Risk-management processes, perspectives, and responsibilities Flashcards
(40 cards)
2 key characteristics of the standard risk-man process
- Sequential, one element precedes the next
- Circular process in continuous use, with no clear distinction of start and end
4 elements of the standard risk-man process
Identify risks > Assess exposure > Monitor exposure > Control exposure > identify …
Risk identification involves…
identifying the risks to which an organisation is exposed, for better or for worse
3 techniques that can be used to identify risk
- Checklists
- Root-cause analysis
- Delphi technique
Risk assessment generally occurs once…
once a risk or a set of risks have been identified
Formula for risk exposure (re. assessment)
Probability (likelihood) of risk event x impact (severity) of risk event = exposure to risk event
Purpose of risk assessment
to determine the potential significance of the risk or risks in question
What will a risk assessment allow?
For risks to be placed in an order to establish their priority
Purpose of risk monitoring
Provide a comprehensive picture of current risk profile in relation to objectives, with an indication of how this might change
Risk monitoring involves the collection and dissemination of a wide range of data, including: (4)
- loss data on previous risk events
- a range of other risk, control and performance indicators
- production of risk reports for board & management
- external risk reports for stakeholders
Risk control involves: (2)
- Application of tools and techniques to influence probability and impacts of a risk event
- Mitigating any secondary disruption effects that may follow initial risk event
Risk control tools include: (4) & example of each
- Physical devises, such as door looks
- Financial tools, such as derivatives
- Transferring risk, such as with insurance
- Detecting tools, such as smoke alarms
What does ERM stand for?
Enterprise risk-management
What is the concept of ERM? *very basic
An extension of the standard risk-man process
Why is ERM not always better than standard risk-man? (3)
- It may not be the right fit for every org
- Its effectiveness depends on how it is implemented
- Poorly implemented ERM processes can do more harm than good
Common definition of ERM
ERM is a process, effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives
One key point to take away from ERM defiition
‘ERM is a process’ - it may be more complicated and sophisticated than standard risk-man, but at its heart it remains focussed on identification, assessment, monitoring, and control of risk
3 essential characteristics distinguishing ERM from standard risk-man process
Holistic - A holistic focus
Value added - An emphasis on value-added risk-man
Formal and informal factors - The blending of formal and informal risk-man tools and activities (standard risk-man generally focussed only on formal)
ERM characteristics - Holistic (3)
- ERM should be applied across an org to embrace all types of risk in every part of an org, recognising interconnectedness
- Avoids issues of standard risk-man which ignores gaps, overlaps and correlations between categories due to silo approach
- Can be implemented with creation of an integrated risk function under the control of a chief risk officer (CRO)
ERM characteristics - Value added (2)
- Risk-man, if applied correctly according to ERM, should create and protect value for an org through effective strategic level risk-man
- This fights against perhaps instinctive view of risk-man as an activity to prevent downside risks, which is therefore inconsistent with (or counter to) strategy and objectives
ERM characteristics - Formal and informal - formal factors relate to…
the tangible systems, processes, procedures, policies, committees and forums that exist within organisations, as well as organisation structures, hierarchies
ERM characteristics - Formal and informal - informal factors relate to…
things like organisational culture, social networks and how risk and risk-management are perceived
ERM characteristics - Formal and informal factors
- Recognises equal importance of formal and informal factors in influencing exposure to risk (standard risk-man generally focusses on only formal)
- Formal factors are the tangible systems, processes, procedures, etc. that exist
- Informal factors are things like organisational culture, social networks, perception of risk and risk-man
5 org wide benefits of ERM
- Improved reporting to support strategic decision-making (through holistic understanding)
- Avoidance of silos (to recognise gaps and overlaps in risk profile)
- Improved operational efficiency and cost effectiveness (through better coordination and less duplication)
- Improved profitability and equity value (through improved efficiency and cost effectiveness, and reduction in risk events)
- Improved ability to achieve other business objectives (as more time to focus on them)