This episode is also available as a blog post: https://riskacademy.blog/skin-in-the-game-if-risk-managers-are-so-smart-why-are-they-not-millioners/--- Send in a voice message: https://podcasters.spotify.com/pod/show/riskacademy/message
This episode is also available as a blog post: https://riskacademy.blog/chancification-wiring-your-organization-for-probability-by-sam-savage/
Send in a voice message: https://anchor.fm/riskacademy/message
This episode is also available as a blog post: https://riskacademy.blog/the-most-inspirational-story-about-risk-management-you-will-ever-read/
Send in a voice message: https://anchor.fm/riskacademy/message
Provide additional risk management training to the in-house risk management team and business units responsible for internal control, audit, finance, strategy and others. Risk managers may conduct it personally or outsource to third party providers. In-depth risk management training should include (this example is based on the actual risk management training provided by Institute for Strategic Risk Analysis and RISK-ACADEMY to some of the largest non-financial companies in Russia):
RISK MANAGEMENT FOUNDATIONS
RISK MANAGEMENT IN DECISION MAKING
PSYCHOLOGY AND RISK MANAGEMENT CULTURE
INTEGRATING RISK MANAGEMENT INTO THE BUSINESS
New hires come from a variety of education and experience backgrounds and most importantly, each new employee has their own perception of what is an acceptable risk. It is important for risk managers to cooperate with the Human Resources department or any other business unit responsible for training, to jointly carry out training on the basics of risk management for all new employees.
One of the risk managers we interviewed mentioned that the risk management induction should not be long. It should take about ten minutes and include the basics of business and investment decisions under uncertainty, key risk management roles and responsibilities and the ISO31000:2018 risk management principles as per the company’s Risk Management Policy.
Tone at the top is very important for risk culture development. Executives and Board members play a vital role in driving the risk management agenda. Nowadays many executives and Board members have a basic understanding of risk management. Auditors, risk management professional associations and regulators have been quite influential in shaping the Board’s perception of risk management.
Unfortunately, not all the messages communicated by the auditors and regulators are sound and some are downright wrong. For example, one of the government agencies in Russia published a guidance document that encourages companies to have a standalone risk management process and in many ways contradict the core principles of ISO31000:2018. Despite our best effort to block the document, it was approved by the government and now most government owned corporations in Russia have to create two parallel risk management frameworks, one for the regulator and one for the decision makers.
It is important for the risk manager to take the lead on forming the Boards and senior managements view on risk management by providing risk awareness sessions and relevant information. Here are some of the most important messages risk managers need to include in their communication with the Board:
It may be appropriate to bring in an independent advisor to conduct risk awareness training for the Boards and senior management to reinforce the messages shared by the risk managers internally.
An active network of “risk champions” is a very effective way to develop strong risk management culture. This network could become the “glue” between the risk management team and the rest of the business. “Risk champions” can be of three types:
"Risk champions” help to implement risk management elements in key business processes and procedures within the organisation. Usually, "risk-champions" are employees who are naturally motivated to effectively manage risks, such as employees responsible for project management, methodology, process improvement, audit, internal control, etc. For larger organisations, it may be necessary to identify "risk-champions" not only for key processes, but also for each geographical area where the company is represented.
Once risk management roles and responsibilities have been documented in job descriptions and committee charters then appropriate and measurable KPIs should be developed. Just like anything else, risk management KPIs need to be integrated into the overall performance management system, better still existing KPIs should be made risk-based instead of separate risk management KPIs.
Risk management is everyone's responsibility. Yet, research in neuroeconomics [1]shows that managing risks is not natural for people, it may even be against human nature. Without proper motivation or with inadequate motivation, employees are often reluctant to consider and disclose risks as part of their decision making. This message was reinforced during our interviews. Companies that have implemented and monitored risk management KPIs for key employees have demonstrated significantly higher risk management maturity.
KPIs should be specific for each role within the overall risk governance model.
For example, KPIs for the CEO may include:
For CFO or COO risk management KPIs may include:
For the employees, a risk management KPI may include timely and accurate risk analysis during core business processes or significant decisions.
[1] https://en.wikipedia.org/wiki/Risk_perception
Every risk manager we have interviewed explained to us that periodic risk culture evaluations help strengthen it. So, we wanted to give readers some practical ideas around it.
There are multiple models which can be used to assess the current state of risk culture, including the risk culture framework developed by the Institute of Risk Management, UK or the risk maturity model developed by G31000 that covers elements of risk culture. Whatever the model risk managers select, they should make sure it is aligned with the ISO 31000:2018 principles.
When reviewing risk management culture, risk managers should, among other things, look at:
Risk managers should regularly discuss culture and attitude to risk with senior management and the Board, as well as help communicate Board and senior management expectations to the employees.
Most modern-day risk managers are familiar with developing a risk management framework or procedure documents. These documents capture risk management roles and responsibilities, outline risk management processes as well as other aspects of risk management. Risk management framework documents became so common, that nowadays they don’t require much effort to develop and there are plenty of free templates available online. The only problem is that nobody in the organisation, except the risk manager and the internal auditor, reads them. Clearly, something is not right.
Over the years, we have discovered a much better way to document risk management frameworks, procedures and methodologies. Instead of writing a separate risk management framework, companies should upgrade its existing policies and procedures to include elements of risk management where appropriate. One investment company that we interviewed documented risk management methodology in the investment manual instead of creating any new risk management documents. This essentially changed how the investment process works, made risk management a critical step in investment decision making, gave investment managers a sense of ownership and had a huge positive impact on the risk culture within the organisation.
The same approach can also be used for any other business process. Instead of creating a single, centralised risk management framework or procedure document, risk managers should review and update existing policies and procedures to include elements of risk management. Some procedures may require a minor update, with only a sentence or two added while others may need whole appendices written to include risk management methodologies. This approach also reinforces the need to create separate risk management tools and methodologies for different business processes.
Risk managers may begin the implementation of the selected risk governance model by documenting risk management roles and responsibilities. It is quite common to describe risk management roles and responsibilities in risk management policy or a framework document. This approach seems simple to implement, yet not very effective, as business units often don’t feel ownership of these documents, instead they consider them irrelevant in everyday business and simply ignore them. There is a better way.
It is considered more effective to incorporate risk management roles and responsibilities into existing job descriptions, operational policies and procedures, various committee charters and working groups. Risk management roles and responsibilities must be identified and documented for all levels of management. As mentioned by a number of the risk managers we have interviewed, it is a much more effective than listing roles and responsibilities in the risk management policy or framework document.
That being said some people feel quite sensitive about their job descriptions, so instead of initiating major changes and updates for the sake of integrating risk management roles and responsibilities, wait for the HR to initiate change on other topics and add risk management points as part of the broader changes.
Some of the common roles and responsibilities include:
Board of directors (if available)
CEO
Risk manager
Other business unit heads:
Work with your HR team to include ISO31000 knowledge and risk management competencies in job descriptions / position descriptions for new hires.
New hires come from a variety of education and experience backgrounds and most importantly, each new employee has their own perception of what is an acceptable risk. It is important for risk managers to cooperate with the Human Resources department or any other business unit responsible for training, to jointly carry out training on the basics of risk management for all new employees.
One of the risk managers we interviewed mentioned that the risk management induction should not be long. It should take about ten minutes and include the basics of business and investment decisions under uncertainty, key risk management roles and responsibilities and the ISO31000:2018 risk management principles as per the company’s Risk Management Policy.
The risk governance model depends on the management and shareholders’ expectations, the regulatory requirements as well as on the risk manager’s competencies and on the resources available for risk management implementation.
The risk governance can be structured using the classical three lines of defence concept:
While commonly accepted and simple in theory, the three lines of defence model is overly idealistic and doesn’t work well in non-financial services. Risk managers may want to consider an alternative and better risk governance structure where:
Based on the experience of the authors the second option is much more effective. CEOs rarely are prepared to pay good salaries for facilitators and methodology experts that have nothing valuable to contribute to a specific decision. Nassim Taleb calls it ‘having the skin in the game’. To him, this is the only way to manage risks. We agree.
Another interesting analogy for the risk manager is the Advocatus Diaboli (Latin for Devil's Advocate) was formerly an official position within the Catholic Church: one who "argued against the canonization (sainthood) of a candidate in order to uncover any character flaws or misrepresentation of the evidence favouring canonization".[1] Supplements to this chapter a five short recording on how a risk manager can play a devils advocate role and what is required.
[1] Helterbran, Valeri R. (1 January 2008). Exploring Idioms. Maupin House Publishing, Inc. p. 40. ISBN 9781934338148.
Listen to two risk managers discussing some of the most controversial and hottest topics in risk right now. See them debate, argue and comment on some of the most common risk management misconceptions.
A large part of risk management success depends on the support and commitment from executives, Board members and key stakeholders.
It is important, as early as possible, to identify specific people at different levels within the organisation who support the concept of risk-based management and are ready to assist the risk manager:
Finding the right sponsors is more of an art, than a science. It’s highly unlikely that the risk manager will be able to convince all Board members or all executives. However, this is not really necessary, as long as the risk manager has support from certain individuals at every level mentioned above.
Risk managers should build relationships and join forces with the other managers responsible for performance improvement initiatives, like lean management, quality, safety, environment, security, internal audit or others. Risk managers should participate in relevant major performance improvement workshops (for example, kaizen sessions during lean projects) to better understand sources of risks and suggested solutions, or at least review the results of those analytical sessions.
Risk managers should make sure that common risk management principles and language are used throughout the organization.
The ISO experts at the ISO Technical Committees level are doing it, making sure the language in ISO9001:2015 and ISO14000:2015 is consistent with ISO31000:2018, so no excuses for the risk managers on the ground.
Here is a small and clever case we came across during our research. One risk manager we have interviewed approached a CEO of a large investment fund to implement risk management across its 90+ portfolio companies. The CEO said it was a good idea, but since the company was a minority shareholder in most portfolio companies, it has to be voluntary, risk manager was not allowed to force them to implement. So, the risk manager played a little trick with the Head of Internal Audit. Here are the steps:
Risk managers should encourage employees to openly raise risk management related issues. This is possible by spending a considerable amount of time every day communicating with their colleagues and staying up-to-date on the latest developments and emerging risks or failures in the internal control system.
Share the risk manager’s contact information with employees or provide a confidential hotline for communicating risks through the internal company website or via the phone. Risk managers should motivate and encourage staff to be proactive about identifying and preventing risks. One of the risk managers we have interviewed started a table tennis tournament to build rapport with other business units and to have regular conversations in an informal setting with other managers. Another risk manager we have interviewed created daily performance and incident reporting meetings to encourage ongoing discussion about potential threats and opportunities. Anything that creates a vision of an approachable and helpful risk manager works.
We, for example, have created a risk management page on the company intranet with a message form to allow people to anonymously send messages to the Head of Risk about any emerging risks. Over the course of three years it was used exactly zero times! Was it a waste of time? Of course not. Because even though no one felt comfortable using the online form, dozens of employees approach me to ask for feedback, comments, opinion or share information about emerging risks or a potential issue.
Risk managers may consider introducing a rewards programme for active participation in risk management activities. It is important to encourage a “no blame” culture and communicate it throughout the company.
Selling risk management to key stakeholders is not simple. Risk managers need to learn to be proud of their contribution to the overall success of the company. Any positive results achieved by managing certain risks to a high standard should trigger the risk manager to share this success both internally and externally. This can be done by presenting at various conferences and industry events or publishing small articles in relevant magazines or web publications. Here is a list of places where we normally publish our work:
Sharing information about risk management will raise risk management awareness internally and reinforce trust and transparency with suppliers, contractors, key clients and regulators externally. Clearly this is only applicable to non-confidential, public information that does not include any trade secrets or other sensitive information.
A number of the risk managers we have interviewed suggested that sharing information about risks and their mitigation with banks, investors, insurance companies and suppliers can result in significant cost savings on finance (lower cost of financing), insurance costs (lower premiums) and the cost of goods.
Another good idea is to participate in annual risk management awards sessions, like the one organised by G31000 globally or by the Institute of Strategic Risk Analysis in Decision Making (ISAR) in Russia.
The best idea, however, is to use risk management to help one or some of the executives achieve their objectives and KPIs and let them promote risk management internally and externally. Noting beats a powerful spokesman to drive the risk management integration message.
Most of the risk managers we have interviewed agreed that having a management level Risk Management Committee has a significant positive effect on the overall risk management culture.
While the composition of the Risk Management Committee can vary from company to company, it should be sufficiently representative to ensure different points of view on risk are considered. Based on our interviews, the best results tend to be achieved when the risk committee brings together supporting functions (finance, risk, legal, security, internal audit) and business units (operations, sales, marketing).
The Committee can either deal with matters related to risk management methodologies and risk management integration into various business processes or it may participate in the decision-making process (investments, projects and other high-risk activities) or both.
The Committee may meet on a regular basis (monthly or quarterly) as well as upon request from the Chairman of the Committee if there are questions that require urgent risk analysis.
This next step is very important to reinforce strong risk culture within the organisation. ISO31000:2018 states “Oversight bodies are often expected or required to:
— ensure that risks are adequately considered when setting the organization’s objectives;
— understand the principal risks facing the organization in pursuit of its objectives;
— ensure that systems to manage such risks are implemented and operating effectively;
— ensure that such risks are appropriate in the context of the organization’s objectives;
— ensure that information about such risks and their management is properly communicated.”
There are various ways of including risk discussion on the Board’s agenda, however we believe that it is more effective to spend fifteen minutes on risk matters during every significant decision than an hour once a quarter or a day once a year.
It is recommended to discuss risks associated with each decision instead of having risk management as a separate agenda item. After all items on Board’s agenda are risk items.
For example, the Board may want to discuss risks associated with the quarterly budget when discussing the actual budget, or discuss project risks when approving project financing, as opposed to discussing the top ten corporate risks at the end of the meeting when all decisions have already been made.
The risk manager should, along with the Board secretary, make the necessary amendments to the presentation templates to include a section on risks for every significant decision. The risk manager, in conjunction with the internal audit, should also ensure that the risk information provided to the Board by the management is complete, accurate and consistent. To improve the quality of such information, risk managers may wish to consider staff training or personally quality check the information before it goes to the Board.
Some Boards may create a separate Risk Committee or expand the scope of the Audit Committee to review matters related to risks. Our experience, when talking to different risk managers during the interviews, shows that this may be more fashionable than practical, since most decisions are taken long before the information is formally presented to the Board of Directors. Several people interviewed mentioned that it makes more practical sense to have a management level risk committee instead.
Nevertheless, the Board level risk committee can play an important oversight role and have a very positive impact on the overall risk culture within the organisation. Sometimes this is called “security theatre”.
Most organisations have already documented their appetite for different common decisions or business objectives. Segregation of duties, financing and deal limits, procurement criteria, investment criteria, zero tolerance to fraud or safety risks – are all examples of how organisations set risk appetites. Appetites or limits for different kinds of decisions and risks has been around for decades. Not all risks, but most of them.
So, what is this recent hype about risk appetite about? Not much really, it’s just another consulting red herring. Contrary to what most modern-day consultants tell us, the authors believe that any attempts in non-financial companies to aggregate risks into a single risk appetite statement is both unnecessary and unrealistic. Even having few separate risk appetite statements is totally missing the point.
After all, risk appetite is just a tool to help management make decisions and be transparent to stakeholders when making these decisions.
Instead of creating separate new risk appetite statements, risk managers should review existing Board level policies and procedures and identify:
We strongly believe that risk appetites should be integrated into existing Board level documents and very rarely, if ever, published as separate risk appetite statements. Also keep in mind, that risk appetite concept non-financial companies have inherited from regulators in banking sector. For banks risk appetite is used a regulator control mechanism. Sometimes we use the analogy of the dog’s leash.
Since most risk managers in non-financial companies are likely to be paid by the CEO and usually work for the management and not the regulator or even the shareholders, risk managers should probably view the concept of risk appetite from a management’s perspective.
It is generally considered a good idea to document an organisation’s attitude and commitment to risk management in a high-level document, such as a Risk Management Policy. The policy may describe the general attitude of the company towards risks, risk management principles, roles and responsibilities, risk management infrastructure as well as resources and processes dedicated to risk management. Section 5.2.1 of the ISO31000:2018 also provides guidance on risk management policy.
An article published by Michael Rasmussen back in October 2010 ‘Enterprise Risk Management Policy Structure’ provides an outline of what should be included in a risk management policy and notes that the organisation’s policy should not be “boilerplate.” The policy should reflect the actual activities undertaken by the company and its attitude and approach to managing its material business risks.
Risk management is useful document to communicate with external stakeholders such as banks, investors, auditors, regulators, key customers and suppliers.
Risk managers should discuss the outcomes of risk analysis with the executive team to see whether the results are reasonable, realistic and actionable. If indeed the results of risk analysis are significant, then the executive management with the help from the risk manager may need to:
Based on the risk analysis outcomes it may be required for the management to review or update the entire strategy or just elements of it. This is one of the reasons why it is highly recommended to perform risk analysis before the strategy is finalised.
At a later stage the risk manager should work with the internal audit to determine whether the risks identified during the risk analysis are in fact controlled and the agreed risk mitigations are implemented.