Take Control of your Risk Management
“There’s a sense of frustration among senior managers that risk management isn’t acting as an enabler for better business decision making. It’s time to align risk appetite; time for a risk management model for a new decade.”
Today, there are new demands on risk management to act as an enabler for better organizational and business decisions. However, outdated traditional models don’t support those organizations or business units that operate and indeed thrive under inherently higher risk conditions. At 4C Strategies we have developed a new model that empowers risk owners and challenges senior management to look at risks from a different perspective. And the results speak for themselves as enterprises begin to see new opportunities and improved financial returns.
Ansgar Toscha, principal consultant at 4C Strategies, has over 20 years of experience as an ERM/GRC supply chain risk management consultant. During this time, he has advised global enterprises and smaller scale companies from a diverse range of business areas and industries. Ansgar is the author of ‘An Introduction to Enterprise Risk Management’.
Hi Ansgar, can you tell us why risk management is important.
In short, risk management is essential to raise risk awareness throughout an organization and improve decision making at all levels. Organizations that should practice effective risk management include those that:
- operate in complex business environments
- run complex product portfolios
- are in heavily regulated industries
How is the traditional risk management model applied?
In the traditional model used by many organizations today, you identify critical risks and then plot the likelihood of them occurring as well as the impact they will have on the organization. This includes:
- strategic risks
- operational risks
- financial risks
- compliance risks
Based on this you define a strategy to move risks from the red and yellow zones to the green ‘safety zone’.
Why is this model inadequate for many organizations?
Many organizations today operate multiple business models, which have fundamentally different levels of risk appetite. This isn’t supported in the traditional risk management model, which has one clear aim – mitigate risks. Why? A business unit with an inherently high risk appetite, may have no alternative but to operate outside the green zone and may even be happy to do so because it has control of the risks. Additionally, some organizations have a proven track record of being successful at responding to risk, but a poor one at evaluating risk, in particular when assessing likelihood. The model simply doesn’t cater for them.
You often meet with senior management in your role, what do they have to say about this?
There’s a sense of frustration among senior managers and board members. Many feel that risk management isn’t acting as an enabler for better business decision making. They encounter the same traditional model again and again which means the conversations around risk remain the same.
You mentioned control earlier, why is this so important?
Control is missing in the traditional risk management model. If you are in control of a high risk, i.e., something in the red zone, you could argue it is no longer a high risk, even if it would have a critical impact on the organization if it occurred.
What advice would you give to organizations looking to get more from risk management?
You need to challenge the status quo, as we have done at 4C Strategies. Simply lowering the likelihood of risks occurring isn’t the answer, especially as the reason a risk is identified in the first place is often because it already happened at some point. Instead, align your risks with risk appetite, and make sure you have adequate control of them.
Is this what organizations can expect to do when using the new 4C Strategies model?
This and much more. The new model changes the conversation around risk and helps organizations take better business decisions. It also provides an ‘at a glance’ overview of the actual effectiveness of risk mitigation over time.
Is the model in use?
It is already being applied by global enterprises and some smaller businesses, with great results. At one company a board member commented “Obviously, risk X equates to a big exposure for us, but as long as we are in control of it and it generates a lot of income, I have no problem with that!” The traditional model wouldn’t trigger this kind of comment.
How can organizations find out more?
We have produced a short paper on it which can be downloaded below. This provides more detail on the model including a simple business example. If an organization is looking to make better business decisions with risk management then they should contact us directly, and we can help them drive this process using our new model.
Best Practices for Countering Disinformation
Remote working: How to ensure information security and IT continuity during COVID-19
4C Strategies COVID-19 Support
As coronavirus-related needs and demands continue to evolve, 4C Strategies is offering specific pandemic support for our clients and wider network. This includes advisory services such as mid-incident COVID-19 reviews, additional operational resources (onsite or virtual) for risk, business continuity and crisis managers, and pre-configured software solutions to securely track, verify and visualise response efforts.
Read more →