When identifying risks, the question often asked is "What keeps you up at night?". Let me explain why this is a, well... risky question to ask.
Consider that the principle goal of risk management is to ensure that an organization performs as expected. In other words, it achieves its objectives. Therefore the risks that you identify need to be directly related to your organizations objectives. Risks not related to the achievement of corporate goals are off strategy - a distraction.
"What keeps you up at night?" is a disembodied question that will result in both relevant and irrelevant risks. Here is the question to ask...
"Considering the objective to... (describe a key objective), what events may prevent the organization from achieving this objective?".
The result will be risk events that are well aligned with management's goals. Feel free to present your interviewee with a list of potential risk internal and external risk categories to refer to when answering the question. For example, economic, competitive, strategic, HR, financial, technology, information, and corporate integrity are some of the major categories. There are up to 100 subcategories that fall under these major categories as well (business is complex!).
This objectives-focused question will ensure that your risk management process is strategic and focused on corporate performance.
[Rich]
richard.m.wilson@ca.pwc.com
ERM is powerful when designed as a performance-focused activity. It's not an audit, nor a compliance process. ERM manages the barriers that prevent organizations from achieving their objectives.
Author:
Richard Wilson develops Performance Risk Management capabilities for complex organizations. He has helped the largest companies in North America manage the barriers to their desired performance.
richard.m.wilson@ca.pwc.com | (416) 941-8374
Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts
Saturday, May 1, 2010
Friday, April 9, 2010
Risk: It's how you word it
One of the greatest risk management challenges I have seen over the years is wording risks properly. It sounds simple enough (and it is!). So why is there such inconsistency in wording risks? The first reason is that there is no universal standard to follow. The second is that there are too many interpretations about what risk is. Finally, risk carries a negative connotation in many organizations, (sadly), so people try to describe their risks in a positive way to position them more favourably.
Well worded risks are a cornerstone to a successful risk management program. If people across your organization end up with multiple interpretations about your risks, the credibility around your risk scores will fall. Getting the wording right is pretty important.
Allow me to suggest an easy and reliable way to word your risks. To begin with, remember that a risk is an event. Secondly, it is an event that may prevent you from achieving your objectives. Therefore, the simplest way to word your risk is" X may happen". For example, "Sr. executives may leave the company", or "Production at the plant may fall by 20%", or "Interest rates may rise above 5%". All of these risks are clear, and since they are worded in the future, should not be threatening to newly emerging risk management cultures.
Follow each risk with "context bullet-points". These are the data points about the risk that people should consider. For example:
Production at the plant may fall by 20%
[Rich]
richard.m.wilson@ca.pwc.com
Well worded risks are a cornerstone to a successful risk management program. If people across your organization end up with multiple interpretations about your risks, the credibility around your risk scores will fall. Getting the wording right is pretty important.
Allow me to suggest an easy and reliable way to word your risks. To begin with, remember that a risk is an event. Secondly, it is an event that may prevent you from achieving your objectives. Therefore, the simplest way to word your risk is" X may happen". For example, "Sr. executives may leave the company", or "Production at the plant may fall by 20%", or "Interest rates may rise above 5%". All of these risks are clear, and since they are worded in the future, should not be threatening to newly emerging risk management cultures.
Follow each risk with "context bullet-points". These are the data points about the risk that people should consider. For example:
Production at the plant may fall by 20%
- our packaging supplier is in financial trouble
- our competitors are trying to hire away plant staff
- our plant wages are not competitive
- unpredictable weather patterns in that region are expected
- etc...
- Do any of your risks begin with "A lack of...", or "The inability to..."? (If so, they are describing situations within which a risk may occur and not the event itself.)
- Do any of your risks contain the words "and", or "or"? (If so, you have combined two events which will be difficult to score.)
- Are your risks worded as objectives in the positive? For example, "Retain our senior executives". It's a great objective but doesn't describe the effect of uncertainty on objectives.
- Is the risk tied to one or more objectives so that it is clear where the challenge to the organization lies?
- Do your risks have contextual data points attached to them?
[Rich]
richard.m.wilson@ca.pwc.com
Saturday, March 27, 2010
ISO 31000 Risk Management
Every once in a while you feel like you have a jump on something good. In Q4 of 2009 I had the pleasure of conversing with Jan Mattingly, one of Canada's foremost experts in all things related to risk. Jan was one of the delegates chosen from an international list of risk experts to draft the ISO 31000 standard. Jan announced with excitement that the new standard was close to release and that it was going to bring a new level of excellence to Canada's risk management environment. She was right!
Recently, I had the honour attending the first public ISO 31000 training session in Canada. It validated my understanding about how they are approaching operational risk management. It is an objectives-oriented approach (risk = The effect of uncertainty on objectives.). In my opinion this is crucial. After all, businesses exist to achieve their objectives, there is nothing more important. So risk management needs to be oriented around the achievement of objectives or else it will only be regarded as an academic exercise by management.
There are well articulated principles of the standard as well, but none stands so tall as the first - "Risk management creates and protects value". Again, business is about value creation, so risk management should pursue the same goal. Managing risk is not a defensive strategy, it's part of your offense. As a member of a Board of Directors, this principle should be your first filter when assessing the effeciveness of a risk management strategy.
I expect that there will be a lot of excitement around this standard. It is not a "check-the-box" certification, but rather a sound process that will lead companies in the right direction. Any company who is managing ambiguity around risk is well advised to head down this path.
[Rich]
richard.wilson@bpsresolver.com
Recently, I had the honour attending the first public ISO 31000 training session in Canada. It validated my understanding about how they are approaching operational risk management. It is an objectives-oriented approach (risk = The effect of uncertainty on objectives.). In my opinion this is crucial. After all, businesses exist to achieve their objectives, there is nothing more important. So risk management needs to be oriented around the achievement of objectives or else it will only be regarded as an academic exercise by management.
There are well articulated principles of the standard as well, but none stands so tall as the first - "Risk management creates and protects value". Again, business is about value creation, so risk management should pursue the same goal. Managing risk is not a defensive strategy, it's part of your offense. As a member of a Board of Directors, this principle should be your first filter when assessing the effeciveness of a risk management strategy.
I expect that there will be a lot of excitement around this standard. It is not a "check-the-box" certification, but rather a sound process that will lead companies in the right direction. Any company who is managing ambiguity around risk is well advised to head down this path.
[Rich]
richard.wilson@bpsresolver.com
Subscribe to:
Posts (Atom)
About The Author
- Richard Wilson
- Richard is a Director in PwC's Risk Advisory practice with clients in both Canada and the United States.
He is an experienced senior executive with 15 years in a CEO or COO role (publically traded and private firms). Richard has been leading risk management implementations for more than a decade incl. 60 C-level risk assessments, and has led online risk assessments for 30,000 people in 25 countries.
He has advised the largest company in the US on risk management, and he has facilitated a risk assessment for the United Nations. Richard has been published in Compliance Week, Canadian Business, and the Globe & Mail and has been a keynote speaker on the topic of risk at many conferences in both Canada and the US since 2004.