RM in Organisations Flashcards
What are two principal purposes of risk management in organisations?
- Reducing uncertainty: RM as information-gathering tool for more effective risk control.
- Anticipation/resilience: Supports prediction and more efficient response to risk:
- Identifying many (but not all) germane organisational risks.
- Assessment/monitoring prioritises scarce control resources against risks.
What is a black swan event?
- Risk events that are high improbable or extremely difficult to predict and quantify statistically.
- ‘Unknown unknowns’ - unacknowledged, unknown events.
- Typically, extremely negative events, with far-reaching impacts.
What are the four RM cycle steps that help support internal control?
- Risk:
- Identification;
- Assessment;
- Monitoring; and
- Control. - RM is supported by compliance reviews:
- Risk-based compliance reviews;
- Internal audits; and
- External audits.
What does a risk-based compliance review typically entail?
Review of employee, management and organisational compliance with laws and regulations:
- Often risk-based - effective RM key;
- Usually involve detailed and frequent reviews where impacts of non-compliance are high; and
- Risk assessment and monitoring suggest a higher non-compliance risk.
What is the function of internal and external audit?
- Internal audit:
- Verification of effective design and implementation of internal policies;
- Review of efficiency of operational processes;
- Compliance review usage re. applicable laws and regulations; and
- Outcome = potential reduction in control failure numbers - failures identified sooner during review, reducing possibility of risk event arising. - External audit:
- Annual review of adequacy of organisational reporting controls;
- Assurance that AR&A are accurate and free of material financial misstatements; and
- Broader controls review indicates whether organisation may continue as a going concern.
=> Effective compliance review and internal audit promotes generally promotes more streamlined external audit completion.
What is the board’s role in RM?
- Formal approval of risk appetite statement (aggregate risk that may be taken).
- Defining strategy that is reflective of organisational values, behaviours and culture.
- Challenging management on risk appetite assunmptions.
- Seeking comprehensive management assurance on non-financial risk monitoring.
- Retention of independent advisors for risk evaluation.
- Provision of strategic advisory guidance to management.
What is value through risk?
- Contemporary tenet of RM that complements reduction of likelihood and impact of negative outcomes.
- Value through risk relates to increasing the probability and impact of positive risk outcomes, using risk-taking as a means of generating additional organisational value.
- Strategic risk refers to organisational appetite to make strategic commercial decisions that may increase total rewards (e.g. Facebook acquisition of Instragram at early stage; entry of tobacco companies into e-cigarettes/vaping but cf. Yahoo declined takeover of Google; Kodak reticient to enter digital photography).
What is adverse risk?
Excessive risk-taking that may cause an organisation to assume greater and less justifiable risks that may jeopardise organisational value.
What are the four key steps in the RM process?
- Risk identification.
- Exposure asssessment.
- Exposure monitoring.
- Exposure control.
Performed sequentially but RM may commence at any of the defined steps.
What does the risk identification stage comprise?
- Identification of negative and positive risks that an organisation is exposed to.
- Variety of tools may be used, including checklists, root cause analyses and the Delphi technique.
What does the risk assessment stage entail?
- In summary: risk probability x risk impact = exposure.
- However, assessment outcomes may not be singular - a range of outcomes is conceivable.
What does the risk monitoring stage involve?
- Provision of a comprehensive overview of the organisation’s prevailing risk profile in relation to its objectives.
- Monitoring therefore refers to activities that:
- Monitor and report upon potential changes to risk exposures; and
- Monitor effectiveness of risk control and risk management activities in general.
What does the risk control stage comprise?
Application of tools and techniques to influence probability and impacts of a risk event, or to mitigate secondary business disruption and reputational effects that may follow an initial risk event.
What is enterprise risk management?
- Extension of traditional risk management process.
- COSO - ERM is a process, effected by entity, applied in strategy-setting and across the enterprise, to identify potential events affecting the organisation and to manage risk within risk appetite.
- Essential characteristics:
- Holistic focus upon all risks across organisation apprised (though this may be achieved with different tools).
- Value-added risk managemet (upside risks managed alongside downside risks); and
- Blending of formal and informal risk management techniques (RM processes, committees, hierarchies v. culture, RM perceptions, behaviours).
What are the key differences between traditional RM and ERM?
- Traditional RM:
- Reactive / incident-based and often bottom-up.
- Possible process divergence re. dissimilar risks.
- Focus on adverse events, with operational/financial impact, using probabilities and financial metrics.
- Limited cross-discipline collaboration. - ERM:
- Proactive, multi-disciplinary with external and internal risk identification.
- Common framework, processes and risk mitigation techniques.
- Cross-organisational analysis of risk impacts.
- Emphasis on synergistic impact of cross-organisational risks.
- Recognises risks may be negative/loss-causing or may result in something positive/revenue-generating not occurring.
- Comprises bottom-up and top-down approaches.