
our offerings.
5. Staff motor vehicle accidents. Driver training and increased selection of vehicles with
safety inclusion standards will continue.
6. Staff changes in the fundraising and planned giving departments could potentially
result in reduced revenue streams. Recruitment has resulted in excellent staff who can
complete their roles very well and prove to be very effective in their responsibilities.
ASSESSMENT CONSIDERATIONS
10.1 THE IMPORTANCE OF RISK ASSESSMENT :
Risk recognition and risk rating together form the risk assessment component of the
risk management process. Risk assessment involves recognizing risks and ranking them to
determine the significant risks facing an organization, project, or strategy. It is defined in
83
British Standard BS 31100 as the overall process of risk identification, risk analysis, and
risk evaluation. Since risk management inputs into strategy focus on making better
decisions, risk assessment is a key risk management input into strategy formulation.
Risks may be inherent to corporate goals, stakeholder expectations, core processes,
and key dependencies. Whichever of these features is selected as the starting point, a risk
assessment can be conducted. The purpose of the risk assessment is to identify significant
risks that may affect the selected feature. While the risk assessment is critical, it is only
useful if the conclusions of the assessment are used to inform decisions and/or to identify
appropriate risk responses for the type of risk under consideration. It should be considered
a starting point of the risk management process and certainly not an end in itself.
An important feature of conducting a risk assessment is deciding whether the risk
identified will be evaluated at the inherent level or at the current (or residual) level. The
innate risk assessment is performed without taking into account the controls currently in
place. This is the approach that has been recommended by internal auditors. Internal
auditors will point out that two risks at the same current or net value may have
significantly different inherent or gross values. It is important to know when this is the
case.
The benefit of conducting a built-in risk assessment is that the difference between
the current level and the built-in level can be identified. This will provide an indication of
the importance of existing control measures and the information is used by internal
auditors to help identify critical controls and set audit priorities. While this may be a useful
approach, there can be considerable difficulty in identifying the value of the inherent level
of risk.
Health and safety practitioners, for example, prefer to conduct risk assessments
with existing controls. This can be a simpler approach, although it relies on the assumption
that current controls will always work with the assumed effectiveness. For example, if an
x-ray machine assessment is being conducted, the safety officer will assume that the
enclosure or cabinet is in good working order and the risk should be assessed on that basis.
The internal auditor would more readily recognize that the enclosure or cabinet is a very
important control factor that should be checked regularly.
10.2 APPROACH TO RISK ASSESSMENT:
There are several approaches that can be taken when planning how to conduct a
risk assessment. One key decision is who will be involved in the risk assessment exercise.
Sometimes risk assessments are conducted by the board of directors as a top-down
84
exercise. Risk assessments can also be conducted by involving staff members and local
department management. This bottom-up approach is also valuable. The opinion of the
chief executive officer (CEO) is very important, especially as it helps to determine the
organization's overall attitude towards risk. There is no doubt that the CEO will be able to
provide a well-structured view of the significant risks facing the organization. The
disadvantage in relying on the CEO's opinion is that the focus tends to be on external risks.
Although the CEO will pay attention to financial management and infrastructure risks,
these internal risks may be is not their primary concern or area of interest.
In general, the overall approach by an organization to risk assessment will be
greatly influenced by the risk assessment technique chosen. Certain techniques require the
involvement of specific individuals and require a specialized approach to conducting risk
assessments. It is important that the approach adopted is consistent with the culture of the
organization. For example, if an organization does not typically hold meetings and
workshops, then workshops may not be the most appropriate approach to risk assessment.
Likewise, if an organization's culture relies heavily on written reports and papers, this may
be the best way to conduct a risk assessment.
The use of voting software has become popular in recent times
This. For organizations such as media companies that are familiar with these technologies,
this may be a very appropriate way to conduct risk assessments. However, for
organizations that are not interested in technology, the use of such tools can be seen as a
gimmick that reduces the value of the workshop. The use of voting software can provide
additional information in risk assessment workshops. Not only is it possible to identify the
majority position in relation to the likelihood and impact of the risk materializing, but it is
also possible to identify the spread of opinion. If there is a wide spread of opinion, this
needs to be explored, as it could represent a possible misunderstanding of the nature of the
risk being discussed.
An important consideration for organizations is whether the risk assessment
process should be top-down or bottom-up. In other words, will senior management lead the
risk assessment process within the organization with information passed down for
validation, or will a series of risk assessment exercises be conducted starting at the
operational level? Table 10.1 provides examples of the advantages and disadvantages of
conducting top-down risk assessment exercises. Top-down risk assessment exercises will
tend to focus on risks related to strategy, tactics, operations, and compliance (STOC) in
that order.
Table 10.2 provides examples of the advantages and disadvantages of conducting a
85
bottom-up risk assessment exercise. As with many aspects of a successful enterprise risk
management initiative, the organization must decide which risk assessment protocols and
procedures are most appropriate. If it is a choice between top-down and bottom-up, the
organization must decide whether visible senior management support for the risk
management initiative is more important than greater involvement from operational
people. A bottom-up risk assessment exercise will tend to focus on risks identified as
compliance, hazards, controls, and opportunities in that order. For most organizations, a
combination of top-down and bottom-up risk assessments will be conducted with risk
managers gathering information from as many stakeholders as possible. Often, the main
obstacle in conducting bottom-up exercises is the greater time commitment required from
the risk management department to attend and/or facilitate a series of risk assessment
exercises.
10.3 RISK ASSESSMENT TECHNIQUES:
There is a wide range of risk assessment techniques available, and the International
Standard ISO/IEC 31010 'Risk Management: Risk Assessment Techniques', was published
in 2009. This standard provides detailed information on the various risk assessment
techniques that can be used. Table 10.3 lists the main risk assessment techniques that are
commonly used and also provides a brief description of each of these techniques. Perhaps
the most common risk assessment approaches are the use of checklists/questionnaires and
the use of brainstorming sessions, usually during risk assessment workshops.
Checklists and questionnaires have the advantage of being usually easy to complete
and less time-consuming than other risk assessment techniques. However, this approach
suffers from the disadvantage that any risk that is not referred to by an appropriate
question may not be considered significant. A simple analysis of the advantages and
disadvantages of each of the most common risk assessment techniques is presented in
Table 10.4.
Given that risk can be linked to other aspects of an organization
As well as or instead of objectives, an easy and simple way to analyze risk is to identify
the key dependencies faced by the organization. Most people in an organization will be
able to identify those aspects of the business that are fundamentally important to its future
success. Identifying the factors necessary for success will give rise to a list of key
dependencies for the organization.
The key dependencies can then be further analyzed by asking what could affect
each of them. If a hazard analysis is being performed then the question is: 'What could
86
damage each of these key dependencies?' If control risks are identified, then the question
can be asked: 'What will cause uncertainty about these key dependencies?' In an
opportunity risk analysis, the question is: 'What events or circumstances will improve the
status of each of the key dependencies?'
For many organizations, quantification of risk exposures is critical and the risk
assessment technique chosen must be capable of providing the required quantification.
Quantification is especially important for financial institutions and the style of risk
management used in these organizations is often referred to as operational risk
management (ORM). Risk workshops are perhaps the most common risk assessment
technique. Brainstorming during a workshop allows opinions regarding the significant
risks faced by the organization to be shared. A common view and understanding of each
risk is achieved. However, the disadvantage is that the more senior people in the room can
dominate the conversation, and challenging their opinions may be difficult and
undesirable.
To conduct structured discussions at risk assessment workshops, several common
brainstorming structures are used. These may be qualitative or quantitative, depending on
the level of risk analysis required. The most common qualitative brainstorming structures
are SWOT and PESTLE analysis. SWOT is an analysis of the strengths, weaknesses,
opportunities and threats facing the organization. SWOT analysis has the benefit of also
considering the upside of risk by evaluating opportunities in the external environment. One
of the strengths of SWOT analysis is that it can be linked to strategic decisions. However,
as it is not a structured risk classification system, it is possible that not all risks can be
identified.
Another common qualitative approach is the PESTLE analysis which considers the
political, economic, social, technological, legal and ethical (or environmental) risks faced
by the organization. Table 11.3 considers the PESTLE risk classification system in more
detail. PESTLE is a well-established structure with proven results for conducting
brainstorming sessions during risk assessment workshops.
Many organizations want to perform a quantitative evaluation of the likelihood of a
risk event occurring. There are several techniques available to perform this quantitative
evaluation. The most common are hazard and operability studies (HAZOP) and failure
mode effect analysis (FMEA). Both techniques are structured approaches that ensure that
no risk is omitted. However, the involvement of various experts is required to conduct an
accurate quantitative analysis.
HAZOP and FMEA techniques are most easily applied to manufacturing
87
operations. HAZOP studies are often conducted on hazardous chemical installations and
complex transportation structures, such as railroads. Also, HAZOP studies of complex
installations, such as nuclear power plants, are often conducted. They can also be applied
to product safety analysis. In both cases, it is a highly analytical and time-consuming
approach, but such an approach will be necessary in a variety of circumstances.
10.4 MATRIX PROPERTIES RISK:
When a risk has been recognized as significant, the organization needs to assess it
so that prioritized significant risks can be identified. Techniques for assessing risks are
well established, but there is also a need to decide what scope there is to improve controls
further. Consideration of the scope for further cost-effective improvements is an additional
consideration that aids clear identification of priority significant risks.
Organizations need to establish risk likelihood and risk impact measures that will
be used throughout the organization. Table 10.5 provides a list of typical definitions in
relation to risk likelihood. Table 10.6 sets out the definition of impact to be used within a
particular organization. In both cases, four different definitions are given and this will
avoid the tendency of the person conducting the risk assessment to choose the middle
option. However, many organizations decide to have more than four options available for
both likelihood and impact. The number of options available will depend on the nature,
size and complexity of the organization.
There are many different styles of risk matrices. The most common form is one that
shows the relationship between the likelihood of a risk occurring and the impact of the
event if the risk materializes. In addition to likelihood and impact, other features of the risk
can be represented on a risk matrix. For example, the scope for achieving further risk
improvement is often represented using a risk matrix. In this case, the risk matrix will
show the level of risk in relation to additional actions that can be taken to improve the
management of that risk, and thus set a target level for it.
A risk matrix can be used to record the results of a risk assessment exercise and
this will provide a simple visual presentation of the significant risks that have been
recognized or identified. In conducting a risk assessment, it is also necessary to rank the
risks against the organization's risk appetite or established risk criteria. The risk rating
stage is referred to in ISO 31000 as risk analysis and the risk rating stage is described as
risk evaluation.
A risk is significant if it could impact more than the benchmark test for
significance for that type of risk. Identification of potentially significant risks will be done
88
during the risk recognition exercise. It is necessary to decide:
•
the magnitude of the event if the risk materializes;
•
a measure of the impact of the event on the organization;
•
likelihood of the risk materializing at or above the benchmark;
•
scope for further improvements in control.
This will lead to a clear identification of the priority significant risks. Most organizations
will find that the total number of risks identified in the workshop is between 100 and 200.
Once the risk assessment is complete, typically the number of priority significant risks
facing the organization is identified as between 10 and 20. The terminology used in ISO
31000 is a combination of the likelihood and impact of a risk, and is considered a risk
level, although this is referred to by many risk practitioners as risk severity. There are
many alternative versions of the table that provide definitions for the terms used to
describe likelihood and impact. An organization will need to generate its own definitions,
based on the size, nature and complexity of that organization. Table 10.5 provides a
general definition of likelihood in terms of the number of occasions when the event is
likely to occur over a 10-year period. Table 10.6 provides a definition of impact that can
be used in hospitals where patient safety is a key consideration.
10.5 RISK PERCEPTION:
When conducting a risk assessment exercise, it is often the case that different
participants in the workshop will have different views on risk. There are several ways to
accommodate differences of opinion. In some cases, voting software can be used to
identify the majority view. This has the benefit that it is a simple way to identify the
average position of the group, while also showing the spread of opinion.
However, it is often useful to discuss why people have different views on a risk. By
exploring why their views differ, it is often possible to reach an agreed common position.
This will have the benefit that more appropriate control measures will then be identified
and implemented. The perception of risk by individuals will is influenced by a number of
factors. The following are thought to raise concerns among the general public in relation to
certain risks to health:
•
involuntary (pollution) rather than voluntary (dangerous sports);
•
unequal (some benefit while others suffer);
•
inevitable by taking personal precautions;
•
arises from an unfamiliar or new source;
89
•
generated from man-made sources, not from nature;
•
cause hidden and permanent damage, possibly years after exposure;
•
pose a particular danger to young children or pregnant women;
•
a threatening form of death (or illness/injury) that elicits a certain fear.
Different views on the importance of risk can be present at different levels of seniority
within the organization. It is useful for the risk assessment process to draw opinions from
all levels of management, so that different risk perspectives can be identified. Again, the
benefits of this approach are better risk communication, a more complete understanding of
the risks, and the identification of appropriate and practical control measures. To
understand the risks facing an organization and be able to conduct an accurate risk
assessment, extensive knowledge of the organization is required. To complete an accurate
risk assessment that correctly identifies significant risks and then identifies critical controls
is a time- and resource-consuming exercise.
When it comes to public perceptions of risk, members of the public often only have
access to incomplete information and are subjected to strong arguments from lobbies and
other special interest groups. Therefore, the public's understanding and perception of risk
may not be sufficiently informed or fully objective. Journalists and news reporters have an
obligation to present news objectively and impartially, which may not be easy when the
people receiving the information do not have a full understanding of the risks involved.
Government risk assessment:
The government will provide an assessment of the risks affecting the public, how it
has reached its decision and how it will deal with those risks. This will also be the case
where new policy developments pose potential risks to the public. Where information must
be withheld, or where the approach deviates from existing practice, it will explain why.
Where facts are uncertain or unknown, the government will seek to clarify what the gaps
in its knowledge are. It will be open about where it has made mistakes and what it is doing
to correct them.
10.6 ATTITUDE TOWARDS RISK :
Figure 10.1 provides an empirical illustration of risk attitude using a standard risk
matrix. It represents the risk attitude of a risk-averse organization. It is becoming more
common for the risk attitude matrix contains four parts. These parts can be represented by
the 4Cs of comfort, caution, concern, and criticality. Risk attitude represents the
90
organization's long-term approach to risk. These descriptors can also be attached to the
four sections on the risk appetite matrix to describe the short-term risk-taking approach.
The relationship between risk attitude and risk appetite is discussed further in Chapter 25.
The darkest areas in Figure 10.1 represent critical risks for the organization. For
risk-aggressive organizations, there are fewer risks of concern, so the 'universe of risk'
considered by the board will be very limited. The phrase 'universe of risk' is often used by
internal auditors to identify audit priorities. Working with a closed or limited 'risk
universe' will increase the likelihood of unidentified significant risks impacting the
organization. Each different stakeholder will have a different 'risk universe' and risk
managers tend to have a 'risk universe' that includes all risks that have been identified, plus
emerging risks that are starting to emerge.
Figure 10.1 illustrates that there will be a level of risk that the organization feels
comfortable taking and incorporating into core processes. This is because, Despite the
likelihood of a risk occurring, the impact is so small as to be insignificant if it does occur.
Similarly, there will be the possibility of a risk occurring that is considered so small that it
is assumed not to occur, even though it would be very serious if it did. For example, most
organizations do not consider the consequences of an emergency landing of a jumbo jet on
their site. The global financial crisis is an example of circumstances where certain risks are
considered so unlikely that they can be ignored. Some banks were dependent on wholesale
money markets, but the likelihood of these markets failing was considered too small to
warrant further analysis or to call for the development of contingency plans to respond to
that situation.
Above these minimum tolerable levels of likelihood and impact, a range of risks
may arise. In general, low likelihood/low impact risks will be tolerated, medium
likelihood/medium impact risks will require some assessment before being accepted, and
high likelihood/high impact risks will not be tolerated. An organization's overall attitude
towards risk can be described by a set of 'risk criteria' and this is the approach taken by
ISO 31000. It should be noted that there is no specific mention of risk appetite in ISO
31000 which supports the discussion of risk criteria. The difference between risk attitudes
and risk appetite may be difficult to explain, but there are similarities with attitudes
towards food and appetite at any given time. Attitude towards food is a set of criteria set or
medium to long-term, but appetite represents the immediate need to eat. The same analysis
can be applied to risk, so that risk attitude is the set risk criteria and risk appetite is the
more immediate need to take risks to achieve goals.
Organizations need to take a risk-by-risk approach when deciding whether a risk is
91
acceptable. Different organizations will set tolerance levels differently and this will be an
indication of risk attitude. Many organizations will take a cumulative review of risk where
all risk exposures are added together, and this is a feature of the enterprise risk
management approach. The organization will then be able to decide whether the overall
risk exposure is acceptable and consistent with the organization's risk attitude. When
considering risk attitudes, perceptions and appetites, it is worth reflecting on the fact that
certain individuals may care more about low-impact risks with a high probability of
occurrence (such as a car accident) than about high-impact risks that are unlikely to occur
(such as an earthquake). These differences in approach are often reflected in the risk
assessment process and can influence the way in which significant risks are prioritized.
When all potentially significant risks have been identified, one approach is to ask
how likely each is to materialize above the significance test threshold. Risks can then be
prioritized as high likelihood, medium likelihood and low likelihood. An alternative
approach is to prioritize the potentially significant risks in terms of the order of impact on
the likelihood of the same. The risks will then be presented as high impact, medium impact
and low impact.
There are different attitudes and perceptions in this approach. The first approach
The first is based on how likely it is that the risk will be significant while the second is
based on how much the risk will impact when it occurs. Neither of these approaches is
better than the other, and which approach is preferred by individual board members (or the
collective board itself) is related to the attitude towards risk, as expressed in the risk
criteria for the organization. The impact associated with a risk is usually measured in terms
of the effect on finances, infrastructure, reputation and/or markets (FIRM). One of the key
requirements of risk management is that the consequences of high-impact events for the
organization's strategy, tactics, operations and compliance (STOC) are successfully
managed.
Risks involved in buying a car:
As an example that brings together the notions of risk appetite and hazard risk,
control and opportunity, consider the decision to buy a car. When deciding which car to
buy, there is a need to evaluate hazard tolerance and acceptance of uncertainty, as well as
the amount of money to invest for the opportunity of owning a new vehicle. Together,
these components represent the risk appetite for buying and running a car. To achieve the
benefits of taking the risk of buying a car, the benefits gained must exceed the costs
incurred.
92
If conducting a risk-based evaluation of a car purchase is to aid the decision-
making process, the intended benefits of car ownership must be established. This is
equivalent to identifying the goals associated with car ownership.
Actual financial capacity and the ability to run the car also need to be considered.
When purchasing a new vehicle, buyers need to ensure that the chosen vehicle will not
incur greater risks and costs than anticipated. Risks associated with owning a vehicle
include insurance, breakdowns, repairs, accidents, servicing and insurance costs, as well as
the purchase price and anticipated annual depreciation. Assume that the decision has been
made to purchase a two-year-old prestigious car. The car will cost less money than a new
vehicle and depreciation costs will be much less (opportunity risk). However, repair and
maintenance costs may be higher than a new vehicle (control risk). Exposure to accidents,
theft, and repair costs will be similar for most vehicles (hazard risk).
Remember that opportunity risks increase the likelihood of achieving the benefits
of owning a car. Control risks increase uncertainty or doubt about achieving these benefits
and hazard risks inhibit achieving the benefits of car ownership.
RISK CLASSIFICATION SYSTEM
11.1 SHORT, MEDIUM AND LONG TERM RISKS :
While this is not a formalized system, the classification of risks into short, medium
and long term helps identify risks related (primarily) to operations, tactics and strategy. This
distinction is not obvious, but it can help further risk classification. In fact, there will be some
short-term risks for strategic core processes and there may be some medium- and long-term
risks that may affect operational core processes. Also, there is always a requirement to ensure
compliance in operations, tactics and strategies. For most organizations, the attitude towards
compliance risk is based on the desire to minimize this type of risk.
Short-term risks have the ability to affect objectives, key dependencies, and core
processes, with an impact that is immediate. These risks can cause disruption to operations
immediately when they occur. Short-term risks are mostly hazard risks, although this is not
always the case. These risks are usually associated with unplanned disruptive events, but can
also be associated with cost control within the organization. Short-term risks usually impact
the organization's ability to maintain effective and efficient core processes related to
continuity and monitoring of routine operations. There is a need to mitigate short-term risks.
Medium-term risks have the ability to affect the organization after a (short) delay after
the event occurs. Typically, the impact of mid-term risks will not be immediately visible, but
93
will be visible within a few months, or at most a year after the event. Mid-term risks typically
impact the organization's ability to maintain effective and efficient core processes related to
tactics management, projects, and other change programs. These mid-term risks are often
associated with projects, tactics, improvements, and other developments. There is a need to
manage these mid-term risks.
Long-term risks have the ability to affect an organization some time after the event
occurs. Typically, impact can occur between one and five years (or more) after the event.
Long-term risks typically impact an organization's ability to maintain core processes related to
developing and delivering an effective and efficient strategy. These risks are related to
strategy, but should not be treated as exclusively related to opportunity management. Risks
that have the potential to undermine strategy and the successful implementation of strategy
can destroy the value of more risks to operations and tactics. Although long-term risks can be
damaging to an organization, there is a need to embrace an appropriate level of risk embedded
in the strategy.
Figure 11.1 illustrates short-term, medium-term and long-term risks in terms of their
source. Risks arise from the operations, tactics and strategies adopted by the organization. For
the sake of completeness, the compliance risk category is also included, as it is an additional
category to operations, tactics, and strategies. need to respond to risks according to whether
they arise from strategy, tactics, operations or compliance (STOC)is summarized by embrace,
manage, mitigate and minimize (EM3). The purpose of the risk management bow tie
illustration is to show that sources of risk can cause events that have consequences.
When a hazard event occurs, it will impact organizational features that may cause
disruption. For this reason, the event shown in the middle of the bow tie will be listed in terms
of the organizational components affected by the event. These components are people, places,
processes and products (4Ps), as listed in Table 3.2. It should be noted that the 4Ps can also be
considered a risk classification system.
The use of bow ties to represent risk management has become increasingly common.
Figure 11.1 provides an example of a bow tie used to represent the three components of risk
source, event and impact. In this high-level representation, risk sources are identified as
strategic, tactical, operational or compliance. Impact is represented using the FIRM risk
scorecard, as described in Table 11.1.
11.2. In the middle of the bow tie is the event, as described by the organizational components
that will be affected by the event. These components are represented in the same way as in
Table 3.2 as people, places, processes and products.
94
11.2 NATURE OF THE CLASSIFICATION SYSTEM RISK:
In order to identify all the risks that an organization faces, a structure for risk
identification is required. A formalized risk classification system allows the organization to
identify where similar risks exist within the organization. Risk classification also allows the
organization to identify who should be responsible for establishing related or similar risk
management strategies. Finally, proper risk classification will allow the organization to better
identify risk appetite, risk capacity, and total risk exposure in relation to each risk, group of
similar risks, or general risk types. FIRM risk scorecards provide such a structure, but there
are many risk classification systems available. FIRM scorecards build on various aspects of
risk, including the timescale of impact, nature of impact, whether the risk is a hazard, control
or opportunity, and the overall risk exposure and risk capacity of the organization. FIRM
scorecard titles organize risk classifications primarily as financial, infrastructure, reputation or
market.
The FIRM risk scorecard can also be used as a template for the identification of
corporate objectives, stakeholder expectations and, most importantly, key dependencies. The
scorecard is an important addition to the risk management tools and techniques available
today. It is compiled by analyzing the ways in which each risk can affect the key
dependencies that support each core process. The use of FIRM risk scorecards facilitates
robust risk assessment by ensuring that the likelihood of failing to identify significant risks is
greatly reduced. As with many risk management decisions, it is the organization that decides
which risk classification system best meets its needs and requirements. In addition to being
classified according to the timescale of their impact, risks can also be grouped according to
the nature of the risk, the source of the risk and/or the nature of the impact or the size and
nature of the consequences.
An organization will choose the risk classification system that best suits its size, nature
and complexity. For example, banks and other financial institutions almost universally
classify risks as market, credit and operational risks. Other commonly used risk classification
systems that can also be used to provide structure to a risk assessment workshop are SWOT
and PESTLE analysis. Figure 11.2 presents an operational version of the bow-tie
representation of risk management, rather than the high-level overview presented in Figure
11.1. Figure 11.2 uses a bow-tie to represent the sources of potential building damage and
retains the impacts as financial, infrastructure, reputational, and market. The potential sources
of building damage are identified as flood, fire, earthquake and break-in.
95
11.3 RISK CLASSIFICATION SYSTEM EXAMPLE:
Table 11.1 provides a summary of the main risk classification systems. These are
COSO, IRM standards, BS 31100 and FIRM risk scorecards. There are similarities across
most of these systems. It should be noted that identifying risks as: 1) hazard, control or
opportunity; 2) high, medium or low; and 3) short-term, medium-term and long-term should
not be considered a formal risk classification system.
Many organizations struggle to find a suitable risk classification system. Often, this is
due to a lack of attention paid to the nature of the risk being classified. The bow tie
representation of the risk management process illustrates that it is possible to classify risks
according to their source, the organizational component that the event impacts and the impact
and/or consequences of the risk materialize. The classification of short, medium and long-
term risks represents the operational, tactical and strategic risks facing the organization. The
categories of disruption to the organization described in Table 3.2 use a classification system
according to the affected organizational components. This is the people, place, process and
product (4P) risk classification system. The FIRM risk scorecard described in Table 11.2
classifies risks according to their impact.
There are similarities in the way risks are classified by different risk classification
systems. However, there are also differences, including the fact that operational risk is
referred to as infrastructure risk in the FIRM risk scorecard. COSO takes a narrow view of
financial risk, with a particular emphasis on reporting. Different systems have been designed
under different circumstances and by different organizations; therefore, the categories will be
similar but not identical. In describing the different risk classification systems, Table 11.1
illustrates that many classification systems offer a combination of source, event, impact and
consequence categories.
British Standard BS 31100 sets out the benefits of having a risk classification system.
These benefits include helping to define the scope of risk management within the
organization, providing a structure and framework for risk identification, and providing an
opportunity to aggregate similar types of risks across the organization. ISO 31000 does not
suggest a risk classification system. To summarize, examples of the benefits of having a risk
classification system include:
•
Accumulated risks that could undermine key dependencies or business objectives and
make them vulnerable can be identified more easily.
•
Responsibility for better management of each different type of risk can be more easily
identified/allocated if risks are classified.
•
Decisions and knowledge about the type of controls to be applied can be taken in a
96
more structured and informed manner.
•
Circumstances where an organization's risk appetite is exceeded (or risk criteria are
not applied) can be more easily identified.
The British Standard states that the number and type of risk categories used should be selected
to fit the size, objectives, nature, complexity and context of the organization. The categories
should also reflect the maturity of risk management within the organization. Perhaps the most
commonly used risk classification systems are those offered by the COSO ERM framework
and IRM risk management standards. However, the COSO risk classification system is not
always helpful and contains some weaknesses. For example, strategic risks may also exist in
operations and in reporting and compliance. Despite these weaknesses, the COSO framework
is widely used, as it is the recognized and recommended approach to meeting the
requirements of the Sarbanes-Oxley Act.
It should be noted that the COSO ERM framework (2004) is a more extensive version
of COSO, and also includes the requirements of the recently updated COSO Internal Control
framework (2013). The reporting component of the COSO internal control framework is
specifically concerned with the accuracy of financial data reporting and is designed to meet
the requirements of section 404 of the Sarbanes-Oxley Act.
11.4 RISK SCORECARD FIRM:
FIRM's four risk scorecard titles offer a classification system for risks to key
dependencies within the organization. The classification system also reflects the idea that
every organization should be concerned with its financial, infrastructure, reputation and
market success. To provide a broader scope for commercial success, the FIRM risk scorecard
headings are as follows:
F Finance;
I Infrastructure;
R Reputation;
M Market.
The features of the FIRM risk scorecard are presented in Table 11.2. Financial and
infrastructure risks are considered internal to the organization, while reputation and market
risks are external. In addition, financial and market risks can be easily measured in financial
terms, while infrastructure and reputation risks are more difficult to quantify.
The inclusion of reputational risk as a separate risk category in the FIRM risk
scorecard is not universally accepted. It is sometimes argued that reputational damage is a
97
consequence of other risks materializing and should not be considered as a separate risk
category. However, if a broader view of risk is taken, it becomes clear that reputation is very
important. This is particularly important when organizations seek to use their brand name to
enter additional markets, or achieve 'brand stretch' as it is sometimes called. There is,
however, a broader argument that all risks are consequences of broader business decisions.
Adopting a particular strategy, undertaking a project and/or continuing an established
operation all involve risk. If organizations did not undertake these strategic, tactical or
operational activities, risks would not exist.
11.5 RISK CLASSIFICATION SYSTEM PESTLE:
Table 11.3 outlines the PESTLE risk classification system. PESTLE is an acronym
meaning political, economic, sociological, technological, legal and ethical risks. In some
versions of the approach, the final E is used to indicate narrower environmental
considerations. This risk classification system is best suited for hazard risk analysis and less
easily applied to financial, infrastructure and reputational risks. The PESTLE risk
classification system is often considered most relevant to external risk analysis. External risks
PESTLE in this context is meant to refer to external contexts that are not entirely within the
control of the organization but where actions can be taken to mitigate those risks. It is often
suggested that the PESTLE risk classification system should be used in conjunction with an
analysis of the strengths, weaknesses, opportunities and threats (SWOT) facing the
organization. A SWOT analysis of each of the six ALU categories is recommended by the
Orange Book.
The advantage of the PESTLE risk classification system is that it provides a clear
analysis of the issues to be addressed in an external context. The PESTLE approach is
probably most applicable in the public sector, as the external factors analyzed with the
PESTLE approach are highly relevant. The PESTLE analysis is a commonly used structure
for risk identification purposes in risk assessment workshops. PESTLE can also be considered
a risk classification system with an emphasis on hazard risk. There are several advantages and
disadvantages of the PESTLE approach. The advantages are as follows:
•
simple framework;
•
facilitate understanding of the broader business environment;
•
encourages the development of external and strategic thinking;
•
anticipate future business threats;
•
helps identify actions to avoid or minimize the impact of threats;
98
•
facilitate the identification of business opportunities.
However, there are certain weaknesses associated with using PESTLE analysis as a means to
identify risks. These weaknesses are as follows:
•
can simplify the amount of data used for decisions;
•
needs to be done regularly to be effective;
•
requires the involvement of different people with different perspectives;
•
access to quality external data sources can be time-consuming and costly;
•
It is difficult to anticipate developments that may affect the organization in the future;
•
risk of capturing too much data which makes it difficult to see priorities;
•
may be based on assumptions that later prove to be unfounded.
11.6 COMPLIANCE, HARM, CONTROL, AND OPPORTUNITIES:
Categorizing risks according to a single risk classification system is not always
helpful. It may not be enough to understand the time scale of the impact, especially when the
nature of the impact is more important. It is for this reason that there will always be
difficulties with a simple system for categorizing risks. Each organization should identify a
risk classification system that suits its particular needs and the nature of the risks it faces.
Risks need to be classified according to source or impact as well as according to the timescale
of impact. Therefore, a combination of the FIRM risk scorecard and the classification of risks
as hazard, control and opportunity risks can be used to provide a complete picture.
It is possible to design a personal risk matrix that classifies risks according to the
FIRM risk scorecard and also classifies them according to whether they are short-term,
medium-term or long-term. This will provide a problem grid that will help identify all
possible significant risks, using a format that can be easily understood. An example of a
completed grid is presented in Table 11.4, which presents the issues that individuals may face
so that their risks can be identified. Many risk classification systems do not address
compliance risks. Risks may be classified as hazards, controls and opportunities or may be
classified as long-term, medium-term or short-term. If any of these classification systems are
used, then it is possible that compliance risks will not be identified, as they do not always
correspond to classification systems based on timescales. A further difficulty associated with
compliance risk is that there is often a requirement for a triggering event. In other words, an
organization may be exposed to a number of compliance risks but it may be difficult to
identify the specific compliance issues that will be problematic.
Table 11.4 illustrates the balance of operational, tactical and strategic issues for each
99
of the four FIRM risk scorecard headings. It can be seen that hazard risks are closely
associated with infrastructure issues and strategic risks are more likely to arise in relation to
market-related issues. The risk classification system discussed in this chapter is most easily
applied to the hazard risk analysis, except that the IRM standard and COSO framework offer
strategic risk as a separate risk category. It will be up to the organization to decide whether to
include the risk category strategic is useful and necessary. FIRM risk scorecards offer a way
to classify strategic and project (or tactical) risks according to the key impacts associated with
the risk, should it materialize.
Like any other core process within an organization, classification of the risks facing a
project is essential, so that the appropriate response to each risk can be identified. Given that
the requirement of any project is that it must be delivered on time, within budget and to
specification, this component offers a way to classify project risks. Separate lists can be
created of risks that threaten the timescale, risks that threaten the budget and risks that will
affect the final specification, performance or quality of the project deliverables.
Classification of Risks in the Financial Sector:
There is no standard risk classification system that can be used by all types of
organizations. Banks face a large number of risks and these are usually divided into three
main categories of market risk, credit risk and operational risk. Often, the risk management
framework and architecture will be different for different types of risks. Market risk is the risk
that occurs due to fluctuations in the financial markets. The bank's assets and liabilities are
exposed to various types of market volatility, such as changes in interest rates and foreign
exchange rates. Market risk is primarily an opportunity risk embraced by the bank.
When a bank gives a loan to a client, there is a risk of the money not coming back, and
this is credit risk. Credit risk is simply the possibility of adverse conditions where the client
does not repay the loan amount. It is primarily a control risk that must be managed.
Operational risk is concerned with the failure of internal systems, processes, technology and
people, and with external factors such as natural disasters, fire, etc. Basel II defines
operational risk as 'the risk of direct or indirect loss resulting from inadequate or failed
internal processes, people and systems or from external events'. Operational risk has gained
profile due to the need to quantify operational risk exposures, increased use of technology and
recognition of the critical role played by people in financial sector processes. Operational risk
is primarily a hazard risk that must be mitigated.
100
RISK ANALYSIS AND EVALUATION
12.1 RISK MATRIX IMPLEMENTATION:
The use of a risk matrix is a very simple way to show the level of risk that a particular
event represents to an organization. A risk matrix is usually used to represent the residual or
current level of risk. This can also be referred to as net risk. When a risk matrix is used to
describe the current level of risk, the vertical axis will usually be labeled as impact. However,
the risk matrix can also be used to represent the gross or inherent level of risk, which is the
level of risk before controls are implemented. When the risk matrix is used to describe the
inherent level of risk, the vertical axis can sometimes be labeled as magnitude.
The concept of consequence is slightly different. Impact is used to represent the
overall level of risk that an organization faces. This level of risk or impact will arise because
of the potential consequences. Therefore, 'consequence' is used as a broader term that provides
more detail and information about how successfully the risk is being managed. For example, a
warehouse fire may represent a major loss that has a high magnitude. If the organization is
fully insured, the impact on finances should be minimal. However, the consequences of a fire
can be significant, if (for example) other stakeholders in the vicinity are impacted and the
reputation of the organization is damaged.
Table 11.4 outlines the various problems that an individual can face. Using this
'problem box', individuals will be able to identify the priority significant risks they face. These
risks are illustrated in the risk matrix shown in Figure 12.1. Having placed the various risks on
the risk matrix, the relative importance of the risks can be easily identified. An overall view
can then be taken as to whether the risk profile (or risk exposure) is within acceptable limits
and within the individual's risk appetite and risk capacity. Large organizations often use a risk
matrix as a means to summarize their risk profile. The risk matrix is very useful and can be
used for a variety of applications. It can also be used to identify the most likely type of risk
response to use.
Impact is not the same as magnitude, as a risk may have a high magnitude in terms of
the size of its occurrence, but its impact and consequences may be smaller. To take another
example, a road transportation company may suffer the total loss of one of its vehicles, but,
depending on the exact circumstances, this may have very little overall impact on the
business. This is especially true if the company does not have enough work to fully utilize the
type of vehicle involved in the loss.
101
Risk1 = Risk 1 is the risk of injury when cycling on main roads.
Risk 2 = Risk 2 is the reduction in pension scheme benefits
Risk 3 = Risk 3 of losing a job or significant source of income
Risk 4 = Risk 4 of losing the friendship of one of the close friend groups
Risk 5 = Risk 5 is suffering from an illness that results in 3 or more days of absence from work.
12.2 DEFAULT AND CURRENT RISK LEVELS:
Many risk management practitioners assess risk at the current (also referred to as
residual) level. However, internal auditors prefer to perform risk assessment at the inherent
level. As discussed in Chapter 10, there are advantages in considering the inherent level of
risk when performing a risk assessment. Considering the inherent level will allow the effects
of individual control measures to be identified. Figure 12.2 illustrates the effect of controls on
the level of risk. Control 1 is an existing control and reduces the risk from the inherent level to
the current (or residual) level and it can be seen that this control has the main effect on the
likelihood of the risk materializing.
Control 2 in Figure 12.2 is an additional control that will be introduced to reduce the
risk from the current level to the target level. It is intended to have a significant effect on the
impact of the risk, but little effect on the likelihood of it materializing. There are three
important levels of risk in the risk matrix shown in Figure 12.2. The default or gross level is
the level of risk that would exist in the absence of controls. The current level is the level at
which the risk exists at the time of the risk assessment, when only Control 1 exists. This is
often referred to as the residual risk level.
The problem with describing the current level as a residual level is that there is an
implication that the risk level is static and that the organization cannot take further risk
mitigation actions. The use of the phrase 'current level' gives a much more dynamic feel to the
risk management process and so the phrase is used throughout this book. However, the risk
level of interest to risk managers is the target level. This is illustrated in Figure 12.2 by the
introduction of Control 2, which is intended to reduce the impact of the risk, so that the
targeted risk level is within the lower left quadrant of the risk matrix, or the tolerance/comfort
zone.
When attempting to set a target level of risk, the concept is often used by health and
safety practitioners seeking to reduce risks to the 'lowest possible' level (ALARP). ALARP is
one of the fundamental principles of risk management for health and safety risks. It is not
necessary to manage risk to the point where it is eliminated, but to the point where the cost of
102
additional control will outweigh the benefits. The concept of ALARP is illustrated in the text
box below.
As Low as Possible (Alarp):
The risk requirement to be ALARP is fundamental and is simply the requirement to
take all measures to mitigate risk where reasonable. In most cases, this is not done through
explicit comparisons of costs and benefits, but rather by applying good practices and
standards and relevant. The development of relevant good practice and standards includes
consideration of ALARP, so in many cases meeting such standards will be sufficient. In other
cases, either where the relevant standards and good practice are less clear, or not fully
applicable, action should be implemented to the point where the cost of additional action (in
money, time or trouble) would be grossly disproportionate to the further risk reduction (or
safety benefit) that would be achieved.
An organization needs to agree on definitions for likelihood and impact. Both
likelihood and impact can be described in terms of low, medium, high and very high. Many
organizations need to be more specific than these general descriptions, depending on the type
of risk and the size, nature and complexity of the organization. Since impact is used to
describe a wide range of consequences, it is more important for organizations to describe low,
medium, high and very high impact. There should be consistency between the definition used
for impact and the significance benchmark tests described in Table 12.1.
12.3 TRUST CONTROL SELF:
The desired effect of individual control measures is illustrated in Fig.
12.2. It is impossible for an organization to be absolutely certain that controls will always be
fully implemented and will be as effective as expected or required. Controls need to be
audited to enable assurance that the selected controls have been properly designed and
implemented and are producing the desired effect.
The degree of control confidence can also be depicted on the risk matrix. If the
effectiveness of the control is uncertain, greater variability of the results can be expected. This
can be shown on the risk matrix by using circles or ellipses to represent the risk, instead of
representing the risk as a single point on the risk matrix. By doing this, the degree of
uncertainty or variability in the outcome can be illustrated in relation to the likelihood and
impact of the event materializing.
An important consideration when conducting risk assessments and when evaluating
the effectiveness of risk management in general, and risk control measures in particular, is the
103
level of confidence that should be placed in a particular control. Two questions need to be
asked: 'How confident are we that this is the correct control?' and 'How confident are we that
it is fully implemented and effective in practice?' When there is limited confidence in the
effectiveness of a control, it will be the role of internal audit to test the control and provide
information on the likely degree of variability of results, should the risk materialize.
It is the internal auditor's responsibility to check that the correct controls have been
selected and that they work correctly in practice. Internal auditors refer to effective and
efficient controls respectively when reviewing these points. The use of effective and efficient
is also included in this book in relation to the organization's core processes. Testing controls is
a key function fulfilled by internal audit and the importance of testing controls should also be
recognized by risk management practitioners. Management needs to receive assurance of
adequate controls and this can come from internal audit activities, or measurements of activity
and project outputs, as well as from management reports. Responsibility for designing and
implementing controls and auditing the effectiveness and efficiency of controls should be
allocated in the risk management documentation.
12.4 4T RISK RESPONSE HAZARDS:
Figure 4.1 provides a diagram of the risk management process. This diagram describes
the stages of the risk management process in relation to hazard risk management. The options
presented for risk response can be described as the 4Ts of hazard management, namely:
tolerate, treat, transfer and terminate. It is possible to illustrate the 4Ts of risk response on a
simple risk matrix and this is done in Figure 15.1. This figure shows that in each of the four
quadrants of the risk matrix, one of the 4Ts will be dominant, as follows:
•
Tolerance will be the dominant responseto low-probability/low-impact risks.
•
Treat will be response dominant to risk high likelihood/low impact.
•
Transfer will be the dominant response for high impact/low probability risks.
•
Terminate will be response dominant to risk high impact/high likelihood.
Options for responding to opportunity risks are identified as the 4Es and opportunity-related
decision-making is described in terms of the 5Es. It is important to note that these responses
are represented as the dominant or most likely response in each quadrant, but circumstances
may dictate that other responses may be required as well, or vice versa. Different and/or
additional responses may be appropriate, depending on the circumstances. For example, if
high-impact/high-likelihood risks are embedded in mission-critical activities, they may be
unavoidable. In this case, it may not be possible for the organization to stop the risk.
104
The difficulty in presenting a simple risk matrix showing the 4Ts of risk response is
that they meet in the middle. Obviously, it cannot be as simple as suggested, because small
changes in the likelihood and impact of a risk can take it from the termination quadrant to the
tolerance quadrant. A slightly modified approach that makes this analysis somewhat more
realistic is discussed in Chapter 16. The practical difficulty for many organizations is that they
may be forced to retain risks that are recognized as being outside the risk appetite, or even risk
capacity, of the organization.
For example, a fire authority may have to accept circumstances where firefighters will
face a critical level of risk that the organization has no choice but to tolerate, despite all
possible controls having been implemented. Where the organization has to tolerate a risk that
is at a critical level, normally enhanced risk monitoring should be implemented. This will
allow the organization to ensure that it takes the earliest opportunity to introduce enhanced
controls as soon as they become available.
12.5 RISK SIGNIFICANCE:
When conducting a risk assessment, it is very common to identify a hundred or more
risks that may affect the objectives, core processes or key dependencies under consideration.
This is an unmanageable number of risks so a method is needed to reduce the number that will
be considered a priority issue for management. In order for an organization to concentrate on
significant risks, a test for risk significance is required. Table 12.1 provides suggestions on the
nature of benchmark tests that can be used to decide whether a risk is significant. For risks
that will have a financial or commercial impact, the benchmark test is likely to be based on
monetary value. For risks that could disrupt an organization's infrastructure or routine
operations, benchmark tests based on impact, cost and duration of disruption are appropriate.
For reputational risks, the most likely benchmark will be based on the adverse publicity that
will occur if the risk materializes.
This may vary according to the nature of the risk and whether it is a financial or non-
financial risk. For large organizations, identifying financial tests for significance can be done
in a number of ways. Many organizations will have authorization procedures for spending
money, so the risk significance test should correspond to the level of authorization, which is
often set out in a formal document referred to as a 'delegation of authority'. For large
organizations, it may be the case that full board approval is required for expenditures that
exceed certain financial thresholds. This is an indication of the amount of money the
organization considers significant. Other tests include a percentage of budgeted profit for the
year or a percentage of the value of the organization's balance sheet (or reserves). Typically, 5
105
percent of annual profit or 0.25 percent of the balance sheet or 0.5 percent of annual turnover
are appropriate tests for significance. For an organization with a balance sheet of £2 billion,
annual turnover of £1 billion and planned annual profit of £100 million, the significant
financial threshold is £5 million.
Financial limits can be used to test whether a risk is significant in relation to the
financial and market risk segments of the FIRM's risk scorecard. For the infrastructure and
reputation segments, identifying benchmark tests for significance may be more difficult. One
test of significance for infrastructure risks is to ask whether the risk would disrupt normal
operations for more than (for example) half a day. For reputational risks, the test for
significance may be to determine how the event will be reported. A report on the front page of
a local newspaper or in the national press may be an indication that the risk should be
considered significant.
An organization, it is possible that the external auditor may
indicates that an amount of £1 million would be considered a material amount when preparing
the organization's accounts. This would provide guidance to company management to use that
amount as the benchmark for the significance test, although it may be slightly lower than the
calculation above. Applying this test during the risk assessment workshop may reduce the
number of risks for further consideration to around 20. The next stage is to identify how likely
it is that each of the 20 potentially significant risks will materialize at or above the financial
threshold level. A risk matrix can be used to record and display the results.
12.6 RISK CAPACITY:
There are several aspects that are important when an organization decides how much
risk to take. Different approaches will be taken for different types of risks. Hazard risk will
give rise to hazard tolerance, control risk will give rise to control acceptance and opportunity
risk will give rise to investment appetite. Overall, the organization will have a total risk
exposure. This is the sum of the total risks the organization has taken on in these three
categories. There will also be compliance risk, but most organizations seek to minimize
compliance risk and have the necessary compliance controls embedded in core processes.
Risk exposure is the actual risk the organization is taking and this may not be the same
as the risk appetite the board believes is appropriate for the organization. There is also another
important risk measure, and that is the organization's risk capacity. This is a measure of how
much risk the organization should take or can afford to take. All of these ways of analyzing
risk should match the organization's attitude towards risk. In simple terms, the board's risk
appetite should be within the organization's risk capacity and greater than or equal to the
106
actual risk exposure the organization faces. A contributing factor to the global financial crisis
was that certain financial institutions were exposed to levels of risk beyond the risk-bearing
capacity of those organizations.
It is not appropriate for an organization to embark on a project that could consume all
its resources. An organization's capacity to accept risk will depend on its financial strength,
the robustness of its infrastructure, the strength of its reputation and brand, and the
competitive nature of the market in which it operates. The faster the market changes, the more
risk capacity the organization should have. For example, if a When an organization faces
significant technological change, strategic options may be limited. Consider an organization
involved in manufacturing DVD players when it becomes clear that streaming technology is
taking over. The organization will face significant risks associated with technological change
and will need to develop a new business model. The company will have to acquire new
production equipment, new skills, and new distribution patterns. It may be that the transfer to
the new technology and the risks involving it are beyond the resources and risk capacity of the
organization. If that is the case, the organization may need to explore strategic options,
including seeking a joint venture partner, finding a buyer for the business or simply
withdrawing from the market.
The box below provides a concrete example of the aftermath of the global financial
crisis. The financial institution discussed here found that its risk exposure was greater than its
risk capacity. Recognizing the situation, the financial institution then released a statement to
shareholders. In this example, the bank clearly stated that its risk exposure exceeded the
organization's risk appetite and even its risk capacity. Many circumstances will arise where
organizations are exposed to risks that could be devastating to them if the risks materialize.
For some organizations, there may be multiple individual and even independent risks, each of
which can be devastating to the organization. In these circumstances, the challenge for the risk
management function is to focus on the circumstances that could trigger one or more of these
risks. In the example in the box, the bank was fortunate enough that circumstances did not
arise that would trigger an event that would destroy its balance sheet.
Bank Risk Capacity:
Risk capacity is the level of risk that a bank considers itself capable of absorbing,
based on its earnings power, without damaging its ability to pay dividends, its strategic plans
and, ultimately, its reputation and business continuity. It is based on a combination of
budgeted, forecast and historical income and expenses, adjusted for variable compensation,
dividends and related taxes. Risk exposure is an estimate of potential losses based on current
107
and prospective risk positions across key risk categories - primary risk, operational risk and
business risk.
These are built as far as possible on the basis of statistical loss measures used in day-
to-day operating controls. Correlations are taken into account when combining potential
losses from risk positions in different risk categories to obtain an overall estimate of risk
exposure. Risk exposures are assessed against a constellation of severe but plausible events
over a one-year time horizon up to a 95 percent confidence level or a 'once in 20 years' event.
The risk appetite is set by the board, which sets an upper limit on the aggregate risk exposure.
A comparison of risk exposure with risk capacity serves as the basis for determining whether
current or proposed risk limits are appropriate. This is one of the tools available to
management to guide decisions on risk profile adjustments.
Risk exposure should normally not exceed risk capacity, but in the recent extremely
difficult market conditions, this relationship does not hold. The bank recorded a large net loss,
indicating that risk exposure remains greater than risk capacity risk. Risk exposure remained
high as a result of the lack of liquidity in the market for securitized assets and due to
significantly elevated levels of volatility in global markets. The reduction in risk exposure
achieved through sales in addition to the significant reduction in risk positions was offset by a
simultaneous reduction in risk capacity due to the downward revision of earnings expectations
as a consequence of the deteriorating economic outlook.
Students also viewed