SlideShare a Scribd company logo
1 of 32
Risk Management
Introduction to
Risk Management
(Theory & Practice)
DCU Risk & Compliance Officer
November 2015
Risk Management
Sections
1) Aims of presentation
2) What is Risk Management (RM)?
3) RM Cycle
4) Categories of risk
5) Risk Register
6) Risk Appetite
7) Tips for success
8) Why RM may fail
9) Summary & conclusion
Risk Management
Aims of this presentation
• To explain why it is relevant
• To explain its components i.e. the “Risk Cycle”
• Guidance on
Preparing a “Risk Register”
Risk management techniques
Reporting on risks
Risk Management
Place for Risk Management?
Risk Management
What is Risk Management?
It is a process to:
 Identify all relevant risks
 Assess / rank those risks
 Address the risks in order of priority
 Monitor risks & report on their management
Risk Management
Risk Management – why do we need it?
Promotes good management
May be a legal requirement depending upon industry or
sector
Resources available are limited – therefore a focused
response to Risk Management is needed
Risk Management
What is a Risk?
 A risk is an uncertain event which may occur in the future
 A risk may prevent or delay the achievement of an
organization’s or units objectives or goals
A risk is not certain – Its likelihood can only be estimated
Note: Not all risk is bad, some level of risk must be
taken in order to progress / prevent stagnation.
Risk Management
Risk Management
Risk Management Cycle – Step 1
Missio
n
• Define
Purpose
Strateg
y
• High level
Plan
Goal
s
• Unit Specific
Targets
Risk Management
Risk Management Cycle – Step 2
Risk Identification – what are the threats and uncertainties
associated with my organization’s or units objectives?
• Separate out the risk into its cause & possible effect
• Be concise & clear
• Do not concentrate on symptoms only
Risk Management
Risk Management Cycle – Step 2 cont.
• Assess the risk’s
 Impact
 Likelihood
(Guidance on both later!)
• Prioritize the risks
• Hint: Get input from appropriate individuals
Risk Management
Risk Management Cycle – Step 3
Challenge & Evaluate Controls
Control: Policy, action, procedure or process designed to
prevent risk or to limit its impact
Do they work, are they effective?
Residual Risk only should be measured
Risk Management
Risk Management Cycle – Step 4
TakeAction!
 For serious risks where controls are
A) Weak
B) Absent
 For risks where the Risk Appetite is exceeded
 Examine Cost vs. Benefit
Risk Management
Risk Management Cycle – Step 4 cont.
Types of Action
A) Tolerate
B) Treat
C) Substitute
D) Terminate
(The choice of the above will be decided upon by your risk
appetite)
Risk Management
Risk Management Cycle – Step 5
Monitor & Report
 Use a standard format for capturing risk data e.g. a “RiskRegister”
 Review all risks at least annually
 Serious risks to be reviewed more often depending on circumstances
 Report on risk to senior management / Board
 Make Risk Register available to stakeholders to show good
governance
Risk Management
Categories of Risks
 There are multiple ways into which risks can be
categorized
 Final categories used will depend upon each
organizations / unit’s circumstances
 Goal is to cluster risks into standard, meaningful
& actionable groupings
 What follows is one example of a type of
categorization
Risk Management
Categories of Risks
Financial
 Reduction in funding
 Failure to safeguard assets
 Poor cash flow management
 Lack of value for money
 Fraud / theft
 Poor budgeting
Risk Management
Categories of Risks cont.
Operational
These risks result from failed or inappropriate policies,
procedures, systems or activities e.g.
 Failure of an IT system
 Poor quality of services delivered
 Lack of succession planning
 Health & Safety risks
 Staff skill levels
 No process to track contractual commitments
Risk Management
Categories of Risks cont.
Reputational
• Organization engages in activities that could
threaten it’s good name
 Through association with other bodies
 Staff / members acting in a criminal or
unethical way
• Poor stakeholder relations
Risk Management
Categories of Risk cont.
Governance & Compliance
• Lack of oversight by Board
• Segregation of duties not defined formally
• Ensuring compliance with funders terms and conditions
• Compliance with applicable legislation
 Safeguarding of vulnerable individuals
 Taxation Law
 Data Protection
 Health & Safety Law
Risk Management
Categories of Risk cont.
Strategic
• Engages in activity at variance with its
stated objectives
• Fails to engage in an activity that would
support its stated objectives
Risk Management
Risk Register
a) What is it?
b) Components
c) How to report on it
Risk Management
Risk Register cont.
 A Risk Register is a management tool used to
record relevant details relating to risks.
 It is a database of information on risks.
 Best kept simple to begin with!
Risk Management – Register Example
Risk Management
Parts of a Risk Register
Risk Description – Clear description of risk, its cause
& consequence
Controls / Actions already in place – List what is actually happening
now which reduces the impact of a risk or its likelihood
Impact – scale of 1 to 5 (1 = minor, 5 = catastrophic)
(Note this is to be residual impact only)
Likelihood – scale of 1 to 5 (1 = remote, 5 = unavoidable)
(Note this is to be residual likelihood only)
Weighting – Its Risk Ranking: a calculated figure i.e. impact x
likelihood
Risk Management
Parts of a Risk Register cont.
Risk Owner – The administrative unit, management position
or group who are in the best position to manage the risk on
an on-going basis
Further Actions Required – The controls / solutions which
have yet to be acted upon which could reduce the impact or
likelihood of a risk
Date – The expected date as to when the actions shown
under further actions required will be in place & effectively
addressing the risk
Risk Management – Emample of a Matrix
Risk Management
Tips for Success
 Involve all levels of staff & management in the process
 Check controls are relevant & effective
 Ensure risk owner takes responsibility for management of
risks under their control
 Focus on risk cause, not its symptoms
Risk Management
Why Risk Management May Fail
 Limitations of scope
 Lack of top management support
 Did not engage all stakeholders
 Failure to share information
 RM not embedded within planning & management
system
Risk Management
Summary & Conclusion
We have covered:
 Definition of risk
 Risk Management cycle
 Categories of risk
 Risk Register – how to guide
 Possible pit falls in a Risk Management process
Risk Management
Place for Risk Management?
Risk Management
Thank You

More Related Content

What's hot

Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksInternational Federation of Accountants
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityJeff B
 
Introduction to risk management
Introduction to risk managementIntroduction to risk management
Introduction to risk managementKannan Subbiah
 
Risk Management Overview
Risk Management OverviewRisk Management Overview
Risk Management OverviewJIGNESH PADIA
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk managementAnu Damodaran
 
Third Party Vendor Risk Managment
Third Party Vendor Risk ManagmentThird Party Vendor Risk Managment
Third Party Vendor Risk ManagmentPivotPointSecurity
 
Risk Management Process Steps Powerpoint Presentation Slides
Risk Management Process Steps Powerpoint Presentation SlidesRisk Management Process Steps Powerpoint Presentation Slides
Risk Management Process Steps Powerpoint Presentation SlidesSlideTeam
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk ManagementColleen Beck-Domanico
 
Risk Management Overview Powerpoint Presentation Slides
Risk Management Overview Powerpoint Presentation SlidesRisk Management Overview Powerpoint Presentation Slides
Risk Management Overview Powerpoint Presentation SlidesSlideTeam
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Andrew Smart
 
Third-Party Oversight & Governance
Third-Party Oversight & GovernanceThird-Party Oversight & Governance
Third-Party Oversight & GovernanceEDR
 
The importance of risk management in business
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in businessr2financial
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Diane Christina
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceResolver Inc.
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance BOC Group
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A JourneyDebashis Gupta
 

What's hot (20)

Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
 
ISO 27005 Risk Assessment
ISO 27005 Risk AssessmentISO 27005 Risk Assessment
ISO 27005 Risk Assessment
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and Sustainability
 
Introduction to risk management
Introduction to risk managementIntroduction to risk management
Introduction to risk management
 
Risk management
Risk managementRisk management
Risk management
 
Risk Management Overview
Risk Management OverviewRisk Management Overview
Risk Management Overview
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk management
 
Third Party Vendor Risk Managment
Third Party Vendor Risk ManagmentThird Party Vendor Risk Managment
Third Party Vendor Risk Managment
 
Risk Management Process Steps Powerpoint Presentation Slides
Risk Management Process Steps Powerpoint Presentation SlidesRisk Management Process Steps Powerpoint Presentation Slides
Risk Management Process Steps Powerpoint Presentation Slides
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management
 
Risk Management Overview Powerpoint Presentation Slides
Risk Management Overview Powerpoint Presentation SlidesRisk Management Overview Powerpoint Presentation Slides
Risk Management Overview Powerpoint Presentation Slides
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard
 
Third-Party Oversight & Governance
Third-Party Oversight & GovernanceThird-Party Oversight & Governance
Third-Party Oversight & Governance
 
The importance of risk management in business
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in business
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Risk management
Risk managementRisk management
Risk management
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A Journey
 
Risk Appetite
Risk AppetiteRisk Appetite
Risk Appetite
 

Similar to Risk Mgt Training Slides (1).pptx

Week 2 Introduction to risk management.pdf
Week 2 Introduction to risk management.pdfWeek 2 Introduction to risk management.pdf
Week 2 Introduction to risk management.pdfJeffreyKwame1
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinsteinRamaica Ona
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinsteinAahil Malik
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinsteinSukumar Reddy
 
Risk Management as a Safety Program Tool
Risk Management as a Safety Program ToolRisk Management as a Safety Program Tool
Risk Management as a Safety Program ToolAtlantaSafetyCouncil
 
Risk Management.docx
Risk Management.docxRisk Management.docx
Risk Management.docxCPA Australia
 
12_BUSINESS RISK ufuhf isbifb MANAGEMENT.ppt
12_BUSINESS RISK  ufuhf isbifb MANAGEMENT.ppt12_BUSINESS RISK  ufuhf isbifb MANAGEMENT.ppt
12_BUSINESS RISK ufuhf isbifb MANAGEMENT.pptbillugamma06
 
Information Security Risk Management
Information Security Risk ManagementInformation Security Risk Management
Information Security Risk ManagementNikhil Soni
 
Risk manajemen-intro
Risk manajemen-introRisk manajemen-intro
Risk manajemen-introAnwar Sadat
 
Risk Management Toolkit
Risk Management ToolkitRisk Management Toolkit
Risk Management ToolkitPeterFranz6
 
Risk Management process.pptx
Risk Management process.pptxRisk Management process.pptx
Risk Management process.pptxMohanVeerabomala
 
Risk Management (1) (1).ppt
Risk Management (1) (1).pptRisk Management (1) (1).ppt
Risk Management (1) (1).pptAjjuSingh2
 
Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Sadia Razzaq
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOPiTech
 

Similar to Risk Mgt Training Slides (1).pptx (20)

Risk management
Risk managementRisk management
Risk management
 
Dealing with Operational and Ecosystem Risk
Dealing with Operational and Ecosystem RiskDealing with Operational and Ecosystem Risk
Dealing with Operational and Ecosystem Risk
 
Week 2 Introduction to risk management.pdf
Week 2 Introduction to risk management.pdfWeek 2 Introduction to risk management.pdf
Week 2 Introduction to risk management.pdf
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
 
Risk Management as a Safety Program Tool
Risk Management as a Safety Program ToolRisk Management as a Safety Program Tool
Risk Management as a Safety Program Tool
 
Risk Management.docx
Risk Management.docxRisk Management.docx
Risk Management.docx
 
12_BUSINESS RISK ufuhf isbifb MANAGEMENT.ppt
12_BUSINESS RISK  ufuhf isbifb MANAGEMENT.ppt12_BUSINESS RISK  ufuhf isbifb MANAGEMENT.ppt
12_BUSINESS RISK ufuhf isbifb MANAGEMENT.ppt
 
Information Security Risk Management
Information Security Risk ManagementInformation Security Risk Management
Information Security Risk Management
 
Risk manajemen-intro
Risk manajemen-introRisk manajemen-intro
Risk manajemen-intro
 
Risk Management Toolkit
Risk Management ToolkitRisk Management Toolkit
Risk Management Toolkit
 
Risk Management process.pptx
Risk Management process.pptxRisk Management process.pptx
Risk Management process.pptx
 
Card Processing Risks.pptx
Card Processing Risks.pptxCard Processing Risks.pptx
Card Processing Risks.pptx
 
Risk Management (1) (1).ppt
Risk Management (1) (1).pptRisk Management (1) (1).ppt
Risk Management (1) (1).ppt
 
Risk1.ppt
Risk1.pptRisk1.ppt
Risk1.ppt
 
Quality risk management
Quality risk managementQuality risk management
Quality risk management
 
Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Risk management ppt 111p (training module)
Risk management ppt 111p (training module)
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_en
 

Recently uploaded

VIP Russian Call Girls in Indore Komal 💚😋 9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Komal 💚😋  9256729539 🚀 Indore EscortsVIP Russian Call Girls in Indore Komal 💚😋  9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Komal 💚😋 9256729539 🚀 Indore Escortsaditipandeya
 
Cleared Job Fair Handbook | May 2, 2024
Cleared Job Fair Handbook  |  May 2, 2024Cleared Job Fair Handbook  |  May 2, 2024
Cleared Job Fair Handbook | May 2, 2024ClearedJobs.Net
 
Austin Recruiter Network Meeting April 25, 2024
Austin Recruiter Network Meeting April 25, 2024Austin Recruiter Network Meeting April 25, 2024
Austin Recruiter Network Meeting April 25, 2024Dan Medlin
 
Webinar - How to set pay ranges in the context of pay transparency legislation
Webinar - How to set pay ranges in the context of pay transparency legislationWebinar - How to set pay ranges in the context of pay transparency legislation
Webinar - How to set pay ranges in the context of pay transparency legislationPayScale, Inc.
 
Employee Roles & Responsibilities: Driving Organizational Success
Employee Roles & Responsibilities: Driving Organizational SuccessEmployee Roles & Responsibilities: Driving Organizational Success
Employee Roles & Responsibilities: Driving Organizational SuccessHireQuotient
 
Situational Questions for Team Leader Interviews in BPO with Sample Answers
Situational Questions for Team Leader Interviews in BPO with Sample AnswersSituational Questions for Team Leader Interviews in BPO with Sample Answers
Situational Questions for Team Leader Interviews in BPO with Sample AnswersHireQuotient
 
Ways to Make the Most of Temporary Part Time Jobs
Ways to Make the Most of Temporary Part Time JobsWays to Make the Most of Temporary Part Time Jobs
Ways to Make the Most of Temporary Part Time JobsSnapJob
 
Mercer Global Talent Trends 2024 - Human Resources
Mercer Global Talent Trends 2024 - Human ResourcesMercer Global Talent Trends 2024 - Human Resources
Mercer Global Talent Trends 2024 - Human Resourcesmnavarrete3
 
Mastering Vendor Selection and Partnership Management
Mastering Vendor Selection and Partnership ManagementMastering Vendor Selection and Partnership Management
Mastering Vendor Selection and Partnership ManagementBoundless HQ
 
Arjan Call Girl Service #$# O56521286O $#$ Call Girls In Arjan
Arjan Call Girl Service #$# O56521286O $#$ Call Girls In ArjanArjan Call Girl Service #$# O56521286O $#$ Call Girls In Arjan
Arjan Call Girl Service #$# O56521286O $#$ Call Girls In Arjanparisharma5056
 
Webinar - Payscale Innovation Unleashed: New features and data evolving the c...
Webinar - Payscale Innovation Unleashed: New features and data evolving the c...Webinar - Payscale Innovation Unleashed: New features and data evolving the c...
Webinar - Payscale Innovation Unleashed: New features and data evolving the c...PayScale, Inc.
 
How Leading Companies Deliver Value with People Analytics
How Leading Companies Deliver Value with People AnalyticsHow Leading Companies Deliver Value with People Analytics
How Leading Companies Deliver Value with People AnalyticsDavid Green
 
HRM PPT on placement , induction and socialization
HRM PPT on placement , induction and socializationHRM PPT on placement , induction and socialization
HRM PPT on placement , induction and socializationRishik53
 

Recently uploaded (14)

VIP Russian Call Girls in Indore Komal 💚😋 9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Komal 💚😋  9256729539 🚀 Indore EscortsVIP Russian Call Girls in Indore Komal 💚😋  9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Komal 💚😋 9256729539 🚀 Indore Escorts
 
Cleared Job Fair Handbook | May 2, 2024
Cleared Job Fair Handbook  |  May 2, 2024Cleared Job Fair Handbook  |  May 2, 2024
Cleared Job Fair Handbook | May 2, 2024
 
Austin Recruiter Network Meeting April 25, 2024
Austin Recruiter Network Meeting April 25, 2024Austin Recruiter Network Meeting April 25, 2024
Austin Recruiter Network Meeting April 25, 2024
 
Webinar - How to set pay ranges in the context of pay transparency legislation
Webinar - How to set pay ranges in the context of pay transparency legislationWebinar - How to set pay ranges in the context of pay transparency legislation
Webinar - How to set pay ranges in the context of pay transparency legislation
 
Employee Roles & Responsibilities: Driving Organizational Success
Employee Roles & Responsibilities: Driving Organizational SuccessEmployee Roles & Responsibilities: Driving Organizational Success
Employee Roles & Responsibilities: Driving Organizational Success
 
Situational Questions for Team Leader Interviews in BPO with Sample Answers
Situational Questions for Team Leader Interviews in BPO with Sample AnswersSituational Questions for Team Leader Interviews in BPO with Sample Answers
Situational Questions for Team Leader Interviews in BPO with Sample Answers
 
Ways to Make the Most of Temporary Part Time Jobs
Ways to Make the Most of Temporary Part Time JobsWays to Make the Most of Temporary Part Time Jobs
Ways to Make the Most of Temporary Part Time Jobs
 
Mercer Global Talent Trends 2024 - Human Resources
Mercer Global Talent Trends 2024 - Human ResourcesMercer Global Talent Trends 2024 - Human Resources
Mercer Global Talent Trends 2024 - Human Resources
 
Mastering Vendor Selection and Partnership Management
Mastering Vendor Selection and Partnership ManagementMastering Vendor Selection and Partnership Management
Mastering Vendor Selection and Partnership Management
 
escort service sasti (*~Call Girls in Rajender Nagar Metro❤️9953056974
escort service sasti (*~Call Girls in Rajender Nagar Metro❤️9953056974escort service sasti (*~Call Girls in Rajender Nagar Metro❤️9953056974
escort service sasti (*~Call Girls in Rajender Nagar Metro❤️9953056974
 
Arjan Call Girl Service #$# O56521286O $#$ Call Girls In Arjan
Arjan Call Girl Service #$# O56521286O $#$ Call Girls In ArjanArjan Call Girl Service #$# O56521286O $#$ Call Girls In Arjan
Arjan Call Girl Service #$# O56521286O $#$ Call Girls In Arjan
 
Webinar - Payscale Innovation Unleashed: New features and data evolving the c...
Webinar - Payscale Innovation Unleashed: New features and data evolving the c...Webinar - Payscale Innovation Unleashed: New features and data evolving the c...
Webinar - Payscale Innovation Unleashed: New features and data evolving the c...
 
How Leading Companies Deliver Value with People Analytics
How Leading Companies Deliver Value with People AnalyticsHow Leading Companies Deliver Value with People Analytics
How Leading Companies Deliver Value with People Analytics
 
HRM PPT on placement , induction and socialization
HRM PPT on placement , induction and socializationHRM PPT on placement , induction and socialization
HRM PPT on placement , induction and socialization
 

Risk Mgt Training Slides (1).pptx

  • 1. Risk Management Introduction to Risk Management (Theory & Practice) DCU Risk & Compliance Officer November 2015
  • 2. Risk Management Sections 1) Aims of presentation 2) What is Risk Management (RM)? 3) RM Cycle 4) Categories of risk 5) Risk Register 6) Risk Appetite 7) Tips for success 8) Why RM may fail 9) Summary & conclusion
  • 3. Risk Management Aims of this presentation • To explain why it is relevant • To explain its components i.e. the “Risk Cycle” • Guidance on Preparing a “Risk Register” Risk management techniques Reporting on risks
  • 4. Risk Management Place for Risk Management?
  • 5. Risk Management What is Risk Management? It is a process to:  Identify all relevant risks  Assess / rank those risks  Address the risks in order of priority  Monitor risks & report on their management
  • 6. Risk Management Risk Management – why do we need it? Promotes good management May be a legal requirement depending upon industry or sector Resources available are limited – therefore a focused response to Risk Management is needed
  • 7. Risk Management What is a Risk?  A risk is an uncertain event which may occur in the future  A risk may prevent or delay the achievement of an organization’s or units objectives or goals A risk is not certain – Its likelihood can only be estimated Note: Not all risk is bad, some level of risk must be taken in order to progress / prevent stagnation.
  • 9. Risk Management Risk Management Cycle – Step 1 Missio n • Define Purpose Strateg y • High level Plan Goal s • Unit Specific Targets
  • 10. Risk Management Risk Management Cycle – Step 2 Risk Identification – what are the threats and uncertainties associated with my organization’s or units objectives? • Separate out the risk into its cause & possible effect • Be concise & clear • Do not concentrate on symptoms only
  • 11. Risk Management Risk Management Cycle – Step 2 cont. • Assess the risk’s  Impact  Likelihood (Guidance on both later!) • Prioritize the risks • Hint: Get input from appropriate individuals
  • 12. Risk Management Risk Management Cycle – Step 3 Challenge & Evaluate Controls Control: Policy, action, procedure or process designed to prevent risk or to limit its impact Do they work, are they effective? Residual Risk only should be measured
  • 13. Risk Management Risk Management Cycle – Step 4 TakeAction!  For serious risks where controls are A) Weak B) Absent  For risks where the Risk Appetite is exceeded  Examine Cost vs. Benefit
  • 14. Risk Management Risk Management Cycle – Step 4 cont. Types of Action A) Tolerate B) Treat C) Substitute D) Terminate (The choice of the above will be decided upon by your risk appetite)
  • 15. Risk Management Risk Management Cycle – Step 5 Monitor & Report  Use a standard format for capturing risk data e.g. a “RiskRegister”  Review all risks at least annually  Serious risks to be reviewed more often depending on circumstances  Report on risk to senior management / Board  Make Risk Register available to stakeholders to show good governance
  • 16. Risk Management Categories of Risks  There are multiple ways into which risks can be categorized  Final categories used will depend upon each organizations / unit’s circumstances  Goal is to cluster risks into standard, meaningful & actionable groupings  What follows is one example of a type of categorization
  • 17. Risk Management Categories of Risks Financial  Reduction in funding  Failure to safeguard assets  Poor cash flow management  Lack of value for money  Fraud / theft  Poor budgeting
  • 18. Risk Management Categories of Risks cont. Operational These risks result from failed or inappropriate policies, procedures, systems or activities e.g.  Failure of an IT system  Poor quality of services delivered  Lack of succession planning  Health & Safety risks  Staff skill levels  No process to track contractual commitments
  • 19. Risk Management Categories of Risks cont. Reputational • Organization engages in activities that could threaten it’s good name  Through association with other bodies  Staff / members acting in a criminal or unethical way • Poor stakeholder relations
  • 20. Risk Management Categories of Risk cont. Governance & Compliance • Lack of oversight by Board • Segregation of duties not defined formally • Ensuring compliance with funders terms and conditions • Compliance with applicable legislation  Safeguarding of vulnerable individuals  Taxation Law  Data Protection  Health & Safety Law
  • 21. Risk Management Categories of Risk cont. Strategic • Engages in activity at variance with its stated objectives • Fails to engage in an activity that would support its stated objectives
  • 22. Risk Management Risk Register a) What is it? b) Components c) How to report on it
  • 23. Risk Management Risk Register cont.  A Risk Register is a management tool used to record relevant details relating to risks.  It is a database of information on risks.  Best kept simple to begin with!
  • 24. Risk Management – Register Example
  • 25. Risk Management Parts of a Risk Register Risk Description – Clear description of risk, its cause & consequence Controls / Actions already in place – List what is actually happening now which reduces the impact of a risk or its likelihood Impact – scale of 1 to 5 (1 = minor, 5 = catastrophic) (Note this is to be residual impact only) Likelihood – scale of 1 to 5 (1 = remote, 5 = unavoidable) (Note this is to be residual likelihood only) Weighting – Its Risk Ranking: a calculated figure i.e. impact x likelihood
  • 26. Risk Management Parts of a Risk Register cont. Risk Owner – The administrative unit, management position or group who are in the best position to manage the risk on an on-going basis Further Actions Required – The controls / solutions which have yet to be acted upon which could reduce the impact or likelihood of a risk Date – The expected date as to when the actions shown under further actions required will be in place & effectively addressing the risk
  • 27. Risk Management – Emample of a Matrix
  • 28. Risk Management Tips for Success  Involve all levels of staff & management in the process  Check controls are relevant & effective  Ensure risk owner takes responsibility for management of risks under their control  Focus on risk cause, not its symptoms
  • 29. Risk Management Why Risk Management May Fail  Limitations of scope  Lack of top management support  Did not engage all stakeholders  Failure to share information  RM not embedded within planning & management system
  • 30. Risk Management Summary & Conclusion We have covered:  Definition of risk  Risk Management cycle  Categories of risk  Risk Register – how to guide  Possible pit falls in a Risk Management process
  • 31. Risk Management Place for Risk Management?