Skip to content
SmartStudy

Enterprise Risk Management

Risk

Enterprise Risk Management

Syllabus tag: KASNEB CPA | Advanced Level | CA31 Leadership and Management | Topic 9 Enterprise Risk Management

Lesson objectives

By the end of this topic, you will be able to:

  • Distinguish the main categories of business risk
  • Explain risk appetite and risk tolerance
  • Apply the likelihood-impact matrix and the four responses
  • Describe the ERM frameworks and the three lines model
  • Explain why risk management fails

Why this matters

Risk management is often treated as a register that is updated quarterly and read by nobody. This topic addresses what makes it actually influence decisions.

Categories of risk

CategoryNature
StrategicWrong direction, competitor action, market shift
OperationalProcess failure, systems, people, supply chain
FinancialCredit, liquidity, market, currency, interest rate
ComplianceBreach of law or regulation
ReputationalLoss of confidence among stakeholders
Political and countryInstability, expropriation, policy change

Reputational risk is usually a consequence rather than a cause. It arises from a failure in one of the other categories becoming public, which is why it cannot be managed in isolation — the underlying risk must be addressed.

Appetite and tolerance

Risk appetite is the amount of risk an organisation is willing to accept in pursuit of its objectives.

Risk tolerance is the acceptable variation around a specific objective.

Risk capacity is the maximum it could bear before failing.

Appetite must be set by the board and communicated, or managers apply their own, which vary and conflict. The frequent failure is an appetite statement written in general terms — "we take a prudent approach to risk" — that gives a manager facing an actual decision no guidance whatever.

Appetite also differs by category. An organisation may accept substantial strategic risk while having almost no appetite for compliance or safety risk, and saying so is more useful than a single overall statement.

Assessment and response

Risks are assessed on likelihood and impact, and the combination determines the response:

Low impactHigh impact
High likelihoodReduceAvoid
Low likelihoodAcceptTransfer

The four responses, sometimes given as the 4 Ts:

  • Terminate (avoid) — stop the activity
  • Treat (reduce) — controls that lower likelihood or impact
  • Transfer — insurance, hedging, outsourcing, contractual terms
  • Tolerate (accept) — where the cost of action exceeds the benefit

Two points examiners look for.

Transfer does not remove the risk. Insurance converts an uncertain large loss into a certain premium, and leaves the operational disruption and the reputational consequence with the company. Outsourcing transfers the activity and not the accountability.

Accepting a risk is a legitimate decision, provided it is conscious, documented and within appetite. The failure is accepting risk by default, because nobody assessed it.

Gross and net risk should be distinguished: the exposure before controls and after them. Reporting only net risk hides how much the organisation depends on a control continuing to work.

:::checkpoint A company insures a warehouse against fire and records the risk as "transferred". Identify what has and has not been transferred, and state what should still appear in the risk register. :::

Frameworks

COSO ERM presents risk management as integrated with strategy and performance, across governance and culture, strategy and objective-setting, performance, review and revision, and information and communication.

ISO 31000 offers principles and a process — establish the context, identify, analyse, evaluate, treat, monitor, communicate — applicable to any organisation.

The three lines model allocates responsibility:

LineRole
FirstOperational management: owns and manages risk
SecondRisk and compliance functions: oversight, framework, challenge
ThirdInternal audit: independent assurance

The model's central claim is that risk is owned by the business, not by the risk function. Where operational managers believe risk is somebody else's department, the first line has failed and the other two cannot compensate.

Internal audit's independence requires that it does not manage or design the controls it assures, which is why it reports to the audit committee.

Why risk management fails

  • A register that is not used. Updated for the auditors, absent from decisions
  • Appetite never articulated, so managers apply inconsistent judgements
  • Focus on the measurable. Operational and financial risks are quantified while strategic risks — the ones that destroy companies — are described vaguely
  • Silo assessment, missing risks that correlate or compound
  • Culture. Where bad news is unwelcome, risks are not reported upward
  • Assumed controls. A control recorded as operating that has quietly lapsed

The most serious is culture. Every framework depends on people reporting problems early, and no framework survives an organisation in which doing so is career-limiting.

:::checkpoint A company's risk register lists forty operational risks with detailed scores and one strategic risk described as "changes in the market". Explain what this pattern suggests and why it is dangerous. :::

Next in Leadership and ManagementProject Management and Performance