RISK MANAGEMENT
Risk can be seen as a
• Mere uncertainty
• As a threat
• As an opportunity
Risk profile
The degree that a business is willing to accept risks in pursuit of
achieving their goals
It is directly related to the strategy of the business
Risk culture
Refers to the collective attitude of the business in accepting risks
Depends if risk taking or risk avoidance are rewarded
Types of risks
• Operational risks – risks that occur during normal operations
e.g. processes, people, data
• Country risks – locating a business in a specific country e.g.
political events, instability
• Strategic risks – poorly formulated mission, vision as well as
unrealistic goals
• Environmental risks – e.g.
Floods/drought, traffic, high crime levels, increased levels of
unemployment, obsolete equipment, level of competition
• Financial risks –
Credit risk – debtor not paying
Fluctuations in the exchange rate
Interest rate increases
Solvency risks – liabilities exceed your assets
• Reputational risk – damage because of consumer complaints,
environmental damage caused by business
Risk assessment
Identify the risk
Using the following methods:
• Risk workshops – internal or external
• Benchmarking – best practice
• Auditing – internal or external
• Stakeholder consultations – if a third party has been identified
• Scenario planning – what if?
• Surveys – asking questions internally and externally
Description of the risk
Describe the risks in detail to ensure everybody understands the risk
issues and their origins
Estimation of the impact of risks
Estimation tools are:
• Pro, Cons chart
• Cost/risk-benefit analysis
• Decision trees
• PESTLE
• SWOT
Plot on estimation matrix
Risk management policy
Develop a comprehensive policy
Communicate to all parties
Implement though out the business
Risk response
Avoidance - prevent or limit the activities that lead to risk e.g. not
investing in RSA
Reduction – limit the possibility of the risk occurring - having strict
control mechanisms
Acceptance – no action to stop or limit the risk - totally beyond control
Risk reporting
• Report to internal stakeholders – people involved in decision
making
• Report to external stakeholders – the general public