1 / 24100%
214
CULTURE RISK
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 9
Learning Outcomes Part Six:
•
describe the key features of a risk-aware culture (LILAC) and how the key
components are defined and can be measured;
•
describe the components of an organization's risk maturity (4N) and their influence on
risk management activities (FOIL);
•
explain the importance of risk appetite and how this can be shown on the risk matrix,
along with risk exposure and risk capacity;
•
review the nature of risk appetite statements and how these can be used to influence
decision-making in organizations;
•
explains the importance of risk training and risk communication and their influence on
an organization's risk culture;
•
summarized the importance of risk training and risk communication, including the use
of risk management information systems (RMIS);
•
explained features framework competency risk and its relationship with planning,
implementing, measuring and learning (PIML);
•
outlines the people skills needed by risk practitioners summarized as communication
(5Cs), relationship, analytical, and management (CRAM).
Case Study
Network Rail: Our approach to risk management:
The goal of our enterprise risk management (ERM) approach is to mitigate risks to the
delivery of safe, reliable and cost-effective services to our customers. ERM supports building
capabilities in all areas of the business to recognize risks and opportunities early. Early
recognition of risk enables us to work collaboratively and proactively with customers,
215
stakeholders and suppliers to better manage our extensive portfolio of work. Across the group,
our approach to risk management balances the need to manage risk with identifying
opportunities to improve performance through careful acceptance of some risks. We recognize
our status as a regulated rail network infrastructure provider and the importance of
maintaining the provision of essential services.
We take an enterprise-wide approach to risk management and have an ERM
framework for the identification, analysis, management and reporting of all risks to strategic
objectives. The framework also takes into account operational risks and recognizes the need
for specific approaches in areas such as safety, project management and information security.
The ERM framework provides a standardized approach to the identification, assessment,
recording and reporting of significant risks. We analyze possible causes of a risk and assess
what the impact would be if the risk were to occur. For each risk, we identify the current
controls and their effectiveness to manage the underlying causes and minimize the
consequences. The full risk assessment process is conducted using the Bow-Tie methodology
which provides a structured approach. We identify risks from a strategic view (top-down) and
from an operational environment (bottom-up) to provide better visibility of risk exposures
across the company.
Ekurhuleni Metropolitan Municipality (EMM): Risk management:
EMM considers enterprise risk management (ERM) to be an essential cornerstone of
good corporate governance and critical to the achievement of its business objectives. The
starting point for the implementation of the municipality's ERM policy is an ERM framework
that respects the needs and aspirations of everyone who has a relationship with EMM. To this
end, all risks that could prevent EMM from achieving its business objectives are proactively
identified on an ongoing basis and formally assessed at least once per year to ensure
achievement of those objectives and for the purpose of reporting on the risk management
process in the annual report. These risks are formally and proactively managed through a
factual approach to decision-making, based on logical and intuitive analysis of data and
information gathered about those risks and planning, organizing, and controlling activities and
resources to minimize the impact of all risks to a level that is tolerable to the municipality and
other stakeholders.
Centralized coordination of the ERM process includes regular awareness programs,
risk identification and assessment, risk monitoring, reporting and independent verification of
the status of internal controls, incident investigation and reporting, and countermeasures
216
across EMM operations, programs, and projects to achieve an integrated ERM system as part
of corporate governance responsibilities. To ensure that the municipality's strategy and,
consequently, its mandate as outlined in the constitution of the Republic of South Africa is
fulfilled, the municipality's ERM program arms its people with the tools and capabilities to
overcome obstacles that arise in the quest to exceed customer and stakeholder expectations.
Ericsson: Corporate governance report:
Ericsson's risk management is integrated into business operational processes to ensure
accountability, effectiveness, efficiency, business continuity and compliance with corporate
governance, legal and other requirements. The board of directors also oversees enterprise risk
management. Risks associated with long-term goals with reference to the core business,
targeted areas and new areas, are discussed and strategies are formally approved by the board
as part of the annual strategy process. Risks associated with annual targets for the company
are also reviewed by the board and then monitored continuously throughout the year. Certain
transactional risks require specific board approval in excess of pre-determined limits:
•
Operational risks are owned and managed by operational units. Risk management is
embedded in various process controls, such as decision and approval toll gates.
Certain cross-process risks are centrally coordinated, such as information security, IT
security, corporate responsibility and business continuity, and insurable risks.
•
Financial risk management is governed by group policy and carried out by the treasury
and customer finance functions, both overseen by the finance committee. The policy
governs risk exposures related to foreign exchange, liquidity/financing, interest rate,
credit risk and market price risk on equity instruments.
•
Ericsson has implemented group policies and directives to comply with applicable
laws and regulations, as well as business codes of conduct and codes of ethics. Risk
management is integrated into the company's business processes. Policies and controls
are in place to comply with financial reporting standards and stock market regulations.
•
Strategic risk is the highest risk to the company if not managed properly as it can have
a long-term impact. Ericsson therefore reviews its long-term goals, key strategies and
business scope annually and continuously works on its tactics to achieve these goals
and to mitigate identified risks.
RISK-AWARE CULTURE
217
24.1 RISK MANAGEMENT STYLE:
We have seen that there are three styles (complements) of risk management, related to
the nature of the risk being considered. Hazard management, control management and
opportunity management define and describe the approach and, to some extent, the level of
sophistication applied to risk management by an organization at a point in time. Hazard risks
will always have a negative outcome associated with them. The maximum exposure to risk
that an organization can accept is the hazard tolerance. Control risks will have a cost
associated with controlling the risk, and this cost can be described as control acceptance.
Opportunity risks have a range of possible outcomes from very positive to very negative. The
desired and planned outcome is of course positive. The organization will be willing to put
resources at risk in pursuit of opportunity risk, and this is an opportunity investment.
The type of risk being considered helps determine the risk management style to be
applied. However, some risks may need to be managed using all three risk management styles,
at different stages in the risk lifecycle. In summary, the four risk management styles can be
seen as follows:
•
Compliance management: based on fulfillment of obligations law, such as health and
safety (1970s).
•
Hazard management: the 'total cost of risk' approach developed by the insurance world
(1980s).
•
Control management: based on the internal auditor's internal control approach
(1990s).
•
Opportunity management: the interface between risk management and strategic
planning (2000s).
Tolerance of danger, acceptance of control, and investment of opportunity are values that are
willing to
borne by the organization. These three components added together are the organization's risk
appetite and represent the total risk exposure that the organization can accept. Total risk
exposure is the sum of risk exposures for individual risks and this actual risk exposure may
differ from the board's risk appetite and/or the organization's risk capacity. Insurance risk
managers will typically manage motor vehicle risk as a loss minimization or 'total cost of risk'
issue. Internal fraud avoidance will typically be managed as an internal control issue and will
be monitored and reviewed by the internal audit department. Risks associated with mergers or
218
acquisitions should be managed as an opportunity issue by the CEO or nominated senior
executive.
24.2 STEPS TO SUCCESSFUL RISK MANAGEMENT :
To improve the risk management performance of an organization, risk management
initiatives are required. The nature of these initiatives will depend on the size, complexity and
nature of the organization. There is no single correct approach to implementing risk
management in an organization. The drivers for undertaking risk management and the
expected outputs and impacts will vary between organizations.
While there is no single correct approach, Table 24.1 describes some key steps in
achieving successful risk management. Appendix C provides an approach that is fully
compatible with the issues mentioned in Table 24.1. The appendix also summarizes the
acronyms used throughout this book and lists the various risk management tools and
techniques associated with each stage in implementing a successful enterprise risk
management initiative.
The first, and perhaps most important, step is to ensure that the risk management
initiative is sponsored by a board member or senior member of the organization's executive
committee. Information on the successful introduction of risk management initiatives is also
available in the various risk management standards and frameworks discussed throughout this
book. As risk management changes and evolves, the steps that different organizations will
take will change. With the advent of governance, risk and compliance (GRC), the context of
risk management has changed and evolved. Risk management professionals need to be aware
of these changes and developments and ensure that their activities are always fully aligned
with other activities in the organization. In other words, risk management activities should
always be fully aligned with the internal context. While it is important to have an overall plan
relating to the implementation of risk management initiatives, it is also important that risk
managers identify barriers to the implementation of initiatives in some detail. Potential
barriers and enablers to the successful implementation of risk management initiatives are
listed in the Table 24.2. There are many factors that will affect the effectiveness of the
approach, including:
•
senior management influence within the department;
•
external influences, including corporate governance;
219
•
the nature of the business, its products and culture;
•
attitude of the company, including RM's previous experience;
•
origins of the risk management department.
The identification of barriers, as listed in Table 24.2, leads to the ability to implement actions
to overcome them. These include the fact that successful risk management requires the
commitment of all parties and that implementation will only be as good as the least committed
members of the department. Analysis of these barriers in the context of a specific organization
will lead to the identification of the best options to ensure that risk management delivers
optimal benefits. There is no single action that will ensure adequate implementation and no
single time frame in which implementation will be fully achieved. According to the
experience of many organizations, full implementation of all stages of this approach can take
between two and five years.
One important consideration regarding the implementation timeframe is the
documentation methodology. If a comprehensive risk management information system
(RMIS) is to be introduced, the timescale for a successful and complete implementation may
be extended.
24.3 DEFINING CULTURE RISK:
Organizational culture is difficult to define. However, it is generally accepted that it is
a reflection of the overall attitude of each management component within a company.
Organizational culture determines how individuals will behave in certain circumstances. It
will determine how an individual feels obligated to behave in all circumstances.
A good risk culture will be a product of individual and group values as well as of
attitudes and behavior patterns. This will lead to commitment to the organization's risk
management objectives. Organizations with a risk-aware culture are characterized by
communication based on mutual trust and a shared perception of the importance of risk
management. There is also a need to share trust in the measures selected controls and a
commitment to comply with established risk control procedures.
Table 24.3 sets out the suggested components of a risk-aware culture.
These components are suggested by recent UK Health and Safety Executive (HSE) research
as leadership, engagement, learning, accountability and communication. This makes the
acronym LILAC. Creating a culture where effective risk management is integral to the way
people work is a long-term goal for most organizations.
220
If an organization decides to raise awareness of security issues, it may decide to
launch a campaign to focus on relevant risks and controls. The campaign should use more
than one means of communication if it is to be successful. An awareness campaign can cover
all the components of LILAC and can extend to:
•
risk awareness training;
•
awareness poster campaign;
•
site inspection;
•
arrangements for defect reporting;
•
flyers and brochures.
Risk management initiatives cannot succeed unless the culture of the organization
accepts them. In order to accept, a risk-aware culture is required within the organization. A
high level of maturity in relation to leadership will require senior management to actively
promote a risk-aware culture. This will include setting risk management performance targets
and ensuring that senior management's commitment to a risk-aware culture is clear. This will
require both verbal and written communication.
Senior management engagement and participation is a critical component to achieving
a risk-aware culture. Engagement can be achieved by adequate training, so that risk ownership
is fully understood. Specialist risk functions should play an advisory or consultant role. There
should be a feedback mechanism to inform staff of any decisions that might affect them. The
existence of a learning culture is critical to the success of a risk-aware culture. A learning
culture allows the organization to learn, and to identify and change inappropriate risky
behavior. In-depth incident analysis and good feedback communication allow a learning
culture to develop. Workshops on risk issues are another key component of a learning culture.
Embedding Risk Management:
Many institutions have established committees to oversee the implementation of risk
management practices and procedures. Often this is a management committee, although it can
sometimes be supported by members of the governing body. One institution has established a
group to advise on the development of risk management processes. Significantly, this group
includes academics from the institution's business school, leveraging existing expertise. This
practice is evident in another institution, where the group, a management sub-committee,
includes an academic expert in risk management from a local business school.
As risk management processes become embedded in the daily routines and
221
management of institutions, these committees will evolve or be replaced. Institutions with
more effective risk management processes are increasingly saddling their senior management
teams with this role, rather than establishing separate committees. In such cases, the risk
management process becomes more effectively embedded because the senior management
team is in a better position to identify and manage risks, and to promote risk management.
One of the institutions visited is exploring a new role for the risk management committee as a
facilitator in sharing good practices between departments.
Accountability is essential if a risk-aware culture is to succeed. However, it is not the
same as a blame culture. The organization must ensure that it moves from a blame culture to a
just culture based on accountability. When investigating incidents, management must
demonstrate care and concern for employees. Employees must feel that they can report issues
and concerns without fear that they will be personally blamed or disciplined. A risk-aware
culture requires good communication of risk information from senior management. Good
communication also requires that reports from all employees, as well as reports from outside
the organization, are welcome and well received. Information on risk performance should be
included in communication activities.
24.4 MEASURING CULTURE RISK:
It can be difficult for organizations to measure risk culture. However, an organization's
risk culture is so important that measurement is necessary. Audit committees will often ask
how seriously a department or location takes risk management. In general, it will be easy to
answer this question qualitatively. However, quantitative measurements are necessary, so that
areas of weakness can be identified and corrective actions planned.
The Canadian Control Criteria (CoCo) framework is a means of measuring an
organization's risk culture. Another measure of risk culture is that the audit committee seeks
to evaluate the level of risk assurance available from the particular unit or division under
consideration. Another way to measure risk culture is to look at the level of risk maturity in
the organization. The next section of this chapter considers the risk maturity model in more
detail. Quantitative measures indicating the level of risk maturity can be taken and areas for
improvement can then be identified. The box below provides an example of risk awareness
and the implementation of risk management into an organization's culture.
Risk Awareness Campaign:
222
The embedding of risk management into the organization is done through three
channels: risk awareness campaigns, implementation of new risk identification processes at
directorate level, and continuous development of existing risk processes at strategic level. The
main objective of the awareness campaign is to make staff aware of their responsibility for
risk, while at directorate level the introduction of the risk register has been done in a
collaborative and inclusive manner. Strategically, the further development of the corporate
risk register aims to bring more rigorous risk control and provide comprehensive evidence and
assurance to the board that risks are being managed.
The quality of risk management policies and the details of requirements and
procedures contained in risk guidelines or protocols will provide an indication of an
organization's risk culture. For many organizations, improving risk culture is a valid strategic
risk objective. This is especially true when areas of weakness in risk awareness levels have
been identified. When undertaking actions to improve risk culture within an organization, it is
important to know that improved risk management processes should lead to improved risk
management outputs. This, in turn, should have a positive impact that provides greater
benefits from risk management. There is no point in improving risk management processes as
a means to improve an organization's risk culture if the overall effectiveness of risk
management efforts is not improved. There is a danger that enhancing and improving risk
management processes within an organization is automatically assumed to have improved risk
culture.
It is possible for risk management processes to be improved without a risk culture
organization is improved. For example, a more aggressive internal audit program can
improve compliance standards, but it does not guarantee that the organization's risk culture
has been improved. Improvements to risk management processes may not provide additional
benefits, whereas improvements to risk culture are expected to provide a better level of risk
assurance. ISO 31000 places great importance on context, and this is illustrated in Figure 6.4.
Information is provided in the standard about the importance of external context, internal
context and risk management context to the organization. Context is closely related to the risk
management culture and the benefits to be gained from improved risk management within the
organization.
Canadian Criteria of Control (CoCo) framework of internal control concentrates on the
control environment within an organization. In addition, the COSO ERM framework (2004)
refers to the internal environment of the organization, not the control environment described
in the COSO Internal Control framework (2013). The control environment and internal
223
environment are measures of the risk culture and the level of risk awareness in the
organization. Improvements in overall risk performance will be achieved through
improvements in the internal context, risk management context, control environment or
internal environment. The level of risk maturity, the achievement of a risk-aware culture and
the fulfillment of the LILAC criteria listed in Table 24.3 are all ways to improve the control or
internal environment.
During the 1990s, a system called the balanced scorecard became a popular
management tool. It is a management system that enables organizations to clarify their vision
and strategy and translate them into action. Many large organizations use the balanced
scorecard as a means to establish a context for the various initiatives undertaken within the
organization. The government agency used as the basis for Figure 28.2 is an example of an
organization that uses a balanced scorecard. If an organization uses a balanced scorecard, it
makes sense to use the same framework for risk management activities. When risk
management processes and procedures are compatible with existing activities, risk
management requirements are more likely to be accepted and met. This represents the
alignment of risk management activities with existing protocols, in order to embed risk
management in the organization and create a more risk-aware culture.
24.5 ACTIVITY ALIGNMENT:
Risk management activities and risk architecture, strategies and protocols should be
aligned with core business processes within the organization. Risk information flows around
the risk management framework and (if successful) this will result in various outputs. These
outputs have been described as mandatory obligations met, assurance provided, improved
decision-making and effective and efficient core processes achieved (MADE2). Most risk
management standards refer to the upside of risk or address the management of opportunity
risk. Project risk management, or risk management control, has become a separate discipline
within risk management, and project risk management is well developed, with separate
guidance material.
When considering the contribution that risk management can make to
organization, it is important to decide whether the contribution will relate to strategy, projects
and/or operations. This decision will enable risk management activities within the
organization to be aligned with other business operations, activities and imperatives. It is
important that risk management activities are aligned with other operations, so that risk
224
management procedures can be fully incorporated into existing management procedures and
activities within the organization. This will also ensure that risk management activities are
carried out in an efficient and embedded manner and are not seen as a separate activity
detached from the management of the organization. There should also be alignment of internal
audit activities with the culture or context of the organization. The approach internal audit
follows when deciding to design a risk-based audit program has two components. First,
internal audit will look at high-risk activities and focus the audit program on those activities.
Second, the risk-based audit program will take into account the level of risk management
maturity throughout the organization. If part of the organization has a less mature approach to
risk, then internal audit may decide to increase the amount of audit activity in that part of the
organization.
Another measure of how well enterprise risk management is embedded in an
organization can be represented by the fragmented-organized-influence-leading (FOIL)
approach. Table 24.4 describes the four stages of risk maturity (as identified by 4N) and the
characteristics associated with the FOIL approach and it can be seen that enterprise risk
management influence increases when all four levels are applied.
A fragmented approach to enterprise risk management exists when different risks are
managed in different departments by specialists who do not always work together. For
example, an organization can have excellent health and safety, security, and business
continuity standards, but the benefits of working together may not have been established. The
next stage is for these activities to become coordinated, so that the company's risk
management approach becomes more organized. All risks are then considered together and
the result is likely to be a comprehensive risk register.
However, there are more benefits to be gained from risk management
company. Organizations that establish ERM activities that have an effect on decision-making
gain these additional benefits. Risk management (and risk managers) influence decision-
making and ensure that risk-related issues are fully taken into account as strategies and tactics
are developed. The final stage is for risk management to lead the development of strategies
and tactics within the organization. This will require risk managers to be part of the senior
management team, so that the development of strategy and tactics is led by risk
considerations, rather than risk implications being considered after strategy and tactics have
been decided.
225
24.6 RISK MATURITY MODEL:
Improved risk management effectiveness can also be measured by the use of risk
maturity models. The level of sophistication of risk management provides an indication of the
benefits that can be achieved from risk management. The level of risk maturity in the
organization is a measure of the quality of risk management activities and the extent to which
these activities are embedded in the organization. The risk maturity model can be used to
measure the current level of risk culture in the organization. The greater the level of risk
maturity, the more embedded risk management activities are in the routine operations
performed by the organization. The characteristics of successfully embedded risk management
will be discussed later in this chapter.
Risk maturity is not the same as considering the level of sophistication that is
achieved by the organization in terms of risk management. An organization may have limited
expectations from risk management, but nevertheless have a very mature approach to the way
in which it seeks to gain the benefits available. The level of risk maturity in an organization is
an indication of the manner in which risk processes and capabilities are developed and
implemented. In immature organizations, informal risk management practices will take place.
However, there may be an existing blame culture when things go wrong and a potential lack
of accountability for risks. Also, the resources allocated to managing risk may not be
appropriate for the level of risk involved. When explicit risk management is implemented,
there will be efforts to keep the process dynamic, relevant, and useful. There will likely be
open dialog and learning so that information is used to inform judgments and decisions about
risks. There will be confidence that innovation and risk-taking can be managed, with support
when things go wrong.
When an organization becomes obsessed with risk, there will be an over-reliance on
processes, and this can limit the ability to manage risk effectively. There will be an over-
reliance on information at the expense of good judgment, and a reliance on processes to
determine the reasoning behind decisions. Individuals can become risk averse for fear of
being criticized and procedures are followed only to meet requirements, not because of the
benefits sought. Table 24.4 sets out a system for determining the level of risk maturity in an
organization in relation to the risk management process. The table establishes four levels of
risk maturity, described as naive, novice, normal and natural (4Ns). The characteristics of
each of these levels are described in the table. Table 24.4 also aligns the 4N model with the
FOIL methodology to describe the risk maturity levels within an organization. Clearly, it is
226
better for organizations to seek higher levels of risk maturity. However, the approach to
achieving risk maturity in an organization should be proportionate to the level of risk the
organization faces.
The level of risk maturity in an organization will help determine the level of
sophistication the organization has in its risk management activities. Image
4.2 Discuss the level of sophistication of the contribution that risk management can make
to the company's activities. The greater the level of risk management sophistication achieved
by an organization, the greater the benefits. Achieving a greater level of maturity in relation to
the risk management process does not necessarily guarantee that a greater level of
sophistication will be achieved, or a higher level of benefits will be obtained.
Nevertheless, achieving a better level of risk maturity can be one of the strategic
objectives of risk management in organizations. If so, the framework A well-established way
to measure risk maturity is needed. It is important that the organization uses a risk maturity
model that is aligned with its own ambitions in relation to risk management maturity and
provides a practical approach that can be embedded within the organization.
Figure 24.1 provides an interpretation of the risk maturity level of an organization,
based on the 4N model. The figure shows that there is a relationship between whether a
behavior is embedded or automatic on the one hand and competent or desirable on the other.
Naive organizations will automatically accept behaviors that are incompetent or undesirable.
A novice organization will realize that the behavior is incompetent or undesirable and will
start making efforts to correct the behavior, but not yet achieve change. However, when
change is achieved, it will move towards better normalized behavior.
The status that an organization achieves with a natural state of risk maturity is that
competent or desirable behaviors will emerge automatically, with little management effort or
enforcement. The achievement at this point is to ensure that behaviors are also consistent. One
of the main reasons for producing risk management policies and procedures is to ensure that
behaviors are consistent appropriate behavior can be consistently achieved. Ensuring
consistently desired behavior is one of the key objectives of risk management initiatives.
Normalized organizations successfully achieve competent behavior or
desirable, but it is not yet automatic. When the organization reaches the stage of becoming
natural in risk management, then competent or desirable behavior will become unconscious or
automatic. This model provides a means to depict the four levels of risk maturity (4Ns) on a
matrix and also shows that the descent from natural behavior back to naive may be a short
227
step for organizations that do not make sufficient efforts to maintain their level of risk
maturity.
Several types of risk maturity approaches exist, including the Criteria of Control
(CoCo) framework. The approach adopted by the CoCo framework focuses heavily on the
importance of risk maturity. The approach of this internal control framework is that if the risk
culture and risk architecture, strategies and protocols are correct, then a good level of risk
management and internal control will be achieved. Another frequently used risk maturity
model is the European Foundation for Quality Management (EFQM) model. Finally, the
similarities between Figures 24.1 and 4.2 are worth considering. There is a need to inform
naive organizations and reform novice organizations. The normalized organization will fit the
requirements and the natural organization will succeed and perform.
THE IMPORTANCE OF APPETITE RISK
25.1 NATURE OF TASTE RISK:
Risk appetite is a very important concept in risk management practice. However, it is a
very difficult concept to define and apply precisely in practice. Risk appetite is sometimes
thought to be determined by the risk criteria set by the organization. Risk appetite or risk
criteria is an important component in the risk rating phase of the risk management process. It
is the next phase of the risk management process after the risk has been assessed in terms of
likelihood and impact. Risk appetite is the immediate or short-term willingness of an
organization to undertake activities that involve risk. Risk attitude and risk criteria represent a
long-term view of risk in the same way that a person would have an immediate appetite and a
long-term attitude towards food. Risk attitude is illustrated in Figure 10.1.
One of the fundamental difficulties with the concept of risk appetite is that, in general,
organizations will have a desire to continue a particular operation, embark on a project or
embrace a strategy, rather than a direct appetite for risk itself. In other words, risk appetite and
risk exposure should be considered as consequences of business decisions rather than as
drivers of those decisions. Risk appetite decisions are usually taken in the context of other
business decisions, rather than as stand-alone decisions. The typical advice in most risk
management standards is that risk should not be managed out of context, so questions of risk
appetite can only be answered in the context of the strategy, tactics, operations, and
compliance activities under consideration. Many commercial organizations generate adequate
228
profits but take too much risk or use the organization's risk capacity inappropriately. Risk
capacity, or an organization's ability to take risks, is not equal to the cumulative sum of all the
individual values at risk associated with the risks the organization faces. This cumulative sum
is the organization's risk exposure. Rather risk appetite is the total value of corporate resources
that the organization's board is willing to risk. Most organizations have not determined the
value they are willing to take on risk (risk appetite), or calculated how much value is actually
at risk (risk exposure), or the organization's ability to take on risk (risk capacity). The various
definitions of risk appetite are shown in Table 25.1 and it is clear that the professional bodies
who Different definitions have resulted in very similar definitions of risk appetite.
An organization should be able to decide how much it wants to take risks, based on the
organization's attitude towards risk. Agreeing on a risk appetite will ensure that the
organization does not place too much (or too little) value on risk. An organization's risk
capacity needs to be fully utilized to ensure that risk-taking is at an optimal level and provides
maximum benefit. Similarly, the organization should not place more value on risk than it
appropriate, given the sector in which it operates and the prevailing market conditions. The
portion of risk appetite attributed to an opportunity can be thought of as the opportunity
investment that the organization is willing to accept. The organization will be willing to invest
resources in opportunities that the organization believes will yield positive returns. However,
the organization should be aware that the value at stake in this way may not result in positive
returns. The implementation of strategic decisions may result in losses. In fact, more value can
be destroyed by the wrong strategic decision than by hazard, control, or even compliance
risks.
An organization may have the desire to invest a certain amount of money in an
opportunity, but it needs to ensure that it has the capacity to bear any losses that may occur. It
also needs to be ensured that the total amount invested, or the value at risk, does not exceed
the capacity of the organization. Careful identification of the nature of the risk and calculation
of the actual risk exposure associated with the opportunity should be done.
25.2 RISK APPETITE AND RISK MATRIX :
Figure 25.1 illustrates the concepts of risk appetite, risk exposure and risk capacity.
Risk appetite is illustrated with shaded boxes on the risk matrix and the organization's overall
risk exposure is shown as curved lines. This illustration represents the risk appetite, exposure,
and capacity for a risk-averse organization. The medium shaded area represents a situation
229
where the organization is comfortable taking risks. The lighter areas represent zones of
caution and concern, where management judgment is required before risks are accepted. Risks
shown in the darkest area are critical risks and these risks will only be accepted if there is a
business case.
The curved line in Figure 25.1 represents the organization's overall risk exposure and
this is the optimal position, where the overall exposure intersects the lighter part. The
organization's risk capacity is shown higher than its risk appetite and risk exposure and is well
embedded within the darker area. This represents the optimal state. This ensures that the
organization takes risks that match the board's appetite and does not exceed its ultimate risk
capacity. Total cost of risk calculations were common in the 1980s and their purpose was to
calculate total risk exposure. These calculations are usually performed by organizations or
their insurance brokers. They allow organizations to determine the total cost of hazard risk to
the organization. The calculation has three main components: insurance premiums, money
spent on loss control measures and the cost of claims not covered by insurance.
Tables have been published on the total cost of risk across different organizations and
it is possible to compare the performance of an organization with other companies in the same
sector. This kind of total cost of risk calculation is useful and is often used as a justification
for setting up an in-house or captive insurance company, as discussed in Chapter 17. The
difficulty with this type of calculation is that it relies heavily on historical information.
Historical loss data is not necessarily a good guide to future loss performance. This approach
is intended to encourage organizations to look for the lowest overall cost of management risk
of harm. Unfortunately, this lowest-cost approach often proves to be a mistake when a major
incident occurs.
Organizations should be aware that the total cost of risk calculation may represent the
lowest cost for hazard risk management, but it may be achieved at a high overall risk position.
It should be noted that purchasing too much insurance may represent an organizational
position that is the lowest risk position but is achieved at a high overall cost. The type of total
cost of risk calculation performed by organizations is now somewhat different. Organizations
often use the concept of risk appetite to perform calculations that identify the level of risk that
the organization is willing to accept. The board's risk appetite can then be compared to the
actual risk exposure that the organization faces. The actual risk exposure in this calculation is
an updated version of the total cost of risk calculation, but it should include all types of risks -
not just the insurable ones.
In general, as the market becomes more volatile, the organization will be forced to
230
increase its risk exposure. This requires discussions in the boardroom that lead to an
agreement to increase the total value the organization is willing to bear and/or find
mechanisms to reduce the total risk exposure. As a result, risk management becomes more
important in times of rapid change and increased market volatility. Risk exposure will also
increase when an organization decides whether to embark on a merger or acquisition.
Organizations need to conduct an opportunity analysis of all acquisition opportunities
and this analysis should include consideration of at least the following features of the
acquisition opportunity:
•
financial strength and reputation of the proposed acquisition;
•
potential to develop further revenues/profits from the acquisition;
•
risks associated with the terms and conditions of the advised purchase contract;
•
anticipated profitability and sustainability of the proposed acquisition;
•
investment required to deliver anticipated future acquisition plans;
•
impact on existing investment and business development plans.
Risk exposure is the actual cumulative total at risk, but is often calculated on a risk-by-risk
basis, without considering whether the risks are correlated. An organization will need to allow
for risk correlation and thus account for the likelihood of risks materializing. When
calculating an organization's total actual risk exposure, it is important that the total cumulative
value at risk is adjusted to take into account whether the risks are correlated.
25.3 RISK AND UNCERTAINTY :
Figure 25.2 illustrates the range of outcomes for different risk exposures. With respect
to opportunity investments, a range of outcomes is possible, from a complete loss of invested
resources to substantial gains. At times, losses may exceed the initial investment, if the total
negative risk exposure associated with the investment is greater than the initial investment is
not calculated correctly. Figure 25.2 represents the relationship between risk and uncertainty.
It illustrates the range of outcomes that are typical for hazard risk, control risk, and
opportunity risk. By including all three types of risk in one figure, it is possible to show that
they are related, interdependent and form a continuum. The sum of all hazard exposures,
control acceptances and opportunity investments will represent the organization's total risk
appetite.
The curved line in Figure 25.2 represents the range of possible outcomes for each risk
position, to within 95 percent certainty or a 1 in 20 chance of being outside that range. An
231
organization may decide that it has a risk appetite such that it is willing to tolerate the hazard
risk shown at point A. The risk appetite of point A represents the risk appetite for that type of
hazard risk. In establishing the risk appetite, the organization will realize that a range of
outcomes for that risk appetite is possible. That range of outcomes is shown as a 95 percent
certainty line.
Likewise, in pursuing the opportunity, the organization will have the appetite
represented by point B. Again, there will be a range of possible outcomes for these
opportunity investments. The desired outcome is a positive return, but losses can be suffered
if the investment is unsuccessful. The range of possible outcomes is shown by the 95 percent
certainty line. Image
25.2 is used to indicate that various outcomes are possible when a value is at stake.
Organizations face a number of risks that can cause disruption. These are the hazard risks that
have been discussed throughout this book and give rise to the organization having exposure to
the hazard. In other words, the organization will be willing to accept exposure to certain risks
of harm as part of its normal operations. Guide 73 defines risk appetite as 'the amount and
type of risk an organization is willing to pursue or maintain'.
There will be costs associated with the risk of harm, both in terms of the cost of
incidents occurring and also in terms of the cost of loss prevention, damage limitation and
cost control activities, including insurance costs. For each hazard risk, there will be a range of
possible outcomes, all negative, and these are illustrated in Figure 25.2. The organization
needs to calculate the possible hazard risks and the costs associated with those risks. It must
be able to decide how much hazard risk it will tolerate, and this is part of the total risk
appetite. Although the organization can decide how much risk of harm it will tolerate, the
actual exposure to the risk of harm may be greater than anticipated. Many hazard risks are
subject to legislation and therefore organizations face compliance risks associated with those
regulated hazards. Almost all organizations tend to have a zero risk appetite for non-
compliance with legislation.
Also, all organizations face uncertainties and control risks that these uncertainties give
rise to. These are risks associated with events that, if realized, will have uncertain outcomes.
As an example of control risk, if all fraud controls in an organization were removed, there
would be a net savings represented by the cost of controls. However, fraudulent behavior
might occur and large losses might be suffered, but there would be uncertainty about how
much fraud would actually result from the removal of all controls.
There will be control risks embedded in the project that the organization is
232
undertaking. The cost of necessary controls can be part of the overall budget for a project.
When planning a large project, it would be unwise not to include the necessary control costs
in the budget for the project. The control costs in the project budget represent the
organization's control acceptance.
25.4 RISK EXPOSURE AND CAPACITY RISK:
Figure 25.3 represents a risk-aggressive organization with a much larger comfort zone
for accepting risk than the organization represented in Figure 25.1. The cautious and
concerned zones are smaller and the darkest zone is a smaller portion of the overall matrix.
This situation can be described as an approach that has a very limited risk universe. Risk
universe for the organization represented by the darkest box and it is only in these areas that
the board of the organization will consider that the risk is significant.
The organization shown in Figure 25.3 has a greater risk appetite, simply because it
has a more aggressive attitude towards risk. By adopting a more aggressive attitude towards
risk, the organization will have less risk in the critical zone. In this case, the 'risk universe' for
the organization's board will be severely restricted. The 'risk universe' shown in the diagram
represents those risks that will be considered at the board level. It can be seen in Figure 25.3
that a risk must have a very high likelihood and impact before it gets attention in the
boardroom.
In Figure 25.3, the highest risk-bearing capacity of the organization is shown as within
the lighter shaded zone. This represents a situation where the organization might take risks
that are beyond the organization's highest risk-bearing capacity. To make matters worse, the
organization's actual risk exposure is also shown in the darkest area. This makes the
organization vulnerable to risk, as the actual risk exposure proves to be far beyond its ultimate
risk-bearing capacity. The identification of risk appetite for an organization requires
assessment, and this assessment can be done at different levels within the organization.
Consideration of risk appetite will be a strategic driver at board level. Risk appetite will likely
be an operational constraint at the line manager level as line managers are expected to operate
within the risk appetite policy that has been set by the board.
At the individual level, it is likely that risk appetite considerations will be a regulator
of behavior. This is because individual staff members should only operate within the risk
appetite framework that has been developed at board level and implemented by line managers.
The definition and application of the risk appetite concept remains a considerable difficulty
233
for risk management practitioners. It is the case that many current risk management standards,
as well as those under development, all state that organizations should recognize their risk
appetite at an early stage. Although ISO 31000 does not explicitly use the phrase 'risk
appetite', it suggests that organizations should establish risk criteria at an early stage.
This seems to contradict a key principle of risk management, which says that risks
should not be managed out of context. Just as risks should not be managed out of context, so
identifying risk appetite out of context is illogical and perhaps impossible. Risk appetite
should be identified in the context of the organization, strategy, tactics, routine operations,
and core compliance processes. There is no doubt that the topic of risk appetite will receive
more attention in the future, and risk management practitioners need to gain a better
understanding of what this concept means and how it is applied. The risk appetite index
described in Chapter 14 takes a somewhat different approach.
Organizations, like individuals, do not actively seek out risk. An individual may be
described as a risk taker, but the reality is that the person enjoys activities that have a high
degree of risk. It is the activity that appeals to the individual in the first instance, not the actual
risk. People can be identified as risk takers because they have hobbies or pastimes that are
high risk. That does not mean that risk-taking for this individual will extend to a busy
intersection without looking. In other words, risk-taking should be seen in the context of the
activity and the desired rewards.
Organizations are similar in that it is the strategy, project or activity that is of interest
to the board, not the actual risk. An organization may embark on a risky strategy, approve a
risky project or execute a risky activity or core process. However, it is the business drivers
and imperatives that board members are primarily concerned with, not the level of risk
involved. It is more often the case that the level of risk comes with the defined strategy, rather
than the risk appetite defining the strategy.
25.5 APPETITE STATEMENT RISK:
Other features associated with risk appetite include the idea that appetite will usually
correspond to a range of possible outcomes. Therefore, around the risk appetite there will be a
certain risk exposure zone or level of risk that corresponds to the appetite. This can be
referred to as the risk tolerance range for exposure to a particular risk. COSO (2004) defines
risk tolerance as:
234
An acceptable level of variation relative to the achievement of a particular objective, and
often best measured in the same units used to measure the related objective. In setting risk
tolerance, management considers the relative importance of the related objectives and aligns
risk tolerance with risk appetite. Operating within risk tolerance helps ensure that the entity
remains within its risk appetite and, in turn, the entity will achieve its objectives.
It should be noted that the nature of risk appetite relates to three different
considerations. For some organizations, risk appetite may be a strategic driver. This would
apply to organizations such as banks and other financial institutions. For banks, risk is at the
heart of the business and an organization's appetite to, for example, lend money to certain
companies or groups of people will be a reflection of its risk appetite and will be a key driver
of the business. If risk appetite is the driver of the business, then organizations will want to
accept risk in order to gain benefits.
For many organizations, risk is not a business driver, but a consequence of the core
compliance strategies, tactics, operations, and processes that the business undertakes. In this
case, risk appetite is unlikely to be a business driver but will be a planning mechanism for the
organization to decide whether it wants to adopt a particular tactic, given the risks that will be
embedded in that tactic, project, or change. Where an organization uses risk appetite as a
planning tool, it will want to operate within a certain tolerance level and manage the
uncertainty associated with risk.
In other circumstances, risk appetite may simply reflect the constraints placed on staff
within the organization. Authorization levels, spending limits and other constraints are often
set out in Delegations of Authority within an organization. The level of authority is a clear
indication of the organization's risk appetite. In these circumstances, risk exposure is a
consequence of the size, nature and complexity of the organization, and the organization will
want to set limits that define risk appetite and thereafter reduce or minimize risk exposure and
possible impacts and consequences. In simple terms, if risk management is about achieving
the most favorable outcome and reducinguncertainty, thenrisk appetite is about identifying
the optimal level of risk that will achieve the most favorable outcome. Risk appetite is a
reflection of the risk attitude and risk criteria that the organization has set and the risks it is
willing to take. Risk appetite can be a driver of strategy, a planning guide for tactics or a set of
operating constraints. Many organizations have attempted to produce risk appetite statements,
without clearly focusing on whether risk is a driver, a planning guide, or a set of operating
235
constraints. If all three approaches are applied, then the risk appetite statement will reflect the
complexity of the approach. Table 25.2 provides a set of risk appetite statements that can be
applied to a college or educational institution.
The stages that will be carried out in developing this risk appetite statement are as follows:
1. Identify stakeholders and their expectations, with reference to
possible range of stakeholders, as defined by the CSFSRS.
2. Determine enterprise-wide risk exposure through analysis of strategy, tactics,
operations and compliance, as set out in the risk register.
3. Establish a desired level of risk exposure that will lead to a risk appetite statement,
which provides a series of qualitative and quantitative statements.
4. Determine the range of acceptable volatility or uncertainty around each type of risk
leading to a statement of acceptable risk tolerance.
5. Reconciliation of risk appetite, risk tolerance with current risk exposure levels and
Plan actions to bring exposures in line with risk appetite.
6. Formalize and ratify the risk appetite statement, communicate the statement with
stakeholders and implement it accordingly.
Logically, risk appetite statements should be structured to align with the risk classification
system used in the organization. Risk appetite statements can be structured based on the
source of the risk, the organizational components that may be affected by the risk event and/or
the impact or consequence category, such as a FIRM risk scorecard, or the organization's
strategy, tactics, operations and compliance (STOC). Network Rail's risk appetite statement
summarized below uses a similar structure to the FIRM risk scorecard. Risk appetite
statements can also be structured in a way that reflects the bow-tie approach to risk
management shown in Figure 11.1. Table 25.3 shows an example of a risk appetite statement
from a manufacturing organization.
Network Rail is not interested in exposure to safety risks that could result in injury or
loss of life to the public, passengers and workforce. Safety drives all key decisions within the
organization. All safety targets are met and improved year on year. In pursuit of its objectives,
Network Rail is willing to accept, in some circumstances, risks that could result in financial
loss or risks including the remote possibility of breaching borrowing limits. It will not pursue
revenue generating initiatives or additional cost savings unless a return is possible.
The Company will only tolerate low to moderate gross exposure for the delivery of
236
operational performance targets including network reliability and asset capacity and condition,
disaster recovery and succession planning, information system damage or information
integrity. The company wants to be seen as best-in-class and respected throughout the
industry. It will not accept any negative impact on reputation with its key stakeholders, and
will only tolerate minimum exposure, i.e. minor negative media coverage, no impact on
employees, and no political impact.
25.6 RISK APPETITE AND LIFESTYLE DECISIONS :
There is a relationship between personal risk appetite and lifestyle decisions.
Decisions will be made about, for example, long-term health issues, depending on family
history and personal lifestyle. Decisions will also be made on medium-term health issues,
based on medical treatment, diet and weight gain. Short-term decisions will also need to be
made on health issues, including those related to exercise, alcohol, and recent illness or
accidents. Individuals need to make lifestyle decisions based on risk attitude, risk appetite,
risk exposure and risk capacity. In relation to health issues, decisions need to be made on the
level of exercise the individual wants to do in the short term to maintain weight within a
healthy range.
There may be a particular appetite for health-related risk issues and
wellbeing, but the exposure a person actually suffers may outweigh the desire for the risk. For
example, people want to smoke, but also want to develop a healthier lifestyle. This is an
example where the appetite for risk may be smaller than the actual risk exposure. There is a
tendency for people to take action when the outcome is immediate, positive and certain.
Therefore, a smoker will want a cigarette because the effects of nicotine will be immediate,
positive and certain. In contrast, quitting smoking will probably result in long-term benefits,
but those benefits will be delayed and uncertain and there will also be a negative feeling of
being without nicotine.
People's attitudes towards risk-taking will vary greatly depending on the type of risk
being considered. For example, individuals may be very risk-averse in the way they drive a
car, but accept significant risk factors in relation to their health. The statement of risk appetite
associated with the risks that individuals are willing to take is, perhaps, as difficult as the
statement of risk appetite for organizations. In both cases, a clear risk attitude will help
determine the appetite for various risk factors.
An individual's willingness to take risks will also depend on the nature of the risk and
237
the ability to apply effective controls. Table 11.4 includes car ownership as one of the
personal financial expenditure issues and Table 3.1 considers specific compliance
requirements, hazards, uncertainties and opportunities associated with owning a car. Table
25.4 outlines some cost-effective controls that can be implemented to reduce harm, manage
uncertainty and embrace opportunities. Overall, the level of expenditure that an individual is
willing to allocate to fund a control will be an indication of that individual's risk attitude and
risk appetite.
This practical example shows part of the embrace, manage, mitigate and minimize
(EM3) approach related to strategy, tactics, operations and compliance (STOC). The overall
approach to personal and organizational issues should be:
•
embrace the risk of opportunity (strategy);
•
managing the risk of uncertainty (tactics);
•
reducing the risk of harm (operations); and
•
minimize compliance risk.
Students also viewed