Enterprise Risk Management
Risk
Enterprise Risk Management
Syllabus tag: KASNEB CPA | Advanced Level | CA31 Leadership and Management | Topic 9 Enterprise Risk Management
Lesson objectives
By the end of this topic, you will be able to:
- Distinguish the main categories of business risk
- Explain risk appetite and risk tolerance
- Apply the likelihood-impact matrix and the four responses
- Describe the ERM frameworks and the three lines model
- Explain why risk management fails
Why this matters
Risk management is often treated as a register that is updated quarterly and read by nobody. This topic addresses what makes it actually influence decisions.
Categories of risk
| Category | Nature |
|---|---|
| Strategic | Wrong direction, competitor action, market shift |
| Operational | Process failure, systems, people, supply chain |
| Financial | Credit, liquidity, market, currency, interest rate |
| Compliance | Breach of law or regulation |
| Reputational | Loss of confidence among stakeholders |
| Political and country | Instability, expropriation, policy change |
Reputational risk is usually a consequence rather than a cause. It arises from a failure in one of the other categories becoming public, which is why it cannot be managed in isolation — the underlying risk must be addressed.
Appetite and tolerance
Risk appetite is the amount of risk an organisation is willing to accept in pursuit of its objectives.
Risk tolerance is the acceptable variation around a specific objective.
Risk capacity is the maximum it could bear before failing.
Appetite must be set by the board and communicated, or managers apply their own, which vary and conflict. The frequent failure is an appetite statement written in general terms — "we take a prudent approach to risk" — that gives a manager facing an actual decision no guidance whatever.
Appetite also differs by category. An organisation may accept substantial strategic risk while having almost no appetite for compliance or safety risk, and saying so is more useful than a single overall statement.
Assessment and response
Risks are assessed on likelihood and impact, and the combination determines the response:
| Low impact | High impact | |
|---|---|---|
| High likelihood | Reduce | Avoid |
| Low likelihood | Accept | Transfer |
The four responses, sometimes given as the 4 Ts:
- Terminate (avoid) — stop the activity
- Treat (reduce) — controls that lower likelihood or impact
- Transfer — insurance, hedging, outsourcing, contractual terms
- Tolerate (accept) — where the cost of action exceeds the benefit
Two points examiners look for.
Transfer does not remove the risk. Insurance converts an uncertain large loss into a certain premium, and leaves the operational disruption and the reputational consequence with the company. Outsourcing transfers the activity and not the accountability.
Accepting a risk is a legitimate decision, provided it is conscious, documented and within appetite. The failure is accepting risk by default, because nobody assessed it.
Gross and net risk should be distinguished: the exposure before controls and after them. Reporting only net risk hides how much the organisation depends on a control continuing to work.
:::checkpoint A company insures a warehouse against fire and records the risk as "transferred". Identify what has and has not been transferred, and state what should still appear in the risk register. :::
Frameworks
COSO ERM presents risk management as integrated with strategy and performance, across governance and culture, strategy and objective-setting, performance, review and revision, and information and communication.
ISO 31000 offers principles and a process — establish the context, identify, analyse, evaluate, treat, monitor, communicate — applicable to any organisation.
The three lines model allocates responsibility:
| Line | Role |
|---|---|
| First | Operational management: owns and manages risk |
| Second | Risk and compliance functions: oversight, framework, challenge |
| Third | Internal audit: independent assurance |
The model's central claim is that risk is owned by the business, not by the risk function. Where operational managers believe risk is somebody else's department, the first line has failed and the other two cannot compensate.
Internal audit's independence requires that it does not manage or design the controls it assures, which is why it reports to the audit committee.
Why risk management fails
- A register that is not used. Updated for the auditors, absent from decisions
- Appetite never articulated, so managers apply inconsistent judgements
- Focus on the measurable. Operational and financial risks are quantified while strategic risks — the ones that destroy companies — are described vaguely
- Silo assessment, missing risks that correlate or compound
- Culture. Where bad news is unwelcome, risks are not reported upward
- Assumed controls. A control recorded as operating that has quietly lapsed
The most serious is culture. Every framework depends on people reporting problems early, and no framework survives an organisation in which doing so is career-limiting.
:::checkpoint A company's risk register lists forty operational risks with detailed scores and one strategic risk described as "changes in the market". Explain what this pattern suggests and why it is dangerous. :::