Well worded risks are a cornerstone to a successful risk management program. If people across your organization end up with multiple interpretations about your risks, the credibility around your risk scores will fall. Getting the wording right is pretty important.
Allow me to suggest an easy and reliable way to word your risks. To begin with, remember that a risk is an event. Secondly, it is an event that may prevent you from achieving your objectives. Therefore, the simplest way to word your risk is" X may happen". For example, "Sr. executives may leave the company", or "Production at the plant may fall by 20%", or "Interest rates may rise above 5%". All of these risks are clear, and since they are worded in the future, should not be threatening to newly emerging risk management cultures.
Follow each risk with "context bullet-points". These are the data points about the risk that people should consider. For example:
Production at the plant may fall by 20%
- our packaging supplier is in financial trouble
- our competitors are trying to hire away plant staff
- our plant wages are not competitive
- unpredictable weather patterns in that region are expected
- etc...
- Do any of your risks begin with "A lack of...", or "The inability to..."? (If so, they are describing situations within which a risk may occur and not the event itself.)
- Do any of your risks contain the words "and", or "or"? (If so, you have combined two events which will be difficult to score.)
- Are your risks worded as objectives in the positive? For example, "Retain our senior executives". It's a great objective but doesn't describe the effect of uncertainty on objectives.
- Is the risk tied to one or more objectives so that it is clear where the challenge to the organization lies?
- Do your risks have contextual data points attached to them?
[Rich]
richard.m.wilson@ca.pwc.com
No comments:
Post a Comment