RISK-ACADEMY: Recent Episodes

Alex Sidorenko

RISK-ACADEMY, controversial thoughts about modern day risk management in non-financial companies

View Details

This episode is also available as a blog post: https://riskacademy.blog/skin-in-the-game-if-risk-managers-are-so-smart-why-are-they-not-millioners/--- Send in a voice message: https://podcasters.spotify.com/pod/show/riskacademy/message

View Details

This episode is also available as a blog post: https://riskacademy.blog/chancification-wiring-your-organization-for-probability-by-sam-savage/


Send in a voice message: https://anchor.fm/riskacademy/message

View Details

This episode is also available as a blog post: https://riskacademy.blog/the-most-inspirational-story-about-risk-management-you-will-ever-read/


Send in a voice message: https://anchor.fm/riskacademy/message

View Details

Provide additional risk management training to the in-house risk management team and business units responsible for internal control, audit, finance, strategy and others. Risk managers may conduct it personally or outsource to third party providers. In-depth risk management training should include (this example is based on the actual risk management training provided by Institute for Strategic Risk Analysis and RISK-ACADEMY to some of the largest non-financial companies in Russia):

RISK MANAGEMENT FOUNDATIONS

  • Definition of risk
  • History of risk management
  • International and national risk management standards
  • Introduction to finance, project management and process management
  • Introduction to statistics
  • Insurance basics

RISK MANAGEMENT IN DECISION MAKING

  • Identification of risks associated with decision making or goals/KPIs achievement
  • Risk analysis in decision making (sensitivity analysis, scenario analysis, Monte-Carlo simulations, decision trees, scoring models)
  • Risk mitigation and risk-based decision making
  • Disclosure, reporting, monitoring and review

PSYCHOLOGY AND RISK MANAGEMENT CULTURE

  • Risk psychology and cognitive biases in decision making
  • Risk management culture
  • Principles of risk management ethics

INTEGRATING RISK MANAGEMENT INTO THE BUSINESS

  • Understanding the organisational appetite for risk
  • A roadmap for risk management integration:
    • Developing new and updating existing policies and procedures
    • Integration into decision making, planning, budgeting, purchasing, auditing etc.
    • Risk management roles and responsibilities, risk management KPIs
    • Integrating risk information into management reporting
    • Resources required for the implementation of risk management
  • Auditing risk management effectiveness
  • Risk management continuous improvement
  • Risk management software

View Details

New hires come from a variety of education and experience backgrounds and most importantly, each new employee has their own perception of what is an acceptable risk. It is important for risk managers to cooperate with the Human Resources department or any other business unit responsible for training, to jointly carry out training on the basics of risk management for all new employees.

One of the risk managers we interviewed mentioned that the risk management induction should not be long. It should take about ten minutes and include the basics of business and investment decisions under uncertainty, key risk management roles and responsibilities and the ISO31000:2018 risk management principles as per the company’s Risk Management Policy.

View Details

Tone at the top is very important for risk culture development. Executives and Board members play a vital role in driving the risk management agenda. Nowadays many executives and Board members have a basic understanding of risk management. Auditors, risk management professional associations and regulators have been quite influential in shaping the Board’s perception of risk management.

Unfortunately, not all the messages communicated by the auditors and regulators are sound and some are downright wrong. For example, one of the government agencies in Russia published a guidance document that encourages companies to have a standalone risk management process and in many ways contradict the core principles of ISO31000:2018. Despite our best effort to block the document, it was approved by the government and now most government owned corporations in Russia have to create two parallel risk management frameworks, one for the regulator and one for the decision makers.

It is important for the risk manager to take the lead on forming the Boards and senior managements view on risk management by providing risk awareness sessions and relevant information. Here are some of the most important messages risk managers need to include in their communication with the Board:

  • Decision quality and how people make decisions under uncertainty;
  • Positioning risk management as a tool to help management make decisions;
  • Risk management should be an integral part of existing business processes and regular management reporting, not a standalone quarterly or annual activity;
  • Risk management is not about avoiding or minimising risks, it’s about making informed decisions.

It may be appropriate to bring in an independent advisor to conduct risk awareness training for the Boards and senior management to reinforce the messages shared by the risk managers internally.

View Details

An active network of “risk champions” is a very effective way to develop strong risk management culture. This network could become the “glue” between the risk management team and the rest of the business. “Risk champions” can be of three types:

  • Official risk coordinators - employees, whose official duties include coordination of risk management processes within individual processes or business units. They are usually responsible for preparing information about risks, monitoring risk mitigation progress, organising risk management events or training. This role becomes less relevant with the integration of risk management into decision making.
  • Unofficial informants – employees, who have established informal, yet trusted relationships with the risk managers. They provide information about emerging risks or changes in the organisation processes or risk profile. A large network of informants is critical for risk managers to stay up-to-date on what is happening in the company. Good risk managers invest significant amount of time to have a network of people who can help with advice or information.
  • Influencers – employees, who support the integration of risk management into the organizational activities and processes because it makes good business sense for the company or them personally. They will usually participate in the Risk Management Committee meetings and will support initiatives proposed by the risk managers.

"Risk champions” help to implement risk management elements in key business processes and procedures within the organisation. Usually, "risk-champions" are employees who are naturally motivated to effectively manage risks, such as employees responsible for project management, methodology, process improvement, audit, internal control, etc. For larger organisations, it may be necessary to identify "risk-champions" not only for key processes, but also for each geographical area where the company is represented.

View Details

Once risk management roles and responsibilities have been documented in job descriptions and committee charters then appropriate and measurable KPIs should be developed. Just like anything else, risk management KPIs need to be integrated into the overall performance management system, better still existing KPIs should be made risk-based instead of separate risk management KPIs.

Risk management is everyone's responsibility. Yet, research in neuroeconomics [1]shows that managing risks is not natural for people, it may even be against human nature. Without proper motivation or with inadequate motivation, employees are often reluctant to consider and disclose risks as part of their decision making. This message was reinforced during our interviews. Companies that have implemented and monitored risk management KPIs for key employees have demonstrated significantly higher risk management maturity.

KPIs should be specific for each role within the overall risk governance model.

For example, KPIs for the CEO may include:

  • an improvement in the risk management culture rating;
  • regularity and quality of risk disclosure to shareholders;
  • achieving risk-adjusted profitability measures.

For CFO or COO risk management KPIs may include:

  • improvement in risk management culture maturity;
  • RAROC (risk-adjusted return on capital);
  • risk-adjusted cash flow and liquidity measures;
  • the number of critical operational events and so on.

For the employees, a risk management KPI may include timely and accurate risk analysis during core business processes or significant decisions.

[1] https://en.wikipedia.org/wiki/Risk_perception

View Details

Every risk manager we have interviewed explained to us that periodic risk culture evaluations help strengthen it. So, we wanted to give readers some practical ideas around it.

There are multiple models which can be used to assess the current state of risk culture, including the risk culture framework developed by the Institute of Risk Management, UK or the risk maturity model developed by G31000 that covers elements of risk culture. Whatever the model risk managers select, they should make sure it is aligned with the ISO 31000:2018 principles.

When reviewing risk management culture, risk managers should, among other things, look at:

  • Whether accountabilities and responsibilities for risk are well documented - A critical component of risk management integration is including responsibility and accountability (authority, resources, competences) for managing risks into all business activities. Top management should ensure that responsibilities and authority for relevant roles with respect to risk management are assigned and communicated at all levels of the organisation.
  • Evidence of risk management competencies - Risk management competences should be developed in all core business units. Risk management competences should also become an important attribute when hiring new personnel to the organisation.
  • Evidence of risk management training and awareness - All employees should receive risk management training appropriate to their level and risk exposure.
  • Whether individual performance management considers risk information - Mature organisations align individual performance management with risk management. Employees should have individual key performance indicators relating to the management of risk and their participation in the risk management processes.
  • Evidence of open communication and transparency - Information about the risks is openly discussed during the decision-making process. Significant risks are given due attention at the management and Board meetings. Executives are receptive to bad news and are ready to discuss risks and risk mitigations.

Risk managers should regularly discuss culture and attitude to risk with senior management and the Board, as well as help communicate Board and senior management expectations to the employees.

View Details

Most modern-day risk managers are familiar with developing a risk management framework or procedure documents. These documents capture risk management roles and responsibilities, outline risk management processes as well as other aspects of risk management. Risk management framework documents became so common, that nowadays they don’t require much effort to develop and there are plenty of free templates available online. The only problem is that nobody in the organisation, except the risk manager and the internal auditor, reads them. Clearly, something is not right.

Over the years, we have discovered a much better way to document risk management frameworks, procedures and methodologies. Instead of writing a separate risk management framework, companies should upgrade its existing policies and procedures to include elements of risk management where appropriate. One investment company that we interviewed documented risk management methodology in the investment manual instead of creating any new risk management documents. This essentially changed how the investment process works, made risk management a critical step in investment decision making, gave investment managers a sense of ownership and had a huge positive impact on the risk culture within the organisation.

The same approach can also be used for any other business process. Instead of creating a single, centralised risk management framework or procedure document, risk managers should review and update existing policies and procedures to include elements of risk management. Some procedures may require a minor update, with only a sentence or two added while others may need whole appendices written to include risk management methodologies. This approach also reinforces the need to create separate risk management tools and methodologies for different business processes.

View Details

Risk managers may begin the implementation of the selected risk governance model by documenting risk management roles and responsibilities. It is quite common to describe risk management roles and responsibilities in risk management policy or a framework document. This approach seems simple to implement, yet not very effective, as business units often don’t feel ownership of these documents, instead they consider them irrelevant in everyday business and simply ignore them. There is a better way.

It is considered more effective to incorporate risk management roles and responsibilities into existing job descriptions, operational policies and procedures, various committee charters and working groups. Risk management roles and responsibilities must be identified and documented for all levels of management. As mentioned by a number of the risk managers we have interviewed, it is a much more effective than listing roles and responsibilities in the risk management policy or framework document.

That being said some people feel quite sensitive about their job descriptions, so instead of initiating major changes and updates for the sake of integrating risk management roles and responsibilities, wait for the HR to initiate change on other topics and add risk management points as part of the broader changes.

Some of the common roles and responsibilities include:

Board of directors (if available)

  • Provide oversight of the overall risk management effectiveness
  • Make Board level decisions with proper consideration for risks
  • Review and establish risk-adjusted appetites/limits for certain business activities, types of risks (usually required by law) or decisions
  • Set risk-adjusted performance targets and KPIs for CEO and the management

CEO

  • Responsible for establishing the overall risk management framework
  • Make decisions with proper consideration for risks
  • Approves the strategy, business plans and budgets based on the risk management information
  • Set risk-adjusted performance targets and KPIs for senior management
  • Provide timely and accurate disclosure for risk-adjusted performance, most significant risks and their treatments to the Board of Directors / investors / owners
  • Allocate responsibility for effective risk management to risk owners
  • Assign responsibility for designing and implementing the risk management framework
  • Allocate resources necessary to perform business activities with risks in mind

Risk manager

  • Design and implement the risk management framework
  • Coordinate risk management activities and provide methodological support for the risk-based decision making
  • Participate in the decision-making process (if required)
  • Participate in the preparation of management reports, providing relevant information about risks and their treatments
  • Coordinate the work of the Risk Management Committee (if applicable)
  • Provide risk management training or integrate risk management into existing trainings
  • Implement activities designed to integrate risk management into the overall culture of the organization

Other business unit heads:

  • Identify, assess and treat risks associated with business activities or decision-making within their area of responsibility
  • Allocate resources necessary to manage risks within their area of responsibility
  • Optimize business processes or decision making based on the information about risks.

Work with your HR team to include ISO31000 knowledge and risk management competencies in job descriptions / position descriptions for new hires.

View Details

New hires come from a variety of education and experience backgrounds and most importantly, each new employee has their own perception of what is an acceptable risk. It is important for risk managers to cooperate with the Human Resources department or any other business unit responsible for training, to jointly carry out training on the basics of risk management for all new employees.

One of the risk managers we interviewed mentioned that the risk management induction should not be long. It should take about ten minutes and include the basics of business and investment decisions under uncertainty, key risk management roles and responsibilities and the ISO31000:2018 risk management principles as per the company’s Risk Management Policy.

View Details

The risk governance model depends on the management and shareholders’ expectations, the regulatory requirements as well as on the risk manager’s competencies and on the resources available for risk management implementation.

The risk governance can be structured using the classical three lines of defence concept:

  • The 1st line of defence - Business units: executives, business department management as well as employees. As part of their daily duties, those listed above are responsible for timely identification, assessment, management, monitoring and reporting on risks. Senior management and the Board of Directors determine the strategy for risk management, approve risk appetite and monitor how major risks are managed.
  • The 2nd line of defence - Functions of risk management and other support functions (such as safety and quality, finance, insurance, etc. are business consultants and are responsible for developing the methodology for managing risks, awareness and training, and methodological support. Sometimes the risk management team also performs a quality control function and aggregates information about the risks.
  • The 3rd line of defence - Internal audit: Independent bodies, such as internal audit, provide independent monitoring that the risk management is carried out as in line with internal policies and procedures, and that the management of key corporate risks is performed.

While commonly accepted and simple in theory, the three lines of defence model is overly idealistic and doesn’t work well in non-financial services. Risk managers may want to consider an alternative and better risk governance structure where:

  • The risk management function is the centre of competence for all risk analysis and is responsible for an independent, timely and quantitative risk analysis for the decisions proposed by management. This approach is different from the traditional three lines of defence, as risk managers take greater responsibility and ownership over some of the risk analysis and maybe even some risks. This allows the risk manager to be directly involved in the process of decision making and to assume the responsibility for the outcomes on par with other executives.
  • In certain cases, the risk manager may have the mandate to block excessively risky transactions or projects that do not meet the strategic goals of the company.

Based on the experience of the authors the second option is much more effective. CEOs rarely are prepared to pay good salaries for facilitators and methodology experts that have nothing valuable to contribute to a specific decision. Nassim Taleb calls it ‘having the skin in the game’. To him, this is the only way to manage risks. We agree.

Another interesting analogy for the risk manager is the Advocatus Diaboli (Latin for Devil's Advocate) was formerly an official position within the Catholic Church: one who "argued against the canonization (sainthood) of a candidate in order to uncover any character flaws or misrepresentation of the evidence favouring canonization".[1] Supplements to this chapter a five short recording on how a risk manager can play a devils advocate role and what is required.

[1] Helterbran, Valeri R. (1 January 2008). Exploring Idioms. Maupin House Publishing, Inc. p. 40. ISBN 9781934338148.

View Details

Listen to two risk managers discussing some of the most controversial and hottest topics in risk right now. See them debate, argue and comment on some of the most common risk management misconceptions.

View Details

A large part of risk management success depends on the support and commitment from executives, Board members and key stakeholders.

It is important, as early as possible, to identify specific people at different levels within the organisation who support the concept of risk-based management and are ready to assist the risk manager:

  • At the executive level – risk managers should find what motivates different executives, the CFO, for example, may be interested in implementing and supporting risk management to show the realistic risk-adjusted results and forecast to the banks and insurance companies to save on financing or insurance costs. Or he may be interested in having a methodology to validate investment projects, because he is not happy with how company was investing in very high risk initiatives lately. The COO may be interested to decrease the level of operational risks. The HR Director may be interested in timely identification of the staff turnover risk, etc.
  • At the Board level – independent directors or other Board members may be supportive of risk management because it provides greater transparency in decision making and creates an additional information channel for them.
  • At the auditor level – risk managers should participate in the audit methodology discussion and try to synchronise risk management methodologies between what is used internally and what external auditors apply.
  • At the regulator level - risk managers should discuss regulators’ expectations and methodologies to try to synchronise risk management methodologies between what is used internally and what regulators expect.

Finding the right sponsors is more of an art, than a science. It’s highly unlikely that the risk manager will be able to convince all Board members or all executives. However, this is not really necessary, as long as the risk manager has support from certain individuals at every level mentioned above.

View Details

Risk managers should build relationships and join forces with the other managers responsible for performance improvement initiatives, like lean management, quality, safety, environment, security, internal audit or others. Risk managers should participate in relevant major performance improvement workshops (for example, kaizen sessions during lean projects) to better understand sources of risks and suggested solutions, or at least review the results of those analytical sessions.

Risk managers should make sure that common risk management principles and language are used throughout the organization.

The ISO experts at the ISO Technical Committees level are doing it, making sure the language in ISO9001:2015 and ISO14000:2015 is consistent with ISO31000:2018, so no excuses for the risk managers on the ground.

Here is a small and clever case we came across during our research. One risk manager we have interviewed approached a CEO of a large investment fund to implement risk management across its 90+ portfolio companies. The CEO said it was a good idea, but since the company was a minority shareholder in most portfolio companies, it has to be voluntary, risk manager was not allowed to force them to implement. So, the risk manager played a little trick with the Head of Internal Audit. Here are the steps:

  • Risk manager created an implementation pack and sent a communication to all portfolio company CEOs a free offer to use the pack and implement themselves. 1 out of 90+ responded and the risk manager worked with them to set the foundation.
  • One month later the risk manager worked with internal audit to include risk management questions into the annual compliance review questionnaire for the portfolio companies.
  • Six months later, not surprisingly, most portfolio companies received non-compliance report for the lack of or limited risk management.
  • Another month later the risk manager once again sent a communication to all portfolio company CEOs a free offer to use the risk management implementation pack. This time more than 65% of all portfolio companies opted in. All this was achieved within a single year. Not bad.

View Details

Risk managers should encourage employees to openly raise risk management related issues. This is possible by spending a considerable amount of time every day communicating with their colleagues and staying up-to-date on the latest developments and emerging risks or failures in the internal control system.

Share the risk manager’s contact information with employees or provide a confidential hotline for communicating risks through the internal company website or via the phone. Risk managers should motivate and encourage staff to be proactive about identifying and preventing risks. One of the risk managers we have interviewed started a table tennis tournament to build rapport with other business units and to have regular conversations in an informal setting with other managers. Another risk manager we have interviewed created daily performance and incident reporting meetings to encourage ongoing discussion about potential threats and opportunities. Anything that creates a vision of an approachable and helpful risk manager works.

We, for example, have created a risk management page on the company intranet with a message form to allow people to anonymously send messages to the Head of Risk about any emerging risks. Over the course of three years it was used exactly zero times! Was it a waste of time? Of course not. Because even though no one felt comfortable using the online form, dozens of employees approach me to ask for feedback, comments, opinion or share information about emerging risks or a potential issue.

Risk managers may consider introducing a rewards programme for active participation in risk management activities. It is important to encourage a “no blame” culture and communicate it throughout the company.

View Details

Selling risk management to key stakeholders is not simple. Risk managers need to learn to be proud of their contribution to the overall success of the company. Any positive results achieved by managing certain risks to a high standard should trigger the risk manager to share this success both internally and externally. This can be done by presenting at various conferences and industry events or publishing small articles in relevant magazines or web publications. Here is a list of places where we normally publish our work:

  • Official RISK-ACADEMY blog https://riskacademy.wordpress.com
  • G31000 LinkedIn discussion forum https://www.linkedin.com/groups/1834592
  • Corporate Compliance Insights www.corporatecomplianceinsights.com
  • Continuity Central www.continuitycentral.com
  • CERM ® RISK INSIGHTS http://insights.cermacademy.com/
  • Insurance Thought Leadership http://insurancethoughtleadership.com/
  • Company newsletters
  • Company intranet portal
  • Company public website

Sharing information about risk management will raise risk management awareness internally and reinforce trust and transparency with suppliers, contractors, key clients and regulators externally. Clearly this is only applicable to non-confidential, public information that does not include any trade secrets or other sensitive information.

A number of the risk managers we have interviewed suggested that sharing information about risks and their mitigation with banks, investors, insurance companies and suppliers can result in significant cost savings on finance (lower cost of financing), insurance costs (lower premiums) and the cost of goods.

Another good idea is to participate in annual risk management awards sessions, like the one organised by G31000 globally or by the Institute of Strategic Risk Analysis in Decision Making (ISAR) in Russia.

The best idea, however, is to use risk management to help one or some of the executives achieve their objectives and KPIs and let them promote risk management internally and externally. Noting beats a powerful spokesman to drive the risk management integration message.

View Details

Most of the risk managers we have interviewed agreed that having a management level Risk Management Committee has a significant positive effect on the overall risk management culture.

While the composition of the Risk Management Committee can vary from company to company, it should be sufficiently representative to ensure different points of view on risk are considered. Based on our interviews, the best results tend to be achieved when the risk committee brings together supporting functions (finance, risk, legal, security, internal audit) and business units (operations, sales, marketing).

The Committee can either deal with matters related to risk management methodologies and risk management integration into various business processes or it may participate in the decision-making process (investments, projects and other high-risk activities) or both.

The Committee may meet on a regular basis (monthly or quarterly) as well as upon request from the Chairman of the Committee if there are questions that require urgent risk analysis.

View Details

This next step is very important to reinforce strong risk culture within the organisation. ISO31000:2018 states “Oversight bodies are often expected or required to:

— ensure that risks are adequately considered when setting the organization’s objectives;

— understand the principal risks facing the organization in pursuit of its objectives;

— ensure that systems to manage such risks are implemented and operating effectively;

— ensure that such risks are appropriate in the context of the organization’s objectives;

— ensure that information about such risks and their management is properly communicated.”

There are various ways of including risk discussion on the Board’s agenda, however we believe that it is more effective to spend fifteen minutes on risk matters during every significant decision than an hour once a quarter or a day once a year.

It is recommended to discuss risks associated with each decision instead of having risk management as a separate agenda item. After all items on Board’s agenda are risk items.

For example, the Board may want to discuss risks associated with the quarterly budget when discussing the actual budget, or discuss project risks when approving project financing, as opposed to discussing the top ten corporate risks at the end of the meeting when all decisions have already been made.

The risk manager should, along with the Board secretary, make the necessary amendments to the presentation templates to include a section on risks for every significant decision. The risk manager, in conjunction with the internal audit, should also ensure that the risk information provided to the Board by the management is complete, accurate and consistent. To improve the quality of such information, risk managers may wish to consider staff training or personally quality check the information before it goes to the Board.

Some Boards may create a separate Risk Committee or expand the scope of the Audit Committee to review matters related to risks. Our experience, when talking to different risk managers during the interviews, shows that this may be more fashionable than practical, since most decisions are taken long before the information is formally presented to the Board of Directors. Several people interviewed mentioned that it makes more practical sense to have a management level risk committee instead.

Nevertheless, the Board level risk committee can play an important oversight role and have a very positive impact on the overall risk culture within the organisation. Sometimes this is called “security theatre”.

View Details

Most organisations have already documented their appetite for different common decisions or business objectives. Segregation of duties, financing and deal limits, procurement criteria, investment criteria, zero tolerance to fraud or safety risks – are all examples of how organisations set risk appetites. Appetites or limits for different kinds of decisions and risks has been around for decades. Not all risks, but most of them.

So, what is this recent hype about risk appetite about? Not much really, it’s just another consulting red herring. Contrary to what most modern-day consultants tell us, the authors believe that any attempts in non-financial companies to aggregate risks into a single risk appetite statement is both unnecessary and unrealistic. Even having few separate risk appetite statements is totally missing the point.

After all, risk appetite is just a tool to help management make decisions and be transparent to stakeholders when making these decisions.

Instead of creating separate new risk appetite statements, risk managers should review existing Board level policies and procedures and identify:

  • significant decisions and risks that already have its appetites set. For example, a company may have a Board level policy that prohibits any business ventures with organisations that utilise child labour. Or it may have a requirement not to invest in high risk ventures above a certain ratio or executives have been delegated authority for any budgetary decisions of no more than 300 million. In cases, where the risk appetite has already been set, risk managers should work with internal auditors to test whether limits are realistic and are in fact adhered to. 80% of the time the appetites for different business decisions have already been set and all the risk manager has to do is to validate, monitor, report any unusual activity.
  • for the decisions and risks where no appetite has been set by any of the existing policies or procedures, the risk manager should work with the process owners to develop risk limits and incorporate them into existing policies and procedures. Main risks can be divided into three groups: "zero tolerance" risks, acceptable within quantitative limits and acceptable within qualitative limits. This is the other 20%. Risk managers should use Monte-Carlo simulation, scenario analysis or decision trees to document risk appetites. Once set and documented, risk appetites or limits for different types of decisions should be reviewed periodically to remain current and applicable.

We strongly believe that risk appetites should be integrated into existing Board level documents and very rarely, if ever, published as separate risk appetite statements. Also keep in mind, that risk appetite concept non-financial companies have inherited from regulators in banking sector. For banks risk appetite is used a regulator control mechanism. Sometimes we use the analogy of the dog’s leash.

Since most risk managers in non-financial companies are likely to be paid by the CEO and usually work for the management and not the regulator or even the shareholders, risk managers should probably view the concept of risk appetite from a management’s perspective.

View Details

It is generally considered a good idea to document an organisation’s attitude and commitment to risk management in a high-level document, such as a Risk Management Policy. The policy may describe the general attitude of the company towards risks, risk management principles, roles and responsibilities, risk management infrastructure as well as resources and processes dedicated to risk management. Section 5.2.1 of the ISO31000:2018 also provides guidance on risk management policy.

An article published by Michael Rasmussen back in October 2010 ‘Enterprise Risk Management Policy Structure’ provides an outline of what should be included in a risk management policy and notes that the organisation’s policy should not be “boilerplate.” The policy should reflect the actual activities undertaken by the company and its attitude and approach to managing its material business risks.

Risk management is useful document to communicate with external stakeholders such as banks, investors, auditors, regulators, key customers and suppliers.

View Details

Risk managers should discuss the outcomes of risk analysis with the executive team to see whether the results are reasonable, realistic and actionable. If indeed the results of risk analysis are significant, then the executive management with the help from the risk manager may need to:

  • Revise the assumptions used in the strategy.
  • Consider sharing some of the risk with third parties by using hedging, outsourcing or insurance mechanisms.
  • Consider uncertainty by adopting alternative approaches for achieving the same objective or implementing appropriate control measures.
  • Accept risks and develop a business continuity / disaster recovery plan to minimise the negative impact of risks should they eventuate.
  • Take the right risks that are within the risk appetite set by the Board or the regulator.
  • Or, perhaps, change the strategy altogether.

Based on the risk analysis outcomes it may be required for the management to review or update the entire strategy or just elements of it. This is one of the reasons why it is highly recommended to perform risk analysis before the strategy is finalised.

At a later stage the risk manager should work with the internal audit to determine whether the risks identified during the risk analysis are in fact controlled and the agreed risk mitigations are implemented.