The types of risk facing an organisation
1 What is risk?
‘Risk is a condition in which there exists a quantifiable dispersion in the possible outcomes from any activity. It can be classified in a number of ways.’
The key word in this definition is ‘quantifiable’. Both the probabilities that a particular outcome occurs and its impact must be known. If the probabilities of different outcomes occurring are not known then we are working under conditions of uncertainty, not risk.
Note that the strict definition of risk allows for good outcomes as well as bad
Insurance companies mostly deal with risk. For example, they maintain detailed statistics of the following:
The chance of a 20 year-old driver having an accident;
The chance of a house burning down
The chance of a burglary
The chance that someone who is 70 dying within the next 10 years
Risk is often expressed in terms of a combination of the consequences of an event (including changes in circumstances) and the associated likelihood of occurrence.
If probabilities, or the chance of an event occurring are not known (uncertainty) then organisations and individuals are working much more in the dark.
2 Types of risk
Risk can be categorised using the following terms:
Pure risk: this is where there is the chance of loss but no chance of a gain. It is also known as ‘downside risk’. Often when risk is mentioned, this is the type of risk meant, but remember that, strictly, ‘risk’ is the spread of all results, good and bad. Examples of pure risk include: fire destroying a factory, an IT system being hacked, an employee being injured at work and fraudulent transactions by an employee.
Speculative risk: this is where there can be both good and bad outcomes. It might occasionally be called ‘two-way risk’. Examples include developing a new product, entering a new market, buying a more advanced machine and developing a new web-site. Each of these could go well or badly.
Upside risk: the possibility of making a gain.
3 Conformance and performance
Risks are an inevitable wen running a business or other organisation. If a business were unable to take any risks it would not buy inventory (in case it wouldn’t sell), it would not extend credit (in case of bad debts), and it would not employ anyone (in case they were no good). The same applies in not-for-profit organisations such as a hospital (where surgeons would not operate in case the patient dies) or schools (where sports would be banned in case a pupil were injured).
Favourable outcomes for the organisation and its stakeholders are not available unless risks are undertaken. The key is the balance between the risk and the organisation’s performance.

IFAC: seek to balance conformance and performance. Compliance is necessary to avoid excessive failure, but it does not produce success.
Higher risks are needed if you are to produce higher returns. Compliance with rules, regulations and controls does not of itself make an organisation successful. However, poor conformance with controls and risk management strategies can certainly lead to organisational failure.
The concept of LARP (as Low As Reasonably Practicable) is useful: for a given performance level, reduce the risk as far as reasonably possible. For example, the risk of bad debts is reduced to zero if credit facilities are not offered, but that might not be reasonable as it will presumably reduce sales. So, the reasonable position might be to offer credit to customers, but to vet them carefully first and set a credit limit. There will still be some bad debts, but the risk has been reduced to a level the company thinks as reasonable. The next chapter deals more fully with risk responses.
A simple matrix can be used to illustrate balancing risks and returns:

Examples could be:
Routine: extending moderate credit to a new customer. The maximum write-off of a debt would be small and the customer will provide some income.
Avoid: entering a joint venture with a company that has a poor reputation. Returns might be small compared with the risk of the company’s goodwill being tarnished.
Identify and develop: support of a well-known charity or sporting event to improve the company’s reputation. This could create a very large increase in competitive advantage and the risk would be low provided the third party were carefully chosen
Examine cautiously: opening operations in a new country. There are considerable risks that the expansion might fail, but is it is successful the rewards could be huge.
4 Categorisation of risks
There are many ways in which risks can be categorised. This isn’t important for its own sake but the categories can act as a checklist when trying to identify and anticipate risks.
One categorisation is strategic, operational, reporting and compliance risks:
Strategic risks: these arise from long term effects such as those relating to the nature and type of business, changes in competitive and legal environments, poor long-term decisions being made. For example, a supermarket which did not respond to the growing popularity of on-line shopping would have opened itself to a long-term decline in profits.
Operational risks: short-term, day-to-day problems. For example, a machine breaking down, a key employee leaving, a fire breaking out in the warehouse or a fraud occurring.
Reporting risks: risks arising because internal and external reporting are not reliable. For example, management accounts containing errors can lead to incorrect analysis and decisions.
Compliance risks: the risks arising form not complying with rules and regulations. Penalties, loss or reputation and removal of operating licenses can all result.
Some major risks are set out below, just to give you an idea of the wide variety of risks that organisations might have to deal with. Each type of risk has one example given:
Environmental: the release of dangerous chemicals into the local river.
Economic: interest rates being increased so that consumer demand is suppressed.
Competitor: a competitor launches a fantastic product.
Product: you launch a poor product
Commodity: the supply and price of raw materials change adversely.
Political, cultural and legal: your product, for example cigarettes, becoming illegal or unpopular
Financial (currency, interest rate, market risk, reporting): you are exporting and the buyer’s currency weakens before you are paid.
Investment: a subsidiary is bought but it turns out that it isn’t as good as you thought it would be.
IT: hacking and release of customer details
Knowledge management: techniques and know-how aren’t captured and recorded so that when employees move-on they leave little behind.
Property: Fire, flood
Health and safety risks: injury to employees and fines by regulators.
Trading risks: irrecoverable debts.
Resource risks: increasing difficulty recruiting the right people
Organisational risks: the organisation is too moribund and too slow to respond to developments in the market.
Inadequate system risks: management information inaccurate and out-of-date.
Fraud risks: theft of cash or inventory.
Probity risks (unethical behaviour): an employee acts unethically and the company’s reputation is damaged.
Reputational risks: products get a name for being unreliable so the company’s reputation is damaged.
5 How much risk should an organisation take on?
‘Risk appetite’ is the term given to describe the amount of risk an organisation is willing to accept in pursuit of value.
Risk appetite is determined by two factors:
Stakeholder’s attitude to risk
Risk capacity, which is the amount of risk that the organisation can bear.
Taking a personal example:
Some people are risk seekers and like to gamble; others are risk averse. So, if betting on a horse race, the risk seekers might be attracted to gamble on the high odds 100 to 1 horse. The risk averse person would tend not to consider that sort of gamble. They have different attitudes to risk.
However, let’s say both people have $100,000 in the bank and were being asked to bet $100. Even the risk averse person might be tempted to go for 100 to 1 odds. In this situation they have high risk capacity because losing $100 is of little consequence. But what if each person had only $100 in the bank? There’s a fair chance that neither would bet $100 because the consequences of losing are so serious: they have very low risk capacity.
So, overall their appetite for risk (ie their appetite for the gamble) depends on their own attitudes plus the risk capacity.
6 Potential advantages of risk management
More predictable cash flows
Well-run systems (eg greater efficiency because routine maintenance is used to prevent the risk of machine breakdown).
Limitation of the impact of disaster (eg, stand-by arrangements are in place to take over IT)
Greater confidence amongst investors, employees, customers, suppliers and partners.
Better matching to risk appetite of shareholders.
Remember organisations should obtain an acceptable balance between risk and return.


