Simple Tools and Techniques for Enterprise Risk Management
eBook - ePub

Simple Tools and Techniques for Enterprise Risk Management

Robert J. Chapman

Share book
  1. English
  2. ePUB (mobile friendly)
  3. Available on iOS & Android
eBook - ePub

Simple Tools and Techniques for Enterprise Risk Management

Robert J. Chapman

Book details
Book preview
Table of contents
Citations

About This Book

Your business reputation can take years to build—and mere minutes to destroy

The range of business threats is evolving rapidly but your organization can thrive and gain a competitive advantage with your business vision for enterprise risk management. Trends affecting markets—events in the global financial markets, changing technologies, environmental priorities, dependency on intellectual property—all underline how important it is to keep up to speed on the latest financial risk management practices and procedures.

This popular book on enterprise risk management has been expanded and updated to include new themes and current trends for today's risk practitioner. It features up-to-date materials on new threats, lessons from the recent financial crisis, and how businesses need to protect themselves in terms of business interruption, security, project and reputational risk management.

Project risk management is now a mature discipline with an international standard for its implementation. This book reinforces that project risk management needs to be systematic, but also that it must be embedded to become part of an organization's DNA. This book promotes techniques that will help you implement a methodical and broad approach to risk management.

  • The author is a well-known expert and boasts a wealth of experience in project and enterprise risk management
  • Easy-to-navigate structure breaks down the risk management process into stages to aid implementation
  • Examines the external influences that bring sources of business risk that are beyond your control
  • Provides a handy chapter with tips for commissioning consultants for business risk management services

It is a business imperative to have a clear vision for risk management. Simple Tools and Techniques for Enterprise Risk Management, Second Edition shows you the way.

Frequently asked questions

How do I cancel my subscription?
Simply head over to the account section in settings and click on “Cancel Subscription” - it’s as simple as that. After you cancel, your membership will stay active for the remainder of the time you’ve paid for. Learn more here.
Can/how do I download books?
At the moment all of our mobile-responsive ePub books are available to download via the app. Most of our PDFs are also available to download and we're working on making the final remaining ones downloadable now. Learn more here.
What is the difference between the pricing plans?
Both plans give you full access to the library and all of Perlego’s features. The only differences are the price and subscription period: With the annual plan you’ll save around 30% compared to 12 months on the monthly plan.
What is Perlego?
We are an online textbook subscription service, where you can get access to an entire online library for less than the price of a single book per month. With over 1 million books across 1000+ topics, we’ve got you covered! Learn more here.
Do you support text-to-speech?
Look out for the read-aloud symbol on your next book to see if you can listen to it. The read-aloud tool reads text aloud for you, highlighting the text as it is being read. You can pause it, speed it up and slow it down. Learn more here.
Is Simple Tools and Techniques for Enterprise Risk Management an online PDF/ePUB?
Yes, you can access Simple Tools and Techniques for Enterprise Risk Management by Robert J. Chapman in PDF and/or ePUB format, as well as other popular books in Betriebswirtschaft & Finanzwesen. We have over one million books available in our catalogue for you to explore.

Information

Publisher
Wiley
Year
2011
ISBN
9781119990642
Edition
2
Subtopic
Finanzwesen
Part I
Enterprise Risk Management in Context
1
Introduction
A pessimist sees the difficulty in every opportunity; an optimist sees the opportunity in every difficulty.
(Winston Churchill)
Risk management has taken centre stage. It is now the most compelling business issue of our time. Shareholders have repeatedly suffered from erratic business performance. Recent history has shown that risk exposure has not been fully understood and risk management practice has been inadequate. Looking back, while economists have cited many reasons for the Asian financial crisis of 1997–1998, clearly foreign exchange risk was a major contributor. After the New York World Trade Center and Pentagon terrorist attack on 11 September 2001, enterprise risk management was found to be wanting. Business continuity planning had been inadequate. In particular, it was found that greater emphasis needed to be placed on IT disaster recovery, human resource management and communication. After the bankruptcies of Enron in December 2001 and WorldCom in July 2002, inadequate corporate governance and the “soft underbelly” of risk management were exposed, arising primarily from the lack of integrity of financial reporting, a lack of compliance with regulations and operational failures. In late August 2005 Hurricane Katrina struck, reportedly the costliest natural disaster in US history. Oil production, importation and refining were interrupted.1 Businesses were suddenly exposed to a surge in energy prices, continuity failures and shipping disruption. Costs of production rose and sales fell. More recently, failure to properly understand and manage risk has been cited as the root cause for the global financial crisis of 2007–2010. So severe was this financial tsunami that many economists have described it as the worst financial disaster since the Great Depression of the 1930s. Boards in the financial sector were accused of being greedy, reckless2 and dysfunctional and in some cases “sheep”, falling into the trap of “group think” due to an apparent absence of independent thinking. In addition, there had been a lack of appreciation of risk at both a business and a macro or industry level. Systemic risk in the financial industry had not been recognised, understood or addressed. Regulators on both sides of the Atlantic and the banks themselves failed to recognise the interconnectedness of banks and the potential domino effect of bank failure. If the financial crisis was not excitement enough, the media have had a field day with a number of high-profile and very damaging business ethics failures relating to bribery, insider trading, invasion of privacy and sexual harassment.
1.1 RISK DIVERSITY
Providing strategic direction for a business means understanding what drives the creation of value and what destroys it. This in turn means that the pursuit of opportunities must entail comprehension of the risks to take and the risks to avoid. Hence, to grow any business entails risk judgement and risk acceptance. A business's ability to prosper in the face of risk, at the same time as responding to unplanned events, good or bad, is a prime indicator of its ability to compete. However, risk exposure continues to grow greater, more complex, diverse and dynamic. This has arisen in no small part from rapid changes in the globalisation of business, speed of communication, the rate of change within markets and technology. Businesses now operate in an entirely different environment compared with just three years ago. Recent experience has shown that as businesses strive for growth, internal risks generated by a business itself can be as large as (or greater than) external risks. The adoption of expansion strategies, such as investment in emerging markets, developing significant new products, acquisition, major organisational restructuring, outsourcing key processes and major capital investment projects can all increase a business's risk exposure.3
A review of risk management practices in 14 large global corporations revealed that by the end of the 1990s the range of risks that companies felt they needed to manage had vastly expanded, and was continuing to grow in number (Hunt 2001). There are widespread concerns over e-commerce, which has become accepted and embedded in society with startling speed. According to the Economist Intelligence Unit (2001):
Many companies perceive a rise in the number and severity of the risks they face. Some industries confront unfamiliar risks stemming from deregulation. Others worry about increasing dependence on business-to-business information systems and just-in-time supply/inventory systems. And everyone is concerned about emerging risks of e-business – from online security to customer privacy.
As a consequence of the diversity of risk, risk management requires a broader approach. This sentiment was echoed by Rod Eddington, former chief executive officer (CEO) of British Airways, who remarked that businesses now require a broader perspective of risk management. He went to say that:
If you talked to people in the airline industry in the recent past, they very quickly got on to operational risk. Of course, today we think of risk as the whole of business. We think about risk across the full spectrum of the things we do, not just operational things. We think of risk in the context of business risks, whether they are risks around the systems we use, whether they are risks around fuel hedging, whether they're risks around customer service values. If you ask any senior airline person today about risk, I would hope they would move to risk in the true, broader sense of the term. (McCarthy and Flynn 2004)
All stakeholders and regulators are pressing boards of directors to manage risk more comprehensively, rigorously and systematically. Companies that treat risk management as just a compliance issue expose themselves to nursing a damaged balance sheet.
1.2 APPROACH TO RISK MANAGEMENT
This evolving nature of risk and expectations about its management have now put pressure on previous working practices. Historically, within both private and public organisations, risk management has traditionally been segmented and carried out in “silos”. This has arisen for a number of reasons such as the way our mind works in problem solving, the structure of business organisations and the evolution of risk management practice. There is clearly the tendency to want to compartmentalise risks into distinct, mutually exclusive categories, and this would appear to be a result of the way we subdivide problems to manage them, the need to allocate tasks within an existing organisational structure and the underlying assumption that the consequences of an unforeseen event will more or less be confined to one given area. In actuality, the fallout from unforeseen events tends to affect multiple business areas and the interrelationships between risks under the categories of operational, financial and technical risk have been overlooked, often with adverse outcomes. Patricia Dunn, former CEO of Barclays Global Investors and former non-executive chairwoman of the board of Hewlett-Packard (HP),4 has previously identified a failing in approach:
I think what Boards tend to miss and what management tends to overlook is the need to address risk holistically. They overlook the areas that connect the dots because risk is defined so “atomistically” and we don't have the perspective and the instrument panel that allows us to see risk in a 360 degree way. (McCarthy and Flynn 2004)
Enterprise risk management (ERM) is a response to the sense of inadequacy in using a silo-based approach to manage increasingly interdependent risks. The discipline of ERM, sometimes referred to as strategic business risk management, is seen as a more robust method of managing risk and opportunity and an answer to these business pressures. ERM is designed to improve business performance. While not in its infancy, it is a slowly maturing approach, where risks are managed in a coordinated and integrated way across an entire business. The approach is less to do with any bold breakthrough in thinking, and more to do with the maturing, continuing growth and evolution of the profession of risk management and its application in a structured and disciplined way (McCarthy and Flynn 2004). ERM is about understanding the interdependencies between the risks, how the materialisation of a risk in one business area may increase the impact of risks in another business area. In consequence, it is also about how risk mitigation action can address multiple risks spanning multiple business sectors. It is the illustration of this integrated approach which is the focus of this book.
1.3 BUSINESS GROWTH THROUGH RISK TAKING
Risk is inescapable in business activity. As Peter Drucker explained as far back as the 1970s, economic activity by definition commits present resources to an uncertain future. The one thing that is certain about the future is its uncertainty, its risks. Hence, to take risks is the essence of economic activity. He considers that history has shown that businesses yield greater economic performance only through greater uncertainty – or in other words, through greater risk taking (Drucker 1979).
Nearly all operational tasks and processes are now viewed through the prism of risk (Hunt 2001). Indeed, the term “risk” has become shorthand for any corporate activity. It is thought not possible to “create a business that doesn't take risks” (Boulton et al. 2000). The end result of successful strategic direction setting must be capacity to take a greater risk, for this is the only way to improve entrepreneurial performance. However, to extend this capacity, businesses must understand the risks that they take. While in many instances it is futile to try to eliminate risk, and commonly only possible to reduce it, it is essential that the risks taken are the right risks. Businesses must be able to choose rationally among risk-taking courses of action, rather than plunge into uncertainty, on the basis of a hunch, gut feeling, hearsay or experience, no matter how carefully quantified. Quite apart from the arguments for risk management being a good thing in its own right, it is becoming increasingly rare to find an organisation of any size whose stakeholders are not demanding that its management exhibit risk management awareness. This is now a firmly held view supported by the findings of the Economist Intelligence Unit's enterprise risk management survey, referred to earlier. It discovered that 84% of the executives who responded considered that ERM could improve their...

Table of contents