Skip to content

Responses to risk

VIVA Subject Guide
YouTube video

1 A framework for risk management

A framework for risk management

The framework is logical and easy to understand.

  • Establish a risk management group and set goals

Ultimately risk management is the responsibility of the board (or, more broadly, those charged with governance). However, like many functions in organisations the board is likely to delegate responsibility to a sub-group of suitable specialists. The board should set goals which reflect the risk appetite of the organisation. For example, if the organisation is an airline, the board would set goals of Zero accidents but it might be prepared to tolerate a degree of risk of bad publicity from over-booking flights.

  • Identify risk areas

It is important not to be complacent about risks. Some will be obvious and well-known but others might be undiscovered until something goes wrong. We will see later in this Chapter methods that might help to discover potential risks.

  • Understand and assess the scale of the risk

Not all risks are equal. Some risks that are discovered might be judged a being of little consequence; others could be of major significance. Techniques will be covered later.

  • Develop a risk response strategy

Having identified and assessed the risks decisions have to be made about what to do about them. The TARA approach will be explained later.

  • Implement strategy and allocate responsibilities

Simply identifying risks and working out suitable responses will not reduce risk: proper actions have to be specified must to be consistently carried out. For example, ensuring that the safety of machines is monitored or that customer credit limits are regularly reviewed. Individuals have to be put in charge of risk management strategies and procedures and must be held accountable for failures.

That sentence is the point most often missed when a question asks how risks should be mitigated. Choosing a heading from the TARA table below is not a mitigation: the answer has to say which specific action is to be taken, by whom, and how often. Two related habits also cost marks — describing the risk at length when the requirement asked only how to mitigate it, and stating a circumstance without saying what could actually go wrong as a result. Say what the consequence for the organisation would be, then give the practical action that reduces it.

  • Implement and monitor controls

Controls must then be implemented. For example, setting out dates by which risks have to be addressed, ensuring that inspections are done at regular intervals or by sending staff on training courses. It is very important to document risk reduction strategies and how those strategies are realised.

  • Review and refine the process and repeat

Of course, the solutions implemented to deal with identified risks are unlikely to work perfectly the first time. They will often need to be improved. But it is also very important to realise that nothing stands still: risks will be evolving all the time and the organisation must keep them under constant review to ensure that all are properly addressed.

2 Identifying risk areas

The trick is to use every method at your disposal to identify risks. Throw the net as widely as you can at this stage. Later, risks might be dismissed as being of little importance, but it is important that as many as possible potential risks are initially considered.

Methods include:

  • Physical inspection and observation (for example, that safety equipment is still used on machinery).

  • Inspect documents (for example, the accident log book).

  • Internal audit. Internal auditors are employees of the company (usually) who examine and report on the organisation systems of internal control. Not only do they report on financial controls but they can also be required to examine systems such as quality control accident reporting and so on.

  • Outside consultants brought in to audit procedures (for example, security consultants to advise on IT security).

  • Observation of competitors’ procedures (question why they carry out operations in a particular way).

  • Enquiries (for example, ask employees, customers and suppliers about problems).

  • Brainstorming (wide-ranging discussions to anticipate potential problems).

  • Checklists (for example, use a checklist to evaluate how a job went and consider action where there had been problems).

  • Benchmarking (falling short of targets can imply that things are going wrong).

  • External events (for example, be alert for economic events that could affect the organisation).

  • Internal events (for example, high staff turnover can indicate problems with employments conditions).

  • Leading event indicators (for example, if a customer takes longer and longer to pay each month then there would appear to be a risk of non-payment).

  • Escalation triggers (for example, if you are late filing a tax return twice, then the third default could be very serious).

  • Event interdependencies (for example, a major customer going into liquidation could cause excess inventory problems).

3 Understand and assess the scale of the risk

The scale of the risk depends on:

  1. The likelihood that the event will occur; and

  2. The impact of the event.

Of course, these will be estimates, particularly the probability of an event occurring. However, precise figures are not needed, just an idea of whether they are ‘high’ or ‘low’. Nevertheless you will see some mathematical techniques that can be used to quantify events.

A very standard tool to assess the scale of the risk is a risk map:

Understand and assess the scale of the risk

Note that there is nothing absolute about the categorisation of these risks. For example, the chance of flight disruption has been assessed as high, but that depends on the airports used. Similarly, the loss of a mobile has been categorised as being of low impact – but this wouldn’t be correct if that mobile was the only place where important contact data is held.

The severity of the risk can be estimated by methods such as:

  • Calculation of average/expected loss, largest predictable loss

  • Exposure of physical assets: total loss, repair, decrease in value

  • Exposure of financial assets

  • Exposure of human assets (injury, death, staff leaving)

Obviously, great attention should be given to risks in the bottom right hand quadrant (high/high) whereas those risks in the top left quadrant are less important.

4 Risk response

The risk responses can be remembered by the TARA approach:

Transfer

Methods of transferring risk include insurance, sub-contracting operations or joint ventures (partial transferring). Insurance is, for example, used to protect against risk in motoring accidents. Individuals do not have bad accidents often, but if they do the consequences can be very severe.

Avoid

The risk has been assessed as being so serious that all possibility of the event occurring should be avoided.

Reduce

Take steps to mitigate the risk. For example, instead of installing a new computer system in every branch over one weekend, run a pilot operation then gradually extend.

Accept

Don’t do anything about the risk. It’s just part of everyday business

(You might occasionally see these approaches referred to as the 4Ts: Transfer, terminate, treat, tolerate).

The four responses can be mapped onto the risk map diagram as follows:

Risk response

So, phones are lost (or stolen) from time to time and most people live with that risk (though insurance is always a possibility and might be taken out for very expensive phones).

The complete breakdown of an IT system could be dealt with by outsourcing the system so the supplier shoulders the risk.

Routine staff turnover has costs associated with it (recruitment and training) so better employment policies might be worthwhile to reduce the cost and disruption.

Flights to an airport with very bad weather or safety records might simply be abandoned because they cause more trouble than they are worth.

5 Assurance mapping

Risk identification and risk mapping identify the problems and their severity, but those processes are a waste of time if suitable responses are not made. Methods available are:

  • Assurance mapping: identifies where defences against risks exist.

  • Risk register: records risks and assigns responsibilities.

The aim of an assurance map is to identify where the safeguards against risks are to be found. Assurance maps identify that an organisation has various lines of defences against risk. Typically, these are:

Line of defence

Source

1st

Management-based assurance. For example, board policies and management review

2nd

Internal procedures and legal-based assurance. For example, health and safety legislation, risk registers, compliance with reporting requirements, procedures and quality control tests.

3rd

Internal audit

4th

Independent assurance. For example, external audit, actuaries, consulting engineers, legal opinions

Note that some organisations might identify slightly different lines of defence. A table is then drawn up listing the risks, their importance and how the lines of defence deal with those risks. For example:

Type of risk

1st line of defence

2nd line of defence

3rd line of defence

4th line of defence

Finance: sufficiency and gearing

IT

Human resources

etc

Here, blue depicts strong assurance, grey depicts middle assurance and white depicts no assurance.

Sometime an additional column is added to show the desired amount of defence against risks. Each row is then scrutinised to ensure that the appropriate defences are in place somewhere in the lines of defences to provide sufficient overall assurance that each risk has been sufficiently countered.

6 The risk register

Identified risks, their probability of occurrence, impact and responses to them should be entered into a risk register. Typical contents of a risk register are:

  • Description of the risk

  • Date identified

  • Its estimated likelihood of occurrence before mitigation

  • Its likely impact before mitigation

  • Pre-mitigation rating

  • The risk owner (who is responsible for dealing with the risk

  • Detailed response strategy to the risk (TARA)

  • Its estimated likelihood of occurrence after mitigation

  • Its likely impact before mitigation after mitigation

  • Post mitigation rating

  • Date by when response should be implemented

  • Date response implemented

  • Signed off by risk owner

The board and risk management committee should take an active interest in the risk register to ensure that identified risks have been satisfactorily dealt with.

7 Gross and net risks

It is important to know these terms:

Gross risk = the risk before any mitigation (reduction) procedures. Gross risk is sometimes referred to as inherent risk.

Net risk = the residual risk after reduction and mitigation.

The gross risk is initially dependent on:

  • The asset: what you are trying to protect. For example, property, cash, people, reputation and so on.

  • The threat: what you are trying to protect against. For example, destruction of property, theft of cash, injury to people, damage to reputation.

  • The vulnerability: weaknesses or gaps that can be exploited. For example, no fire alarms, cash not banked, no hand rails on stairs, poor PR.

The gross risk can be reduced to a lower net risk, or residual risk by reducing any of these variables through the application of counter-values or counter-measures.

Management must then decide whether the residual risk is within the organisation’s risk appetite.

image2.jpg

Examples:

Asset: the inventory in warehouse; threat: fire; vulnerability: full of inflammable material

Counter values could be:

Asset: reduce the amount of inventory

Threat: impose no-smoking rules (if not already present),

Vulnerability: install smoke detectors and a fire suppression system that is suitable for the type of inventory stored.

Asset: valuable sales manager; threat: moves to a competitor; vulnerability: enticing offers from competitors.

Counter values could be:

Asset: divide sales over two managers (each person is half as valuable).

Threat: impose contracts that require 3 – 6 months’ notice to make moving more difficult

Vulnerability: offer good pay, conditions and prospects.