Showing posts with label Elements of Risk Management. Show all posts
Showing posts with label Elements of Risk Management. Show all posts

Tuesday, October 13, 2009

Different views, the same risks: representing uncertainty, assumptions and perspective

1:26 AM Posted by: Slamun Atlanta 0 comments

Increasingly, the word ‘uncertainty’ is being used in place of ‘risk’. Many of the definitions of ‘risk’ found in risk management guidelines and standards are of the type: ‘risks may represent threats as well as opportunities’. Alternatively, there are processes that deal with risks and opportunities, the two being treated as separate and distinct. This stylized representation of uncertainty limits the way risk managers record, analyse and assess risks, and constrains the relationship between the risk management process and that to which it is being applied. Risks (and opportunities) are defined in relation to what we will call the ‘base position’ (cost estimate, project schedule, operational process, etc). However, how do we tell if that base position was optimistic or pessimistic, realistic or fantastic?
The answer is: we cannot, except by inference from the level of assessed risk exposure. From a strategic perspective, it is hard to understand what the results of a risk management process are telling us. Is a given project really extremely risky, or is it merely that the base cost estimate was extremely optimistic?
This issue, which relates to the context in which any risk management process is implemented, is typically dealt with through phrases like ‘following good industry practice’, ‘benchmarking’, etc, to give credibility and confidence in the base position. However, since each project is unique, and given that the same set of risks can be and are looked at from different perspectives (eg a client organization
issuing a tender as against bidders competing for the work), how can we compare the risks identified by each party without understanding how optimistic or pessimistic each base position is from a strategic perspective? Can a senior decision maker be confident that the risk management process takes the optimism or pessimism of the base position into account, particularly if the personnel taking part in the risk management process are not aware of that information themselves? It is apparent, therefore, that many current risk management standards and processes are not sufficiently sophisticated to address the complexities, nuances and additional dimensions of uncertainty.

Leading effective business risk management

1:25 AM Posted by: Slamun Atlanta 0 comments

Over the last two decades, business risk management has evolved and established itself as a key management discipline. Many organizations use sophisticated systems to help them measure and control the multitude of different risks facing today’s businesses. However, with the increasing understanding of different disciplines of risk, risk management practices have developed in a fragmented way. Specialist teams and departments within the same organization manage different types of risk, such as operational, financial, compliance and project risk, without much coordination between them. The publication of COSO’s Enterprise Risk Management Framework in 2004 challenged the ‘silo’ view of business risk by introducing the concept of integrative organization-wide risk frameworks. These aim to harmonize the risk management approaches across different departments and enhance the organization’s ability to take an overview of its aggregate risks. Risk at operational level is generally well understood, and some type of bottomup risk management system of risk identification and reporting is used by the majority of businesses. However, systematic risk management is not always embraced with the same rigour at higher levels of the organization. Risk is perceived to be mainly the responsibility of executive units – the financial department or the health, safety and security, or risk functions. Most organizations may still be reluctant to recognize risk as an important strategic driver.
Board directors lead the development of corporate strategy, but may not take an equally active role in the identification and management of the risks that may threaten the delivery of the strategy. Risk identification and management are not seen as an inherent part of strategic development and, as a result, risks associated with strategic plans tend to be ignored or underestimated. Consequently, management is unable to allocate appropriate levels of resources to ensure that strategic risks can be effectively mitigated. The role of leadership teams in ensuring that key business risks are understood and successfully managed by the organization is crucial. The discussion that follows sets out the different ways that today’s business leaders can contribute to effective business risk management in order to enhance the organization’s ability to protect itself against strategic threats, while at the same time enhancing its ability to generate value.

Enterprise risk management solutions

1:22 AM Posted by: Slamun Atlanta 0 comments

Today, banks are facing more regulatory requirements, more stringent rating agency oversight, and investor confidence issues. To meet these new challenges, many organizations are examining their policies, methodologies and infrastructure (PMI). These three building blocks form the core of any enterprise risk management environment (Crouhy, Galai and Mark, 2005).
Policies define the tolerance that an organization has for risk. The policies should be consistent with business strategy and should be communicated both internally and externally. The methodologies are the underlying mathematical models that are tied back into performance management. These models must be properly designed, implemented and vetted. The infrastructure refers to having the appropriate people and operational processes (such as data, software, systems, etc) in place to control and report on the risks (Crouhy, Galai and Mark, 2005).
In the past 10 years, there have been countless books, journal articles and other published works that describe a plethora of different ways an organization can calculate risk measures. These vary from a measure that looks only at one specific risk factor to more integrated measures, for example economic capital.
Over the years, the market has endured the US savings and loan crisis, the October 1987 market correction, the 1997 Asian financial crisis, and more recently the 2007 sub-prime mortgage crisis in the United States, now affecting the global banking community. Every one of these market events stresses the importance of having good risk measures and good risk management policies, methodologies and infrastructure. Of these three challenges, the bank is responsible for establishing its own policies and methodologies. These policies and methodologies will be influenced by the internal management organization as well as external factors such as regulatory oversight and investor confidence.
The third challenge, infrastructure, is where the bank may benefit from external, third-party experience in terms of personnel, business processes and information technology (IT). While many banks have internal IT departments, most will agree that technology is not part of a bank’s core competencies. In this case, it may be best for the organization to leverage the knowledge, experience and products from third parties that do have hardware and software development among their distinctive core competencies. This chapter will focus on the information technology infrastructure required to support good enterprise risk management policies and methodologies.

Rethinking the risk management rule book

1:20 AM Posted by: Slamun Atlanta 0 comments

Global recalls of seemingly obscure but omnipresent raw materials and ingredients; international food safety scares over staple foods; concerns and confusion around when, and at what level, the presence of certain chemicals in food or packaging is a hazard; labelling confusion and verification disputes…
These kinds of food and drink health and safety scares are becoming ever more commonplace all over the world and in all sectors, from flavours to baby food and confectionery. And, increasingly, they illustrate why conventional ways and means of anticipating and dealing with risk and full-blown food-borne threats are no longer adequate and demand a rethink.
This chapter looks at a new momentum in cross-silo collaboration in risk management in this industry, as well as the supply chain drivers that are forcing boardroom teams to sit up and take notice of risk and reputation management as central planks of their business strategy and brand longevity.

Risk management in a business change environment

1:16 AM Posted by: Slamun Atlanta 0 comments

There are many good reference texts on risk management; here are quotes from a few good examples:
■ ‘Risks are present in every business activity we undertake’ (OGC, 2007b).
■ ‘Executives ignoring the threats from their competitors run the risk of their organization lagging behind and losing market share, whilst the organizations who embrace risk, often gain advantage and capitalize on opportunities’ (IoD, 2006).
■ The objective of risk management is ‘To add maximum sustainable value to all the activities in the organization. It marshals the understanding of the potential upside and downside of all those factors which can affect the organization. It increases the probability of success, and reduces the probability of failure and the uncertainty of achieving the organization’s overall objectives’ (IRM, AIRMIC and ALARM, 2002).
So, is it better to take on risk or avoid it? The benefits of managing risk should be obvious, but while there is much written on how to manage business or strategic risk and programme or project risk there is little text available on how to manage risks within a business change environment. To put this into context, consider Outperform’s business change wheel in Figure 1.3.1. If you start at the top of the figure, and set the organization off in the right direction, you will be setting the strategy. At the next level, you will: identify the changes necessary to meet the business strategy; and track and monitor the benefits accrued by the successful delivery of programmes and projects that were developed to meet the key performance indicators set by the strategy. This chapter is focused on how to manage risks at this level, called ‘right projects’.

Enterprise risk management: finding the optimal blend of enterprise-wide solutions

1:12 AM Posted by: Slamun Atlanta 1 comments

Enterprise risk management (ERM) provides a means to improve business practice and culture proactively. However, it also has its roots in selecting the correct mix of risk controls and, indeed, solutions for an organization’s unique risk appetite, tolerance and capital structure. Regulation has been a driver of ERM in the majority of industries, especially for highly regulated sectors such as banking, insurance, and energy and utilities, but its broader benefits in optimizing risk treatment choices are starting to be leveraged more effectively.

An appetite for risk

1:06 AM Posted by: Slamun Atlanta 0 comments

One of the most important challenges for management today is determining the risk appetite of the corporation. Current economic uncertainties, scandals such as Enron, Parmalat and WorldCom, and a generally complex business environment have created the need for a robust framework that enables management to evaluate and improve risk management and provide confidence to board members, investors, regulators, investors and rating agencies.
Determining the risk appetite requires a clear articulation of the company’s approach to risk taking, including the nature of the risks, the amount of risk the company wants to carry and the desired balance of risk and reward. Running a business of any size involves choices, and the board’s aim will be to match the effect of decisions as closely as possible to the risk appetite and for the implications of those policies to follow through into day-to-day operations. Maximizing returns while remaining within the risk limits is, clearly, not a new concept. What has changed is the rigour and comprehensive approach that companies are increasingly expected to apply to the identification, measurement and management of the uncertainties involved across the board: to strategic, financial, operational and hazard-related risks.
Regulators and rating agencies want assurance that the company applies a robust approach to all the risks to which the business is exposed in a global way, not one that buys fire insurance for its buildings but fails to anticipate a competitor’s attack on a valuable intangible asset or that becomes aware too late that an acquisition has a legacy of environmental pollution exposures from discontinued activities. The traditional risk management approach starts with categorizing risks, important because it permits the company to define and organize the risk management functions and activities. Classification makes risk manageable. At the same time, it tends to compartmentalize it.
Within such confines, the risks may be well managed, but the business can remain vulnerable because the global view is missing. Interrelated exposures, cross-enterprise risks and gaps in responsibilities may not be evident from the perspective of a business unit or function, but, nonetheless, they must be managed or they will remain a threat to the company’s objectives and the legitimate expectations of shareholders and regulators. Furthermore, the traditional risk management approach focuses on loss prevention for tangible assets rather than on creating opportunities through tangible and intangible assets.
This sets the scene for enterprise risk management (ERM). ERM differs from risk management in scale, comprehensiveness and volume. By definition, the scope of the investigation is the enterprise, but this does not mean that it addresses all risks equally or that there is no focus on critical areas. Its aim is to make management aware of the necessity for communication and coordination across the different risk silos, and of taking a global view. There are many definitions of ERM. My company has adopted the following:
‘Understanding the key risks facing the entire organization, and aggregating this information, so that the right decisions can be made about where to allocate capital to facilitate business improvement.’
Thus, the value of ERM goes beyond compliance and avoidance of surprises to better usiness performance and more efficient use of capital. Armed with robust information about the company’s exposures and their relative weight, the directors will be able to take strategic decisions that maximize opportunities within the defined risk appetite.
Further, if the analysis highlights interrelationships between risks, it may be possible to change processes or locations, create controls to reduce the exposure or use insurance to bring it to an acceptable level. It should also enable the company to spot opportunities that would be only weakly correlated or that would diversify risk with its existing activities. In this way, a company can exploit business opportunities that would otherwise make its exposure to risk unacceptable

 


2009 Protect your Business. All rights reserved.
Powered by Beta Templates and Blogger.
Template and Icons by DryIcons.com