191
RISK MANAGEMENT RESPONSIBILITIES
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 8
22.1 RESPONSIBILITY ALLOCATION RESPONSIBILITY:
Everyone who works for an organization needs to be made aware of their risk
management responsibilities, as do contractors and suppliers. There are many professionals in
large organizations who have an understanding of risk and make a major contribution to the
successful management of significant risk priorities. Unfortunately, there is not always a
common view of risk management or the issues that are important to the organization.
Ownership of core processes, key dependencies and risks is important, as it allows risk
management and the audit committee (see Section Eight) to monitor actions and
responsibilities. This ownership is important for all risks, although the audit committee will
only monitor prioritized significant risks.
Confusion of responsibilities and reporting structures should be eliminated. There
should be a clear statement of responsibility for the following aspects of management of each
prioritized significant risk:
•
set the necessary risk standards;
•
implementing risk standards;
•
monitoring risk performance.
A detailed set of responsibilities will ensure that the roles of risk owners, process owners,
internal audit, risk management functions, staff members, contractors, and outsourced
operations and others are clearly defined and understood. The allocation of responsibilities to
committees, as part of the risk architecture is also an important consideration. Membership,
responsibilities and reporting structures will typically be described in each committee's terms
of reference.
Information on the ownership of each priority significant risk should be included in
the risk register. It is important that the activities of risk managers, risk management
committees, audit committees, internal auditors and others do not diminish local ownership of
significant risks. Managers should view risk ownership as an integral part of managing core
processes and business activities, not as a separate issue that is the responsibility of
192
professional risk management specialists and/or internal audit practitioners.
22.2 RESPONSIBILITY RANGE:
Table 22.1 presents examples of the range of risk management responsibilities of line
management, key functional departments, and individual employees involved in risk
management. The risk management professionals involved will include the following
individuals (at a minimum), depending on the size of the organization:
•
insurance risk manager;
•
company treasurer;
•
finance director;
•
internal auditor;
•
compliance manager;
•
health, safety and environment manager;
•
business continuity manager.
The structure of Table 22.1 is also important. Items 1, 2 and 3 allocate responsibilities to the
management of the organization. Item 1 relates to the allocation of responsibilities to top
management, being the board and executives. Item 2 relates to the allocation of responsibility
to department heads or middle management. Item 3 relates to the allocation of risk
management responsibilities to staff. Together, these three layers of management represent
the first line of defense in ensuring that adequate attention is paid to risk management and
internal control.
Item 4 of Table 22.1 describes the responsibilities of the risk manager for the
organization. Item 5 sets out the responsibilities of specialist risk management functions, such
as health and safety or business continuity. In providing specialist support to management,
these functions can be considered a second line of defense in achieving satisfactory risk
management and internal control. Item 6 of Table 22.1 sets out the responsibilities of the
internal audit manager. Internal audit activities can be considered the third line of defense in
ensuring adequate standards of risk management and internal control. Externally, insurance
brokers, insurers, accounting firms, and external auditors also have a contribution to make to
improving risk management within their client organizations. It is important that risk
management professionals work together. However, it is also important that the benefits of
risk management are incorporated into the core processes of the organization.
193
Three Lines of Defense:
The objective of operational risk management is not to eliminate operational risk
altogether, but to manage risk to an acceptable level, taking into account the cost of
minimizing risk compared to the resulting reduction in exposure. Strategies for managing
operational risk include avoidance, transfer, acceptance and mitigation by control. To ensure
appropriate responsibility is allocated for the management, reporting and escalation of
operational risk, the group operates a 'three lines of defense' model which outlines the
principles of roles, responsibilities and accountabilities for operational risk management.
The three lines of defense model and policy standards apply across the group and are
applied taking into account the nature and scale of the underlying business. The standards
provide direction for delivering effective operational risk management. They consist of
principles and processes that enable the identification, assessment, management, monitoring
and reporting of operational risks consistently across the group. The purpose of the standards
is to protect the group from financial loss or damage to its reputation, customers or staff and
to ensure that the group meets all necessary regulatory and legal requirements.
There is a need to ensure that risk management receives a sufficiently high profile. It
is usually a board member who sponsors risk management awareness on the board and
presents risk management reports to the board. Typically, the risk manager will report to those
board members, and be responsible for the risk architecture, strategy and protocol (RASP).
One of the most important responsibilities to be allocated is that of a 'risk owner'. ISO Guide
73 defines a risk owner as 'a person with the authority and accountability to make decisions to
treat, or not to treat risks'. The guide also states that anyone who has accountability for an
objective also has accountability for the risks associated with that objective and the
implementation of controls to manage those risks.
22.3 LEGAL RESPONSIBILITY MANAGEMENT:
There is a growing trend in many countries to ensure greater clarity with respect to the
obligations of company directors. The common law duties of directors have evolved over the
years in most countries. The Companies Act 2006 in the UK has consolidated the common
law duties of directors and codified the general duties, as follows:
•
act in accordance with allocated responsibilities;
•
act in accordance with the company's constitution;
•
promote the success of the company;
•
conduct an independent assessment;
194
•
exercise reasonable care, skill and diligence;
•
avoid/declare conflicts of interest;
•
does not receive benefits from third parties.
Directors' responsibilities are important in relation to risk management, and adequate risk
management will assist in the successful fulfillment of these obligations. Risk management is
essential in promoting the success of the organization and exercising reasonable care, skill and
diligence. Directors of organizations need a good understanding of risk management so that
they will be in a better position to meet their legal and other duties.
Typically, the board of directors will be either executive or non-executive directors of
the organization. In certain organizations, such as charities and most government departments,
executive directors will meet separately as an 'executive committee' and non-executive
directors will form a 'board of governors'. Typically, executive directors will be full-time
employees at the organization with specific areas of responsibility. Non-executive directors
have an important role in risk management within the organization. However, this role is
usually limited to audit, assurance, and compliance activities. It may not be appropriate for
non-executive directors to be involved in individual risk management, due to conflicts with
non-executive audit responsibilities and because executive directors are in a better position to
understand and address the risks facing the organization. . The box below provides examples
of non-executive director roles and expectations. In general, non-executive directors should
not be directly involved in the day-to-day management of the organization. In most cases,
their role is to assist with strategy formation and performance monitoring. Strategy
implementation is the responsibility of the executive directors.
22.4 MANAGER ROLE RISK:
The typical historical role of the insurance risk manager is presented in Table 22.2.
Traditionally, risk managers have been involved in assessing overall risk policies and
procedures with support from the board. Decisions on insurance risk management issues and
the provision of statistical analysis of insurance losses have been part of this historical
responsibility. Insurance risk managers need to evaluate the current status of risk management
and reflect on the current state of the insurance market. Rising insurance rates and more
sophisticated approaches to risk financing have affected the amount of insurance purchased
by large organizations. In many cases, there is less insurance being purchased and this leads to
reduced premium expenditure and a lower budget for the insurance risk management
department.
195
There is no single reporting position established in the organizational structure for the
risk manager. Currently, risk managers may report to human resources, the finance director or
the company secretary. Sometimes, risk managers report to the corporate treasurer and,
sometimes, the chief executive officer (CEO).
There is still a need for risk management facilitators and coordinators in most large
organizations. This will allow organizations to apply risk management tools and techniques to
a wider range of issues. Risks have historically been divided into insurable (pure) and non-
insurable (speculative) risks. From a business success perspective, this is an artificial division
between risk types. The risk manager must be responsible for the corporate learning that must
take place so that the organization can understand the benefits of risk management. As the
person responsible for risk architecture, strategy, and protocol (RASP), the risk manager will
be responsible for developing strategies, systems, and procedures by which the required risk
management outcomes for the organization are achieved.
Historically, insurance risk managers may not be involved in strategic management
and organizational development. The broader role now required of a risk manager should lead
to greater involvement in project management and strategy formulation and delivery. Risk
managers who enjoy a wide range of responsibilities will have a very challenging role in the
organization. It will be a role that allows the risk manager to gain a better level of
understanding and involvement than most other roles or functions achieve.
Perhaps, the title 'risk manager' has too many historical connections to be used as an
apt description of what is now needed. There is a need to find a new title and redefine the role
of risk management at the same time. The importance of developing organizational resilience
may offer an opportunity for risk managers to evolve into 'risk and resilience managers' and
fulfill a much broader role designed to better align with organizational success.
Many organizations in the financial and energy sectors have identified the benefits of
unifying credit, market and operational risk management. It has long been the case in the
financial sector that risk management is separate from insurance purchasing. The development
of the chief risk officer (CRO) role reporting directly to the CEO reflects this fact. Given that
one of the key principles of risk management is that the approach to risk should be
proportionate to the level of risk the organization faces, it is unlikely that most organizations
will need to appoint someone with the seniority of a CRO. Nevertheless, organizations should,
when reviewing their risk architecture, decide on the appropriate range of responsibilities and
seniority level of risk managers. The introduction of the title 'chief risk officer' is not
universal, but is becoming common in the specialist financial and energy sectors. The box
below provides an overview of the evolving role of the chief risk officer. For organizations
196
where a CRO is proportionally appointed, the contribution that such an individual can make
will be substantial.
As a champion of the ERM process, the CRO plays a critical role in bringing together
different risk management processes to ensure that the company's limited resources are
applied effectively. The COSO ERM framework defines the CRO's role as working with other
managers to establish effective risk management, monitor progress, and assist other managers
in reporting relevant risk information up, down, and across the organization.
Internal auditors should work with the CRO as part of their risk management duties. In
this role, internal auditors are responsible for evaluating the accuracy of ERM reporting and
providing independent and value-added recommendations to management on its ERM
approach. IIA International Standards specify that the scope of internal audit should include
evaluating the reliability of reporting effectiveness, operating efficiency and compliance with
laws and regulations.
22.5 RISK ARCHITECTURE IN PRACTICE :
Figure 22.1 shows the risk architecture for a typical large corporate entity subject to
the requirements of the Sarbanes-Oxley Act. This risk architecture should be established in
the risk management manual for the organization. The terms of reference of the various
committees and a schedule of activities should also be established, both in the risk
management manual and in the risk management activities calendar. This schedule of
activities should be aligned with other enterprise activities within the organization.
For large organizations with non-executive directors, the audit committee should also
feature in the risk architecture. The role of the audit committee and the role of the head of
internal audit are important in fulfilling the organization's risk management strategy. For
organizations subject to the requirements of the Sarbanes-Oxley Act, there will also be a
requirement to ensure that all information disclosed by the company is accurate. In many large
organizations, this requirement has resulted in the formation of disclosure committees. The
role of the disclosure committee is to check the source and correctness of all information
disclosed by the organization. Sarbanes-Oxley requires that financial information be evaluated
to a higher level of scrutiny.
The organization's risk architecture establishes a hierarchy of committees and
responsibilities related to risk management and internal control. In the structure shown in
Figure 22.1, the enterprise risk management committee focuses on executive risk management
activities. Risk management responsibilities for activities at the divisional or unit level should
be allocated to divisional management. Divisional management is responsible for
197
coordinating the identification of significant risks at the divisional level, compiling a risk
register for the division and ensuring that adequate controls are identified and implemented.
Divisional management should be provided with guidance from the group risk
management committee. If there is a divisional committee, it should be required to submit
reports to the group risk management committee, so that a company or group overview of risk
management priorities can be established. For public sector or charitable organizations, the
risk architecture will be slightly different. Figure 22.2 sets out a typical risk architecture for
charities. In this case, risk management activities are focused on governance and risk
committees. The information flow and control of risk management activities is illustrated by
the arrows in Figure 22.2. It is clear from Figure 22.2 that risk governance for charities is a
much more important issue than in many other organizations. There are reports that charity
trustees regard governance issues as their top concern. This implies that many charity trustees
consider that governance is more important than raising money for the charities they support.
This could be an example of concerns about risk management becoming so great that it
undermines the nature of the organization.
There are many ways to establish risk management reporting lines. The reporting
structure should be proportionate to the level of risk and complexity of the organization. For
high-risk organizations, such as in the financial sector, the risk committee is likely to be a
direct sub-committee of the board. In these circumstances, it is likely that the risk committee
will be chaired by the group finance director and will have other senior representation from
the board. In general, the risk management committee should be an executive committee
composed entirely of executive directors with no non-executive director membership. This is
because risk management is an executive function and non-executive directors are mainly
responsible for audit and risk assurance. Usually, the risk management committee will submit
a report to the audit committee, and it will be an opportunity for non-executive directors to
evaluate risk performance and obtain risk assurance.
For organizations that do not operate in a high-risk environment, the risk committee
may not need to report directly to the main board. In these circumstances, the risk committee
may be a sub-committee of the executive committee or operating committee. In all cases, the
corporate structure for risk management should be proportionate to the level of risk in the
organization and the size, complexity, nature and risk exposure of the organization. However,
there is no specific structure that is right for an organization's risk architecture. Provided that
the risk committee delivers the required results, the membership and terms of reference will
be decided by the organization. Nevertheless, the general point remains that risk management
is an executive function, while audit activities should be led by non-executive directors.
198
22.6 COMMITTEE RISK:
Table 22.3 sets out typical responsibilities for the risk management committee (RMC).
Most large organizations already have an audit committee, chaired by a senior non-executive
director. The options considered by many organizations are to expand the role of the audit
committee to include all aspects of risk management or to establish a separate risk
management group chaired by an executive director.
There is a strong argument for the RMC to be an executive group, rather than part of
the existing non-executive audit committee. This is necessary because risk needs to be
managed proactively as an executive responsibility. The existing audit committee will likely
treat risk management as a non-executive (reactive) compliance audit. Separation of executive
responsibility for risk management from non-executive responsibility for compliance audit
and review would also be consistent with the principles of good corporate governance.
Some organizations have established the RMC as a sub-committee of the audit
committee. If this is the case, action needs to be taken to ensure that risk is managed as an
executive responsibility, rather than audited as a compliance/assurance issue. In fact,
establishing the RMC as a sub-committee of the audit committee may disrupt the work of the
RMC due to increased bureaucracy and an unhelpful emphasis on audit and compliance,
rather than proactive risk management. RMC membership is another question that needs to be
answered. A fundamental decision to be made in large organizations is whether the risk
management committee should be a strategy and policy setting group of small senior
executives or whether it should be a knowledge sharing group with representatives from each
unit or department in the organization. The answer will depend on the structure of the
organization and the intended role of the committee.
The terms of reference and positioning of risk committees in an organization's risk
architecture have been the subject of much discussion. There is an argument that the risk
committee should be an executive function only, as risk management is the responsibility of
top executive management in the organization. However, for some business sectors, the level
of risk that an organization should take is a fundamental business strategy decision. This is
certainly true in banks and other financial institutions. In these circumstances, deciding on the
risk appetite and monitoring the actual risk exposure becomes the responsibility of the high-
profile board.
Therefore, the risk committee needs to be a board committee with both executive and
non-executive membership. Even in these circumstances, however, the risk committee will
probably not be a non-executive committee, as is the case with the audit committee. If the risk
199
committee is established as a sub-committee of the board, then it is important for the
organization to maintain the integrity of the three lines of defense model. The terms of
reference of the risk committee and its position in the risk architecture are fundamentally
important decisions for any organization. In all circumstances, the arrangement should be
appropriate for the organization and aligned with its activities business. Also, the nature of the
risk committee should be appropriate and proportionate in the context of external, internal and
organizational risk management.
Simply put, there is no single answer that fits all organizations.
In many cases, a separate risk management committee may not be proportional to the level of
risk the organization faces. In these cases, the responsibilities that should be carried out by the
risk committee still need to be allocated to a committee with appropriate seniority. Some
organizations allocate risk management responsibilities to the executive committee or finance
committee of the board.
The overall goal is to achieve prioritized, validated and audited improvements in risk
management standards within the organization. Therefore, the risk management committee
and audit committee should operate in a mutually supportive manner. However, combining
the two committees into one group, or putting one committee ahead of the other will not be
the best way forward for most organizations. The main concern when combining risk and
audit committees is that the organization will then be operating a two-line of defense model,
rather than a three-line of defense model that would provide greater protection.
SELECTED HAZARD RISK CONTROL
23.1 COST OF RISK CONTROL :
The default risk level is the risk level without control measures. It is sometimes
referred to as the gross risk level. The current risk level is the level that takes into account the
control measures currently in place. It is sometimes referred to as the net risk level or residual
risk. Throughout this book, 'current level' has been used instead of 'residual level', as this
implies a much more dynamic approach to risk management.
Figure 23.1 provides an illustration of the control effect or control vector when a
control is applied. When considering inherent, intermediate (when more than one control is
applied) and target risk levels, organizations should be aware of the costs involved in applying
controls. The cost of control measures should be considered as part of the total cost of risk to
the organization. The organization can then evaluate whether the controls in place are cost
200
effective.
As can be seen in Figure 23.1, a series of lines can be drawn for Risk A to represent
the effect of each individual risk control measure. It is clear that the longer the line, the greater
the control effect. Similarly, the longer the line, the greater the control effort, in terms of time,
effort and money management. For Risk A, three controls (Control A1, Control A2 and
Control A3) are required to achieve the target risk level. For Risk B, only one control is
required (Control B1) and this indicates that more effort is required to maintain Risk A at the
targeted risk level. Management and internal audit need to be aware of this, so that they can
ensure that all controls (especially for Risk A) are operating effectively and efficiently.
A simple diagram like Figure 23.1 illustrates the distance between the default and
current risk levels. If a lower target risk level is set, additional control effort will be required
in moving the risk level from the current to the new target level (not shown in the figure).
This simple illustration of the control effort is important, and shows that there is value in
conducting risk assessments at the default risk level (where possible), so that the required
control effort can be clearly identified and illustrated.
If calculations are made of the risk exposure at the initial level and further calculations
are made of the risk exposure at the new level, the overall benefit of each control can be
measured. Consideration of the cost of each control can then be made, so that a cost-benefit
analysis of the individual controls can be completed. This will be an important exercise for the
organization to undertake, so that cost-effective risk control priorities can be established.
Risk treatment is sometimes referred to as risk response or risk control, and it includes
the selection and implementation of measures to reduce the likelihood of risk and the impact
of risk. The types of controls described in Chapter 16 should be considered in turn when
deciding on the nature and extent of risk control activities that should be implemented. When
reasonably practical, it is clear that preventive controls should be introduced as the first
choice. If prevention is not possible, then corrective controls should be introduced to
minimize the likelihood and impact of an adverse event.
When risks have been prevented and corrected to the most effective level in terms of
cost, the organization should then consider direct controls designed to direct the actions of
those involved in managing a particular risk. Finally, and in addition to the other three types
of controls, the application of detective controls may be appropriate. Detective controls are
used in a variety of applications, including health and safety. The examples in the section
below cover the major hazard risks that may be of concern to an organization, as outlined in
Table 15.2. In each case, this section describes what could go wrong in relation to the hazard,
and the considerations and issues that need to be evaluated. Control options available in
201
relation to the particular risk are considered, followed by consideration of necessary and
appropriate controls.
Table 16.2 provides examples of the four types of controls described in Chapter 16 as
applied to two types of hazard risk. The examples of fraud and health and safety are selected,
so that the application of different types of controls for these two hazards may be illustrated.
For other hazards not listed below, a similar general approach can be taken and possible types
of controls listed, using the format of preventive, corrective, directive and detective controls.
When selecting and implementing controls, it is important to ensure that cost-effective
controls are selected. Figure 23.2 plots increasing levels of control (horizontal axis) against
increasing control costs and reducing potential losses (vertical axis). By adding the total
control cost and equivalent potential loss for each level of control, the figure illustrates that
there is an optimum level of control that represents the lowest combined cost as the sum of the
control cost and potential loss levels.
It can be seen in Figure 23.2 that a significant reduction in potential losses is achieved
by the introduction of low-cost controls. This part of the diagram is labeled 'Cost-effective
controls'. The middle section of the diagram illustrates that spending more on controls
achieves a reduction in the net cost of risk up to a certain point. In this segment, judgment is
required to spend additional amounts on controls. On the right side of the diagram, spending
more on controls only results in a marginal reduction in potential losses. In this segment,
further controls are not cost-effective.
23.2 LEARN FROM CONTROLLING:
The examples discussed in this chapter provide an oversight of the various hazard
risks that an organization can face. There are many other examples of risks that have been
discussed throughout this book. A constant feature of all types of hazard risks is that decisions
should be made on the most appropriate and cost-effective controls that should be introduced.
Uncertainty in terms of likelihood, impact and consequences is at the core of the
risk management. Both Figures 23.2 and 23.4 illustrate that judgment is required when
performing risk analysis and risk evaluation, as well as when consideration is given to existing
controls and the need for additional controls. In all cases, judgment based on the best available
information is required.
Another important advantage of learning from controls is that unnecessary and
inappropriate complex controls will be identified and steps can be taken to remove controls,
modify or replace them with more cost-effective options. Risk assessment activities should
consider ongoing reviews of the controls in place, as the level of risk will be affected by the
202
nature and quality of the controls. The role of monitoring controls is an established area of
expertise for internal audit.
Learning from controls may be primarily concerned with improving their efficiency.
However, it is also necessary to ensure that they are effective and that they are the correct
controls. Internal audit will help evaluate the effectiveness and efficiency of existing controls
and this will help learning from controls. Evaluation of controls should also take into account
the level of reward sought. Therefore, there is a need to evaluate strategies and tactics, as well
as evaluate the effectiveness and efficiency of hazard and compliance controls. Throughout
this chapter, the emphasis is on hazard control, with details presented on some of the more
common hazards that many organizations will face. The ideas and principles described in this
chapter are also appropriate for opportunity management, and Figure 23.4 illustrates how the
relationship between risk exposure and anticipated reward influences business decisions.
Initially, as the risk exposure increases, higher rewards will be expected and the
increased rewards outweigh the increased risk exposure. Eventually, there will be an increase
in exposure, but no increase in expected reward, so there is no benefit in taking that extra risk.
Between these two situations, an increase in risk exposure will result in a marginal increase in
anticipated reward. It is in this intermediate area that management judgment is required as to
whether an increase in risk exposure is in the organization's best interest. While it may not
seem appropriate to increase risk exposure for a marginal increase in anticipated reward, it
may be necessary to meet existing customer requirements or to help meet long-term business
objectives.
The analysis in Figure 23.4 relates to opportunity risk. There is a similar analysis that
can be performed in relation to hazard risks, where the cost of further controls should be
evaluated against the reduction in risk exposure that will result. When deciding whether to
introduce further controls, organizations need to also consider risk appetite and make
judgments regarding the risks they are willing to take in pursuit of strategic objectives.
23.3 FINANCIAL RISK CONTROL
A hoax
One of the main areas of financial risk faced by all organizations is fraud, which can
be committed by employees, customers, or suppliers. Also, fraud can be committed by the
organization itself by improperly reporting operating results. The requirements of the
Sarbanes- Oxley Act are primarily aimed at avoiding fraudulent reporting by organizations.
Fraud occurs when there is a motive to do so, the organization has assets worth
stealing, there is an opportunity to commit theft or fraud, and there is a lack of adequate
203
controls. Concerns about fraud should also include measures designed to reduce theft. This
would include the provision of security fences and gates, as well as the provision of security
guards, better lighting, and secure building access.
Organizations need to conduct an analysis of the effectiveness of their fraud controls.
This is an area where internal audit is often involved. This analysis should examine losses in
money or goods, as well as evaluate areas where controls are insufficient. The analysis should
be a proactive review that should include an analysis of vulnerable assets, who is responsible,
how fraud can be committed and the effectiveness of existing controls. In addition to
conducting an analysis of the effectiveness of existing controls, organizations should make an
annual review of the circumstances in which fraud has been detected. These reports should be
provided to the audit committee.
To prevent fraud, organizations should introduce a corporate fraud policy that sets out the
organization's attitude towards fraud, methods to control and investigate it, responsibilities for
fraud control and details of resources allocated for fraud detection. Arrangements for
whistleblowing and policies for dealing with persons suspected of fraud should also be
established. Risk control measures related to fraud can be divided into the categories listed
above as preventive, corrective, directive and detective. The following methods are available
to organizations to minimize fraud:
•
improve recruitment procedures;
•
reduce the motive for fraud;
•
reduce the number of assets that are worth stealing;
•
minimize the opportunity to steal;
•
increase the level of supervision;
•
improve financial controls and management systems;
•
improve fraud detection;
•
improve record-keeping.
Historical Liability:
One of the most difficult areas of financial risk for organizations relates to their
exposure to historical liabilities. These liabilities arise from the organization's previous
activities, or acquired parts of the organization that were purchased along with its historical
liabilities. A particularly difficult area to measure for industrial organizations is prior
exposure to agents that can give rise to delayed industrial diseases. The most obvious example
is exposure to asbestos and the potential development of mesothelioma, a malignant cancer of
204
the pleura or lining of the lungs. For many organizations, mesothelioma-related claims arise
30 or 40 years after the alleged exposure. Exposure will have occurred at a time when
insurance arrangements may be difficult to confirm and evidence of precise working
conditions is no longer available.
Another area of exposure to historical liabilities relates to pension funds. In the past,
many pension funds offered pension arrangements linked to the final salary earned by
employees. These were often referred to as defined benefit pension plans. The risks associated
with the value of the pension fund and the level of pension to be purchased by the available
funds were borne entirely by the employer in defined benefit pension plans. There has been a
strong recent trend towards pension arrangements that build up a sum of money available for
employees to purchase a pension upon retirement. Staff members are required to contribute
money to their pension fund, and these arrangements are commonly referred to as defined
contribution pension plans. In these arrangements, the risk attached to the value of the fund
has been considerably reduced and the risk associated with the value of the pension to be
purchased by the fund has been transferred to the employee.
Certain risk control issues of concern to employers relate to defined benefit pension
plans and obligations to persons who are no longer employed by the company but have
pension rights under a defined benefit pension plan. These are often referred to as deferred
benefits. Organizations need to look at risk control options to deal with these deferred
benefits. Available options include encouraging former staff members with deferred benefits
to opt out of the scheme by paying them a sum of money, transferring the deferred benefit
arrangement to an insurance company by payment of an annuity premium or seeking to
transfer the deferred benefits to a captive insurance company.
Historical liabilities of this type are, by definition, more of an issue for organizations
that have been around for some time. This means that the organization will have a long
history and third parties will be able to pursue liabilities that arose some time ago. These
historical liabilities may be more severe if the organization has changed in nature over time,
especially if it is a much smaller organization than it once was. Also, organizations that have
undergone a lot of acquisition and merger activity will be more at risk.
23.4 RISK CONTROL INFRASTRUCTURE
Occupational health and safety:
One of the key areas of concern related to infrastructure risk for organizations is
workplace health and safety. This is a highly regulated topic that should be a priority concern
for all organizations. It is an established discipline within risk management, although it is
205
often managed as an independent function. Health and safety risks faced by organizations
include prosecution by regulatory authorities, being sued by injured employees and disruption
caused by accidents and dangerous occurrences. Many health and safety tools and techniques
are applied within wider risk management activities and there is no doubt that the full
cooperation of health and safety specialists is essential to the success of any risk management
initiative.
Conducting risk assessments in relation to health and safety has been
established long ago. These risk assessments can be general when the risk is relatively low.
For high-risk activities, specific written detailed risk assessments are usually required.
Features of the risk assessment include identification of the hazard, identification of who
might be injured by the hazard and an analysis of how serious the injury would be. Details of
existing controls and precautions, along with information on any further action required,
should also be included as part of the risk assessment. The sole purpose in conducting a risk
assessment is to ensure that controls are adequate and that people are not inappropriately put
at risk.
There is an established hierarchy of controls in relation to health risks and
safety and this hierarchy is listed in Table 16.2. The overall generic control categories of
preventive, corrective, directive and detective controls also apply to fraud risk, and Table 16.2
shows the equivalent categories of fraud controls compared to the established terminology for
the health and safety hierarchy at work controls. After conducting a health and safety risk
assessment, organizations need to introduce controls that will include strategies to minimize
risks (preventive controls), strategies to control hazards (corrective controls), along with
strategies to control staff and exposure (directive controls). Finally, health and safety controls
intended to detect early signs of ill health may also be necessary in certain circumstances
(detective controls). Stress management in the workplace is an example where detective
controls may be appropriate to identify early warning signs that stress is affecting staff.
The range of workplace hazards that should be considered when conducting a risk
assessment will depend on the exact nature of the organization.
Detailed guidance is available on managing specific health and safety risks,
included:
•
dangerous machine;
•
pressure system;
•
noise and vibration;
•
electrical safety;
206
•
harmful substances;
•
manual lifting and handling;
•
slips, trips and falls;
•
display screen equipment;
•
human factors and repetitive strain injury;
•
radiation;
•
vehicle and driving risks;
•
fire safety;
•
stress in the workplace.
Property Fire Protection:
One of the most common causes of loss and disruption for manufacturing,
warehousing and leisure and retail businesses is fire. More than half of organizations that
experience a major fire fail to fully recover from the event. Fire is a very serious event for
manufacturing, transportation/distribution and retail, and especially for residential, hospitality
and leisure occupancies. There is also a strong relationship between the level of on-site
building security and the prevention of arson attacks.
When designing a fire risk strategy, it is important for organizations to evaluate fire
risks in relation to common causes of workplace fires. Most workplace fires are caused by
one or more of the following:
•
electrical hazards;
•
hot work;
•
machine;
•
smoking materials;
•
flammable liquid;
•
poor housekeeping;
•
combustion.
The most important reason for implementing fire precautions is to protect the safety of people
who may be affected by the fire. Careful attention should be paid to the adequacy of fire exits
and the provision of emergency evacuation signs. Also, buildings should be of proper
construction and fire escape routes should be adequately protected, possibly with the use of
sprinklers if necessary. While human safety is the most important consideration in relation to
207
fire safety, organizations must also evaluate the potential disruptions that could occur. The
application of loss control techniques for fire prevention is well established. Adequate
attention should be paid to loss prevention, damage limitation and cost control.
Prevention of property loss involves implementing preventive controls to avoid fires.
These preventive controls will include maintenance of electrical installations, avoidance of
sources of fire and proper storage of flammable and combustible materials. Corrective
controls will include the installation of sprinkler systems and the provision of fire separation
arrangements. The use of directive controls will reduce the impact of the fire and the amount
of damage caused by the fire. Directive controls include directions and information for
employees on actions to take in the event of a fire. This will include early notification to fire
authorities, as well as the use of portable fire extinguishers by employees where this can be
done safely. Finally, detective controls include the provision of fire and heat detectors and
regular patrols by fire and security personnel to detect fires at an early stage.
IT Security:
One of the key dependencies for most organizations is the information technology (IT)
infrastructure. A computer system failure can be a very disruptive event for many
organizations. One of the most established examples of disaster recovery planning (DRP) is
related to IT infrastructure. Computer data loss can be very serious for an organization, and is
more likely to be related to hardware problems than other issues such as software problems,
power failures, or human error. The consequences of an IT failure can include:
•
losing business or customers;
•
loss of credibility or goodwill;
•
cash flow problems;
•
decrease in service quality;
•
inability to pay staff;
•
work backlog or production loss;
•
data loss;
•
financial loss;
•
loss of customer account information;
•
loss of financial control.
With the increasing reliance on computer systems, it is important for organizations to identify
losses that can occur and take action to manage the associated risks. It is generally considered
208
that the main causes of losses associated with IT systems are as follows:
•
theft of computers and other hardware;
•
unauthorized access to IT systems;
•
the entry of viruses into the system;
•
hardware or software errors and failures;
•
user error, including loss or deletion of information;
•
IT project failure.
Most organizations need to set up an IT policy designed to ensure the correct use of data as
well as protect the organization's IT infrastructure. The policy should include information on
IT system responsibilities, details of backup procedures, anti-virus and spyware procedures,
personal data usage, personal internet usage, and personal email restrictions. Most
organizations will allow a certain amount of personal use of computer systems by employees.
However, this should not be allowed to become excessive and special restrictions should be
placed on internet access to inappropriate websites. Another area of concern for organizations
is data protection and the use or disclosure of personal information by organizations. Most
countries have extensive legal requirements relating to the protection of personal data stored
on computers.
Computer and IT failures will occur from time to time and organizations must ensure
adequate backup arrangements, so that only limited data is lost. Organizations with a very
high dependency on their IT infrastructure should have a detailed DRP in place. In many
circumstances, this will extend to arrangements for an emergency duplicate backup computer
facility, available either in a mobile trailer brought to the organization's existing office
location or at an alternative location. Emergency backup facilities can range from complete
duplicate facilities with up-to-date information (often referred to as hot-start facilities) to
alternative computer systems that have no preloaded data (referred to as cold-start facilities).
There are various options for backup systems that are a combination of these two approaches,
and these are commonly referred to as hot-start facilities.
HR Risks:
All organizations require a workforce of employed staff/contractors and/or volunteers.
Therefore, there will always be human resource risks inherent to the operations of any
organization, regardless of the size, nature and range of activities undertaken.
There are a number of risk areas associated with the work of staff and the utilization of human
resources within the organization:
209
•
employee engagement and termination;
•
legislative and regulatory compliance;
•
recruitment, retention and skills availability;
•
retirement arrangements;
•
performance and absence management;
•
health and safety.
Large organizations usually have human resources personnel and/or expertise available in the
HR department. There is a general feeling that large organizations are more prone to HR risks
than smaller ones. This belief is based on the thought that people know each other better in
small organizations and there are fewer individuals involved, so closer working relationships
exist throughout the organization. It is assumed that these closer working relationships mean
that the organization is less vulnerable to legal action or other disruptions caused by personnel
issues.
In recent times, however, it has become clear that smaller organizations also face
significant HR risks. In response to this realization, most small organizations now produce a
staff handbook that sets out the terms and conditions of employment, including arrangements
for sickness absence, maternity and annual leave, appraisals, workplace conduct, and roles
and responsibilities. Organizations need to establish arrangements that will ensure full
compliance with relevant employment laws, including diversity arrangements, to ensure that
there is no discrimination based on ethnic origin or physical ability. When building on these
basic legal requirements, organizations should look at the opportunities that will arise from
supportive, clear and beneficial recruitment, retention and employment practices.
23.5 RISK CONTROL REPUTATION
Brand Protection:
One of the most valuable assets of any organization is its brand name, and it is
important to avoid damage to the organization or its brand. Brand damage can occur for
several reasons, including:
•
government policy changes;
•
changes in the market;
•
new entrants to the market;
•
price and specification competition;
•
counterfeit and fake goods;
210
•
inappropriate behavior of franchisees;
•
failure of the sponsor or joint venture partner.
A recent trend is the use of established brands to sell goods or services that have no clear link
to the brand itself. For example, supermarkets are now selling insurance and other financial
products, as well as selling gasoline from front yard garages. Extending or expanding a brand
in this way is a great opportunity for many organizations, but the brand extension must be
appropriate and credible and successful. Most organizations recognize the value of their
brands and have procedures in place to identify brand extension opportunities. However,
brand ownership in many large organizations is sometimes not well defined. Successful use of
brands to expand into new product areas and new business sectors should only be undertaken
if there is clear responsibility within the organization for managing the brand.
In addition to brand extension, there has been a trend lately to allow branded
concessions to be set up within other organizations. It is now common to see well-known
catering brands running restaurant and café facilities in large department stores. This trend is
developing alongside an increase in high-profile sponsorship deals. For example, many sports
clubs have new stadiums that are actually called after their major sponsors. Many
organizations operate on a franchise basis, where brands are franchised to other individuals or
businesses. These developments in branding allow for maximum benefits to be gained from
high-profile brands. However, there are significant risks attached to these opportunities, and
the use and expansion of brands continues to be an issue that requires careful management.
Successful management of a franchise brand has many challenges. The expectations
and requirements of the franchisor or brand will be set out in a detailed contract in most cases,
although some franchise organizations have been around for a long time and early franchisees
may not have rigid contractual conditions. Most franchisors provide extensive training for
franchisees, including training on product quality. An important issue for many franchisors is
the organization of supply procurement. Often, franchisors will prohibit sourcing supplies
locally, so that the products delivered by franchisees are always consistent.
Environment:
One of the rapidly growing concerns in society is global warming and how the
activities of individuals and organizations can have an impact. Environmental concerns can
range from issues relating to historical soil contamination and water supply contamination, to
industrial emissions into the atmosphere and the desire for organizations to be seen as green.
Waste disposal is an issue that concerns all organizations. For organizations that produce
industrial waste, the legislation is very detailed on how the waste should be treated and the
211
arrangements for disposing of it. For commercial organizations that do not produce industrial
waste or by-products, there are still issues of concern. Commercial waste disposal can be
expensive and most countries require or (at least) encourage large amounts of recycling.
Therefore, the concern of many organizations is related to minimizing the amount of
commercial waste they generate, as well as adopting other green policies. For many
organizations in the public sector, detailed recycling arrangements and recycling targets are
becoming important due to greater scrutiny of the performance of public bodies.
Arrangements that could be investigated would include sourcing supplies or raw materials that
have less impact on the environment and/or are easier to recycle. Organizations may also wish
to introduce recycling policies and make special arrangements for the collection of recyclable
waste materials. For some organizations, there is also scope to look at travel arrangements and
encouraging employees to use public transport where possible, as well as reducing the number
of trips employees make.
For industrial operations, there are detailed standards, rules and regulations, with
enforcement agencies having considerable powers. In addition to paying attention to
legislative requirements, these regulators will also pay attention to broader public opinion and
seek to evaluate the following issues:
•
What are the possible environmental impacts?
•
How harmful is this impact to the environment?
•
How likely is it that this impact will occur?
•
How often and where will this impact occur?
23.6 RISK CONTROL MARKET
Technology Development:
One of the major challenges organizations face is meeting customer expectations and
demands. This challenge is further complicated by the continuous development of technology.
Organizations that supply technology-based consumer goods face constant challenges, which
can be turned into a series of sustainable opportunities. Changes in the technologies used to
provide home and mobile communications and entertainment have been considerable in
recent times. Until recently, home entertainment and mobile entertainment were based on
CDs. Organizations operating in this area were faced with the introduction of MP3 technology
and had to make decisions about which technology to pursue. The investment required to
change technology is considerable and the market risk is significant. For organizations that
identify (and influence) developments correctly, the rewards prove to be enormous. In rapidly
212
changing markets, technological advantage can be significant but the challenge of correctly
identifying the technologies most likely to succeed is ever-present and the investment required
is substantial.
Consumer decisions regarding new technologies are led by convenience, quality, price
and fashion. Another factor influencing consumer decisions and the availability of new
technologies is that significant developments in this type of technology are taking place all
over the world. Therefore, few organizations have the resources to conduct the research
necessary to develop products based on new technologies. Also, these are the same
organizations that design, manufacture, and supply goods that utilize new technologies.
To take advantage of these new technologies, many organizations must enter into joint
venture partnerships, sharing expertise and sharing the costs of developing new technologies.
The selection of joint venture partners can be difficult and the right decision is critical. When
developing a new entertainment technology to be introduced worldwide, there are sometimes
efforts made by competitors to agree on the technology to be adopted. This strategic approach
has the advantage that research costs are shared and technology battles can be avoided.
However, the disadvantage is that the scope for large future competitive advantages is
reduced.
Regulatory Risk:
One of the most difficult risk issues for many organizations is regulatory risk. A key
component of the COSO framework is the achievement of compliance by organizations.
Compliance may appear to be a relatively straightforward issue, but there are often
complexities associated with potential regulatory changes, changing regulatory environments,
and different regulatory requirements in different regions. Different societies have different
and changing views towards certain commercial sectors. For example, the sex industry has
different standards and different regulatory frameworks in different parts of the world. Also,
gambling faces different public attitudes, different regulatory frameworks, and variable
restrictions on activities in different countries. Ensuring regulatory compliance and
maintaining good working relationships with regulators can be difficult, especially when
public opinion changes and/or regulatory frameworks are being developed or modified.
There has been much recent consideration of the difficulties associated with ensuring
compliance in the purchase and delivery of multinational or global insurance programs. Two
main issues have received considerable attention. These are payment of insurance premium
taxes in different territories and acceptance of insurance provided in a country by an insurance
company that is not present in that territory. (Insurance written by an insurer with no presence
213
in a territory is referred to as non-admitted insurance.) With regard to global insurance
policies, issues arise when a global policy is issued by a large company based in one
particular country, but with insurance coverage that applies across all of the organization's
operations and in several different countries. Each country will have its own regulations
regarding the payment of insurance premium tax on the portion of the insurance premium that
relates to the organization's operations in that country. Also, many regions of the world do not
allow non-admitted insurance policies.
The range of risk control options available to an organization that wants to achieve
compliance is, of course, restricted. Compliance is a basic requirement of all business and
commercial activities. Ensuring compliance may require cooperation with third parties and
detailed advice from specialists with expertise in the discipline in that part of the world. In the
example of insurance, it may be necessary for local insurance companies to engage in
insurance programs in regions where unaccepted insurance is not allowed, and this will add
costs to the insurance program. Also, arrangements for the payment of insurance premium tax
may need to be made through a third-party fiscal representative in the territory where the tax
is payable.