1 / 31100%
160
STRATEGY RISK
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 7
Part Five Learning Outcomes:
Explain the importance of dynamic business models and their relationship with
strategy, tactics, operations and compliance (STOC) activities;
Outline the components and importance of business models and how these are
supported by organizational resilience;
Explain the importance of corporate social responsibility, including supply chains,
ethical trade risks and the importance of reputation;
Describe the key components of a risk architecture, strategy, and protocol (RASP) for
an organization and how these fit together;
List the main sections of the general risk management manual, explain the importance
of each section and summarize the various risk documentation and records;
Explain the importance of the allocation of risk management responsibilities, including
the governance responsibilities of non-executive directors;
Produce practical examples of controlling selected hazard risks, including financial,
infrastructure, reputational and market risks;
Describe the learning process from controls to ensure that controls are cost-effective
and risk/reward decisions are appropriate.
Case Study:
AMEC Foster Wheeler: Key risks and uncertainties
The Board has overall responsibility for risk management, for determining risk
appetite with respect to key risks, for the implementation of risk management policies and for
reviewing the effectiveness of the risk management system. Global mandatory procedures
detailing the risk management process are used at project, operating unit, business unit and
group level to identify key risks that could have a significant impact on the ability to achieve
objectives.
161
These are recorded in a risk register and evaluated to determine the likely impact and
likelihood of occurrence. Control measures are developed to reduce or eliminate risks deemed
unacceptable. Risk owners are identified and given responsibility for ensuring actions are
implemented with appropriate review dates. The risk register is reviewed and updated at least
quarterly with the relevant risk owners. The risk committee is chaired by the chief executive
and meets at least twice each year to:
Review and advise the board on Amec Foster Wheeler's risk appetite with respect to
key strategic risks, taking into account current and future macro-economic, financial,
political, business and sector environments;
Review and approve risk management strategies, policies, procedures and processes;
Review and report to the board on the effectiveness of the risk management system;
Review the Amec Foster Wheeler plc risk register and make recommendations
accordingly;
Review new or emerging risks and any potential impact they may have on risk appetite
and Amec Foster Wheeler's ability to manage those risks;
Review any issues raised by other board committees that impact Amec Foster
Wheeler's risk profile;
Review and consider reports on key risk issues such as new businesses and geographic
locations for operations or projects;
Consider trends and concentrations of internal or external risks.
BBC: Internal control assurance:
We review the effectiveness of the internal control system, taking into account
findings from internal and external audit reports. Our work in this area is influenced by
reports from the Director of Risk and Assurance on the effectiveness of internal controls,
identified fraud, and loss and assurance mapping. We seek assurance from management that
control issues identified by internal audit are being addressed. We considered audit assurance
on the implementation of actions from a number of recent high-profile independent reviews in
areas such as severance payments, tax treatment of casual workers, child protection and
whistleblowing arrangements. We considered audit assurance over a number of high profile
implementation and change programs regarding the upgrade of underlying IT systems and the
introduction of improved financial control processes.
We considered the processes for managing significant risks within the BBC and the
BBC's risk appetite in the context of its key strategic and operational risks and how it manages
162
its key strategic projects. We continue to have an ongoing interest in project assurance so that
we can ensure that lessons from previous projects are are taken to forward. Overview our
of plan audit plan considers how audit work on project assurance is integrated with
management's own project assurance activities. We assure ourselves that ongoing project
assurance activities include both governance and technical assurance. Emperor Watches &
Jewelry: Risk management
The risk management process includes risk identification, risk evaluation, risk
management measures, and risk control and review. Management is delegated to identify,
analyze, evaluate, respond to, monitor and communicate risks associated with any activity,
function or process within its scope of responsibility and authority. An attempt is made to
evaluate and compare the level of risk with a predetermined acceptable level of risk.
For risk control and monitoring, this involves making decisions regarding which risks
are acceptable and how to handle those that are not. Management will develop contingency
plans for possible scenarios loss. Accidents and other situations involving losses or near
losses will be properly investigated and documented as part of efforts to manage risk. The
Group is subject to certain risks that affect its ability to operate and protect assets. The key
risks identified and their respective strategies are set out below:
1. Dependence on HK/Macau/Singapore tourism:
changing the business model;
expanded business to the domestic consumer market by customizing store
locations;
adjust the stock portfolio with more affordable products to suit domestic
consumers.
2. Economic, political and social conditions in HK/Macau/Singapore (e.g. strong HKD
against other currencies, continued austerity initiatives in China):
exploring opportunities to develop networks in other countries;
be careful in purchasing and stock replenishment;
relocating stores in the PRC;
develop and maintain multi-tier target customer segments.
3. Dependence on major watch suppliers and watch brands:
continues to expand its jewelry business;
maintain strong and close relationships with watch suppliers;
maintain a broader portfolio of brands.
163
4. Rent increases at retail stores:
bargaining for lease negotiations or lease concessions;
capitalize on the upcoming trend in declining rents in prime shopping areas to
maintain a balanced presence in strategic and profitable geographical areas.
BUSINESS PROCESSES CORE
19.1 DYNAMIC BUSINESS MODEL:
Organizations will often set business objectives and strategic objectives as separate
documents. When seeking to ensure that risk management makes a full contribution to the
organization, it is important to look at both sets of objectives and explore the relationship
between them. Business objectives will often relate to the annual budget that the organization
has produced. This budget will contain details of anticipated sales as revenue and cost of sales
as expenses. Underlying the organization's business objectives will be the business delivery
model (or business model for the short term) that the organization has developed. For
example, a membership organization will seek sponsorship from organizations that provide
services to the membership. These sponsorship revenue sources will be a fundamental part of
the business model and annual business objectives. The membership body needs to estimate
the revenue from membership subscriptions and from sponsorships, and determine what
services will be provided to members in exchange for their membership fees and what benefits
will be provided to sponsors in exchange for their sponsorship money.
The risks inherent in the business objectives are related to the robustness of the
business model and the efficiency of the business model. When conducting an annual budget
risk assessment, events that could undermine sponsorship and membership revenue, along
with events that could disrupt service and benefit delivery, should be considered. The core of
the business objectives usually relate to the organization as it exists today. The box below
identifies the essential features of the business development model. Keep in mind that an
organization will have a version of their current business model, as discussed in Chapter 2.
20. The business model is supported by business objectives and annual business plans. The
organization will also have a plan to develop and improve the business model in line with the
long-term strategy. Figure 19.1 explains how the existing business model is developed by
applying tactics to achieve that long-term strategy. The existing business model is defined by
the existing operations or 'where the organization is now'.
164
Delivery Model and Business Development:
Whenever a business is established, it either explicitly or implicitly uses a particular
business delivery model that describes the architecture of value creation, delivery, and capture
mechanisms used by the business enterprise. The essence of a business delivery model is that
it defines the way a business delivers value to customers, persuades customers to pay for
value, and converts those payments into profit: it thus reflects the organization's beliefs about
what customers want, how they want it, and how the company can best manage to meet those
needs, get paid for doing so, and make a profit. Business delivery models are used to describe
and classify businesses, but are also used by management at within the company to explore
the possibility of future development. The improvement of the business delivery model in the
future is achieved by the implementation of the business development plan. In fact, an
established business delivery model will be the basis for creative organizations to develop
future strategies.
Most organizations realize that the existing business model will not continue to be
openly successful. If business objectives are to be delivered year on year, then the business
needs to evolve. This development can include exploring greater sponsorship opportunities,
delivering new services and products that will generate new revenue, and improving
efficiency in the delivery of the existing business model. The development of a business
model to meet strategic objectives can be considered a business development model and is the
main topic of this chapter.
To place risk management in the context of business operations, it is necessary to
consider a simplified business development model. Figure 19.1 describes the basic elements
of a simplified business development model. The first stage for an organization is to decide on
the strategy it wants to deliver. Strategic objectives will be determined by considering the
organization's mission statement, corporate goals and stakeholder expectations. The
organization should set a strategy that is capable of delivering the organization's mission
statement. In other words, the organization's strategy needs to be effective and efficient.
Once the overall strategy is set, the tactics that will realize it need to be identified. If
the strategy requires changes to core processes or the introduction of new core processes, then
projects or work programs will be required. The tactics introduced by the organization must
ensure that effective and efficient core processes to deliver the desired results in the most
cost-effective manner are in place. In relation to operations, the desired state of the
organization is the continuity of normal efficient operations without unplanned interruptions.
Figure 19.1 explains the stages described above. Strategy can be seen as 'where the
organization wants to be'. A review of the organization's operations will gather information
165
about 'where the organization is now' and tactics determine 'how the organization will get
there'. This is a three-stage approach to business model development that has events at its
center. In many circumstances, these events will represent risks that could materialize.
Another component of this business development model is the reporting of operating results.
Actions and events can be good, bad or routine, and allow the organization to monitor
what progress is being made against business strategy, tactics, operations and compliance.
These actions and events impact the organization and its ability to maintain effective,
efficient, and compliant business operations and core processes. Although compliance core
processes are not specifically mentioned, they represent the means by which the organization
ensures that it meets its legal and contractual obligations. Compliance core processes should
support all activities of the organization and will be similar to operational core processes.
Strategy identification will require an approach based on opportunity management. Delivery
of tactics, often through projects, will require attention to uncertainty and control risk
management will be important. Effective and efficient execution of operations will require
special attention to the successful management of hazard risks.
19.2 BUSINESS PROCESS TYPES:
An organization will have business processes in place and these may be satisfactory to
generate the necessary revenue and control costs so that business objectives are achieved. To
ensure that risk management has adequate input into the delivery of business objectives, the
objectives should relate to routine operations within the organization. However, it is not
uncommon for organizations to fail to set business objectives as usual. Most objectives tend to
be annual change objectives that relate to the delivery of the strategic plan for the
organization. In summary, for risk management to fully contribute to the success of the
organization, objectives need to be fully established that encompass strategy, tactics, and
operations.
Core processes are those that are fundamental to the continued success (or even
existence) of an organization. Core processes ensure that the organization is able to achieve its
mission and goals and meet stakeholder expectations. Each core process creates value and is
designed to deliver one or more stakeholder expectations Importance. There are four basic
types of core processes. These are processes that are designed, implemented and managed to
ensure the following:
strategy development and delivery;
tactics, project, and improvement management;
166
continuity and monitoring of routine operations;
activities designed to ensure compliance.
Activities are individual jobs or tasks that are built into processes that deliver stakeholder
expectations. The process itself is designed and intended to add value to the organization, but
the addition of extra activities will add costs. Therefore, the challenge is to develop a core
process that is effective as well as efficient. After identifying stakeholder expectations, core
processes can then be implemented to ensure that these expectations are delivered to the level
that the organization has decided is appropriate. No organization is in a position to fully
deliver all expectations to the level desired by all stakeholders. Often, this is because the
expectations of different stakeholders conflict.
Weaknesses or gaps in the organization's core processes are likely to be present, as
follows:
There may be weaknesses associated with strategy development and delivery. These
weaknesses will result in the organization failing to maintain its position as a market
leader. They give rise to a leadership gap.
There may be weaknesses related to management tactics, including project and
product or service improvements. These weaknesses will result in failure to compete
with competitors. They give rise to a competition gap.
There may be weaknesses related to failure to ensure efficiency, continuity and regular
monitoring of operations. These weaknesses will result in failure to maintain efficient
operations. They give rise to efficiency gaps.
There may be weaknesses associated with activities designed to meet mandatory
requirements placed on the organization. These weaknesses will result in failure to
maintain reputation. They give rise to compliance gaps.
19.3 STRATEGIES AND TACTICS :
A business strategy is a statement of what the organization wants to achieve and how
it plans to achieve it, and is based on strategic decisions about the future of the organization.
Establishing a detailed business strategy allows the organization to convey its mission, goals,
strategies, and plans. The overall objective of risk management inputs into strategy is to
ensure effective and efficient strategies and strategic decisions that will deliver the desired
results. The primary risk management input into business strategy is most likely the risk
assessment. This is a critical component to strategy formation. Risk assessment of existing
strategies and any proposed new strategies should be conducted. If there are clear strategic
167
options, then a risk assessment of each viable option should be carried out individually.
Some organizations exist in highly competitive markets that are undergoing significant
technological change. In these circumstances, there are significant risks associated with the
business and major strategic decisions must be made. Often, these decisions are related to
technological developments that challenge the way organizations deliver customer solutions.
Technological change can require large, speculative investment decisions and these decisions
establish the tactics to be implemented. Investment decisions may be speculative because of
untested new technologies or because there are alternative technologies available.
A risk assessment of strategic options needs to be conducted, including an analysis of
stakeholder expectations, existing customer requirements and existing staff skills, as well as a
strengths, weaknesses, opportunities and threats (SWOT) analysis. Strategic options available
to the company may include joint ventures, outsourcing of work, sub-contracting or
investment in new technologies. A detailed risk assessment of the strategic options will ensure
that the board has the best information available to make the correct strategic decisions.
Events and other circumstances that could reduce the successful delivery of the strategy
should be identified during the risk assessment. The organization will then be able to decide
on the controls that should be implemented to optimize the possible impact if any of these
risks materialize.
Often, strategic objectives will relate to the development of a business sector and the
organization's reputation within that sector. In this way, reputation enhancement and
individual brand development become opportunity risks for the organization. The
fundamental importance of brand and reputation is discussed in more detail in Chapter 20.
Tactics are the means by which the organization will deliver the business strategy. Tactics
need to be properly selected, implemented and controlled to ensure effectiveness and
efficiency of operations and should also provide reliability of financial reporting and
compliance with applicable laws and regulations. The desired outcome is effective, efficient
and compliant core business processes. Changes to core processes are delivered by projects,
and the importance of risk management in projects is discussed in Chapter 31 of this book.
When undertaking a project, organizations need to be mindful of the risks in the project that
can stop it from being delivered on time, on budget, and to specification.
However, there is a further consideration associated with projects and that is the
effectiveness of the core process improvements that the project is designed to deliver. There is
little benefit in having a project delivered on time, within budget and to specification if the
required improvements in the effectiveness and/or efficiency of the core processes are not
achieved. For example, the installation of a new business software system may be delivered
168
by a successful project, but if the new software system is inadequate, or does not deliver all
the anticipated additional benefits, then the core business process improvements may not be
achieved.
Key risk management inputs into tactics and projects are risk assessment, risk response
improvement, and review and monitoring activities. The goal in conducting a project risk
assessment is to identify the necessary controls. When these controls have been implemented,
the effectiveness and efficiency of the controls need to be reviewed. Overall, the goal is to
ensure that the tactics and the project itself are effective and efficient. An effective tactic
means that the core process is the correct process to deliver what is needed. An established
core process may be fully efficient, but that does not mean that it is the correct or most
effective core process that the organization can implement. To ensure that the core process is
fully effective, changes will be required through projects that will be designed to ensure that
the strategy is delivered. Developing more effective core processes will be how the
organization ensures that it continues to satisfy customers, financiers, and other stakeholders.
To ensure that effective core processes are in place, the business model and business
objectives may need to change.
19.4 EFFECTIVE AND EFFICIENT OPERATIONS:
The overall goal of risk management input into operations is to achieve operational
efficiency that is protected from unplanned disruptions. Operational disruptions are most
likely to be caused by realized hazard risks. The design of efficient operational core processes
that are free from disruptions will give the organization a significant competitive advantage or
put the organization in a better position to deliver value for money.
Risk management can have a major impact on an organization's operations. All stages
of the risk management process are relevant to the efficient continuity of core business
processes without interruption. Risk recognition and assessment (risk assessment), responding
to significant risks, resource control, reaction planning, risk reporting and review and
monitoring are all important inputs. In short, risk management inputs into operations need to
be comprehensive if operations are to be efficient and uninterrupted. Internal audit also has an
important role to play in the efficient execution of operations. Internal auditors often refer to
the added value that internal audit activities bring. This added value relates to the evaluation
of control activities, especially those related to operations. Not only must operations be
effective and efficient, but the controls in place must also be effective and efficient. The
internal audit activity has an important role in providing appropriate risk assurance and
providing confirmation of compliance, where relevant.
169
All organizations need effective and efficient operations. In difficult financial and
economic circumstances, it is important that existing operations continue to be conducted as
efficiently as possible. The efficiency of operations will determine whether the annual budget,
which includes annual business goals, is achieved. Part of ensuring the success of an
organization is by improving the efficiency of operations. Delivering more efficient
operations can be done by developing activities so that they require fewer resources, and this
may involve cutting costs.
There is no point in operations being efficient if they are based on the wrong core
activities or processes for the organization. For example, it is possible to organize a very
efficient means of travel to your destination by car, so the activity of traveling by car becomes
as efficient as possible. However, it might be more effective to travel by train. In the busiest
cities in the world, you can hire a taxi and travel to your destination quite efficiently.
However, a more effective way of traveling may be using the underground or metro system,
which may prove to be faster and cheaper.
The business model is described in more detail in Chapter 20. It defines the offering
customers delivered by an organization's resources and supported by that organization's
financial resilience and reputation (CORR). The business model (as represented by the
acronym CORR) is discussed in more detail in Chapter 20. Therefore, the business model
represents the current (or existing) activities and operational core processes of the
organization. Strategies and tactics will be designed to improve and refine the business model
by increasing the effectiveness and efficiency of the core operational processes. It is important
to note that the business model represents the current status of the operational core processes
in an organization.
19.5 ENSURING COMPLIANCE:
The reasons for conducting risk management activities are described as mandatory,
assurance, decision-making, and effective and efficient core processes (MADE2). Core
processes are identified as strategic, tactical, operational and compliance (STOC). There is a
clear link between the rationale for conducting risk management and the effectiveness and
efficiency of the core processes. Mandatory requirements are met by the organization, because
they are needed by stakeholders. Stakeholders who can impose mandatory requirements
include regulators, customers/clients and financiers. Mandatory requirements must be met and
this will be done by the organization by ensuring that effective and efficient compliance core
processes are in place within the organization. Failure to comply with stakeholder
requirements can have significant implications for most organizations. In the extreme, failure
170
to comply with the mandatory requirements of a license may result in the license being
withdrawn by the regulator and may jeopardize the very existence of the organization.
In almost all cases, there will be multiple ways in which mandatory requirements
imposed by stakeholders can be met. While the core process of compliance must be effective
and efficient, there will be risks involved, and risk management input will have an important
role in designing compliance processes, protocols, and procedures. This is an example of how
risk management expertise and support can enable organizations to achieve compliance in a
way that is not only effective, but also efficient and thus a competitive advantage.
The culture in many organizations will be highly compliant with a strong desire to
adhere to the mandatory obligations placed on the organization. This is a positive attribute and
supports the ethos of the organization, but if compliance is not achieved in an effective and
efficient manner, wasted resources and competitive disadvantage will result. Part of the role of
the risk management professional is to facilitate the development of core processes effective
and efficient compliance that achieves compliance in the most cost-effective manner.
For example, most organizations will have health requirements and
mandatory safety placed on them by legislation and enforced by regulators. Some
organizations may complain about the statutory obligations imposed on them, and seek to
avoid compliance if they believe there will be no consequences, or they think that they can
'get away with it'. An organization with a more sophisticated approach to risk management, as
illustrated in Figure 4.2, will adopt the approach that achieving compliance with health and
safety requirements will not only improve operational efficiency, but a good safety record
could be a factor in securing new contracts and new clients.
19.6 REPORT PERFORMANCE:
Operational reports show how well the strategy is being delivered. Data needs to be
available on an ongoing basis, so that management can respond and modify core business
processes as necessary. Operational reports also provide information that can be used to
prepare reports to stakeholders on the organization's performance. However, organizations
need to decide what to report and disclose to stakeholders and the format to use for those
reports. To ensure accurate reporting and disclosure, appropriate control activities need to be
implemented. In the United States, the Sarbanes-Oxley Act (SOX) sets out duties that are
primarily concerned with the accuracy of financial reports to shareholders.
Key risk management inputs into performance reporting are reporting line risk
assessments and data handling procedures. SOX duties have increased the attention paid to the
control of reporting procedures. Section 404 of SOX requires that financial statements and
171
financial reporting procedures be attested by external auditors to ensure that they are accurate.
Aspects of the business development model can also be applied to personal strategic goals and
the achievement of personal success. Many books have been published on actions to ensure
career success and the personal traits of highly successful people. The box below provides a
list of simple actions to ensure career advancement. Although not organized in the format of
Figure 19.1, the suggestions provided are fully compatible with an analysis based on: 1)
where do I want to be? 2) where am I now? and 3) how will I get to where I want to be?
REPUTATION AND BUSINESS MODEL
20.1 BUSINESS MODEL COMPONENTS:
All organizations will have a business model that represents how they deliver the
customer offering. Organizations that are public sector, third sector or would consider
themselves to be non-commercial organizations will still have a means to convey their vision
and/or mission statements. The means of delivering the defined customer offering is the
organization's business model. In short, the customer receives the offer from the organization
because it makes use of the available resources. The customer offer is supported by the
resilience of the organization and by arrangements to ensure that the organization remains
sustainable.
Figure 20.1 illustrates the components of the business model as customers, offerings,
resources and resilience (CORR). Each of these components is described in more detail in
Figure 20.1, and can be summarized as follows:
Customers include customer segment analysis, recruitment and retention, and how the
product or service will be delivered.
Offerings refer to a customer's value proposition and the associated benefits provided
to that customer.
Resources include organizational data, capabilities and assets, as well as partnerships
and networks.
Organizational resilience is reputational (based on ethos and culture) and financial
resilience (based on expenses and income).
The importance of the business model is that it represents how core operational and
compliance processes work together to deliver the customer experience. It is important for
organizations to understand the business model, so that they can conduct a strengths,
weaknesses, opportunities and threats (SWOT) analysis of the existing business model. A risk
172
assessment of the existing business model will enable organizations to evaluate the efficiency
of the existing arrangements and identify events that could disrupt the efficient delivery of the
offering, as well as identify opportunities to improve operational efficiency and compliance.
It is important to note that a business model represents an existing mechanism for
delivery of customer offerings and provide a description of operational and compliance
activities. Risk assessment of the existing business model will enable the organization to
identify options for improvement of the customer offering and/or business model. The
identification of an updated business model will represent the strategic position that the
organization wants to achieve. Tactics to implement that strategy will need to be designed, as
identified in Figure 19.1.
Business models can be very complex and have many dependencies, including
suppliers and outsourced facilities. Weaknesses and inefficiencies in the existing business
model need to be identified and business model analysis is an additional way to conduct a risk
assessment. The importance of resilience in business models is discussed in the next section.
Another important factor in business models relates to reputation and ethical trading. A
particular consideration for many organizations is corporate social responsibility in the supply
chain. Business model analysis will allow organizations to assess the supply chain and
identify inherent risks, including ethical risks that could damage the organization's reputation.
20.2 RISK MANAGEMENT AND BUSINESS MODELS :
Each component of the business model can be subject to a risk assessment. The
business model represents how the organization fulfills its vision and mission statements, as
well as its goals and objectives. Although the offering is at the core of the business model, the
starting point is often an assessment of the customer segments at which the offering will be
targeted. Risks are associated with identifying and securing customers and providing
customer service and support. Distribution routes and channels are critical in the provision of
customer offerings. The offering itself is important and is at the core of the business model. It
is important that the offering refers to the resources and capabilities available to provide the
intended customer with the value position and associated benefits. The nature and use of the
resources and how they are structured represent a number of risks and these must be evaluated
during the risk assessment of the business model. An important part of the business model is
the resilience of the organization, along with its reputation. There are many alternative
versions of business models, but some fail to provide an adequate profile for the
organization's reputation.
Culture and ethics, and organizational reputation are discussed later in this chapter.
173
Reputation often characterizes the sector in which an organization operates. Reputation is
often considered an aspect of any organization. Reputation also has a sustainability
component where the organization wants to maintain and/or enhance its reputation. All
business models need to be sustainable and this is usually represented by the financial
sustainability of resources and the need to balance expenditure with revenue streams.
Sustainability often has a broader context and may also include environmental considerations.
The scope of the sustainability requirements of the organization and its business model needs
to be included in the risk assessment. The business model assessment will focus on
operational hazards or risks, along with compliance risks. To achieve an effective and
efficient business model, operational risks need to be mitigated and compliance risks need to
be minimized.
Having identified the business model and conducted a risk assessment, the
organization then needs to decide whether the existing business model is sustainable. If it is
deemed that there is room to improve the business model, a new or modified business model
needs to be identified. Achieving this enhanced business model becomes the strategy of the
organization. The way the business model is modified to achieve the strategy can be
considered the tactics of the organization and these tactics will be implemented through
projects and/or work programs that achieve the required changes.
Strategic risks associated with improving the business model need to be embraced and
risks associated with implementing tactics need to be managed. The overall approach of
embracing strategic risk, managing tactical risk, mitigating operational risk and minimizing
compliance risk, is referred to in this book as EM3. A component of a successful business
model is successfully recruiting new customers and drawing customers into a deeper
relationship with the organization, so that the relationship is sustainable and becomes more
secure. Therefore, business model refinement requires not only recruiting additional
customers, but also maintaining existing customers at an ever-increasing level of customer
satisfaction.
20.3 REPUTATION AND GOVERNANCE COMPANY:
Figure 28.1 illustrates corporate social responsibility (CSR) as part of an organization's
overall corporate governance requirements. All types of organizations should be aware that
good corporate social responsibility standards can enhance reputation and build stakeholder
value. Conversely, incidents, events and losses associated with poor social responsibility
standards can create bad publicity and destroy stakeholder value.
The importance of good standards of corporate social responsibility is widely
174
recognized and achieving good standards can enhance organizations with:
protect and enhance reputation, brand and trust;
attract, motivate and retain talent;
managing and mitigating risk;
improve operational and cost efficiency;
granting a business license to operate;
develop new business opportunities;
creating a safer and more prosperous operating environment.
There are various definitions available for corporate social responsibility. It is generally
accepted that CSR is a broad agenda involving organizations looking at how to improve their
social, environmental and local economic impacts as well as their effects on society and
human rights. The CSR agenda also includes consideration of fair trade issues and the fight
against corruption. Before corporate social responsibility became a widely used term, some
organizations used to refer to social, ethical and environmental (SEE) issues. The CSR agenda
includes all the issues that were previously included in the SEE agenda.
There is no doubt that CSR is an issue for large multinational corporations as well as
for locally based small businesses and the public sector. Indeed, it is relevant for all types of
organizations, including charities. The definition of corporate social responsibility by the
European Commission is as follows:
Corporate Social Responsibility is the concept that a company is responsible for its impact on
all relevant stakeholders. It is an ongoing commitment by business to behave fairly and
responsibly and contribute to economic development, while improving the quality of life of its
workforce and their families, as well as local communities and society at large.
20.4 CSR AND RISK MANAGEMENT :
The scope of issues covered by CSR is presented in Table 20.1. The range of topics
extends from health and safety issues to broader considerations related to employees,
customers, suppliers, communities, the environment, and the products/services provided by
the organization. The CSR and risk management agendas are both very broad and have
significant overlap.
Many of the issues listed in the table are risk-based subjects, including workplace
health and safety and environmental impacts. However, managing these issues only as risks
will fail to fully address the CSR agenda. Nevertheless, it is a good starting point. Many risk
175
assessment workshops consider corporate social responsibility and social, ethical and
environmental considerations in the topics evaluated.
When assessing the CSR agenda, risk managers should take the opportunity to bring
risk management tools and techniques to the wider agenda. The risk management approaches
of risk assessment, identification of control measures and compliance auditing are transferable
approaches to corporate social responsibility and, indeed, the wider corporate governance
agenda. Most organizations regard CSR as a reputational issue and see the component parts of
CSR as a risk of harm. Such organizations will consider that they need to reform their core
processes and procedures to meet these requirements. This may be an accurate starting point
for many organizations. However, as Figure 4.2 illustrates, what starts as a hazard risk can
evolve into a control risk and eventually into an opportunity.
Like other areas of risk management, organizations should seek to develop their level
of sophistication in relation to CSR. Having reached the stage of fulfilling CSR obligations,
organizations should then look at the opportunities that exist. For example, it is now
commonplace for supermarkets to offer goods that have been purchased on a 'fair trade' basis
and gain additional sales from offering this range of products. Corporate social responsibility
is an area of concern where it is likely that public opinion will be at the forefront of thinking
in many organizations. CSR issues therefore represent a great opportunity for organizations to
develop corporate social responsibility plans and actions that respond to public opinion.
Treating the CSR agenda as a dynamic and proactive set of issues will allow organizations to
gain reputational advantages.
Many organizations have stakeholders that they don't necessarily want. This is
certainly the case with some energy companies. Oil, coal and mineral exploration are
scrutinized by environmental pressure groups. Even if they are 'unwanted stakeholders',
environmental pressure groups are legitimate stakeholders in these organizations and can
bring considerable influence to bear on their activities. Environmental pressure groups have
firm demands on the CSR agenda.
The list of issues in Table 20.1 provides an indication of stakeholders who may have
an interest in the CSR agenda. Employees, customers, suppliers, and the general public are the
key groups that are stakeholders in an organization's CSR agenda. For CSR issues related to
the environment, it can be said that everyone is a stakeholder in an organization's behavior
when that behavior impacts the environment.
An example of the impact that pressure groups can have is shown by the following
report on the website of the environmental action group Greenpeace. The report relates to
Shell's proposed disposal of the Brent Spar oil storage facility in the mid-1990s.
176
Brent Spar Shell:
In 1995, Greenpeace activists occupied the Brent Spar oil storage facility in the North
Sea. Their aim was to stop plans to scuttle the 14,500-ton installation. The action was part of
an ongoing campaign to stop the dumping of waste into the sea and pitted Greenpeace against
the combined forces of the British government and the world's largest oil company at the time.
Spontaneous protests in support of Greenpeace and against Shell broke out across Europe.
Some Shell stations in Germany reported a 50 percent drop in sales. Chancellor Kohl raised
the issue with the British government at the G7 meeting. But despite the UK government's
refusal to drop plans to allow the Spar to be dumped overboard, public pressure proved too
much for Shell and in a dramatic victory for Greenpeace and the marine environment, the
company reversed its decision and agreed to dismantle and recycle the Spar on land.
The decision led to a ban on ocean dumping of such rigs by the international body that
regulates ocean dumping. Prior to the Brent Spar campaign, a number of oil companies had
planned ocean dumping of obsolete installations, such as oil storage buoys (like Shell's Brent
Spar) and oil rigs. Greenpeace's actions and the support of people across Europe ensured that
no such structures are dumped to this day.
20.5 ETHICAL SUPPLY CHAIN AND TRADE :
Failure to ensure appropriate ethical behavior is increasingly recognized as a major
business risk. Newspaper reports describing bribery and other forms of other dishonesty has
serious consequences for the company's reputation and future profits. Easy access to
information on the internet can result in organizations being investigated and exposed for
unethical trading and/or unfair treatment of suppliers. If unethical behavior extends to illegal
activities, this can damage the organization itself. Illegal behavior and forgiving actions that
fall outside of an organization's governance rules can have serious consequences. The
perceived need to bribe officials in certain regions is unethical and illegal.
There are several areas where unethical trading can result in reputational damage, loss
of future profitability, and refusal on the part of customers and suppliers to deal with the
organization. These issues include:
failure to comply with rules and regulations;
trade with unwanted foreign governments;
excessive payments to political parties;
tax avoidance or questionable tax arrangements;
inappropriate criticism of competitors;
177
false accusations against competitors;
unethical alliances with competitors.
Another feature of the supply chain that may result in accusations of unethical trade relates to
the sourcing of products produced under socially unacceptable working conditions. In
addition, product quality and failure to deliver value for money can result in reputational
damage and can be associated with unethical trade. Goods that do not meet current safety
standards may result in adverse publicity and damage to reputation.
When a sports club decides it wants all merchandise sold to fans to be ethically
sourced, it needs to look at the controls it can place on the importer to ensure that it only
acquires merchandise from ethically produced sources. The club can ask the importer to make
regular CSR reports as part of the contract terms and conditions. This report will include the
following information:
details of the policies that importers have on the ethical behavior of suppliers;
confirm the terms and conditions of the manufacturing contract;
a statement that the manufacturer does not perform sub-contracting work, unless
authorized;
details of staff training, accident/absence rates and salary/conditions;
results of audit/physical inspection of the production site.
The club can then advertise to fans that all goods come from ethical sources and encourage
other teams in the league to do the same. This will gain good publicity and promote the club
as having a high sense of corporate social responsibility.
Positive reporting on corporate social responsibility issues can be a significant benefit
to the organization. This will be especially true when the organization operate in areas where
the public is suspicious. The public may not be sympathetic to an organization, due to
perceptions of the business world and/or the organization itself. When an organization
operates in a sector that does not have universal public support, there may be merit in
producing an ethics policy. The importance of an ethics policy will be reinforced if the
organization also conducts an ethics audit.
For example, a sector that does not have the full support of the public is gaming and
gambling. Therefore, organizations operating in this field should look to improve the
reputation of the sector by working with competitors on social responsibility standards for
problem gambling. An individual organization can then benefit further by being able to
demonstrate that it exceeds the minimum standards set for the sector. Many organizations now
include comments on corporate social responsibility in their annual reports and accounts, and
178
some produce separate CSR supplements. The production of reports on corporate social
responsibility activities allows organizations to benefit from the CSR agenda.
Where an organization has a positive story to tell about CSR achievements, it will take
the CSR agenda from a need for reform to a position where the organization can demonstrate
that it is compliant. The next stage in the development of this sophistication is for the
organization to demonstrate that adherence to the CSR agenda enables it to perform better and
more successfully meet stakeholder expectations.
Corporate Social Responsibility Reporting:
The annual report must:
Include information on social, ethical and environmental-related risks and
opportunities that could significantly affect the company's short-term and long-term
value and how they impact the business;
Describe the company's policies and procedures for managing risks to short-term and
long-term value arising from social, ethical and environmental issues;
Include information on the extent to which the company has complied with its policies
and procedures for managing social, ethical and environmental risks;
Describes the verification procedures for social, ethical and environmental disclosures,
which should be such as to achieve a reasonable level of credibility.
20.6 THE IMPORTANCE OF REPUTATION:
Reputation is fundamentally important for organizations. In fact, it is often said that an
organization's reputation is the most valuable asset it has. Because reputation is so important
and can be easily lost, organizations must ensure that they understand the basis of their
reputation. Reputation is based on the size, nature, and complexity of an organization, but it
would be useful to put more structure into what makes a good reputation. There have been
many attempts to identify the components of reputation. Table 20.2 shows the components of
reputation and these are also illustrated as a spidergram in Figure 20.2. The four main
components of reputation (CASE) are as follows:
Capabilities, including goals and resources;
Activities, including process and finance;
Standards, including service/product and support;
Ethics, including values and integrity.
Reputation is a component of a FIRM's risk scorecard and is generally considered a
179
consequence of other events occurring. The importance of a good reputation is that customers
or clients will have a desire to trade with that organization.
Organizations must therefore look carefully at the reputation of the sector they are
working in, as well as their own reputation within that sector. Many organizations deliberately
plan actions that will enhance their reputation and thus achieve greater success. An
organization must have the necessary capabilities to plan strategies, implement tactics,
continue operations and ensure compliance. Capabilities should be reflected in a clear
statement of purpose, intent or commitment. The activities an organization undertakes will
depend on the sector in which it operates. Also, the organization will need the necessary
finances and financial stability to support its activities. Together, an organization's capabilities
and activities define that organization from an internal perspective.
The organization will offer a range of services and products and standards of service
and service delivery will be an important component of reputation. Finally, the organization
will have business ethics that demonstrate its integrity. Integrity will be demonstrated, to
some extent, by performance monitoring to learn and achieve continuous performance
improvement. The use of a chart, such as the one shown in Figure 20.2 will allow an
organization to map its overall reputation, in the context of the sector in which it operates. For
each of the four segments, or eight attributes, an organization should be able to plot its current
status in ratings of 1 to 4, representing poor, adequate, good, and excellent. It will then be
possible for organization to identify the sectors that represent the greatest threat to the
organization's reputation. Table 20.3 provides examples of how threats can arise.
This chapter has considered the importance of reputation in general and used corporate
social responsibility as an example of one of the key pillars of reputation. However, reputation
is a broader issue than just business ethics. Indeed, customers will often trade with an
organization even if they do not believe that it has an ethical business model. Although only a
cursory view and discussion of reputation has been included in this book, the ultimate
importance of reputation is fully recognized, especially in relation to risk management.
The importance of brand and reputation is recognized by all organizations. Some
companies that deal directly with the public seek to build a reputation based on trust and
ethical behavior. For many organizations, this is not the latest innovation, but is the ethos that
underpins their customer offering. The importance of reputation is demonstrated by the
excerpt from the 2015 Annual Report and Accounts from Unilever PLC in the text box below.
Monitoring Reputation:
Global businesses working in many countries face many issues in their day-to-day
180
operations. Therefore, it is imperative that the responsibility committee The company seeks
regular briefings on the systems and processes in place to manage issues. The Committee
requests an annual summary of the most material issues Unilever addresses, which in 2015
included issues such as climate change, food and beverage taxation, responsible use of
technology and human and labor rights.
Given the committee's role in ensuring Unilever's reputation is well managed, it may
also seek independent views on how Unilever is perceived in society. One of the major annual
surveys on reputation in sustainability is conducted by a research institute and its
methodology draws on the views of over 800 sustainability experts in more than 80 countries.
It reveals that a growing number of them see that corporate leadership in sustainable
development is primarily driven by making sustainability part of the company's core business
model. Some 38 percent of respondents said that Unilever 'integrates sustainability into its
business strategy', placing it well above the rest in this regard.
RISK MANAGEMENT CONTEXT
21.1 ARCHITECTURE, STRATEGY, AND PROTOCOLS :
This section provides information about the risk architecture, strategy, and protocol
(RASP) for an organization. The RASP provides details of the risk management framework
for the organization and it helps to define the risk management context. Table 21.1 describes
the key features of the risk architecture, strategy and protocol in more detail. The most
important component of the RASP is the risk management policy statement. The RM policy
will set the organization's overall strategy towards risk management. Other parts of the overall
risk management manual define risk management roles and responsibilities and establish the
protocols to be followed.
The risk architecture, strategy and protocols create a risk framework that supports the
risk management process. British Standard BS 31100 provides notes on the risk management
framework stating that it should include objectives, mandate and commitment to managing
risk (strategy), and organizational arrangements that include plans, relationships,
accountabilities, resources, processes and activities (architecture), and that the framework
should be embedded in the organization's overall strategic and operational policies and
practices (protocols).
Risk architectures, strategies, and protocols are equivalent to risk frameworks, as
described in ISO 31000. As a result, the risk architecture, strategy, and protocols represent the
181
context of risk management within the organization. The risk strategy component will
typically be set out as a one-page statement of what the organization wants to achieve with
respect to risk management. ISO 31000 refers to this one-page statement as the risk
management policy.
The risk management policy will be part of a larger risk management manual in many
organizations. Most large organizations will document their risk protocols as a set of risk
management guidelines. The range of guidelines required will vary according to the size,
nature and complexity of the organization. The types of documentation that need to be kept
are as follows:
risk management administration records;
risk response and improvement plan;
event report and recommendations;
risk performance and monitoring reports.
One of the standard documents produced by organizations as part of their risk management
initiatives is the risk register. Risk registers can be produced for various operational, project
and strategic purposes. Possible risk register formats are discussed in Chapter 7 and the basic
format is illustrated in Table 7.1.
The working relationship between risk management and internal audit is critical. Risk
management's expertise lies in assessing risk and identifying existing controls and additional
controls. Internal audit has its expertise in evaluating controls and testing their efficiency and
effectiveness. Successful implementation of risk management initiatives will require close
cooperation and understanding between risk management and internal audit. The RASP
should describe in detail how this close cooperation will be achieved in practice.
Risk architecture defines how information about risk is communicated throughout the
organization. Risk strategy defines the overall goals that the organization wants to achieve
with respect to risk management. Risk protocols are the systems, standards, and procedures
implemented to fulfill the established risk strategy. The risk architecture forms part of the risk
management framework. The risk management framework, in turn, is part of the overall risk
governance arrangements within the organization.
Risk Management Policy for the Board:
Introduction
Risk management is an integral part of good management practice and an important
part of corporate governance. This strategy statement outlines the arrangements in place to
182
ensure the council identifies and addresses the key risks it faces. The council has adopted
proactive risk management arrangements to enable decisions to be based on comprehensively
assessed risks, ensuring the right action is taken at the right time. How successful the council
is in addressing the risks it faces can have a major impact on the achievement of key
strategies, priorities and service delivery to the community. A risk management strategy helps
support the council's goal of becoming a world-class organization.
Destination:
The goal of this strategy is to:
fully integrate risk management into the board's culture and its strategic and service
planning processes;
ensure that the risk management framework is understood and applied by staff with
operational responsibility for risk;
communicatingthe board's risk management approachto stakeholders;
ensuring the benefits of risk management are realized through maximizing
opportunities and minimizing threats;
ensuring consistency across the board in risk management.
Risk Management:
The focus of good risk management is the identification and handling of risks. This
increases the likelihood of success and reduces the likelihood of failure and the uncertainty of
achieving objectives. Risk management should be an ongoing and evolving process that runs
throughout the council's strategy and service delivery. Learning lessons from past activities
helps inform current and future decisions by mitigating threats and optimizing the utilization
of opportunities. Celebrating and communicating successful risk management in turn
encourages a bolder but calculated approach.
21.2 ARCHITECTURE RISK:
The risk management organization and setup of an organization can be described as a
risk architecture. The risk architecture establishes the communication channels for reporting
risk management issues and events. It is essential that the risk architecture reinforces the fact
that the responsibility for managing a risk remains with the owner of that risk. In order for risk
management to be fully incorporated into the core processes and operations of an
organization, a clear statement of responsibility for risk management is required. In addition,
183
as part of the analysis of each significant risk, risk management responsibility needs to be
clearly allocated to the following aspects of risk management:
development of risk strategies and standards;
implementation of agreed standards and procedures;
audit compliance with agreed standards.
Risk architecture can be represented diagrammatically as a means of identifying committees
with risk management responsibilities and the relationships between those committees. The
importance of an organization's risk architecture is discussed in Chapter 22 and an example of
a typical risk architecture is provided. The risk architecture will include details of the terms of
reference of the various committees. It will include details of the membership and
responsibilities of the various committees. The risk architecture should also provide
information on how risk information is communicated between the various committees.
The risk architecture shows the relationship between the various committees that have
been established in the organization. The membership and responsibilities of the committees
need to be defined in the appropriate terms of reference. The risk architecture will also include
details of the reports received by each committee and the reports required from those
committees. An important aspect of the risk architecture is to ensure that risk escalation
procedures are embedded in the organization, including appropriate breach reporting
arrangements.
When considering the various documentation that needs to be created, organizations
should distinguish between risk protocols recorded in the risk management manual and
documents or reports intended to track and monitor changes and improvements. The risk
management manual can be considered a static record of processes and procedures, while the
other documentation, for example the risk register, should be a dynamic record of planned or
ongoing actions. As a result, the risk register should be considered a risk management action
plan.
21.3 RISK MANAGEMENT STRATEGY:
It is important for organizations to have a clearly defined strategy in relation to risk
management. The risk management strategy for the organization will be set out in the risk
management policy statement. The strategy needs to be based on the organization's overall
approach to risk and risk management. An important component of that risk strategy is the
requirement that there is risk management input into strategy, tactics, operations, and
compliance (STOC).
To establish a risk management strategy, important decisions need to be made about
184
the organization's risk appetite. Risk appetite will be based on the organization's opportunity
investment, control acceptance and hazard tolerance. It is important that the risk appetite is
within the total risk capacity of the organization. Decisions will need to be made on how risk
capacity will be calculated. Also, thought needs to be given to how the organization's total
risk exposure will be recorded and used in the decision-making process. The measurement of
an organization's total risk exposure is an important feature of operational risk management,
as discussed in Chapter
30. There are important decisions to be made regarding the risk process to be adopted by the
organization, as well as decisions about the design and implementation of the risk
management initiatives that will be planned and implemented to meet the requirements of the
risk strategy.
The risk management strategy will include details of what the organization wants to
achieve with respect to risk management. The strategy may set out details of the desired level
of risk maturity, along with information on the expected level of contribution from risk
management. As a result, the risk management strategy will set out the way in which risk
management activities are aligned with other activities in the organization and the expected
contribution of risk management activities.
21.4 RISK MANAGEMENT PROTOCOL:
The risk management manual will set out responsibilities for risks as well as
arrangements for implementing policies. Risk management protocols will be set out in a series
of risk procedures and guidelines and these will be described later in this chapter. Procedures
and protocols for conducting risk assessments of strategies, projects and operations need to be
established in writing. The organization will also need to establish guidelines on the
frequency and nature of risk reports and who is responsible for collecting the information.
Typically, risk management protocols need to be reviewed annually, so that they
remain up-to-date. The risk protocol should also describe the level of record keeping required.
The range of risk management documentation that may be required is wide and Table 21.2
provides an overview of the types of documents that may be appropriate. Risk management
protocols describe the various activities performed on behalf of risk management. Protocols
define the activities to be performed and how they will be performed. Risk management
guidelines usually refer to standards that must be achieved. In some cases, they include details
of existing controls. This is especially true for guidelines that identify procedures to be
performed. These procedures will provide direction for directors, managers and staff within
the organization.
185
21.5 RISK MANAGEMENT GUIDE:
The extent of documentation produced by an organization in relation to risk
management will vary considerably. The documentation produced should be proportionate to
the level of risk the organization faces, in accordance with the applicable principles of risk
management, as listed in Table 5.1. Whatever is produced needs to be structured in a way that
is appropriate to the organization and aligned with other activities taking place within the
organization. The first part of the risk management guide is the risk management policy. A
sample risk management policy statement for the board is presented in the box on page 246.
The policy sets out the risk strategy for the organization. It is a statement of intent and sets the
risk management context for the organization. The risk management policy should facilitate
the successful implementation of risk management within the organization.
The risk management manual contains details of all responsibilities, procedures,
protocols and guidelines regarding the risk management process and risk management
framework for the organization. An illustration of the appropriate content for a risk
management manual is presented in Table 21.3. The manual should confirm the protocols for
performing activities, as set out in the risk guidelines for the organization. The risk guidelines
can be created as a separate set of documents, so they can be more easily updated. The risk
management manual will include the strategy that the organization wants to achieve with
respect to risk management, as the risk management policy. The risk management manual will
also set out details of the systems and procedures to be put in place to monitor performance, as
well as the means for reporting and communication on risk management. It will, in effect,
define the context in which risk management activities take place.
A set of risk management protocols or guidelines needs to be established, and a typical
set of protocols is listed in Table 21.4. Risk protocols provide more information on how risk
protocols should be interpreted and how they should be delivered. Risk management protocols
can be seen as fixed instructions relating to risk management. They will often require record
keeping, for example a risk register.
Detailed risk management protocols or guidelines will be established:
risk assessment procedures;
risk control objectives;
risk resource management;
reaction planning requirements;
risk assurance system.
186
The established risk framework or architecture to achieve adequate risk management should
also be presented in the risk management manual. Furthermore, individual companies within
the group will operate within the established framework and set up their own additional
procedures and protocols where necessary. In particular, the risk management manual should
include details of at least the following:
board member responsible for risk management;
language and perception of risk within the organization;
framework for identifying significant risks;
the role of risk managers and internal auditors;
terms of reference for the risk management committee;
risk management structure or risk architecture.
Many organizations find it necessary to update the risk management manual annually, even if
the overall risk management strategy remains unchanged. This is done for a number of
reasons, including a desire to ensure that risk management activities and the overall risk
management approach are in line with current best practices. Updating the risk management
manual, including the risk management policy, annually also gives the organization an
opportunity to identify risk priorities for the coming year and ensure that appropriate attention
is paid to significant risks. Publishing an updated risk management policy annually also
ensures that the board gives proper attention to risk management and that the organization
understands that it is a dynamic activity that requires constant management attention.
21.6 MANAGEMENT DOCUMENTATION RISK:
Table 21.4 shows the extent of risk management guidelines or protocols that an
organization may need to establish. It should not be seen as an exhaustive list and other types
of protocols, guidelines or procedures may be required, depending on the exact nature of the
organization and the risk strategy it follows.
The development of a risk management manual, including a policy statement, is a
good opportunity for the organization to establish detailed procedures on various risk
management topics, as well as set risk management priorities for the year. Next. For example,
many organizations create annual health and safety and/or environmental policies and
procedures, and these should be an integral part of the risk management documentation. Many
organizations face significant risks that require regular or even constant management
attention. This is especially true in the case of hazard risks, where health and safety policies
and procedures, business continuity plans and disaster recovery plans (for example) need to be
187
regularly updated.
For many organizations, risk guidelines will be in writing. Other organizations will
operate a more informal way of embedding risk management into management activities. Risk
guidelines often include details of the risk management structure in place at the organization.
Also, details of risk strategies and risk protocols need to be included in risk guidelines. They
should also include details of the (internal) control responsibilities of managers. The structure
described in Table 21.4 reinforces the importance of the activities involved in the risk
management process. Each of these activities produces several outputs, and the required
outputs can be discussed in the risk manual.
The guidelines need not include a set of risk controls or loss control standards, but
should explain how risk control decisions will be made, implemented and audited. In fact, risk
guidelines for a diverse group of companies cannot include physical control requirements and
standards. Each unit, division or department should set its own standards for risk control,
including health and safety, fire safety, physical security, information security and
environmental protection. This may be appropriate due to the diverse nature of different units
within the organization. Risk guidelines should specify ways to achieve embedded risk
management in the organization. The establishment of strategies, standards and procedures
needs to be done within the framework of the risk guidelines. The format of the risk
guidelines will depend on the organization and the nature of the risks it faces.
Typically, these guidelines will contain at least the following information:
financial and authorization procedures;
insurance arrangements;
manager's control responsibility;
project risk management;
incident reporting and investigation;
event planning and reaction;
physical risk control objectives and responsibilities.
Table 21.2 sets out the various risk management documentation that an organization may need
to keep. In order to successfully embed risk management, it is necessary to maintain various
risk management records. These records will include details of various risk management
activities, including:
risk management administration;
risk response and improvement plan;
event report and recommendations;
188
risk performance and certification reports.
Embedded risk management will be achieved when the risk management activity cycle is
fully aligned with the organization's planning cycle. The main purpose of risk guidance is to
help managers understand the organization's risk management framework. This understanding
will ensure that managers give appropriate attention to risk implications when making
decisions. Risk guidelines for organizations also provide practical guidance to managers on
how to fulfill their risk management responsibilities. Keeping the necessary records will allow
the organization to demonstrate successful implementation of the risk guidelines. Risk
management administration documentation should include (at least) the items listed in Table
21.2.
It is not the intention that risk management record keeping be overly bureaucratic or
burdensome. However, adequate records need to be kept so that information is available for
decision making, necessary advice to managers can be accessed and confirmation can be
provided to auditors that the necessary controls have been properly implemented. The
importance of record keeping is highlighted below.
Importance of notes:
There are many benefits to be gained from implementing records management.
Records management is a key driver in improving organizational efficiency and offers
significant business benefits. Records management:
reduce the time spent by staff searching for information;
facilitate effective information sharing;
reduce unnecessary duplication of information;
identify how long records need to be kept;
optimize legal admissibility of records to defend malicious litigation;
support risk management and business continuity planning.
In short, records management improves control over information assets, frees up staff time
and other resources, and helps protect individuals and organizations from a variety of risks.
Records management means that too much reliance is not placed on the memories of a few
individuals.
The only reason to conduct a risk assessment is so that current controls can be
validated and the need for further action to improve risk control can be identified. The risk
register is a means of recording information about current controls and details of intended
additional controls. It is important that the risk register should not be a static document. It
189
should be treated as a dynamic element and considered a risk action plan for the unit or
organization as a whole. In addition to the risk response plan, information should also be
recorded about responsibility for individual controls. If additional controls are required, then
deadlines, as well as responsibilities, for the implementation of such enhanced controls should
be noted.
Part Four of this book discusses risk response options in more detail. For hazard risks
and control risks, the risk register is the location to record details of significant threats. A
detailed analysis of risk improvement plans will be required. Often, risk improvement plans
will require capital expenditure, and this may need to be approved through expenditure
authorization procedures within the organization. It is standard practice to generate risk
registers for projects, especially for construction and software projects. Risks to construction
and software projects can create a lot of uncertainty and the risks are usually control risks.
Again, the record of actions taken to minimize uncertainty should be dynamic, and subsequent
actions should be planned.
It is a common criticism of risk registers that they are conducted once or twice a year
and represent a static picture of the risks facing the organization. To be effective and make a
significant contribution, risk management needs to be a dynamic activity that produces
outputs that impact the organization. If this is going to happen, then the risk register needs to
be a document that drives change and improvement. Perhaps, it would be better if the risk
register is referred to as the 'risk management action plan' for the organization. Event reports,
analysis, and recommendations relate to recording the details of events that occur and
managing the impact and consequences of those events. Details of incident investigations and
analysis of business operations performance, along with risk improvement recommendations,
are all covered in this type of risk management documentation. Risk improvement
recommendations address significant control weaknesses and aim to eliminate the potential
for material or significant failures in the future.
Recording events is an important activity, especially with regard to hazard risks. Also,
recording and analyzing events during the project will be very important. Event reports are
most relevant to hazard risks and controls. The annual evaluation of risk performance will also
generate reports that require detailed analysis. Risk performance evaluation is an important
role for internal audit. Clinical risk management is a well-developed branch of the risk
management discipline. Accurate record keeping is essential to identify that appropriate risk
mitigation actions have been taken, as well as to provide a record of any clinical accidents that
occur. The box below provides an overview of the importance of record keeping in relation to
clinical risk management.
190
Managing Clinical Risk:
Even if all adverse clinical events could be avoided, the legal costs of malpractice
litigation cannot be eliminated. While very few injuries resulting from negligence lead to
claims, there are many negligence claims in cases where there is no injury and no negligence.
This means that, if proper risk management processes and systems are in place, hospitals and
doctors should be able to refute allegations of negligence in these circumstances and
successfully argue that no compensation payments should be made.
The implementation of risk management activities in hospitals is the direct
responsibility of hospital management. Nevertheless, clinicians have an important role to play
by developing an understanding of the importance of risk management and helping to devise
practical approaches to record that procedures have been followed and any incidents have
been recorded.
Performance reports and risk certifications include consideration and analysis of initial
reports of operating results, as well as more formal statements and certified reports to
stakeholders. In some cases, certification of the organization's operating results will be
conducted as a formal attestation of operating results. This approach is required by the
Sarbanes-Oxley Act in relation to financial reporting.
This attestation will often be carried out by a third party, such as an external auditor.
Such an attestation can also relate to an evaluation of the effectiveness of the control
activities.
Management will be keen to receive details of risk performance. This will be
particularly important when the organization is faced with a risk portfolio that brings the total
risk exposure close to the limits of the organization's risk appetite and/or risk capacity. For
example, an organization may have budgeted for a certain level of losses in relation to hazard
risks. If this budget is challenged, then careful monitoring of losses will be required to ensure
that exposure to certain types of hazard risk is not exceeded. Hazard tolerances may be limited
so organizations need to monitor hazard losses very carefully. For example, transportation
companies need to monitor the number of motor vehicle accidents and the frequency of
damage associated with the vehicles the company runs.
Students also viewed