Module 9 - Thinking Through a Risk Management Lens Flashcards
Define “enterprise risk management.”
“Enterprise risk management” is defined as the culture, capabilities and practices, integrated with strategy setting and its execution, that entities rely on to manage risk in creating, preserving and realizing value for stakeholders. A more in-depth look at the definition of enterprise risk management emphasizes its focus on managing risk through:
(a) Recognizing culture and capabilities
(b) Applying practices
(c) Integrating with strategy setting and its execution
(d) Managing risk to strategy and business objectives
(e) Linking to creating, preserving and realizing value.
Define “culture,” “capabilities” and “practices” in the context of enterprise risk management.
Culture is developed and shaped by the people at all levels of an entity by what they say and do. It is people who establish the entity’s mission, strategy and business objectives and put enterprise risk management practices in place. Risk “culture” is defined as the attitudes, behaviours and understanding about risk, both positive and negative, that influence decisions and reflect the mission, vision and core values of the entity.
Enterprise risk management “capability” provides a core capability to an entity in its pursuit of competitive advantages to create value. Enterprise risk management helps the entity develop the skills needed to execute the entity’s mission and vision and to anticipate the challenges that may impede success. It enhances capacity to adapt to change and increases resilience and ability to evolve in the face of marketplace and resource constraints.
Risk “practices” are the methods and approaches deployed within an entity related to managing risk. Practices used in enterprise risk management are applied from the highest levels of an entity and flow down through divisions, business units and functions—applied to the entire scope of activities as well as to special projects and new initiatives. It is part of decision making at all levels of the entity. Practices are intended to help people within the entity better understand its strategy, what business objectives have been set, what risks exist, what the acceptable amount of risk is, how risk impacts performance and how to manage risk. In turn, this understanding supports decision making at all levels and helps to reduce entity bias.
Outline the premises that underpin the benefits of taking an enterprisewide approach to risk management.
An enterprisewide approach to risk management is based on the premise that every entity—whether for-profit, not-for-profit or government—exists to provide “value” for its stakeholders. A related premise is that all entities face uncertainty, generally understood to be something not completely known or the condition of not being sure of something, in the pursuit of value. Effective enterprise risk management allows decision makers to balance exposure against opportunity, with the goal of enhancing the entity’s capabilities to create, preserve and ultimately realize value for stakeholders.
Define “stakeholders,” and differentiate between internal and external stakeholders. Provide examples of stakeholders in group benefit plans or employer-sponsored pension plans who stand to benefit from effective risk management practices
“Stakeholders” are parties that have genuine or vested interest in an entity. Internal stakeholders are parties working within the entity such as employees, management and the board. External stakeholders are any parties not directly engaged in the entity’s operations but who are impacted by it, directly influenced by its environment, or influence its reputation, brand and trust. Key stakeholders in a group benefits plan or an employer-sponsored pension plan can include the employer (plan sponsor), employees (plan members), beneficiaries of the plan members, plan service providers and any relevant regulatory bodies such as the Canada Revenue Agency (CRA) or the pension regulator for the province or territory in which the plan sponsor operates.
Explain how the value of an entity is influenced by management decisions.
Management decisions, from overall strategy decisions to day-to-day decisions, can determine whether value is created, preserved, realized or eroded.
(a) Value is created when the value of deployed resources (such as people, financial capital, technology and processes) is less than the benefits derived from that deployment.
(b) Value is preserved when the value of resources deployed in day-to-day operations sustains created benefits. For example, value is preserved with the delivery of superior products and services, which results in satisfied customers and stakeholders.
(c) Value is realized when stakeholders derive benefits created by the entity. Benefits may be monetary or nonmonetary.
(d) Value is eroded when management implements strategies that do not yield expected outcomes or fails to execute day-to-day tasks.
Explain how enterprise risk management interfaces with strategy.
“Strategy” refers to an entity’s plan to achieve its mission and vision and to apply its core values. A well-defined strategy provides a road map for establishing business objectives and drives the efficient allocation of resources and effective decision making.
Enterprise risk management does not create the entity’s strategy, but it influences its development. It informs the entity on risks associated with alternative strategies considered and, ultimately, with the adopted strategy. It evaluates potential risks that may arise from strategy, including how the chosen strategy could affect the entity’s risk profile (specifically the types and amount of risk the entity is potentially exposed to). It also evaluates the critical assumptions underlying the chosen strategy by looking at how sensitive strategy alternatives are to changes in the assumptions (i.e., whether they would have minimal or significant effect on achieving the strategy).
Explain how enterprise risk management can influence an entity’s ability to adapt, survive and prosper.
Every entity sets out to achieve its strategy and business objectives in an environment of change. Market globalization, technological breakthroughs, mergers and acquisitions, fluctuating capital markets, competition, political instability, workforce capabilities, and regulation, among other things, make it difficult to know all possible risks to a business strategy and business objectives. Risk is always present and always changing. While it may not be possible for entities to manage all potential outcomes of risk, they can improve how they adapt to changing circumstances. This is sometimes referred to as “organizational sustainability.” Enterprise risk management focuses on managing risks to reduce the likelihood that an event will occur, managing the impact when one does occur and adapting as circumstances dictate.
Outline benefits of integrating enterprise risk management with strategy setting and performance management processes.
The benefits of integrating enterprise risk management with an entity’s strategy setting and performance management processes vary by entity. However, implementing enterprise risk management may increase the entity’s ability to:
(a) Expand the range of opportunities for creating value
(b) Identify and manage entitywide risks
(c) Reduce surprises and losses
(d) Reduce performance variability
(e) Improve resource deployment
Explain how events, uncertainty and severity impact risk.
In the context of enterprise risk management, an “event” is an occurrence or set of occurrences. “Uncertainty” is the state of not knowing how potential events may or may not manifest. “Severity” is a measurement of considerations such as the likelihood and impacts of events or the time it takes to recover from events. Some risks have minimal impact on an entity, and others have a larger impact.
In the context of risk, events are more than routine transactions; they are broader factors that affect the entity such as changes in the governance and operating model, geopolitical and social influences, and contracting negotiations. Some events are readily discernable—a change in interest rates, a competitor launching a new product that affects financial viability, or a cyberattack. Other events are less evident, particularly when multiple small events combine to create a trend or condition. For instance, it may be difficult to identify specific events related to global warming, yet that condition is generally accepted as occurring. In some cases, entities may not even know or be able to identify what events may occur. The risk of an event occurring (or not) creates uncertainty.
Explain why an event with a positive outcome can also pose a risk.
Commonly, the focus is on those risks that may result in a negative outcome, such as damage from a fire, losing a key customer, or a new competitor emerging. However, events can also have positive outcomes, and these must also be considered. Events that are beneficial to the achievement of one objective may at the same time pose a challenge to the achievement of other objectives. For example, if a company’s product launch has higher-than-forecast demand, it introduces a risk to supply chain management, which may result in unsatisfied customers if the product cannot be supplied.
Outline the benefits of integrating enterprise risk management with strategy setting and strategy execution processes.
When enterprise risk management, strategy setting and strategy execution processes are integrated, an entity is better positioned to understand:
(a) How mission, vision and core values form the initial expression of acceptable types and amount of risk when setting strategy
(b) Possibility of strategies and business objectives not aligning with the mission, vision and core values
(c) Types and amount of risk the entity potentially exposes itself to from the strategy that has been chosen
(d) Types and amount of risk to executing its strategy and achieving business objectives.
Define “mission,” “vision” and “core values,” and explain how they relate to an entity’s purpose.
“Mission” is the entity’s core purpose, which establishes what it wants to accomplish and why it exists. “Vision” is the entity’s aspirations for its future state or what the entity aims to achieve over time. “Core values” are the entity’s beliefs and ideals about what is good or bad, acceptable or unacceptable, which influence the behaviour of the entity and how it wants to conduct business. Together, these elements communicate to stakeholders the entity’s purpose. For most entities, mission, vision and core values remain stable over time, and during strategy planning they are typically reaffirmed. Yet the mission, vision and core values may evolve as the expectations of stakeholders change.
Explain the significance of alignment among strategy, mission, vison and values to enterprise risk management.
Mission and vision help to establish boundaries for strategy and bring focus to understanding how decisions may affect strategy. Mission, vision and core value statements guide in determining the types and amount of risk an entity is likely to encounter and accept. If an entity’s strategy is not aligned with its mission, vision and core values, its ability to realize mission and vision may be significantly reduced. This can happen even if the (mis)aligned strategy is successfully executed.
Describe the focus of enterprise risk management in the context of strategy execution. Provide an example.
The focus of risk management in the context of strategy execution is on understanding the strategy as it is set out and what risks there are to its relevance and viability. There is always risk to executing strategy; a variety of techniques can be used to assess it.
For example, assume a health care provider sets a business objective of providing high-quality patient care. To assess risks associated with its execution, the provider considers risks relating to factors such as employee capability, medical care and treatment options, health care legislation requirements and health record management requirements. If these execution risks become significant enough, the health care provider may revisit its strategy and objectives and consider revisions or select other alternatives that have a more suitable risk profile.
Explain the roles of the governance and operating models in enterprise risk management.
An entity’s governance model defines and establishes authority, responsibility and accountability. It aligns the roles and responsibilities to the operating model at all levels—from the board of directors to management, divisions, operating units and functions.
An entity’s operating model describes how management organizes and executes its day-to-day operations. It is typically aligned with the legal structure and management structure. Through the operating model, employees are responsible for developing and implementing practices to manage risk and stay aligned with the core values of the entity.
Both models influence the ability to identify, assess and respond to risks to the achievement of strategy.