108
CONTROL LOSS
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 5
13.1 POSSIBILITY RISK:
Risk likelihood indicates how often the risk is expected to materialize. It can also be
described as risk frequency. However, using the phrase risk frequency assumes that risks
occur regularly. The more general term risk likelihood is used throughout this book. Risk
likelihood can be determined on an inherent basis for each specific risk, or it can be
determined at the current risk level, taking into account existing control measures.
For hazard risks, previous history may be a good indication of how likely the risk is to
occur. For a fleet of motor vehicles, there must be a history of accidents and vehicle damage.
Controls will be put in place to reduce the likelihood of these occurrences. Road haulage
companies should assess the likelihood of vehicle damage on an inherent basis and also on the
basis of current controls. However, there are difficulties in assessing the inherent likelihood of
vehicle accidents, as certain assumptions must be made about what effect the removal of
controls will have on the likelihood of accidents.
Even if an assessment of the likelihood of damage at an inherent level cannot be made,
companies still need to determine the importance of vehicle maintenance programs in
preventing vehicle damage and whether maintenance activities provide value for money. With
respect to vehicle accidents, companies may have driver training procedures in place and,
again, the effectiveness of these procedures can be determined by evaluating the inherent and
current levels of risk. Whether the level of risk is evaluated at an inherent level or at a current
level, there is no doubt that comparing fleet performance to industry average performance
would be a useful exercise.
An example of a control measure that affects the magnitude of risk but may not affect
the likelihood is the use of seat belts in cars. In simple terms, drivers wear seat belts to reduce
the impact of an accident, as seat belts have no effect on the likelihood of an accident
occurring. Drivers wear seat belts as a control measure when an accident occurs. Sports clubs
want to reduce the likelihood of key players being absent. Absence can be caused by
109
inappropriate behavior of a player, so it is necessary to sanction the person. Therefore, the
club may decide to introduce a 'code of conduct' for senior players, and this will include a
commitment by each player to follow an appropriate healthy lifestyle. Failure to adhere to the
code of conduct will result in financial and other penalties.
Clubs may also decide that additional controls are needed to reduce player
absenteeism, including fitness monitoring and social support for overseas players who have
recently moved to the country to join the team. Also can It was agreed that efforts should be
made to place contractual limits on the ability of national teams to call up overseas players.
These measures will be carried out in addition to other loss control activities, such as
excellent medical facilities to provide immediate medical care and mitigate damage in the
event of an injury. Also, companies can purchase insurance to protect themselves from
financial losses associated with the absence of players.
13.2 MAGNITUDE RISK:
Reducing the magnitude of hazard risk is very important. For hazard risks, the
magnitude is often referred to as the inherent severity of the risk should it materialize.
Reducing the overall severity of the hazard risk will be achieved by reducing the impact and
consequences when an adverse event occurs. A seat belt on a car can reduce the impact of an
accident, but it has no effect on the likelihood of an accident occurring. It is possible for a
serious fire to occur that results in considerable property damage and is considered very
severe and costly. However, in reducing the severity of a serious fire, the requirement is to
reduce the impact of the fire on the organization's finances, infrastructure, reputation and
market (FIRM). Actions to reduce the impact will concentrate on limiting damage at the time
of the fire and controlling costs after the event. Consequences relate to the effect on the
organization's strategy, tactics, operations and compliance (STOC). Loss control is concerned
with mitigating the magnitude, impact and consequences of adverse events.
Damage limitation is also an important feature of reputation risk management. When a
serious incident occurs that attracts public attention, an organization must be able to protect its
reputation by assuring stakeholders that it responded appropriately to the event. It is almost
always the case that the CEO or head of the company will arrive at the scene of a serious train
or plane crash. There are instances where a serious incident has occurred and media
management by the organization has been very poor. In these cases, it is likely that
insufficient attention was paid to pre-incident planning, so the damage to the organization's
reputation was not effectively minimized at the time of the incident. Organizations also need
to pay attention to cost containment. Cost containment after an event is usually based on the
110
business continuity plan (BCP) or disaster recovery plan (DRP) that the organization created
before the incident occurred. The development of effective BCPs and DRPs will put the
organization in the best position to ensure that the overall cost of the incident is kept as low as
possible.
Fire Control in Hotels:
Given the long emphasis on fire danger, it is perhaps not surprising that improvements
in sprinkler systems have been a hallmark over the past 40 years. The single most impressive
innovation relating to fire is the advent of suppression mode sprinklers. Standard sprinklers
are control mode sprinklers, which control the fire until someone comes to put it out. The fire
can get bigger and produce a lot of smoke.
As hotel fixtures became more susceptible to smoke and water damage, the desire was
to suppress the fire, not just control it. New sprinklers resulted in a smaller area exposed to
fire with less smoke and less damage. Sprinkler technology has evolved significantly. Where
we had one standard spray sprinkler head, we now have extra-large orifice heads and rapid
response sprinkler heads with pre-suppression. The use of sprinkler systems has also spread
from more traditional manufacturing facilities to light hazard exposures such as offices and
nursing homes.
Companies are becoming more involved in loss control efforts. For example,
The hotel undertook two initiatives in the early 1980s using controlled fire to prove the
efficacy of plastic piping in hotel room sprinkler systems. Prior to the successful tests,
sprinklers relied on iron pipes, which were more difficult to install than plastic and which
rendered rooms unusable for days during reinstallation.
13.3 RISK DANGER:
The range of hazard risks where reducing the magnitude of adverse events is important
would include fraud, health and safety, property protection and efficient operation of IT
systems, as well as incidents with the potential to damage reputation. Table 13.1 provides a
list of key dependencies that can give rise to a risk of harm, using the FIRM risk scorecard
structure. When a hazard risk arises, actions need to be taken to reduce the magnitude of the
event, as well as mitigate its impact and consequences. While the primary focus of hazard risk
management is on loss prevention, successful hazard risk management should also include
considerations of damage limitation and cost containment. There is a growing trend in the
insurance market towards settling claims in a more efficient and cost-effective manner. This
trend is partly based on organizations' drive to return to normal operations as soon as possible.
111
Indeed, some insurers refer to this type of initiative as 'cost containment'. As mentioned
earlier, reducing incident severity should be seen as part of an overall effort to implement loss
control within an organization. An integrated approachto loss controlis important because
itwill enable an organization to control the likelihood and impact when a hazard risk
materializes. In fact, loss control should be considered as prevention loss plus damage
limitation plus cost containment.
Although the most important component of loss control is loss prevention, hazard risks
can materialize despite the best efforts of the organization. Adequate assessment of the hazard
risk is essential, so that proper pre-planning of during-loss and post-loss actions can be done.
Plans should be made to ensure that the damage caused by the incident is kept to a minimum
and the cost consequences of the event are also tightly controlled and controlled.
Figure 13.1 shows how a bow tie can be used to illustrate the three components of loss
control. Before an event occurs, the organization will have controls in place to achieve loss
prevention. As the event develops, steps must be taken to limit the damage caused by the
event. After the event, cost containment controls through business continuity and
arrangements to reduce repair costs should be activated. Disaster recovery plans will be
relevant during the damage limitation stage and the cost containment stage. The relationship
between the three components of loss control and the type of control to be selected is
discussed in more detail in Chapter 16. The types of hazard control are described in Chapter
16 as preventive, corrective, directive and detective.
13.4 LOSS PREVENTION:
Another way to look at loss control activities is that loss prevention is about reducing
the likelihood of an adverse event occurring, although it will also be concerned with reducing
the magnitude of the event that does occur. Damage limitation is concerned with reducing the
magnitude of the event when it materializes. The contribution of damage limitation will be
greatest if actions are planned that can be implemented when the event actually occurs. Cost
containment relates to reducing the impact and consequences of the event. Cost containment
will be concerned with ensuring the lowest repair costs, as well as business continuity plans to
ensure that the organization can continue operations after damage to the affected assets.
Techniques for loss prevention will vary according to the type of hazard risk being
considered. For health and safety risks, loss prevention is related to eliminating the activity
completely or ensuring that, for example, hazardous chemicals are no longer used. For risks to
buildings, loss prevention techniques involve controls such as the removal of sources of fire
and the control, containment and separation of flammable or combustible materials. Loss
112
prevention techniques will also include smoking restrictions and other measures taken to
reduce dangerous behavior by people using the building. For fraud and theft risks, loss
prevention techniques will include separation of responsibilities and security marking of
expensive items. Fraud prevention techniques may also involve pre-employment screening.
More detailed considerations on health and safety risks and fraud prevention are set out in
Chapters 16 and 23.
13.5 DAMAGE LIMITATION:
Damage limitations in relation to fire hazards are well established. Although sprinkler
systems are often thought of as a loss prevention measure, they are actually the primary
control measure to ensure that only limited damage is done when a fire occurs. Other damage
limitation factors associated with fire include the use of fire separation within buildings, the
use of fire enclosures and well-trained arrangements for moving, separating or protecting
valuables. Following the fire at Windsor Castle in 1992, arrangements were quickly made to
remove valuable works of art from areas of the castle that were (until then) unaffected by the
fire.
Workplace accidents still occur, despite considerable attention being paid to health
and safety standards and other loss prevention activities. Provision of adequate first aid
arrangements is an obvious damage limitation activity and appropriate first aid facilities are
provided by most organizations. For some high-risk factory work, emergency care
arrangements and even medical facilities are provided on site. In some cases, these medical
facilities will include specialist treatment facilities related to the particular hazards on site. An
example is the provision of cyanide antidotes in factories where chromium plating activities
are carried out using cyanide plating solutions. A simpler example is the provision of
emergency eyewash bottles at hazardous chemical handling sites.
The Deepwater Horizon oil spill in the Gulf of Mexico in 2010 provided many risk
management lessons. One of the key issues is that oil spills take several weeks to stop. Loss
prevention measures are taken to prevent oil spills from starting and cost containment
measures are taken to manage cleanup, recovery and business continuity costs. Perhaps, the
damage limitation measures are not as strong as they may need to be. As the oil leak lasted
several weeks, there was an opportunity to implement damage limitation measures. However,
it seems that these measures were not sufficiently planned in advance.
13.6 DETENTION COSTS:
When the risk of harm materializes despite efforts made for loss prevention and efforts
113
that have been made to limit damage, there may still be a need to contain the costs of the
event. For example, among the activities to minimize the costs associated with a serious fire
are detailed arrangements for rescue and arrangements for decontamination of special items
that have suffered water or smoke damage. Cost containment in relation to fire will also
include arrangements for specialist recovery services. The actions to be taken to ensure that
post-incident costs are minimized should all be set out in business continuity, disaster
recovery and crisis management plans, as appropriate. The topics of business continuity
planning and disaster recovery planning are discussed in more detail in Chapter 18.
A further consideration relevant to cost control after an incident is what insurers refer
to as 'increased operating costs'. Most material damage/business interruption insurance
policies will allow for payment of increased operating costs. This may arise when an
organization has to subcontract certain production activities, or has to carry out manufacturing
work at one of its other plants, which may be located some distance away. If a manufacturer
discovers that defective goods have been released into the market, a number of actions
become necessary. The organization should develop a plan before the event to inform
customers about the fact that faulty goods are on the market and how to identify them. The
box below considers the importance of product recalls in these circumstances.
Product recall risk management:
Any company or organization that manufactures, assembles, processes, wholesales or
retails products can be financially impacted by the direct or indirect costs of a product recall.
Direct costs can include wages for staff who have to implement the recall plan. Other direct
costs include communication and This may entail purchasing airtime on radio and television
and notices in newspapers or industry publications.
Indirect costs can include lost production time for staff who have to
focus on the recall process, as well as the hiring of temporary employees to ensure continued
production. However, the biggest indirect cost is the impact of adverse publicity on market
share. Product recalls should be designed for:
•
protect customers from bodily injury or property damage;
•
removing products from the market and from production;
•
comply with specific regulatory requirements;
•
protect the company's assets.
114
DEFINING THE SIDE OF RISK
14.1 UPSIDE RISK:
Defining the upside of risk is one of the biggest challenges for risk management. The
overall contribution of risk management is to help deliver mandatory obligations, assurance,
enhanced decision-making, and effective and efficient core processes (MADE2). However,
there is a desire among risk management practitioners to identify a more dynamic range of
benefits that successful risk management can deliver. Often, these are benefits that are
unexpected or greater than expected from risk management.
Various interpretations of the phrase 'risk reversal' are possible, and some of these are
offered in Table 14.1. There is a belief among risk management practitioners that risk
management makes a significant contribution to an organization's operations, and this
contribution is often described as the upside of risk. In simple terms, the upside of risk is
achieved when the benefits derived from taking the risk outweigh any benefits that would
result from not taking it. In other words, the organization has received an overall benefit from
undertaking the activity that resulted in exposure to the risk or set of risks involved.
For example, a manufacturing company that produces waste products
By-products that create disposal problems can achieve reverse risk by selling unwanted by-
products or by identifying means to add value to waste products and selling them as another
product stream. This is an example of identifying a hardship for a business and, in solving that
hardship, obtaining additional benefits that were not foreseen and not available. Simply put,
the benefit of risk may be the reward for taking the risk in the first place. Climbing a
challenging mountain may be a significant risk, but the benefit of taking that risk is when the
climber has reached the top safely and earned that reward. Another approach is to say that risk
management is concerned with achieving the best possible outcome and reducing uncertainty
or volatility. If this is accepted as the definition of risk management, the gain from risk is
simply achieving what the organization wants to achieve, by taking the risks embedded in the
strategies, tactics, and/or operations involved.
Another interpretation of risk advantage is that risk assessment workshops should also
focus on identifying risks that have positive outcomes. The risk assessment workshop will
therefore answer questions such as: 'What events will create better than expected outcomes?'
A list of positive outcome risks can then be identified and actions can be taken to make those
upside risks more likely to occur and/or have more favorable impacts and consequences when
they do materialize.
115
A more satisfactory explanation of the benefits of risk is that the organization will be
able to undertake activities that it would not want to undertake otherwise. In a commercial
sense, this allows the organization to capture business opportunities that competitors either do
not want to take, or consider too risky. This may be because of greater efficiencies within the
organization, or because a cost-effective way to change the organization with development
projects has been identified that competitors have failed to recognize. At a strategic level, this
increased risk may arise from the organization identifying means to target business
opportunities, but only the profitable components of those business opportunities.
A further way to look at the upside of risk is to reflect on business ventures that turned
out to be successful in circumstances where failure could have been foreseen. This is a
somewhat retrospective approach based on analysis: 'it could have gone wrong, but it didn't,
and therefore we enjoyed the benefits of taking that risk.' This approach to the upside of risk
depends on the organization's desire to pursue risky ventures, albeit with adequate controls,
that lead to positive outcomes in situations where competitors may be unwilling to take risks.
Finally, there is a risk upside analysis that reflects the benefits of having a robust risk
management process. Achieving the benefits of MADE2, especially the benefits associated
with mandatory obligations, may be considered a sufficient reason to undertake risk
management initiatives. In these circumstances, certain organizations may consider that
achieving compliance with mandatory obligations is a beneficial risk.
In its simplest form, and particularly in relation to hazard risk, the advantage of risk is
that the losses are smaller. However, that is not a very compelling reason for senior managers
to support risk management initiatives. Perhaps the easiest thing to explain and the most
convincing thought is that the advantage of risk is the ability to pursue business opportunities
that competitors will not accept. It would also be part of the explanation to say that
competitors would be too risk-averse to take on such high-risk opportunities.
With so much talk about the upside of risk, this is a problem for risk management
practitioners. The range of analysis from less adverse to formalized opportunity management
is vast and lacks focus. The board of an organization will not be persuaded by a broad and
vague set of concepts and approaches. Clearly, the risk management discipline needs to gain a
better understanding of the benefits of risk and sell the message to the board. There may also
be scope for risk management standards to take a more coherent approach to the upside of
risk. The approach used in some risk management standards is that the 4Ts should be
expanded to include a fifth T of 'taking risks' and become the 5Ts. Very often, the standards
set fail to recognize that organizations will take opportunities and desired rewards, rather than
deliberately taking risks for their own sake.
116
The story in the box below is an example of an individual who saw an opportunity
and capitalizes on that opportunity. He does not seek, embrace or take risks, except to the
extent that it is embedded in taking the opportunity. It is the case that individuals who are seen
as risk takers are, in fact, individuals who are willing to explore opportunities that others may
consider too risky. Their behavior is about embracing opportunities, not necessarily enjoying
taking the associated risks.
Honesty Box and Profit from Risk:
Consider the case of a vendor on Wall Street, New York City, who sets up a booth and
sells donuts and coffee to passersby as they enter and exit their office building. During
breakfast and lunch hours, he always had a long queue of customers waiting. He noticed that
the waiting time discouraged many customers who left and went elsewhere. He also noticed
that, because he was a one-man show, the biggest obstacle preventing him from selling more
donuts and coffee was the disproportionate amount of time it took to make change for his
customers.
Finally, he placed a small basket on the side of his stand filled with notes and coins,
trusting his customers to make their own change. You might think that customers accidentally
miscounted or deliberately took an extra quarter from the basket, but what he found was the
opposite - most customers responded honestly, often leaving a larger tip than usual. In
addition, he was able to move customers at twice the speed because he didn't have to make
changes. In addition, he found that his customers liked to be trusted and kept coming back. By
extending trust in this way, he was able to double his revenue without adding any new costs.
14.2 OPPORTUNITY ASSESSMENT:
Successfully embracing business opportunities is more likely to be achieved if the
organization conducts an opportunity assessment. Many consulting firms conduct a detailed
evaluation of each new business prospect. The organization will look at the new prospect and
evaluate the scope profitable partnerships, opportunities to earn additional income, and
reputational benefits that may arise from having such potential clients as customers.
Opportunity assessments can be conducted in relation to new business ventures, as well as
new clients. This opportunity evaluation is designed to identify additional business
opportunities that could arise from winning that client's business. The evaluation will also
look at the potential downsides of successfully acquiring client leads. When conducting such
an opportunity assessment, there should be a possibility that the organization will inform the
prospective client that they do not wish to tender for the business.
117
Consider an option for theaters that find that fewer people are comes to the show and
decides to look at opportunities to take more money from those who continue to attend.
Options could include general improvements to the catering facilities within the theater and
the provision of organic produce at the theater restaurant. Additionally, there is the possibility
of selling specific show-themed merchandise. In addition to looking at increasing revenue
during performances, theatres can also look at sponsorship arrangements and open dialog with
local businesses to discover what types of productions are most likely to gain local support
and sponsorship. In the future, part of the assessment of each proposed new production could
include evaluating the level of sponsorship that might be available. In addition to generating
greater revenue, this approach also allows theaters to stage productions that are deemed too
risky.
Many organizations already practice opportunity management, although it may not be
seen explicitly as a risk management approach. Ideally, opportunity management should be
incorporated into procedures for developing and implementing strategies and tactics and/or
capitalizing on business opportunities. Some organizations do not have explicit opportunity
management procedures for the evaluation of new business prospects, or for the evaluation of
merger/acquisition opportunities. When attempting to identify opportunities, many
organizations facilitate risk assessment workshops that attempt to identify and analyze hazards
and opportunities at the same time. Figure 14.1 provides an example of a risk matrix that can
be used to record the results of such risk assessment workshops. The exact design of the risk
matrix and the descriptors of likelihood and consequence will vary between organizations.
Figure 14.1 should be treated as one example or illustration of how to record the outputs of a
risk assessment workshop.
One of the challenges when conducting a risk assessment workshop that includes both
opportunities and hazards is that many people need to attend the workshop. Hazards tend to be
associated with operations and compliance, while opportunities tend to be associated with
strategy and tactics. As with hazard risks, the identification and analysis of opportunities
should be followed by an evaluation of the opportunity and identification of actions or
controls that need to be put in place to ensure that the anticipated benefits are more likely to
be achieved. The opportunity assessment methodology described earlier in this section needs
to be applied to the opportunities that have been identified, analyzed and recorded on the risk
matrix.
118
14.3 INDEX RISK:
The risk profile of an organization can be represented in many ways. The most
commonly used method is to prepare a risk register containing details of the significant risks it
faces. However, the drawback of a risk register is that it is usually a qualitative evaluation of
individual risks. Organizations need to develop tools to measure, evaluate, and calculate the
total risk exposure of the organization. One of the features of an enterprise risk management
approach is to develop a consolidated view of the organization's risk exposure. The approach
based on calculating the total risk exposure of an organization is similar to the approach taken
to risk measurement and quantification in operational risk management. This section
introduces the idea of a 'riskiness index'. The idea is to present a semi-quantitative approach
that takes a snapshot of the overall level of risk embedded in the organization. The overall
level of risk will take into account the strategy currently followed by the organization, the
projects underway, and the nature of routine operations performed. This approach can offer an
opportunity to benchmark risk management performance and track changes over time.
Table 14.2 presents a series of questions that can be used to develop a risk index for an
organization. The table uses the FIRM risk scorecard structure as a means to categorize risks.
Using the risk index, the organization should be able to identify the level of risk it faces in
financial, infrastructure, reputation, and the level of risk it faces in the marketplace. After
completing the risk index, the organization can then look for additional controls to reduce the
level of risk. The main focus of risk management is then just to reduce the level of riskiness in
the organization without affecting strategy, tactics, operations or compliance (STOC). The
advantage of risk then becomes that the organization can follow the desired STOC at the
lowest achievable risk level reasonable and cost-effective. The level of risk identified by the
riskiness index represents the organization's risk exposure. The board can then compare this
level of risk exposure to the organization's risk capacity and the board's attitude to risk.
Calculating an organization's riskiness index requires identifying the hazard risks that
the organization actually takes on. In other words, evaluating the riskiness index of an
organization helps identify the actual risk exposure of the organization. After identifying the
actual level of risk embedded in an organization, the board of that organization can then ask
whether the risk portfolio is within the risk appetite and/or risk capacity of the organization
and in line with the board's risk stance. . The 2016 version of the UK Corporate Governance
Code contains the following requirements for companies listed on the London Stock
Exchange:
119
The Board is responsible for determining the nature and extent of key risks it is willing to take
in achieving its strategic objectives.
Organizations should take care to ensure that, having identified the risks they are taking by a
mechanism similar to calculating a risk index, the board does not then simply decide that the
risk taken at this time should be equal to the desired risk to take.
14.4 REVERSE IN STRATEGY:
The organization will have a mission statement, along with a set of corporate
objectives and an understanding of the expectations of different stakeholders in the
organization. The organization's board will then need to develop effective and efficient
strategies that will deliver exactly what is expected in terms of mission, goals and
expectations. To make the correct strategic decisions, the organization's board will need
access to risk information. A risk assessment of the proposed strategy, along with a risk
assessment of any viable alternative strategies, should be conducted. The availability of this
risk assessment information will ensure that strategic decisions are more likely to be correct.
For opportunity risk, there may be less data available to predict
possible risks. An organization may see an opportunity to gain new clients or develop and
market a new product. An accurate risk assessment of the likelihood of positive and negative
events will be required to determine whether the new venture should proceed. When a new
product is launched, the requirement may be to increase the likelihood of positive events
occurring. If a new product is launched, advertising and press coverage will need to be
maximized so that this remains cost-effective. Therefore, measures should be taken to
increase the level of media interest in the launch.
The strategic core process brings together the disciplines of strategic planning and risk
management. Strategic planning is a systematic process of gaining consensus at the board
level on a small number of issues that can have a major impact on the long-term performance
of the organization. Strategic issues are critical, and failure to implement a strategy or
inappropriate strategy selection can be one of the most devastating risks to hit an organization.
Strategy implementation is usually achieved by developing tactics that are implemented
through projects and ultimately delivered by operational core processes. The operational core
processes in place at any given time represent the organization's business model, as discussed
in more detail in Chapter 20.
Risk management activities are designed to ensure the best possible outcome and
120
reduce uncertainty. Therefore, the advantage of risk in strategy is that risk management efforts
help design effective and efficient strategies. The implementation of such strategies will be
achieved through the tactics employed. The tactics will be designed to improve the core
processes within the organization, so that the organization uses the most effective and
efficient core processes. The boxed example illustrates a risk management attitude that sees
risk as opportunity. This approach to organizational management shows a willingness to
accept the positive side of risk.
14.5 REVERSE IN PROJECT:
It is important that every organization adopts the correct core processes. Core
processes can be thought of as the collection of activities that deliver stakeholder expectations
specific interests. This is what is meant by the core processes allocated by Business Process
Re-engineering (BPR) practitioners. There is a difference between efficient and effective
processes. An efficient process means that there are no disruptions and no excess costs.
However, the process may be wrong to meet the requirements cost-effectively. Where
processes need to be improved, projects will usually be undertaken and changes achieved. In
circumstances where a series of projects are required, this is often referred to as a work
program. When a project, or work program, is implemented by an organization, it is usually a
desire to improve the effectiveness and/or efficiency of a core process.
By conducting an adequate risk assessment of the intended changes,
The organization must be able to ensure that projects are more successfully delivered on time,
within budget and to specification. Achieving the upside of risk in project or program
management requires that projects are adequately managed and that the correct projects or
priorities have been selected by the organization. Often, organizations will conduct post-
implementation reviews to ensure that the expected benefits of the project have been delivered
in practice. These reviews are often conducted by internal audit and are designed to ensure
that the project was successfully implemented, delivered the required benefits and was overall
of value. During difficult financial times, it is important for organizations to select projects
that are not only successful, but also represent the best allocation of limited resources when
compared to alternative projects that have not been selected.
Risk management in projects is associated with the implementation of tactics designed
to achieve the strategy. In some organizations, projects that will implement tactics are only
approved if the project reduces risk. For example, if a certain activity could fail due to poor IT
systems, the project should be designed to make the activity more robust. Thus, risks will be
reduced and it should be possible to quantify the benefits that will result from more efficient
121
activities due to better use of human resources and due to fewer IT system failures. In
summary, the benefit of good risk management in projects is that projects are more likely to
be completed on time, within budget, and with the required quality. Risk management
activities will help with project execution and, at the same time, help manage situations when
results differ from what was expected as the project progresses. These different outcomes will
indicate whether the tactics have worked and the correct project has been selected. Negative
differences need to be reduced and positive differences will be accepted, as this is one
example of the positive side of risk.
Embracing Opportunities:
Consider two simple examples where the global financial crisis has resulted in an
advantage or a gain of risk for organizations. An international restaurant brand has found that
landlords in downtown locations are looking for tenants. This has allowed the restaurant
business to relocate to busier parts of the city center at lower rents, while also increasing trade
and profits. With reduced industrial activity due to the global financial crisis, power
generation companies have been able to decommission old generating facilities and
expensive, and thus reduced the overall cost per unit of electricity production. This has
improved earnings per unit and allowed the company to revise strategic plans for additional
generation capacity in the future to reduce generation costs in the long term.
14.6 REVERSE IN OPERATION :
It is a fundamental requirement for organizations that they have effective and efficient
operations. Efficient operations should make the best use of the organization's resources and
should operate without unplanned interruptions. Conducting efficient operations that use
minimum resources and produce maximum output will provide the greatest benefit to the
organization. Operations should also be effective as they represent the best way to conduct
operations. For example, it is possible to travel efficiently by car or bus across a busy city.
However, an effective way to travel in many large cities is through metro or underground
systems.
Evaluation of operations risk management can enable organizations to deliver the most
effective and efficient activities, operations and processes. By delivering the most effective
and efficient operations, commercial organizations can achieve an advantage over competitors
and perform work at a lower cost and still make a profit. For public services, the delivery of
effective and efficient operations is equally important. Most public services have targets for
service delivery that can be complex and challenging. Failure to anticipate and manage risks
122
appropriately can undermine public service delivery. The contribution of risk management
will also help achieve continuous service improvement by bringing flexibility and resilience
in the way services are delivered. These contributions based on risk management can be
considered as part of delivering risk benefits.
In a competitive market, achieving upside risk is often to the detriment of competitors,
suppliers or other third parties. However, seeking advantages from risk-taking requires
awareness of the possibility of unforeseen losses. Deciding not to do something because it
appears to be more dangerous may actually result in increased risk. Further aspects of risk
appetite and personal perceptions of risk are discussed in Chapter 25. In terms of business
decisions about operational risks, it is important that they are taken objectively. Personal
views and perceptions of risk can lead to incorrect business decisions. Ensuring the
availability of accurate risk information for making business decisions is one of the key
responsibilities of risk managers.
Chapter 7 emphasizes that establishing context is the first stage in the risk
management process. The risk indices set out in Table 14.2 provide a useful structure for
establishing both the external context and the internal context of the organization. When
setting the context, it is important to consider the upside of the risk and how opportunities will
arise for the organization and how these opportunities can be leveraged, within the
organization in relation to strategy, tactics, and operations. Finally, it is important to note that
there is an upside to be achieved in relation to compliance risk. For some organizations, there
will be regulators that grant licenses and, without a license, the organization cannot operate.
In these situations, a good working relationship with the regulator can often provide a higher
risk. This is especially true if the organization seeks to influence the regulator to request
tighter controls over regulated activities. In this way, the organization will set high standards
that it can achieve, with the expectation that competitors may suffer losses, if they also have
to achieve these high standards, but cannot do so without additional costs.
RISK RESPONSE
Learning Outcomes Part Four:
•
Describe risk response options in terms of tolerate, treat, transfer and terminate (4T),
and explain how these can be displayed on a risk matrix;
123
•
Explain the benefits of using a risk matrix to illustrate default, current and target risk
levels and the effect of controls;
•
Describe the types of controls available, in terms of preventive, corrective, directive
and detective (PCDD) controls;
•
Explain the use of risk matrices to identify key control types for different types of
hazard risks and the concept of 'hazard risk zones';
•
Explains the importance and structure of insurance and the circumstances under which
insurance is purchased and the purpose of captive insurance companies;
•
Explain the importance of insurance purchasing activities from cost, coverage,
capacity, capability, claims and compliance (6Cs);
•
Summarize the importance of business continuity planning (BCP) and disaster
recovery planning (DRP) and provide practical examples;
•
Describes the approach taken during business impact analysis (BIA) and the
importance of established business continuity standards, such as ISO 22301.
Case Study:
Intu Properties: Insurance renewal
As part of the renewal process for 2015, insurers were invited to visit Intu centers to
see the business in action. As a result, significant interest was generated and a reduction in
Intu's insurance renewal rates of over £1 million on a like-for-like basis was achieved and
passed on to tenants.
The site visit was accompanied by a detailed presentation highlighting how Intu's
proactive approach reduces risk for insurers and businesses, for example:
•
National Counter Terrorism Security Office links for all centers;
•
Documented crisis management plans and procedures;
•
Documented contingency plans, e.g. threat level response, business impact
assessment;
•
Annual desktop testing of emergency plans for all centers;
•
Invest in ongoing training and development for employees to help them carry out their
responsibilities to a high standard;
•
Inspection process of retailer channel work to reduce fire risk;
•
An independent fire survey conducted in all managed centers;
•
Direct liaison with loss mitigation companies to minimize the impact of incidents;
•
24-hour CCTV is used in all centers;
124
•
The police presence in the centers includes a number of police stations within the
centers.
The Walt Disney Company: Disclosures about market risk:
The Company is exposed to changes in interest rates primarily through its borrowing
activities. The company's objective is to reduce the impact of changes in interest rates on its
earnings and cash flows and the market value of its borrowings. In accordance with its policy,
the company targets fixed-rate debt as a percentage of its net debt between a minimum and
maximum percentage. The company transacts business globally and is subject to risks
associated with changes in foreign exchange rates. The company's objective is to reduce
fluctuations in earnings and cash flows associated with changes in foreign exchange rates,
allowing management to focus on core business issues and challenges.
The Company enters into option and forward contracts, which change in value as
foreign currency exchange rates change, to hedge existing foreign currency assets, liabilities,
firm commitments, and foreign currency transactions that are expected but not firmly
committed. In accordance with the policy, the company hedges forecasted foreign currency
transactions for periods generally not exceeding four years within specified minimum and
maximum annual exposure ranges.
Risk response:
Gains and losses on these contracts offset changes in the US dollar equivalent value of
the related forecasted transactions, assets, liabilities or firm commitments. The major
currencies hedged are the euro, Japanese yen, Canadian dollar and British pound. Cross-
currency swaps are used to effectively convert foreign currency denominated borrowings into
US dollar denominated borrowings.
Australian Mines Limited: Risk assessment and management:
The Board reviews the company's risk management system and control framework,
and the effectiveness of its implementation, annually. The board also considers risk
management at its regular meetings. The company's risk profile is reviewed annually on
advice from management including, where appropriate, as a result of regular interaction with
management and relevant staff from across the company's businesses.
The board or senior management of the company may consult with the company's
external accountants on external risk matters as necessary. The company's risk management
125
system and control framework for identifying, assessing, monitoring and managing its
material risks, as established by the board in conjunction with management, includes:
•
Continuous monitoring of management and operational performance;
•
Comprehensive budgeting, forecasting and reporting system to the council;
•
Approval procedures for significant capital expenditures above threshold levels;
•
Regular board review of all significant areas of financial risk and all significant
transactions that are not part of the company's normal business activities;
•
Regular presentations to the board by management on risk management;
•
Comprehensive written policies related to specific business activities;
•
Comprehensive written policies related to corporate governance issues;
•
Regular communication between directors on compliance and risk issues; and
•
Consultation and review process between the board and external accountants.
The board requires that any major proposal submitted to the board for decision be
accompanied by a comprehensive risk assessment and, where required, management's
proposed mitigation strategy. The company has an insurance program that is regularly
reviewed by the board. The board receives regular reports on budgeting and financial
performance. A system of delegated authority levels has been approved by the board to ensure
business transactions are properly authorized and executed.
TOLERATE, TREAT, TRANSFER, AND END
15.1 4T OF RESPONSE DANGER:
The priority of significant risks facing the organization are those that have:
•
High or very high impact in relation to the benchmark test for significance;
•
High or very high probability of materializing at or above the benchmark level;
•
High or very high coverage for cost-effective control improvement. In general, only
prioritized significant risks require attention at the most senior level of the organization.
However, it is appropriate that compliance risks also receive attention in the boardroom. In
practice, the board will expect these compliance risks to be well managed and the board will
only receive regular/annual reports describing risk performance, or special reports if specific
issues arise. The organization will strive to introduce effective and efficient controls to
minimize compliance risks. The benchmark test for significance should be set at a level that
represents a significant impact to the organization. After identifying the priority significant
126
risks, the organization will then need to review the existing controls and decide whether
further action is required. For hazard risks, the range of available responses is often described
as the 4Ts.
There are various terminologies available to describe risk response options. In fact,
British Standard BS 31100 and ISO 31000 use the term 'risk treatment' as a more general
description. For example, the British Standard defines risk treatment as 'the process of
developing, selecting and implementing controls'. Similarly, ISO 31000 defines risk treatment
as 'the development and implementation of measures to modify risk'. The terminology used in
the Orange Book has been adopted for this text for the risk response stage of the risk
management process. The options for responding to risk can then be identified as the 4Ts.
Appendix B contains information on alternative definitions used by various publications.
Further information and a brief description of each of the 4Ts are presented in Table
15.1 The 4Ts of hazard risk management can be summarized as:
•
tolerate;
•
treat;
•
removal;
•
end.
Figure 15.1 shows that there is a dominant response in relation to each of the 4Ts, according
to the position of the risk on the risk matrix. For low likelihood/low impact risks, the primary
response is tolerance. For risks that are high likelihood/low impact, the primary response is
treat. For risks that are low likelihood/high impact, the primary response is transfer, and for
risks that are high likelihood/high impact, the primary response is termination. To provide
context to the range of risks under consideration, Table 15.2 provides examples of the range of
potentially significant risks associated with FIRM risk scorecard titles. The assessment of each
risk will allow the organization to place the risk on the risk matrix. The position of the risk on
the risk matrix will then indicate the most likely response to that risk. If the risk assessment is
conducted at the current risk level, the effect of existing controls will already have been
evaluated as part of the risk assessment exercise.
Consider the case of a theater that needs to respond to the increasing use of agents who
require payment at the time of booking, rather than after the performance. Also, a recent
failure of actors to show up on the night of a performance caused considerable financial loss
to the theater. This results in the theater reviewing its booking and performance arrangements
for actors and deciding on an appropriate response in relation to all 4Ts. The theater may
127
decide that it should tolerate new booking fee arrangements. It also decides that in order to
handle/reduce risk, it will only deal with established agents in the future and terminate
existing agreements with agents who have proven unreliable in the past. The theater might
also investigate the possibility of purchasing insurance, so that the theater can transfer the cost
of a show that is canceled because an actor failed to show up on the night.
15.2 RISK TOLERANCE:
Risk tolerance is defined in Guideline 73 as the readiness of an organization or
stakeholder to bear risk after risk treatment to achieve its objectives. The Guide then adds that
risk tolerance may be influenced by legal or regulatory requirements (compliance). The
comment about legal or regulatory requirements is particularly relevant, where organizations
often have to tolerate risks due to legal or regulatory requirements, even in circumstances
where the organization does not want to tolerate that risk. It should be noted that tolerance
relates to specific or individual risks, rather than the more general approach represented by
risk appetite. Risk appetite refers to the amount and type of risk that an organization wishes to
pursue or maintain.
There is terminological confusion between when an organization is willing to tolerate
risk and the concept of risk tolerance. The concept of tolerance usually relates to an
organization's willingness to maintain or tolerate risk, even if that risk is higher than the
organization would choose to accept. Another concept is risk tolerance. Many organizations
use risk tolerance in the technical sense to represent a broad range of acceptable risks. In
Figure 25.1, the center of the concerned zone and the caution zone draw boundaries around
the risk tolerance. Like the engineering use of the word tolerance, these zones define the
boundaries where the organization wants the level of risk to be limited.
An organization may have to tolerate risks that have a current level outside its comfort
zone and risk appetite. At times, an organization may even have to tolerate risks that are
beyond its actual risk capacity. However, this situation will not be sustainable and the
organization will be vulnerable during this period. When the risk of harm is considered to be
within the organization's risk appetite, the organization will tolerate that risk. Risk tolerance is
indicated as the approach to be adopted in relation to risks with a small probability of low
impact. However, the organization may decide to tolerate a high level of risk as it relates to
potentially profitable activities or relates to core processes that are fundamental to the nature
of the organization.
It is unusual for hazard risks to be accepted or tolerated before risk control measures
are implemented. In general, risk only becomes tolerable when all cost-effective control
128
measures have been taken, so the organization accepts or tolerates the risk at its current level.
Certain control measures may have been implemented because the inherent level of risk may
not be acceptable. Control efforts attempt to move risk to quadrant quadrant of the risk
matrix, as illustrated in Figure 16.1. Sometimes risks are simply accepted as part of an
arrangement where one risk is balanced against another. This is a simple description of
neutralizing or protecting risks, but at a business level this may be a fundamentally important
strategic decision. For example, a power company operating independently in a northern state
of the United States may have to accept the impact of temperature variations on electricity
sales. By merging (or setting up a joint venture) with a power company in a southern state, the
combined north/south operation will be able to smooth out temperature-related variations in
electricity sales. The joint operation would then sell more electricity in the northern states
during cold weather, when demand in the southern states is low. Conversely, the joint
operation would sell more electricity for air conditioning units in the southern state in
summer, when electricity demand in the southern state is low.
the north may be lower.
15.3 TREAT RISK:
When the level of risk exposure (likelihood) associated with a particular hazard is high
but the potential loss (impact) associated with it is low, the organization will want to treat the
risk. Risk treatment will often be done with the risk at its inherent and/or current level, so that
when the risk has been treated, a new current level or target level can be tolerated.
Measures to improve risk control standards will always be under constant review
within an organization. On a personal level, wearing a seat belt when driving a car or
installing an intruder alarm at home are examples of risk reduction measures. Improving risk
control standards in relation to physical (insurable) risks is well known. Installing sprinklers
to buildings, providing enhanced building security arrangements and employee safety checks
are all examples of risk improvement measures designed to better manage the risk of harm.
When identifying suitable risk treatment options, the organization needs to look at the
effect of the treatment on the likelihood of the risk materializing as well as look at the impact
of the risk if it materializes. Cost-effective risk treatments need to be selected and the effects
of different control measures can be shown on a risk matrix, as in Figure 16.1. There are
terminology issues associated with treating risks. ISO 31000 considers that 'treat risk' is the
main heading under which various options exist, such as:
•
Avoid risk by deciding not to start or continue the activity;
•
Take or increase risks to pursue opportunities;
129
•
Eliminate sources of risk;
•
Change the possibility or consequence;
•
Share the risk with another party or parties;
•
Maintain risk with the right decisions.
Other risk management standards refer to 'risk response' as the main heading and this is the
approach taken in this chapter. Using risk response as the main heading then brings up the
options to tolerate, treat, transfer and terminate. As with all terminology issues, the
organization must establish its own risk vocabulary, which is consistent with the external,
internal and risk management context. In some cases, terminology will be determined by the
external context. For example, banks and other financial institutions will need to use
regulatory terminology. Sometimes, the terminology is determined by the internal context
within the organization. If the terminology developed within the organization does not match
the terminology in ISO 31000, it may be that risk managers are better advised to use the
terminology that already exists within the organization, rather than trying to introduce a new
term or new meaning to an existing term.
15.4 TRANSFER RISK:
When the likelihood of a risk occurring is low but the potential is high, organizations
will want to transfer that risk. Insurance is a well-established mechanism for transferring the
financial impact of losses arising from hazard risks and (to a lesser extent) control risks. The
issues associated with using insurance as a risk transfer mechanism are discussed in more
detail in Chapter 17. In some cases, risk transfer is closely linked to the desire to eliminate or
stop the risk. However, many risks cannot be transferred to the insurance market, either
because of very high insurance premiums or because the risk under consideration is
(traditionally) uninsurable.
Risk transfer can be achieved by conventional insurance and also by contractual
agreements. It is also possible to find joint venture partners, or other ways to share risks.
Hedging or risk neutralization can therefore be considered a risk transfer option, as well as a
risk treatment option. The cost of risk transfer is a component of risk financing. Again, there
are variations in the definitions used. With respect to risk financing, both BS 31100 and ISO
31000 agree that risk financing involves the cost of contingent arrangements for the provision
of funds to meet the financial impact of realized risks. Such arrangements are typically
provided by insurance, and insurance is, therefore, finance that is contingent on certain
insured events occurring. The difference between the definitions in BS 31100:2008 and ISO
130
31000:2009 is that ISO 31000 also considers that the cost of risk financing should include the
provision of funds to meet the cost of risk treatment. In this text, control resources are
considered a separate step in the risk management process. This is another example
illustrating that there is no universally agreed or common language of risk.
There is another terminology issue with the use of the phrase 'risk transfer'. ISO 31000
recommends that risk sharing should be used in preference to risk transfer. The argument is
that risk can never be fully transferred and whatever the intentions of the parties, risk will
always, to some extent, be shared. This is an accurate analysis, but the choice of terminology
used within an organization will also be influenced by other factors. In relation to risk sharing,
the insurance industry uses the term risk transfer. It may be difficult for enterprise risk
managers to enforce the use of the phrase risk sharing when insurance managers within the
organization prefer to use the terminology of risk transfer because it is the standard
terminology used in the part of the external context that is the insurance market.
15.5 STOP RISK:
When risks have a high likelihood and high potential impact, organizations will want
to stop or eliminate the risk. Perhaps the trade risks in certain parts of the world or the
environmental risks associated with continuing to use certain chemicals are unacceptable to
the organization and/or its stakeholders. In these circumstances, an appropriate response
would be to eliminate the risk by stopping the process or activity, substituting an alternative
activity or outsourcing the activity associated with the risk. An organization may want to stop
a risk, but it could happen that the activity giving rise to it is fundamental to the ongoing
operations of the organization. In such circumstances, the organization may not be able to stop
or eliminate the risk completely and thus needs to implement alternative control measures.
This is a particular issue for public services. There may be certain risks that have a
high likelihood and impact, but the organization cannot stop the activity that gives rise to the
risk. This may be because the activity is a statutory requirement placed on a government
agency or public authority. Public service imperatives may limit the ability to stop the
activity, so the organization needs to introduce control measures, to the extent that they are
cost-effective.
It is likely that the control measures will be a combination of risk treatment and risk
transfer. When these control measures are implemented, the level of risk will move to a level
where the organization will be able to tolerate the risk. Due to the variable nature of risks, it
may not be possible to get all risks to a level that suits the organization's risk appetite. The
organization may find that it has to tolerate risks beyond its empirical risk appetite to continue
131
performing certain activities.
15.6 STRATEGIC RISK RESPONSE:
The overall approach to control and opportunity risk management is similar to the
approach adopted for hazard risk management. However, there are sufficient differences in the
range of options available to be presented separately. Keep in mind that projects usually
reflect and implement tactics that used to implement the strategy. Figure 16.1 illustrates the
4Ts of hazard risk management and the types of controls most likely to be associated with
each type of hazard risk response. Control types are considered below. This chapter has dealt
almost exclusively with responding to hazard risk. The 4Ts represent options for reducing
hazard risk. Figure 15.2 shows that there is a range of responses available for opportunity risk
management. Developing and implementing effective and efficient strategies will require
evaluating the level of risk associated with each available strategy and the level of reward that
the strategy will provide. The 4Es of opportunity management are defined as exist, explore,
exploit and exit. There is a close relationship between the 4Es and the status of the
organization, as illustrated in Figure 15.2. Start-up operations will face higher levels of risk
and low potential rewards. Entrepreneurial opportunities will be explored at this time. As the
organization grows, the potential rewards will increase while the level of risk will remain
high. The organization will strive to achieve growth, but may feel that the growth is too slow
or the level of risk remains too high, in which case he will exit the operation.
After a period of growth, the organization must achieve a high appreciation for risk
reduction. This represents the phase in which the organization will exploit opportunities until
competitors arrive. This is a mature operation. All mature operations are faced with the
possibility of decline, although many organizations choose to exist in mature and declining
markets, where risk exposure is low and so are the potential rewards. The application of the
4Es to the management of strategic, opportunity, or speculative risk is consistent with the
description of risk and reward offered by Figure 2.2. However, the pursuit of opportunity risk
and the development of strategic objectives are the most important issues for many
organizations. Risk management input into strategic decision-making may not always be as
robust and well-structured as risk management input into operations and projects.
The allocation of dominant response and control types to each of the four quadrants
shown in Figure 15.2 is similar to the 4T allocation using hazard risk management. Being in a
mature or declining market is akin to accepting uncertainty in tactics and tolerating hazard
risk. Exploring opportunities is similar to looking at options to deal with hazard risk. It is in
the area of opportunity utilization and exit opportunities where the difference in approach
132
between hazard and uncertainty management compared to opportunity management becomes
most apparent.
Figure 15.3 shows a refinement of Figure 15.2 in that areas of high risk and high
potential reward are evaluated in a little more detail with consider risk appetite. An
organization may find that it has a viable business opportunity but lacks the resources to
exploit it on its own. Under these circumstances, the organization has three main choices. It
may exit the opportunity because it does not have the risk appetite or risk capacity to pursue
that opportunity. It may sell the opportunity to an organization that does have the appetite,
capacity, and resources to capitalize on the opportunity or it may seek to share the
opportunity.
Exiting the opportunity may be the right choice, as the organization does not have the
risk appetite, capacity, or resources to pursue the opportunity and has not been able or willing
to find a partner to buy or share it. However, most organizations with a viable opportunity will
want to benefit from the identification of that opportunity. Selling the opportunity may
provide a profitable exit, but sharing it with, for example, a joint venture partner may be a
better long-term option. Entering into a joint venture partnership will reduce the level of risk
the organization faces, but will result in profit sharing. This decision will depend on the
business strategy, risk appetite, risk capacity and availability of suitable business partners. In
addition to joint venture partnerships, the utilization of business opportunities can be done by
risk sharing, using means such as outsourcing to share risks with other parties in the supply
chain.
It should be noted that Figure 15.3 represents a flowchart from inception (Explore
opportunities) to growth (Expand), then to a mature organization (Exploit) before moving to
decline (Exist). Therefore, it is similar to Figure 2.2. However, it has the additional
refinement that when the organization wants to expand, it will have the option to exit if the
organization's risk appetite and/or risk capacity will be exceeded. This expands the 4E
approach to 5E, depending on the risk appetite. The text box below provides an example of
the approach applied to opportunity management, though the terminology (as is often the
case in risk management) slightly different.
Opportunity Evaluation and Response:
The purpose of evaluation and response is to decide which opportunities require a
response and what response is recommended. The following are key terms and concepts when
deciding how to respond to opportunities and they can be used in combination:
133
•
Increase: the opportunity equivalent of 'reducing' risk is to increase the opportunity by
increasing its likelihood and/or impact.
•
Exploitation: equivalent to the 'avoid' response, but the 'exploitation' strategy seeks to
make the opportunity actually happen.
•
Ignore: an 'acceptance' strategy takes no action to address the risk of harm, and
opportunities can be ignored, with a reactive approach but no explicit action.
•
Opportunity sharing (transfer): a 'sharing' strategy for opportunities seeks partners
capable of managing opportunities that can maximize the chance of occurrence.