Showing posts with label risk appetite. Show all posts
Showing posts with label risk appetite. Show all posts

Tuesday, August 28, 2012

Innovation is Creativity x Risk Taking

Innovation is impossible to achieve without taking a necessary amount of risk. In a world where the success rate of new product entries in the grocery business is 1 in 100, it is inevitable that every success sees failures along the way.

An effective innovation leader should encourage creativity and risk taking, while also practicing a tolerance for failure.

To foster initiative and innovation, ask yourself these questions.
  • Do you allow free research and development (R&D) time?
  • Do you invest in innovation: money, people, resources?
  • Do you celebrate failure and risk taking?
In a tough economy the willingness to take risks can wither, so it’s critical to let team members know that failure will not result in punitive measures.

A strong leader practices failure management by setting and agreeing on the risk taking bandwidth or budget. It is ok to fail but that failure should be seen and recognized as a learning experience.

Fear of failure is an innovation killer, so here are some simple steps to develop a failure management plan that will lead to a culture of sustainable innovation.
  1. Clearly communicate the risk profile you are asking your people to adopt and state why it is important to the organization’s success. This limits your potential loss, while opening up the floor for creativity and risk taking.
  2. Never allow an unsuccessful risk to hamper a team member’s opportunities and advancement. A culture of innovation depends on trust.
  3. Create and communicate the results of an award program created with a high intraorganizational profile. It should, ideally, reward risks that pay off and “gee, nice try’s” that don’t.
  4. Establish a formalized, non-accusatory process for harvesting key learnings from unsuccessful risks. Distribute these lessons learned. The key here is that all risks, whether successful or not, contribute towards the end goal.
  5. Give your people the situational risk assessment tools they need to help them improve their risk-taking decisions. This can include risk scoring systems to identify different levels of risk, and ways to deal with adverse situations as part of a preventive strategy.

Wednesday, July 4, 2012

New guide to Examining Business Risk published by the Institute of Directors (IoD)

A new guide to business risk, published by the Institute of Directors (IoD) in association with Airmic, Chartis, PwC and Willis, urges UK Board members to improve their understanding and management of risk in order to successfully deliver growth and prevent future crises.

“Business Risk – A practical guide for Board members” lays out in detail the roles and responsibilities of the board in assessing and managing business risk, the risk challenges currently facing UK businesses and the structural, personal and strategic solutions which can be used to address these challenges.

Comments about the guide:
Simon Walker, Director General of the Institute of Directors, said: “If companies and the economy as a whole are to grow in today’s environment, it is vital that directors put risk management at the heart of business strategy.

Understanding risk helps you to become more enterprising without jeopardising your business. On the other hand, take the wrong kind of risk and you are heading for disaster, whilst avoiding risk altogether means you are condemned to stagnation. This guide will help directors get this crucial balance right.”

Alpesh Shah, director in PwC’s Actuarial Risk Practice, said: “There are few aspects of a board’s functioning that are as crucial to long-term corporate success as risk management.

Organizations that understand the risks they face and can articulate their risk appetite and define their risk strategy accordingly can have better decision-making, greater agility and a sharper competitive edge.

The practical points in this guide will be invaluable as Board members strive to achieve this.”

Daniel Wilkinson, CEO of Willis UK, said: “Unpredictable emerging threats like cyber, reputational and supply chain risks require Boards to take a long-term focus on building resilience throughout their organizations rather than having a traditional risk management policy based solely on anticipation.

The resilience approach will help companies respond quickly and dynamically to threats by ensuring that the right expertise and processes are in place.”

Tuesday, March 20, 2012

PwC report identifies a ‘fundamental shift in risk management’

Economic turmoil, political upheavals and natural disasters, all combined with advancing globalization and rapid technology progress, are creating a new era of risk for businesses and causing a fundamental shift in risk management practices, according to a new PwC US 2012 annual report.

Entitled ‘Risk in Review’ the report is based on a survey of more than 1,000 executives and risk management leaders.

"2011 marked a year of reckoning, and many companies are still struggling to create an effective approach to managing the ever-widening risk landscape. Businesses are scrambling to fix weak links in their systems stemming from non-traditional risks such as social media and digital technology, to dealing with the realities of operating in today's global marketplace," said Dean Simone, leader of PwC's US Risk Assurance practice.

"In this new risk era, corporate boards and senior management have a crucial role to play to ensure they set the right culture and align their strategy to risk imperatives."

According to the report, forward-looking companies are responding by shifting their risk management focus in several fundamental ways: from internal to external, from operational to strategic and from bottom-up to top-down.

To better prepare themselves to deal with unexpected events for the upcoming year and beyond, companies installed new risk management organizational structures, have put in place a new breed of risk management leadership and have adopted innovative techniques such as scenario analysis and predictive indicators.

To address changing risk landscape, PwC recommends the following risk management approaches for 2012:

Increasing cross-communication: Place greater emphasis on communications and data sharing in 2012 and take steps to improve cross-functional and departmental communication.

Improving data quality and reporting: Enhance global economic teams to help improve data quality and put in place improved processes for reporting data. Different business units should meet periodically with different business units to review and exchange information and data as a form of early alert to possible upcoming risks to the business.

Better forecasting and scenario analysis: Leverage more sophisticated tools such as early-warning systems and contingency plans to reconfigure approaches to manage risk (i.e. set up scenario models or Monte Carlo analysis geared to the nuances of the business, run models as events unfold, etc.)

Elevating the chief risk officer (CRO): Put risk management role on the proactive offensive instead of reactive defense by giving CROs more cross-functional access and ability to effect decision-making.

Integrating risk management: Manage risk holistically by continuing to integrate risk management into decision-making processes relating to ‘traditional’ functions (i.e. strategic planning). Don't exclude new areas of risk (i.e. talent management and outsourcing), but address and integrate them into decision-making processes.

Bolstering IT: Address data privacy and security concerns and take stock of where to build better processes, practices, procedures and technical defenses. Shifting technology and heightened competition for new customers in new markets are also exposed to more risks, so it's imperative to study the setbacks and successes of peers who pioneered the use of these new technologies.

Greater board involvement: Understand the risks facing a company and have in-depth discussions with management to make sure those risks are being handled properly. The discussion should also cover potential risks that are not yet on management's radar and what the implications of those emerging risks might be.

To download a full copy of the report visit: http://www.pwc.com/riskinreview

Thursday, October 27, 2011

Institute of Risk Management issues new guidance on risk appetite

The Institute of Risk Management (IRM) has published new guidance on the subject of risk appetite and tolerance aimed at helping organizations better understand the risks they take when pursuing their strategic objectives.

IRM's guidance document has been endorsed by the Chartered Institute of Internal Auditors, the Chartered Institute of Management Accountants, the Institute of Chartered Secretaries and Administrators, The Chartered Institute of Public Finance and Accountancy and Alarm, the public risk management association.

IRM Deputy Chairman Richard Anderson, the main author of the report, explained: "Risk appetite today is a core consideration in any enterprise risk management approach for organizations of all types, yet there is little widespread understanding about what it means and how it can be applied. In the light of the explicit requirement in the UK Corporate Governance Code for boards to understand the nature and the extent of the risks that they face, IRM decided to take the lead on drawing together some practical guidance on the subject, aimed at board members as well as risk professionals.

We are particularly pleased that other respected professional bodies are supporting our work - risk is everyone’s business and a common understanding and approach helps us work together to address this challenging area."

Anderson continued, "Our underpinning precept is that organizations can only progress by taking those risks that they need to embrace and managing down those that they wish to avoid.

Our recommended approach to risk appetite, based on the wide experience of our members and also benefitting from an extensive consultation exercise earlier this year, is intellectually rigorous as well as highly practical.

We think we have managed to outline a process which should be proportionate to an organization's risk management maturity, capability and culture and, most importantly, supported by appropriate data.

Nevertheless, we do not think that this is the last word on the subject in such a fast-moving environment and we are extremely interested in receiving feedback on this work."

The IRM paper Risk Appetite and Tolerance is available for free download at http://www.theirm.org/publications/risk_appetite.html

Managing cloud risks

Adopting cloud computing may save money, but how does it change risk? The cloud allows the procurement of IT services from both internal and external suppliers to be optimized because the services are delivered through the Internet in a standard way.

The cloud is not a single model, but covers a wide spectrum from applications shared between multiple tenants to virtual servers used by one customer and hosted internally.

The key benefit of a cloud approach is one of scale; the cloud provider can potentially offer a better service at a lower cost because the scale of their operation means they can afford the skilled people and state-of-the-art technology necessary to deliver a secure service.

In general, a large cloud provider is likely to provide a better and more secure IT service at a lower cost than a small to medium sized enterprise could provide itself.

While the public cloud offers applications shared by multiple customers, the private cloud provides applications and infrastructure that are dedicated to a particular organization.

It allows organizations to outsource the management of their IT infrastructure while retaining tighter control over the location and management of the resources.

The price to pay for this is that the costs are likely to be higher than for a public cloud because there is less potential for economy of scale, and resilience may be lower because of the limit on service resources available.

The information security risks associated with cloud computing depend on both the service model and the delivery model adopted. The specific risks depend on the organization and their individual requirements.

The common security concerns across this spectrum are ensuring the confidentiality, integrity and availability of the services and data delivered through the cloud environment.

The approach to managing risks from the perspective of the cloud service user is one of due diligence - ensuring that the requirements are clearly understood, the risks are assessed, the right questions are asked and the appropriate controls are included in the service level agreements.

The principal information security related issues that organizations adopting cloud computing need to address are summarized below. Because of the wide spectrum covered by the cloud, their priority will depend on the cloud model adopted and the individual circumstances:

- Ease of purchase: anyone can buy access using a credit card. Your organization may already be using a cloud service without a proper assessment of the risk.

- Service contracts: those offered by cloud providers are often ‘take it or leave it’ and may contain less onerous obligations on the provider than a normal SLA. Key issues include: who owns the data, and how difficult would it be for you to get it back?

- Compliance: identify the business requirements for compliance with laws and regulations and ensure that the cloud provider is able to answer how they will meet these needs.

- Service location: identify the legal issues that relate to the jurisdiction of the geographic location of the cloud provider, the service and the data, and ensure that service contracts address these issues.

- Data security: identify and classify the business data that is involved and specify the security requirements for this data in terms of confidentiality, integrity and availability.

- Availability: identify the service availability requirements and assure that the provider is capable of meeting these.

- Identity and access management: specify the business needs for identity management and access control and assure that it will be delivered securely.

- Insider abuse of privilege: confirm that the cloud service provider has processes and technology to properly control privileged access.

- Internet threats: determine the level of protection needed against Internet-based threats and ensure they the steps to be taken both by the cloud provider and internally are adequate.

- Monitor: Within the cloud service, meet the business and legal requirements of the client while separating the data relating to different clients.

Taking a good governance approach, such as COBIT, is the key to safely embracing the cloud and the benefits that it provides. COBIT provides guidance to:

- Identify the business requirements for the cloud-based solution. This seems obvious but many organizations are using the cloud without knowing it.

- Determine if the functionality is currently provided by an existing internal service. If so what are the options?

- Determine the governance needs based on the business requirements. Some applications will be more business critical than others.

- Develop scenarios to understand the security threats and weaknesses. Use these to determine the risk response in terms of requirements for controls and questions to be answered. Risk IT: Based on COBIT provides an ideal framework for this.

- Understand what the accreditations and audit reports offered by the cloud provider mean and actually cover.

Cloud computing can reduce costs by providing alternative models for the procurement and delivery of IT services.

Many organizations have already adopted an outsourcing approach to internal functions that are not core and this approach naturally extends to IT.

However, they need to consider the risks involved in a move to the cloud and good governance provides a way for this.

For more information, visit www.isaca.org/cloud for a free ISACA white paper.

What makes a great risk manager?

Active Risk, conducted a major survey of risk professionals in mid-2011.

Phase One analysis, based on over 250 completed responses from around the globe, has shown some surprising results and provides important advice for organizations implementing enterprise risk management programmes.

As demands placed on risk professionals increase and evolve, this new research has given an insight into the types of individuals organizations need in their risk team to produce the best chance of meeting corporate and project risk objectives.

The research also provided an understanding to the training and development required to grow and retain risk professionals; strategies to improve the effectiveness of communications between risk managers and other departments such as sales, finance, contracts and projects and the actions necessary to reduce stresses on the risk team.

Risk professionals completed an online psychometric survey based on the well-established DISC profiling methodology and received a confidential personalized profile report in return.

The cumulative results were used to identify the main personality types active in the profession. Three groups emerged.

The largest percentage (60 percent) represented ‘Technicians’ with the characteristics for accuracy and logical action traditionally associated with risk managers.

More surprisingly over 30 percent of those who responded to the survey emerged as ‘Evangelists’ who are optimistic and inspiring leaders.

This new breed of risk manager could prove instrumental when imbedding a corporate risk culture.

Finally, just under 10 percent of risk professionals who took part in the survey were ‘Drivers’ with determined personalities more usually associated with sales professionals.

To participate in the confidential survey and to download the Phase One summary report, go to www.activerisk.com/risksurvey

NIST: New Guidlines for Conducting Risk Assessments

Risk assessment is the topic of the newest special publication from the National Institute of Standards and Technology (NIST).

Guide for Conducting Risk Assessments (NIST Special Publication 800-30, Revision 1), an extensive update to its original 2002 publication, is the authoritative source of comprehensive risk assessment guidance for federal information systems, and is open for public comments through November 4.

Overall guidance on risk management for information systems is now covered in Managing Information Security Risk: Organization, Mission, and Information System View (NIST SP 800-39), issued last March.

The updated SP 800-30 now focuses exclusively on risk assessments, one of the four steps in information risk management.

Information risk assessments help organizations:
  • Determine the most appropriate risk responses to ongoing cyber attacks or threats stemming from man-made or natural disasters;
  • Guide investment strategies and decisions for the most effective cyber defenses to help protect organizational operations (including missions, functions, image and reputation), organizational assets, individuals, other organizations and the US nation; and
  • Maintain ongoing situational awareness of the security state of an organization's information systems and the environments in which those systems operate.
The guidance in the revised publication has been significantly expanded to include more information on a variety of risk factors essential to determining information security risk, such as threat sources and events, vulnerabilities and predisposing conditions, impact, and likelihood of threat occurrence.

The publication describes a three-step process to help organizations prepare for risk assessments, successfully conduct risk assessments and keep assessment results up to date.

Guide for Conducting Risk Assessments also describes how to apply the risk assessment process at the three tiers of the risk management hierarchy outlined in Special Publication 800-39.

Sample templates, tables and assessment scales for common risk factors are provided for users to adapt to their own organizational risk assessments based on the purpose, scope, assumptions, and constraints of the assessments.

Guide for Conducting Risk Assessments (Special Publication 800-30, Revision 1) may be downloaded from here. Please send comments to sec-cert@nist.gov by Nov. 4.

Social engineering risks explored

Check Point has published the results of a new survey revealing that 42 percent of UK enterprises, and 48 percent internationally, have been victims of social engineering attacks, experiencing 25 or more such attacks in the past two years at a average cost of over £15,000 per incident.

The survey report, ‘The Risk of Social Engineering on Information Security’, shows the most common sources of social-engineering threats are phishing emails (47 percent) and social networking sites (39 percent).

The survey found that new employees (52 percent) and contractors (44 percent) were cited as the most susceptible to social engineering techniques, emphasising that hackers target staff that they suspect are the weakest security links in organisations, using social networking applications to gather personal and professional information on employees to mount spear phishing attacks.

According to the global survey of over 850 IT and security professionals, 86 percent of businesses recognise social engineering as a growing security concern.

A majority of respondents (51 percent) cited financial gain as the primary motivation of attacks, followed by competitive advantage and revenge.

The highest rate of attacks was reported by energy and utility organizations (61 percent) with non-profit organisations reported the lowest rate (24 percent), reinforcing gain as the key reason for attacks.

“Although the survey shows that nearly half of enterprises know they have experienced social engineering attacks, 41 percent said they were unsure whether they had been targeted or not.

Because these types of attacks are intended to stay below an organization’s security radar, the actual number of organisations that have been attacked could be much higher. Yet 44 percent of UK companies surveyed are not currently doing anything to educate their employees about the risks, which is higher than the global average,” said Terry Greer-King, UK managing director for Check Point.

Further findings from the survey report are:

  • The threat of social engineering is real – 86 percent of IT and security professionals (80 percent in the UK) are aware or highly aware of the risks associated with social engineering. Approximately 48 percent of enterprises globally (42 percent in the UK) surveyed admitted they have been victims of social engineering more than 25 times in the last two years.
  • Social engineering attacks are costly – Survey participants estimated each security incident costing anywhere between $25,000 and over $100,000, including costs associated with business disruptions, customer outlays, revenue loss and brand damage. 36 percent of UK respondents cited an average incident cost of over $25,000 (£15,000).
  • Lack of proactive training to prevent social engineering attacks – 34 percent of businesses do not have any employee training or security policies in place to prevent social engineering techniques (4 percent in the UK).
  • Financial Gains are the primary motivation of social engineering - Financial gain was cited as the most frequent reason for social engineered attacks, followed by access to proprietary information (46 percent), competitive advantage (40 percent) and revenge (14 percent).
While social engineering techniques rely on taking advantage of a person’s vulnerability, the prevalence of Web 2.0 and mobile computing has also made it easier to obtain information about individuals and has created new entry points to execute social engineering attacks.

Greer-King added: “An organization’s employees are a critical part of the security process as they can be misled by criminals, or make errors that lead to malware infections or unintentional data loss. Many organizations do not pay enough attention to the involvement of users, when, in fact, employees should be the first line of defence. A good way to raise security awareness among users is to involve them in the security process and empower them to prevent and remediate security incidents in real time.”

Read the report (PDF).

Our security paradigm is out of date

At a recent Cloud Security event, the president of the UK & Ireland chapter of the Cloud Security Alliance (CSA UK & Ireland) said that the perception of security as a concept is out-dated.

According to Des Ward, the current focus on complying with the myriad of assurance frameworks is taking focus away from the obligations placed on organizations to identify and manage the risks to their information assets; which, in turn, places an inordinate and inappropriate burden on external service providers to satisfy the concerns of organizations with no common terms of reference.

“The discussion following my presentation was very interesting as it highlighted that, whilst security in the cloud services environment is clearly a concern for many IT security professionals, there is still a lack of assurance within the external supply chain as whole,” said Des Ward, President, CSA UK & Ireland.

“What this tells me is that, whilst the message on security is getting through to businesses, there is no consistent language to determine whether the service provider will operate the controls to a level that assures the client that their risks are managed appropriately.

This proves to me that the current security mindset is little more than managing risks to achieving compliance rather than empowering organizations to understand the controls required to manage the risks to their information.”

“It is important”, says Ward, “to understand that all organizations in the UK and Ireland, on both sides of the public/private sector divide, have an explicit obligation under law to ensure that personal and corporate information is managed in a safe manner.

“The current compliance overload over the past four or five years has led to an inordinate focus on managing risks to compliance rather than understanding the risks to information – and this focus has meant that we look to overuse of technical controls to show due diligence to ensure that when a breach occurs, that penalties will not be levied; it is not designed to reduce the likelihood of breaches themselves,” he adds.

“This approach is, in my humble opinion, unsustainable, as it does not look to the implementation of the controls and fails to address the business risk management issue that exists in most organizations.

This is turn has no more benefit to the business than placing money in the shredder.” he explained.

“A classic case of these issues”, he says, “was the ICO's recent engagement with Lush after the cosmetics retailer suffered a payment card breach; although the outcome was favourable for all concerned, the key lesson to be learnt is that the current compliance boundaries can now be crossed by another interested party.

What stops the ICO from looking beyond the compliance scope of PCI and entering its own jurisdiction which is the entire business?

“The current lack of corporate information governance in today's businesses will soon result in increased penalties and I feel that this case will be a tipping point; despite the clamour for more prescription from assurance frameworks, my own experience is that many implementations of the PCI DSS are tightly scoped and shows there is little appetite for additional level of prescription that comes with little more benefit than a licence to undertake business on the internet.

This proves to me that the current focus on compliance risk management as we know it is nearing an end, and something else is required to assist organizations to understand and manage the risks to their information going forward.”

Thursday, July 7, 2011

The Human Brain has difficulty calculating RISK!


The human brain struggles with comprehending risk. We find it difficult to translate the mathematical fact of probability into an accurate assessment of danger. This can be especially true in medicine, where emotion frequently clouds rational thinking.

In one study, Gigerenzer and his colleagues asked doctors in Germany and the United States to estimate the probability that a woman with a positive mammogram actually has breast cancer, even though she’s in a low-risk group: 40 to 50 years old, with no symptoms or family history of breast cancer. To make the question specific, the doctors were told to assume the following statistics couched in terms of percentages and probabilities about the prevalence of breast cancer among women in this cohort, and also about the mammogram’s sensitivity and rate of false positives:

The probability that one of these women has breast cancer is 0.8 percent. If a woman has breast cancer, the probability is 90 percent that she will have a positive mammogram. If a woman does not have breast cancer, the probability is 7 percent that she will still have a positive mammogram. Imagine a woman who has a positive mammogram. What is the probability that she actually has breast cancer?

The trick is to think in terms of “natural frequencies” — simple counts of events — rather than the more abstract notions of percentages, odds, or probabilities. As soon as you make this mental shift, the fog lifts.

This is the central lesson of “Calculated Risks,” a fascinating book by Gerd Gigerenzer, a cognitive psychologist at the Max Planck Institute for Human Development in Berlin.

In a series of studies about medical and legal issues ranging from AIDS counseling to the interpretation of DNA fingerprinting, Gigerenzer explores how people miscalculate risk and uncertainty. But rather than scold or bemoan human frailty, he tells us how to do better — how to avoid “clouded thinking” by recasting conditional probability problems in terms of natural frequencies.

The correct answer is roughly 9 percent.

How can it be so low? Gigerenzer’s point is that the analysis becomes almost transparent if we translate the original information from percentages and probabilities into natural frequencies:

Eight out of every 1,000 women have breast cancer. Of these 8 women with breast cancer, 7 will have a positive mammogram. Of the remaining 992 women who don’t have breast cancer, some 70 will still have a positive mammogram.

Imagine a sample of women who have positive mammograms in screening. How many of these women actually have breast cancer?

Since a total of 7 + 70 = 77 women have positive mammograms, and only 7 of them truly have breast cancer, the probability of having breast cancer given a positive mammogram is 7 out of 77, which is 1 in 11, or about 9 percent.

Notice two simplifications in the calculation above. First, we rounded off decimals to whole numbers.

That happened in a few places, like when we said, “Of these 8 women with breast cancer, 7 will have a positive mammogram.”

Really we should have said 90 percent of 8 women, or 7.2 women, will have a positive mammogram. So we sacrificed a little precision for a lot of clarity.

Second, we assumed that everything happens exactly as frequently as its probability suggests. For instance, since the probability of breast cancer is 0.8 percent, exactly 8 women out of 1,000 in our hypothetical sample were assumed to have it. In reality, this wouldn’t necessarily be true.

Things don’t have to follow their probabilities; a coin flipped 1,000 times doesn’t always come up heads 500 times. But pretending that it does gives the right answer in problems like this.

Although reformulating the data in terms of natural frequencies is a huge help, conditional probability problems can still be perplexing for other reasons. It’s easy to ask the wrong question, or to calculate a probability that’s correct but misleading.

Thursday, January 6, 2011

Risk Management in Tough Times

Risk management and governance policies and structures are being provided increasing authority, visibility and independence. However, this is within a planned increases in investment and spending that is more than modest and may even experience shrinkage.

The reality is that the natural tension and conflict between the risk functions and the business’ aspirations for higher profit growth still exists. The real conflict is in how some balance and compromise can be achieved?

Key findings in the current environments, are:

* Strategic risk management is currently in an embryonic stage of maturity. Executives view the identification of new and emerging risks as a key objective of risk management, but roughly two-thirds of them believe their organisation is weak at anticipating and measuring future risks.
* Few organisations truly involve risk functions in key business decisions. Few companies expect risk functions to participate in strategic decision making in the near future. It tends to be a garnish on the side.
* Risk management needs to shift its role and emphasis from preventative activities towards a more proactive and supportive one. Risk managers need to expand far beyond providing supervisory, policing controls and monitoring to also include identifying opportunities to achieve and enable business objectives.

Window of Opportunity

Will increasing interest in including the risk function in strategy formulation simply a passing trend or temporary phase?

Hopefully, the interest will be permanent, but not without difficulties, and there are real obstacles.
1) Business line managers may continue to view the risk function as inertia and a brake on their 'innovative' activities, slowing sales and profit growth.

2) Technical knowledge and experience by boards of directors and executives is simply not adequate to fully understand how to integrate risk and performance management into strategic growth.

On a positive note, risk management is gaining influence and using more structured modeling and analytics software. Some better informed managers are creating a richer organisational culture for metrics and risk awareness that considers opportunities, not just threats.

Invulnerable Today, Rudderless Tomorrow

Half of the 25 companies that passed the rigorous tests listed in the once-famous book by Tom Peters and Robert Waterman, “In Search of Excellence,” today either no longer exist, or are in bankruptcy.

What happened? Well, when an organisation and it's executives start to achieve results or becomes successful, they become more stability orientated and adverse to risk taking. Forgetting that maintaining their risk appetite /profile and taking calculated risks, is essential for organisations to change and continue be innovative.

Wednesday, December 2, 2009

Thinking Cautiously about Risk Appetite

How does the current trend for Caution in Risk Management affect business potential?

Because well-considered risk taking is critical to business growth and success, not just for individual companies but also to enable or entitle the expansion of a properly functioning economy.

Food for Thought
Business-to-business lending and borrowing always involves a high degree of risk. Therefore, curtailing that appetite for risk can directly hobble entrepreneurship, deprive deserving businesses of capital, and reinforce deflation.

Take a Positive Stance
Moreover, for any business, the assessment of risk should not dwell on the potentially damaging prospects but also on the opportunities; potential rewards and gains. If you take an overly cautious stance this is more difficult to do or can create a restrictive position.

Although the need for risk taking is recognised by both businesspeople and economists, a lot of this is based on theoretical lip service and rhetoric, rather than real positive and optimistic determinations and outlooks.

Complexity
The complexity of risks in the global economy severely tests many companies, both in their judgment about how much risk to take and in their controls for tracking and managing it. What doesn’t help the situation in any way are sponsors and senior management teams who are not comfortable or practiced at discussing risk in the context of strategic decision making or in articulating those expectations to the organisation.

Positive Solution
To overcome the problem of over cautious risk taking, sponsors, senior managers and companies needs a fresh, more rigorous definition of the appropriate level of risk the organisation can accept or endure. The organisation needs to stress its structure, confirm its strengths and articulate its risk appetite.

Set the Appetite
In addition to asking how much risk to avoid and how much to accept, we need to prepare for the possible downside. Leaders should be setting a better example, by defining how much risk they want and establishing how much capital they are willing to stake against it.

Result Focus
Clearly this is only part of the algorithm, because the result of all this effort is to achieve as much potential and capital gain. The whole organisation should be involved and open to this discussion on risk appetite.

Trading on the edge
Traders and deal makers are at the sharp end of it. They, of all people need to fully understand the risk appetite of the company and the part that their individual deals might have in the corporate-wide performance, because they are the ones that have to implement it effectively.
Unshackle and empower your people, by giving them a clear framework, an appetite for risk and a plan for success.