We see a striking contradiction in all businesses: the sharply increasing need for Enterprise Risk Management, as opposed to risk managers' persistent reports of low perceived value of their own processes. Correctly implemented, High Quality Risk Assessment will not only address uncertainty, but even solve chronic business problems. Join Edward Robertson, successful ERM practitioner and thought leader, to discover a simple process that delivers clear value.
SHOW NOTES
IntroductionThe key questions entertained at the level of the C-suite with regard to ERM are likely these three, to which I give an answer in summary:
a. What exactly is ERM?
Due to uneven development in the field, the definition has to be selected from among many, or created. I offer a carefully crafted definition.
b. Is there a verifiable value proposition?
Yes. An incremental, low-risk and trial implementation will yield results, successively:
(1) with respect to clarity of the strategic identity and aims;
(2) by supporting execution on goals and objectives;
(3) by analyzing and solving business problems.
c. How can it be integrated, quickly and efficiently, with existing planning and management?
By:
(1) establishing sound planning, and
(2) using the principles of successful program implementation.
An elaboration on these answers is given over the course of the podcast series.
Main points
Enterprise Risk Management essentially comes from the worldview of rational planning.
Preparedness in the form of Business Continuity and Emergency Planning can be considered the cornerstone of an ERM program.
ERM has developed in such a way that there is a multiplicity of definitions.
The planning regime itself is all-important.
Survey results show little confidence in the quality and utility of the results of risk assessment.
This leads us to value, as the core practice in ERM, what I call High Quality Risk Assessment.
The second main pillar of a successful program is to be acutely aware of a body of knowledge addressing generic program success. This seems to be little-appreciated in the management world.
The titles and job descriptions of those managing risk is varied.
Managers responsible for ERM often have trouble with conceptual hurdles.
The use of scenario analysis: a. for specific circumstances; b. for future resilience.
Risk managers: strive to define your aims, and quickly prove the value of Enterprise Risk Management as a practice which brings scrutiny to the uncertainty inherent in plans.
Thank you for your attention. Anyone wanting support materials can go to riskcommentary.com.
KEY QUOTE
”Enterprise Risk Management holds the promise of capturing the entire spectrum of risk across the organization. This book answers the need for a generic ERM methodology, proven by experience in the field, in both public and private sectors.” (Robertson 2016 back cover)
LINKS(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
BOOKS, COURSES, and CONSULTING CONTACT
RiskCommentary.com
SHOW NOTES
Introduction
Opportunity, as conceived of in ERM discourse, is discussed. Then we improve upon this by presenting the notion of a structured program for innovation.
Main points1. Opportunity - origin of the idea in ERM
2. Opportunity - how can we make sense of the idea?
3. Opportunity - as innovation
4. Innovation
a. an established discipline
b. within the grasp of the risk manager; an expanded role
5. Innovation - Free Online Introductory Course
6. Innovation - Paid Course
7. Innovation for Risk Managers - accredited course through RIMS
Summary
Opportunity is yet another term form the world of finance that requires interpretation for meaningful application in Enterprise Risk Management.
Managing opportunity must, in the end, resolve to a structured search and development; i.e., innovation.
Innovation courses Edward has online:
one free introductory;
a second, paid and in-dept
a third, accredited for RIMS Fellow designation, by Riosk & Insurance Management Society, New York.
KEY QUOTE
”...risk managers can borrow from the practice of innovation and use a structured method to seek out, evaluate, greenhouse and develop new ideas” (Robertson 2016 p.112)
LINKS
(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
Technology implementation - 3-part discussion, LinkedIn audio posts
innovation - successful tech implementation
COURSES
Innovation - free introductory course
Innovation - paid course
Innovation for Risk Managers - accredited course
SHOW NOTES
Introduction
Due Diligence (defined) and High Quality Risk Assessment: how are they used in a complementary fashion in major projects?
Main points1. Reflections on financial risk management (Ep 17): quote from L. Burke Files.
2. Definition of due diligence.
3. How due diligence is distinct from yet complementary to risk assessment: order of operations.
3. a. Due diligence in major investment projects: example of detailed schema using a maturity matrix:
- review of firm|
- management team
- business model
- deal structure
The old adage is “high returns = high risk”. Is it strictly accurate?
Example: An investment structure and management team with a relatively low risk profile may have significant returns designed into the product.
Conversely, a low-ROI product may be subject to uncontrollable conditions, or have sub-standard management, and thus carry high risk.
With this methodology, risk takes on a comprehensive and properly differentiated character. We want separate views of:
- level of maturity of the firm, management team, business model and deal structure;
- the anticipated returns (due to the nature of the investment); and
- the risk profile affecting execution.
Summary1. Due diligence has to do with checking against pre-set authoritative criteria; risk assessment has to do with investigating the uncertainty associated with plans to execute goals and objectives.
2. The two are complementary methods that help you take your analysis of candidate projects beyond the single dimension of a probability estimate of success (assuming you even have a relevant Risk Rating database).
3. Use criteria arranged in levels of accomplishment to assign a maturity score in one or another aspect.
4. We used the categories of firm, management team, business model and deal structure in a sample due diligence system. You can create the system that is relevant to your business.
5. Check your project management methods to ensure you are using due diligence, as applicable, and risk assessment at all phases of major projects. The risk register helps you not only design contract clauses but also guide the ongoing management.
KEY QUOTE“The practice of due diligence has evolved into SOX checklists... Best practice awards are given to the weightiest presentations (by the pound) and third part vendors are predominantly selling ‘perfect solutions’ for enterprise risk management that will seriously impede your ability to conduct business.” (L. Burke Files, Due Diligence for the Financial Professional, 2010, p.6)
LINKSRobertson, E. Enterprise Risk Management Tools and Templates, 2016. p. 35 - Enterprise Risk Management maturity matrix, based on Carnegie-Mellon methodology.
Mark C. Paulk, Bill Curtis (CAST Research Labs), Mary Beth Chrissis, Charlie Weber Capability Maturity Model for Software (Version 1.1)
The original article whose methodology has been borrowed and applied to many aspects of business.
Episode: 017
Date: Tue 21 Sep 2021
Title: Is Financial Risk Management Equivalent to ERM?
EPISODE SUMMARYEnterprise Risk Management, for some, consists solely of Financial Risk Management. Is this sound? We offer commentary on quantitative modelling and its place in ERM.
SHOW NOTES
Introduction
Financial risk management consists of a suite of quantitative methods. Are they foolproof?
Main points1. Quantitative analysis as risk management
Value at Risk; Credit Risk
Monte Carlo simulations
Stress testing
Cash flowing projects and investments; IRR and WACC
Chief limitations of quantitative models
Forecasts and probability estimates
Proprietary internal risk rating systems
2008-2009 financial crisis: crisis in risk management methods?
Adequacy of methods vs sincerity of application (corruption)
Recommendations:
Bring financial models to the table
Assess their relevance in a well-informed strategic context
Use High Quality RIsk Assessment; in other words, mult-disciplinary risk identification
Quotes from the financial experts
What constitutes due diligence?
What is the worldview that quantitative modeling represents?
Summary1. Quantitative models are only as valid as the the scope and assumptions built into them.
2. Calculations and estimates often rely upon historical statistical information. Data often does not exist for the given investment candidate, or it lacks credibility or relevance.
3. Improperly specified models cannot display accurate stress test results.
4. Many firms with good financials and sound insurance portfolios have crashed because they ignored strategic risk that could not be discerned in quantitative models.
5. Financial decisions should be considered using the results of quantitative models, subject to a multi-disciplinary round-table review in the process we call High Quality Risk Assessment.
KEY QUOTE
”...a new kind of blindness: the one induced by new technology and elaborate quantitative models.”
(B. Voyles ) Voyles and other financial experts mentioned quoted in Robertson, p.98
LINKS
”...much more is being underwritten, correlated, and contemplated [by major insurers] than the traditional hazard risks.”
Interview of LoriAnn Lowery-Biggers and colleague Sean Murphy by John Czuba of Legal Talk Network:
https://legaltalknetwork.com/podcasts/insurance-law-podcast-am-best/2019/10/enterprise-risk-management-strategies/
(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
SHOW NOTES
IntroductionThe curious juxtaposition of need vs poor take-up, as explained in Episode 1.
Steps in Analyzing and Fixing Poor Take-Up in ERM Programs
cogent risk register using properly formed risk statements
review guidelines for planning; goal formulation; setting context; and risk ID facilitation
review Likelihood and Consequence schemas with a view to simplifying, if appropriate
granularity of risk analysis corresponds to context
groups may not engage with text-based risk process (use more verbal, visual in daily stand-ups)
What about “opportunity”? Ref: Innovation.
What about other risk management sub-disciplines?
Summary
Aim for information directing action to reduce uncertainty.
Simplify the program and focus on efficiency; integrate it with planning and management.
Review the principles of program success (Ep 15): make sure you’re not falling into common pitfalls.
KEY QUOTE
“The result [of High Quality Risk Assessment] is a body of risk information that is fresh and revelatory, leading to problem solving. When that happens at your risk ID session, it is unmistakable. People see the logic of the method and acknowledge that it is working.”
LINKS
(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
SHOW NOTES
IntroductionIn our last episode, we focused on maintaining a light footprint, as ERM should not be an extraordinary administrative burden. Now let’s continue the story of successful implementation by employing the success factors shown in studies.
Summary
clear goals and objectives - how to formulate them?
senior executive support - how to secure meaningful exec support?
KEY QUOTE“Master the principles of program success that have already been studied, and really apply to all administrative programs, all management initiatives -- not just ERM.”
LINKS(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
Program implementation -- failure and success factors: please see the resources I listed in Episode 3.
SHOW NOTES
IntroductionHow can we roll out Enterprise Risk Management with a minimal footprint? The answer is to use a principles-based approach. Once High Quality Risk Assessment is grasped, we can turn to an implementation that meets crucial criteria efficiently.
What is ERM in relation to your entire management practise?
Please see my book if you want to investigate the following elements of the ERM implementation:
SummaryHow do we maintain a minimal footprint in the implementation?
1. practitioners prove to themselves the value of risk ID in early stages at trial sessions;
2. the roll-out is incremental, not command and control; organic growth prevents wasted investment;
3. working methods are already effective thanks to the using rigour in definitions and process in risk ID;
4. formal elements of the program are not overblown; they are minimal and have a specific utililty;
5. benefits are of two kinds: the immediate, observable ones reported by practitioners which can justify continued roll-out, vs. the long term and eventual outcomes that become measurable over time.
We will continue the discussion always keeping to a principles-based approach. This allows you to consider the principle in question and apply it in your own way, following the requirements of your own particular organizational culture and business.
The next episode will review in a more complete and systematic way the principles of successful ERM implementation.
KEY QUOTE“Program managers of new initiatives are under pressure to show results, and it is easy (but risky) to communicate promises rather than demonstrate the work. Focus on a low-key approach that relies on evidence of benefits.” (Solving the ERM Puzzle... p.75)
LINKS(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
=====
TRANSCRIPT
SHOW NOTES
Introduction
So far we have discussed the technique of High Quality Risk Assessment sufficiently to enable initial experimentation. The question then arises: who actually is leading this work? What are the requisite qualifications and background? Is any special training needed?
Significance of the Enterprise Risk Management champion- implementation lead
Formal role, title and training- multiplicity of titles
- varied training
- facilitation
Background and qualities- critical thinking
- leadership
- influence and persuasion - properly understood
Functions- promotes risk ownership
- leads experimentation
- coordinates minimal, essential documentation
- reports
- celebrates success
- in sum: builds capacity
Summary1. implementation lead must understand the theory
2. able to lead trial sessions and explore the value inthe new practice
3. no formal training is essential, except perhaps facilitation skills
4. competencies: critical thinking; lead the coordination of results;
5. use influence and persuasion to lead others o their own success
What constitutes success?- how can we make ERM part of the corporate DNA? See quote (next).
KEY QUOTE”the ERM champion’s success in instituting ERM will not hinge on the degree of authority leveraged. The reason is that willing participation in genuine Enterprise Risk Management... is not a response to formal authority. It is an outcome of seeing the value of the new process.” (Robertson 2016, Solving the ERM Puzzle, p.24)
LINKS
(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
SHOW NOTES
Facilitating risk assessmentLast episode in our our discussion on how to facilitate High Quality Risk Assessment, we covered finer points on how to facilitate the session, as well as the minimum necessary steps to assess risk: Likelihood, Consequence, Existing controls; Tolerance. This methodology is presented as a generic model for your consideration.
Risk register - what goes into it? Let’s move on now to consider carefully the full significance of the risk register.
What have we accomplished so far?
Do we have a one-dimensional risk assessment? No, it is multi-disciplinary. Do we have notes from a wandering discussion? No, we have the result of a disciplined procedure.
In fact, we have semi-quantitative analysis; that is, the numerical ranking of a series of qualitative statements which might otherwise have simply been lumped together indiscriminately.
The qualitative statements (risk statements) are themselves a product of refinement, informed by:
- sound planning process;
- opinion of key persons;
- consistent definition of context and risk;
- contemplation of many sources of risk (risk categories).
Significance: Quality is being infused into the process at each step -- without necessarily spending more time in planning and meetings than was done previously.
The risk ID process, using the closely defined and consistent formulation of risk statements -- always focused on the intended goals and objectives -- results in a document expressing a concentration of careful analysis.
The result: the risk register participants start to perceive the risk profile in a much more nuanced and insightful manner than they were able to do before.
Breakthrough Risk MitigationIf the risk register is developed as we recommend, how does it lead to formulating mitigation action that is truly “breakthrough” and dramatic?
2 procedures- expert participants in risk ID and mitigation sessions
- sorting on risk information to shed light on the risk profile
novel interpretation of risk profile: identify fundamental risks- the risk profile that is more than the sum of its parts, thanks to the rigour in the process
- the insight is then possible into previously unnamed fundamental risks that undermine the business
- could be a trust issue, or personnel burnout, or something involving attitudes and motivations
- the sheer rigour in the process leads to addressing the issue and novel solutions
evidence-based decisions- the risk register enables evidence-based decisions, where subjective experience can be gathered in a process that has credibility and rigour
consider values as serious risk criteria to arrive at novel solutions- e.g., the mechanics of the operation seem fine, but confident complaints (and harm to the business) are values-related
creativity and innovation- introducing imaginative and unorthodox solutions
- taking it offline as special project
- do not short-change this part of the process
How is the risk register used going forward?- transformed from a static snapshot to a dynamic management tool
Summary
KEY QUOTE”Poorly understood chronic problems often have to do with the nebulous and difficult questions of communications and working relationships...” (Robertson, p.58, Section 2.5 Risk Mitigation and Review)
LINKS(E. Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
(E.Robertson 2006) Navigating the Labyrinth: Risk Analysis for Tough Issues
This article relates 2 case studies: the consideration of corporate values led to breakthrough mitigation.
SHOW NOTES
Let’s review what we accomplished by using a round table of experts (described last time) for risk identification, then go ahead with further detail on the process: how to facilitate High Quality Risk Assessment. There are four key criteria essential to risk assessment.
Instead of the disparate and vague risk information often gathered through interviews and informal, ad hoc approaches, we used an ordered method. We want to benefit from many person-years of experience and professional memory, mapped against a common context, in the most efficient way possible, within the constraints of the limited resources.
Risk identification, done properly, is:
And referring to earlier podcast episodes, we see the quality of our risk ID rests on a firm foundation of informed planning and proper goal formulation.
Conducting the risk identification and assessment session- the best use of meeting time;
- balance between free-flowing discussion and close analysis (risk formulation);
- practical tips in facilitating the session;
- my method is what I call LIFT: Listen; Interpret; Formulate; Test;
- your personal facilitation style;
- demonstration of method: skills transfer.
Risk assessmentWhat are the four aspects of risk assessment, to be captured in the risk register?
- particular design of the risk register: see recommendations in Tools and Templates;
- Likelihood (probability); Consequence (severity);
- Existing controls, not considered as just financial controls;
- Risk tolerance - use short high-medium-low statement in risk register;
- Making sense of “risk tolerance” (see article on risk tolerance and risk appetite);
- Order of operations at the risk identification session
Summary
The definition of High Quality Risk Assessment was given in Ep 04; I repeat it here for convenience.
The most advantageous method for risk identification is the round table of experts approach.
KEY QUOTE
Definition of High Quality Risk Assessment“The comprehensive identification and analysis of phenomena that could prevent the achievement of objectives, or compromise associated values, of a researched and planned program, followed by a principled response.” (Solving the ERM Puzzle, p.11)
LINKS(Robertson 2016) Enterprise Risk Management Tools and Templates(Robertson 2016) Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation
RIMS document, pdf download Exploring Risk Appetite and Risk Tolerance
Main points
We discussed last time how supposed risk ID methods are a hodgepodge of (often problematic) procedures, addressing either ways to get at people, or to get at the content, or ways to think. What is needed is all of those elements in a coherent method.
What is the preferred method for High Quality Risk Assessment?
Preferred method: round-table of experts; several advantages; number and selection of participants
Prepared session: agenda, context paper and facilitation aids, including charts and risk categories
Risk formulation: rules - see blog post
Facilitation: tracing through the context; proper conceptualization of risk
Review: conceptual and procedural foundation
Notice that in our preparatory work, we have:
- a proper concept and definition of risk ID and assessment (Ep. 004)
- a procedural grounding in proper planning (Ep. 005, 006)
- a procedural refinement in the creation of a Context Paper for the risk ID session (Ep. 007,008)
- avoided pitfalls entrained by some of the conventional risk ID advice (Ep. 009).
With that kind of preparation, you can rest assured that the risk ID session itself will go much more smoothly, and yield much better results, than the informal, unstructured attempts that usually characterize the first efforts by people trying to get started in risk management.
The question arises once more: is all of this too much work? I don’t think so. In much of what I describe, it really is a matter of doing what you’re already doing, but improving the quality.
Summary statement of your expected result:
As required in our definition of High Quality Risk Assessment (Ep. 4), we have to identify risk:
So, there we have a summary description of all the prerequisites and elements of an effective risk identification exercise. In the next episode, we can continue our work in the the round table session by assessing the risks, once they are identified and formulated.
KEY QUOTE
The deliverable for a risk ID and assessment session: "A comprehensive list of risks, arranged in several categories of analysis, with criticality rankings and mitigation measures, arrived at by consensus, to inform an improved business plan." (Robertson p.36)
LINKS
E. Robertson Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation (2016)
Main points
Let’s discuss the confusion entrained by the supposed risk ID methods set out in conventional literature:
· interviews and surveys, questionnaires
· audits, physical inspection
· brainstorming
· networking with peers, industry groups
· judgemental - speculative, conjectural, intuitive
· history, failure analysis
· examination of personal experience or past agency experience
· incident, accident and injury investigation
· scenario analysis
· decision trees
· SWOT analysis
· flow charting, system design review
· work breakdown structure
Conclusions
We find that the items in this list are a hodgepodge of (often problematic) procedures, mere ways of thinking with no associated process, and examinations of risks already matured (compliance breaches, accidents and incidents that occurred in the past).
I surmise that the reason for such dismal survey results extended over years (see Episode 1) is that managers who had no experience in risk ID tried it without clear methods or definitions, and so quickly became disillusioned with the quality of the results. Make sure you understand the pitfalls and deficiencies of random “methods”.
Following upon the very definition of risk given in the standards, a complete methodology is required. We present High Quality Risk Assessment. In our discussion so far you will find:
High Quality Risk Assessment definition (Ep. 004)
procedural grounding in proper planning (Ep. 005, 006)
KEY QUOTE
“Such a multiplicity of [risk ID] methods might entrain confusion about the object of the exercise.” (Robertson, p.42)
LINKS
E. Robertson Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation (2016)
SHOW NOTES
Main points
Summary of the series to date. At this point in our podcast series we established the rationale and practical working definitions for Enterprise Risk Management. Now we are discussing methods, in particular the all-important core practice in Enterprise Risk Management, which I call High Quality Risk Assessment.
Establish the Context. The first step (after, perhaps, communicate and consult) is usually taken to be: “Establish the Context.” What do the standards mean by that? They are rather vague about whether this applies only to the ERM initiative itself or not, we start with establishing the context for the purpose of preparing for a particular risk assessment.
Context Paper. To that end, in the last episode we explained in detail the best possible preparation for risk assessment is: it is to write what I call a Context Paper. The Context Paper sets out important headings. The purpose is twofold: to create a highly useful aid to facilitation; and to create a testament to due diligence.
This follows on the important realization that a risk session facilitator must not fall into the trap of trying to identify risk in business settings where there are no goals and objectives.
This, in turn, led us to consider over the course of two podcast episodes, the nature and quality of the planning regime in the organization.
Now the question arises, what if we can’t fit our operations to match the suggested headings? What if, especially, we don’t have a business with neat, hierarchical “goals” and “objectives”? Is that the only way to express our intended actions?
Special examples of Context
Consider these examples of what we can legitimately call “context” for the purpose of risk ID:
a. budgets
b. formal projects (project management)
c. contracts
d. workflows: administrative procedures or technical processes
e. performance management regimes
f. specialized disciplines
Caution: these various alternative contexts must still somehow express goals or intended actions that are clear, well-formulated, and substantiated through research.
Summary: What did we cover today?1. A review of the true utility and rationale for “Establish the Context”.
2. The primary way to prepare for a risk ID session: write what I call the Context Paper.
3. Various types of context alternatives that can be encountered.
4. We reiterate necessity for the risk manager to scrutinize the planning prior to conducting risk ID.
KEY QUOTE
“The ERM champion must scrutinize the planning and even coach managers to adopt a complete planning practice... As a consequence, the risk information ultimately developed will make clear sense.” (Robertson, p.31)
LINKS
E. Robertson Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation (2016). The discussion on Establish Context begins in Chapter 2.2.
SHOW NOTES
Main points
At this point in our podcast series we have deconstructed some of the misconceptions in the field; we reiterated the persisting and obvious need for Enterprise Risk Management; and we introduced viable definitions for both ERM and what I take to be its core process, High Quality Risk Assessment. You probably feel how my working methods trace a fairly tight logic.
Let’s continue that train of thought by considering now the step in High Quality Risk Assessment called Establish the Context.
What do the standards mean by “Establish the Context”? For ERM itself? or for a particular risk assessment?
What is the true significance of “Establish the Context” in an effective ERM program?
Hands-down, the best preparation for risk assessment is: write what I call a Context Paper.
Conclusions
If you compare your results to that of firms that simply use an informal approach, you will find that looking after your planning regime and preparing a context paper will move you light years ahead in conducting risk management.
Summary: What did we cover today?The true meaning and purpose of Establish the Context.
The headings in what I call the Context Paper, used to prep a risk ID session:
1. Title of the plan under scrutiny
2. Goals and objectives of that plan
Corporate values
Risk categories
Stakeholder analysis
Procedural and due diligence points
Deliverable
Process in preparing the context paper.
KEY QUOTE
“Do not introduce as risk things into the risk ID session which should, properly speaking, simply be trends and conditions that are already known -- that should have been taken into account in the formulation and design of the plans themselves.”
LINKS
E. Robertson Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation (2016)
The discussion on Establish begins in Chapter 2.2.
SHOW NOTES
Main points
Last episode we started with an examination of the planning regime, as the first step in High Quality Risk Assessment.
I mentioned that an 80/20 rule seems to obtain, 80% of our efforts as risk managers is properly spent on fixing the quality and extent of the planning. For that reason, we expand that discussion today.
We set out steps in a planning process to help you assess and fix how planning is approached in your organization.
Recall:
What is the evolutionary stage of the organization?
self-identification - Strategic Identity
environmental scan - the outward view
formulation of goals and objectives
Let’s situate our organizational practices in a wider planning and management schema. As explained, good planning is the necessary condition for effective risk management.
But, pausing for a moment to take a wider view, these questions naturally arise: are there not hundreds of different types of planning and management techniques? How are they inter-related?
Planning and management schema
Is strategic planning dead?- common attitudes: planning
- strategic planning is popular; yet somehow mysterious and ineffective (kinda sounds like ERM!)
- Mintzberg’s article “The Rise and Fall of Strategic Planning“
- his true complaint: not predictive; focused on quantitative targets; not participatory
- quote from Wall & Wall article: better characterization of strategic planning
Recommended practicesSubsequent research: Effective strategic planning is:
· an iterative process; participatory, involving dialogue and exchange between planners and the rest of the employee group
· well-informed by detection of trends, conditions and emergent issues; it has to stay relevant in order to arrive at creative and innovative solutions, rather than simply state a static target based on last year’s results
· helps promote an integrated culture, and a sense of belonging to the firm, based on common values
benefits of strategic planning, including psychological benefits and improvement of morale
highlight on implementation
lists of criteria are useful for risk assessment!
ConclusionsWhat is the best definition Strategic Planning?
What is the rationale for Strategic Planning?
Does this imply an extraordinary amount of work?
Summary: What did we cover today?1. We reiterated that to begin High Quality Risk Assessment (our core practice in ERM), we must review the planning practice.
2. We reviewed the steps in a suggested planning process (discussed in more detail in Ep 5).
3. We situated strategic planning and many other techniques in a sort of grand schema.
4. Rationalize planning, meetings and management techniques: there is potential for meaningful change
5. We discussed the reason for negative impressions of planning.
6. We cited examples from the literature to show the best practices.
7. We finished with a recommended definition of Strategic Planning and its ultimate rationale.
KEY QUOTE
“Traditional planning fails to take into account the creative processes and discoveries that generate breakthroughs.” (article ~ Wall, S. and Wall ,S.R.)
LINKS
Aldehayyat J & Anchor J (2010) “Strategic Planning Implementation and Creation of Value in the Firm”
Wall, S. & Wall, S R (1995) “The Evolution (Not the Death) of Strategy”
E. Robertson Strategic Planning: Process, Templates and Effective Implementation (2019)
SHOW NOTES
Main points
Longer Term Agenda: High Quality Risk Assessment
Today’s agenda
We can only address point 1 today: investigate and fix the planning practice. We cannot start straight in with risk ID! We must prepare by scrutinizing the organization’s planning regime! I think you will find it an important key to successful ERM.
Why this obsession with the planning practice in the organization? Why can’t we simply start with risk identification?
The intuitive, informal approach -- does it work?
The importance of the planning language.
The spectrum from non-planning, to plans (improperly formulated), to plans (unsubstantiated).
Properly formulated goals.
Properly informed goals.
The economic reasons for planning and risk management: the crucial point in the development trajectory of business organizations, as well as public agencies and non-profits.
Planning and risk management regimes are crucial to the evolution of the organization.
Conclusions: we need proper planning as the logical precursor to risk management.
Complete planning practice
Strategic identity
special relationships; clients and constituents- mission
values
capacity for change
Looking outward
Synthesis
vision
gap analysis
formulation of goals and objectives
Beneficial psychological effects of engaging staff in planning process.
Summary: Let’s review what we’ve covered today.
High Quality Risk Assessment is a precise method: the core practice that generates value in the ERM regime.
We cannot start with risk ID, but must discuss the planning practice of the organization.
Many organizations will be deficient in the documentation, formulation or background research.
At a crisis point in their development, firms have to build proper management systems or experience mediocre performance.
We can suggest the steps in a complete planning process.
As staff participates in research and planning, the company can experience a profound renewal.
80% of the risk management team’s work could be to investigate and gain cooperation to improve the whole strategic and operational planning practice. The benefits, however, are significant.
KEY QUOTE
We must have proper planning as the logical precursor to enterprise risk management. Yet we ask: “Why do so many strategic plans end up on the shelf? It’s curious, given that strategic planning is among the most popular of management tools.” (Robertson, 2019, p. iv)
LINKS
E.Robertson Strategic Planning: Process, Templates and Effective Implementation (2019)
SHOW NOTES
Introduction
In prior episodes, I devoted time to critique what I take to be some of the misconceptions in the field of Enterprise Risk Management. I explained, at least in part, what may have caused them, and highlighted the extraordinary need for good risk management that faces us today, even though difficulties in implementation, linking to strategy and proving value are still persisting.
With that as background, let’s start to look into my recommended ERM process. We won’t have time to discuss the whole implementation, of course, but we can begin with some practical and descriptive definitions.
Main points
Should I just give definitions or discuss rationale behind them?
I think it’s important to tell you the “why”, the rationale, as our preferred approach to ERM is a conscious one, without accepting advice uncritically.
Definitions: rationale and approach
rationale for creating my own definitions
does a risk management technique reach ultimate truth?
principle
authoritative
Definition 1. Enterprise Risk Management
What is the significance of the elements in the definition?
Must risk sub-disciplines or sub-frameworks use High Quality Risk Assessment?
The points that I’m insisting on really are points pertinent to quality, rather than additional administrative burden.
Definition 2. High Quality Risk Assessment.
How to operationalize this practice, as indicated by the elements in the definition.
Significance of High Quality Risk Assessment process
This is the essential practice in an ERM regime. Start with this, because if you don’t get this right, there’s really no point to continuing with ERM. But when the High Quality Risk Assessment Process is finely honed it starts to enable incisive analysis of complex problems.
Summary: what have we accomplished today? We considered:
a working definition of Enterprise Risk Management
the risk ID and assessment method called High Quality Risk Assessment
the necessity to develop and refine your risk ID and assessment process
the planning practice
In our next podcast episode, we will look closely at how to conduct High Quality Risk Assessment, and how to see that it is the details of the process are so important to guarantee the quality -- to make the magic happen -- in your risk identification and assessment process.
KEY QUOTE“One key message here is: do not fall into the trap of trying to lead a risk ID session, much less implement an entire ERM program, where goals and objectives are poorly defined.” (Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation p.32)
LINKS
E.Robertson Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation (2016)
SHOW NOTES
Introduction
In Episodes 1 and 2, we asked: Why is ERM so incredibly convoluted and seemingly complex? and began to answer this question by explaining that there has been a proliferation of advice, leading to a confusion of foundational definitions, and core methods and practices. We did some myth-busting, an examination of misconceptions: and in this episode, we look at the remaining myths in the list of issues I identified. In each case, I’ll be giving you the lesson or point to take away for application in your own risk management regime.
Main points
[01:40] Myth #8: Managers, directors, analysts, CEOs, etc. know how to implement new programs.Take-away: In fact, the studies reporting on the implementation of management initiatives in all sectors show that failure and under-delivery are quite high, and there is a considerable literature on the causes. This should be taken into account when designing and implementing the ERM regime.
[04:42] Myth #9: Enterprise Risk Management can best be implemented by using a software application.Take-away: Technology and enterprise software implementations are indeed a notorious when it comes to program failure and chronic under-delivery, with extraordinary costs. Establish and understand your own business process and investigate thoroughly the success factors in IT implementation before contemplating a large commitment of resources to tech “solutions”. Above all, do not fall prey to the myth that the technology, in and of itself, will inspire acceptance and take-up of the new management program, whether it is ERM or something else.
[0639] Myth #10: Defining “risk tolerance ” is essential to an ERM program.
Take-away: It is not necessary to make grand statements of risk tolerance, especially in non-financial organizations. It is perfectly acceptable to simply express goals, values, and aspirations, then employ risk tolerance as one of the criteria to evaluate identified risks. Those risks that affect more closely our core mission, we will have a low tolerance for, and thus try to mitigate. Other identified risks will be more peripheral to our mission and so less critical. Tolerance then is a relative, not absolute, notion.
[08:37] Myth #11: Monitoring compliance constitutes effective ERM.Take-away: A compliance regime may be appropriate for the business or organization. But the danger is to construe apparent compliance as real adherence to the regulations or code. Risk assessment must investigate the possibility that a check-the-box or superficial monitoring operation is actually missing breaches. Then again, successful operational complliance will be insufficient if the organization does not examine strategic risk in light of the wider environment, industry trends, etc.
[11:23] Myth #12: Linking corporate strategy to ERM is difficult and complex.Take-away: The risk ID and assessment process (I advocate for a process I call High Quality Risk Assessment) should be scalable and applicable to any context, including, of course, the strategic plan itself. We naturally assume that you have arrived at goals and objectives through a planning process. The questions then become: is the strategic plan well founded? Is it substantiated through research into industry trends and conditions? And is it properly formulated in terms of actionable goals? If the answer to any of these is no, then that is your first important risk.
[15:09] Myth #13: ERM takes 3-5 years to implement.
Take-away: Successful implementation, even in a complex organization can be a matter of weeks or months -- not years. I give the example of a post-secondary institution where I was the consultant for a successful ERM implementation in 18 months, and it is a robust practice that has stood the test of time.
[16:25] Myth #14: Good ERM predicts the future; it is effective forecasting.
Take-away: Forecasting uses historical data to establish the probability of certain definite outcomes, and so relies on the statistical method. Enterprise Risk Management, by contrast, rarely has the pertinent statistical data to bring to bear upon the full range of strategic and operational decisions, and so uses a round table method. We identify the uncertainties associated with a given plan, and then take immediate action to mitigate and nullify them.
KEY QUOTEEstablish and understand your own business process and investigate thoroughly the success factors in IT implementation before contemplating a large commitment of resources to tech “solutions”. Above all, do not fall prey to the myth that the technology, in and of istelf, will inspire acceptance and take-up of the new management program.
LINKS
Program implementation failure
A synopsis of various studies.
http://www.strategies-for-managing-change.com/support-files/researchprogramfailure.pdf
Technology implementation failureScroll down to audio post: innovation: successful tech implementation part one
https://www.linkedin.com/in/edward-robertson-801b5012/detail/recent-activity/shares/
The question is: How are these applications faring? The answer is, not very well.
Risk tolerance vs risk appetiteRIMS document, pdf download
Exploring Risk Appetite and Risk Tolerance
Compliance“Steering clear of compliance pitfalls” © Key Media Pty Ltd.
Unattributed, 31 May 2010. Corporate Risk and Insurance. Excerpt:
“The most common pitfall in compliance programs is an overreliance on policies, procedures and systems, according to Ulysses Chioatto, director of SSAMM Management Consulting.
A cursory glance over all the convictions and enforceable undertakings by ASIC in the past five years highlights this overreliance on policies, procedures and systems by financial services providers in their compliance programs, said Chioatto, with little to no work on people – or to put it another way, the company’s culture.
‘Both internal and external auditors as well as compliance and risk officers pore over documents, flowcharts, plans and reports from computer risk and compliance applications, yet breach registers are overflowing, or worse still, completely empty.’ “
SHOW NOTES
Introduction
In the first episode, we asked: Why is ERM so incredibly convoluted and seemingly complex? Why is there not better take-up? Why is there such a strange juxtaposition between the obvious need for ERM and the stagnation of methods and results?
We began to answer these questions by explaining that there has been a proliferation of advice, leading to a confusion of foundational definitions, and core methods and practices. We can understand this more profoundly with an examination of myths or misconceptions that, until you really look closely, are quite naturally bound to have.
Main points
Myth #1: ERM is one thing. No, there is a proliferation of methods and definitions.
Take away: The definition of ERM you select or invent must be suited to your business, shared as common understanding among participants, and quite definite in its instructions to operationalize. Many definitions are too vague.
Myth #2: International standards (ISO 31000; COSO, etc.) give ERM implementation guidance. No, they are too general in nature. Don’t try to follow such standards as specific guides to implementation.
Take-away: International standards are best used as reference documents giving, for example, the outline of the stages of the risk process and a glossary of terms. But a company policy based on the international standard will require interpretation and adaptation to your business.
Myth #3: ERM is unproven. No, there undoubtedly examples of successful practice. But successful ERM occurs in specific instances that may not be comparable or commensurable, due to the confusion of definitions explained above.
Take-away: If the principle of managing uncertainty pro-actively is sound, then the team can proceed with implementation incrementally, taking care to prove value at each step. ERM in specific instances may well be proven, but you will likely have to build your own case studies.
Myth #4: ERM imposes an unacceptable administrative burden. It would seem so, but only if the risk ID and assessment process is ineffective. First of all, managing uncertainty and fixing problems at the front end is always preferable to cleaning up after a risk has been realized. Further, people don’t quite realize how much time already lost in poorly managed meetings.
Take-away: After initial work to build a risk register, it enables very efficient meetings, while managing uncertainty in a structured manner.
Myth #5: ERM is the purview of audit & finance. This is commonly the case, but does it make sense for audit to identify risk, if they are responsible for the quality of the risk process itself? We want audit to maintain its impartiality. With regard to finance, often ERM is construed solely as financial risk. But we want financial risk to be analyzed not in isolation, but as part of the total picture of risk.
Take-away: ERM is the umbrella, the overarching risk function, under which risk in all domains is managed -- subject to the common lens of strategic aims and corporate goals.
Myth #6: All the various pre-existing risk disciplines and practices will be replaced by ERM. People in various risk management practices (eg., health and safety; environmental assessment; IT security) sometimes believe that ERM will try to impose its own methods on them. On the contrary, they can continue with their own proven methods, but will still participate in ERM -- how?
Take-away: Risk management sub-frameworks or sub-disciplines need not conform to a single method, but their criteria and final reporting must align with coporate strategic aims and corporate values.
Myth #7: Managers in all verticals can reasonably be asked to conduct risk assessment. On the contrary, most people in administrative settings are non-experts in conducting risk assessment -- and doing it in an ad hoc or intuitive manner gives bad results.
Take-away: Don’t let people waste time in lengthy informal discussions of risk. Rather, make sure they get practice and training in a rigorous and well-defined process: high quality risk assessment (which we will explain at length, later in this podcast series).
Resources
“over 80 risk management frameworks...”
Ahmad, Saudah et al. (2014) “Enterprise risk management (ERM) implementation: Some empirical evidence from large Australian companies”
“30% of time spent in meetings was unproductive...”
S. Rogelberg, et al. “Wasted Time and Money in Meetings: Increasing Return on Investment”
SHOW NOTES
Introduction
[00:40] Welcome to the Risk Commentary podcast - Episode One! Who is this podcast for?
There are people in the risk management space who are just shopping around for core concepts, because they are charged with leading the risk management initiative and are not sure where to begin. Others, and I seen this more and more in recent years in workshops, have an existing practice, but somehow it is getting bogged down, and the risk managers are not sure how to demonstrate the value of the practice. Others, especially in the C-suite or on the board, are wondering whether anyone has really solved this whole notion of ERM and proven its value. There is too much noise, and so that situation, there is no point in investing in a process that doesn’t have a clear methods and value proposition.
If any of those descriptions matches your situation, you’ve come to the right place, because I want to examine first what is wrong with ERM, and then continue with how to do it right. This serial podcast, presenting material, as best as I can manage, in a logical order, from teardown and exploding myths, to foundational concepts, to full implementation.
[02:22] Mission: “To help you develop an Enterprise Risk Management program that is conceptually sound, practical, and of demonstrable worth. I describe a low risk, incremental process that imposes a minimal footprint and delivers on a clear value proposition.” ~ From Preface of my book.
[02:52] Credentials: Risk Management professional; former Senior Manager of Enterprise Risk Management in BC Provincial Government; author, speaker and educator. Please see bio on my website.
[03:24] COVID: Did COVID prompt the motivation for this podcast? No, the material in this podcast is not driven by current events; it consists of perennial principles. My answer in brief to the whole COVID phenomenon is twofold:
to be aware of Business Continuity and Emergency Planning. “It can be argued that Business Continuity and Emergency Planning (BCEP) is the cornerstone of the ERM plan. If disaster risk is not covered, it is a serious deficiency.” (E.R. 2016)
to consider innovation methods (I can recommend my free introductory course on innovation).
Main Points
[04:50] Is ERM Dead? The motivation behind this question is the extraordinary contradiction between 1. the unprecedented need for Enterprise Risk Management and 2. the lacklustre ERM survey results.
[05:19] The need for effective risk management was expressed by a risk management professional, LoriAnn Lowery-Biggers, back in October of 2019, and you will see how prescient her comments were for us today:
”...we are in an unprecedented and evolving landscape unlike anything that we have ever seen historically
So a few key trends that are driving this increased focus, particularly from the board and the C-suite levels are rapid speed of business model interruption and disruption, industry changes, corporate tax reforms, political uncertainty, increasing workplace violence, reputational and headline risks, cyber threats unlike we’ve ever seen, crisis management needs, new litigation, regulatory risks and scrutiny, innovation and technology disruptions. “
Later in her comments she says that the solution is to “instill it [ERM] into the corporate DNA”.
[06:53] Survey results. Let’s consider those comments in juxtaposition to certain survey results. I’m referring to the April 2021 edition of the study entitled The State of Risk Oversight - An Overview of Enterprise Risk Management Practices (published by AICPA and North Carolina State University). I will choose a few stats from this study to illustrate my point. While progress has been made in certain areas, many of these discouraging results are part of a multi-year trend of stagnation. So for example:
“83% respondents noted that the volume and complexities of risks have drastically increased over the past 5 years...”
Here we have confirmation for the need for risk management. But with regard to the levels of practice:
only 35% the percentage of respondents reported having a full Enterprise Risk Management practice in place. It has been between 25 and 25% for the past 8 years;
only 25% reported that this practice was ‘mature’;
only 35% reported that risk is addressed when discussing the organization’s strategic plan;
“about half of organizations surveyed formally define the term ‘risk’ ”;
“heavy emphasis on risks related to technology, legal/compliance, and financial issues”... less focus on “emerging strategic/market/industry risks”;
“Organizations continue to struggle to integrate their risk management and strategic planning efforts”;
Why is progress impeded? The respondents answer that “Risks are monitored in other ways besides ERM; Too many pressing needs; No requests to change our risk management approach; Do not see benefits exceeding costs.”
[10:21] I conclude from these survey results that there are very pressing questions: Why is ERM so incredibly convoluted and seemingly complex? Why is there not better take-up? Why is there such a strange juxtaposition between the obvious need for ERM and the stagnation of methods and results?
[10:39] To answer this, I’m going to propose a thesis: it has to do with how ERM has developed over the years. Quite naturally, there has been an attempt by all major institutions, associations and firms in the industry to capture the market and position themselves as the authority, with an inevitable proliferation of advice.And here we see foundational and conceptual confusion, with regard to definitions, methods and practices -- it has to be said -- often by people who had never actually implemented ERM. And I don’t pretend to answer all contradictions in the field, or comprehend or judge the entire industry, because undoubtedly there are outstanding examples of good practice. And yet I daresay that these outstanding examples -- wherever they may be -- are rarely codified or universally understood, much less accepted as standards.
The reader/listener will object that I’m simply adding my own voice to the cacophony. But I do stand on my track record, and claim that I can deliver on my mission statement; which I will repeat it here:
“To help you develop an Enterprise Risk Management program that is conceptually sound, practical, and of demonstrable worth.”
It is a method that is internally consistent, applicable to both public and private organizations or all sizes; tested over years with clients in all kinds of administrative settings, and judged to be of value by practitioners and third party auditors.
[12:55] Conclusion. Really, it is the mission of this podcast to enable risk champions to succeed. But in order to do so, I must begin with a tear-down of sorts, in the form of exploding prevalent myths in Enterprise Risk Management. That will be the subject of the next few episodes!
[14:19] If my message so far resonates with you then I encourage you to subscribe to the podcast. You can do so on your podcast player app. If you visit RiskCommentary.com and subscribe, you will receive:
Show notes;
Full show and interview transcripts;
One-time ebook give-away Risk Management Tools and Templates;
No spam policy; infrequent notifications.
Key quotes
Is ERM Dead? ”We are in an unprecedented and evolving landscape unlike anything that we have ever seen historically.” This from the former President of Lloyd’s of London for North America... and yet only 35% of those surveyed have a full Enterprise Risk Management practice.
Links to sources mentioned
Book: Solving the Enterprise Risk Management Puzzle: Secrets to Successful Implementation (E.R. 2016)
Linked In bio for LoriAnn Lowery-Biggers:
https://www.linkedin.com/in/loriann-lowery-biggers-12963b15
Interview of LoriAnn Lowery-Biggers and colleague Sean Murphy by John Czuba of Legal Talk Network:
https://legaltalknetwork.com/podcasts/insurance-law-podcast-am-best/2019/10/enterprise-risk-management-strategies/
The State of Risk Oversight - An Overview of Enterprise Risk Management Practices by AICPA
(American Institute of Certified Public Accountants) and North Carolina State University. April 2021.
https://www.aicpa.org/content/dam/aicpa/interestareas/businessindustryandgovernment/resources/erm/downloadabledocuments/aicpa-erm-research-study-2021.pdf