SlideShare a Scribd company logo
1 of 2
It is widely accepted that risk is calculated by multiplying the impact of an event by its probability of
occurrence. Here, Hernan Huwyler has a look at some alternatives for measuring risk and how they fit
into the day-to-day risk management framework
THE AUTHOR
Hernan Huwyler is a risk
management and internal
control specialist. His
background includes
management positions
with Veolia, Tenaris,
Baker Hughes,
ExxonMobil and Deloitte
Enterprise Risk Services
where he has served in
financial, audit and
compliance leadership
roles. He teaches
postgraduate courses in
risk, audit and
compliance at Instituto de
Empresa, Universidad
Complutense de Madrid,
the Comillas Pontifical
University and the Centro
de Estudios Financieros.
n the early days of enterprise risk
management as a discipline, it was
widely accepted that risk was calculated
by multiplying the impact of an event
by its probability of occurrence. Over time,
risk professional circles developed several
concepts to provide ever greater insights
to the actuarial approach based on impact
and frequency. Heat maps and risk
dashboards gradually integrated additional
measurement variables by using colors,
symbols and dot sizes. These new
concepts had not yet developed to
standard definitions and uses; and terms
are often mixed up by risk practitioners.
This article is aimed at clarifying common
definitions and specific benefits of
additional dimensions for measuring risks.
It allows customization of risk methodology
and registry to accommodate wider
stakeholders’ needs.
Velocity
This refers to the time elapsed from the
event occurrence until the performance is
impacted by a gain or a loss. It assesses
how fast the chain of events will actually
affect the business, in other words, the
speed of onset. For instance, a high-risk
velocity is a situation in which the
consequences are immediately reflected
into the business objectives such as a fire,
an earthquake and many other natural
hazards. Diseases caused by decades of
exposure to asbestos and the many
resultant legal claims are good examples of
low velocity risks. Understanding the
velocity of events is a key step in measuring
the impact of risks.
The velocity of risk can be linked to the
need for effective crisis management with
early detection and urgency for developing
action plans. It helps to assess how much
time will be available to prepare a
response and the number of warnings the
company will receive before a risk strikes.
Even the time elapsed to reflect the impact
of risk is discounted by calculation
methodologies, such as value-at-risk.
Showing this variable in risk maps helps
managers to prioritize action plans.
A related dimension, ‘risk persistence’, may
also show how long the effects of the risk
event are expected to last. Some ERM
practitioners divide risk velocity into the time
to impact from the occurrence to when the
consequences are felt and the time
to react, from the occurrence to when
the contingency actions should start.
Vulnerability
This refers to the tendency of assets to be
affected by risks. It assesses how well the
assets of a company are prepared to react
to risks, including the mitigation plans and
the crisis management skills. This variable
is highly popular in information security,
health and disaster risk assessments.
A highly vulnerable asset increases both the
impact and the frequency of risks. For
instance, a high vulnerability risk is a
situation in which there are deficiencies or a
lack of capacity exposing assets to threats.
Examples include, coastal areas in a
tsunami risk, unvaccinated people in an
epidemic, or unsecured servers in a hacking
attack. Understanding the drivers of
vulnerability is
30 The Risk Universe May 2017
a key step in identifying mitigation plans.
The vulnerability of a risk can be linked
to business resilience. Risk managers
make better unbiased assessments when
identifying the underlying vulnerabilities of
the physical and intangible assets under
evaluation. This dimension also allows for
monitoring the evolution of residual risks
after implementing the mitigation factors,
strategies and controls which build
resilient companies.
Effectiveness
This refers to how effectively the
underlying processes and assets are
controlled by the company. For instance, a
robust control and compliance environment
helps in the effectiveness of risk
management plans. High effectiveness
reduces the probability
Measuring risk
volatility allows
identification of
needs
for horizon
scanning,
Monte Carlo
simulations,
stress testing
and other
scenario-based
analyses
Measuring risk
of a risk occurring. Measuring the
confidence in the effectiveness of controls
helps to integrate risk into comprehensive
GRC initiatives.
Preparedness
This refers to how effectively the
company reacts once an event occurs, for
instance by having implemented
contingency plans, cost and schedule
reserves or incident management tools.
This dimension assesses the capacity to
respond to and recover from a risk event. It
measures the ex-ante investments in
implementing early warnings, emergency
and contingency measures and business
continuity plans. High preparedness
reduces the impact of a risk, particularly for
high-velocity risks.
The preparedness dimension can be
linked to the risk communication, the
training program and the need for testing
and improving contingency plans for
disruptive risks. The analysis of this
dimension is relevant for operational and
compliance risks, but critical for strategic
risks.
Volatility
This refers to the stability of a risk over
time, which makes its measurement
difficult. The nature of emerging risks and
unfamiliarity with new and undefined risk
factors increases volatility. For instance,
ever-changing compliance regulations
increase the risk of receiving sanctions and
litigation. Risks cannot be properly
modelled and measured when the volatility
in their factors is high to extreme.
Measuring risk volatility allows
identification of needs for horizon scanning,
Monte Carlo simulations, stress testing and
other scenario-based analyses.
Risk programs adapt expeditiously in a
more uncertain and volatile world. In this
context, enterprise risk management
should improve the continuous process to
predict how the reputational and financial
performance will be impacted by different
variables. Risk managers should be
pragmatic when deciding what dimensions
are cost-effective to support the decision-
making process of their companies.
May 2017 The Risk Universe 31

More Related Content

What's hot

INFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAM
INFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAMINFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAM
INFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAM
Christopher Nanchengwa
 
ISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final VersionISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final Version
Duncan O. Ogutu; CPA, CFE
 

What's hot (20)

Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwylerStronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
 
Quantitative Data-Driven Risk Management and Internal Audit
Quantitative Data-Driven Risk Management and Internal AuditQuantitative Data-Driven Risk Management and Internal Audit
Quantitative Data-Driven Risk Management and Internal Audit
 
INFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAM
INFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAMINFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAM
INFORMATION AND COMMUNICATIONS TECHNOLOGY PROGRAM
 
Risk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and ImplementationRisk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and Implementation
 
International Standard on Assurance Engagements ISAE 3000 Audits
International Standard on Assurance Engagements ISAE 3000 AuditsInternational Standard on Assurance Engagements ISAE 3000 Audits
International Standard on Assurance Engagements ISAE 3000 Audits
 
IFCA Congress How the post-pandemic will shape the compliance agenda
IFCA Congress How the post-pandemic will shape the compliance agendaIFCA Congress How the post-pandemic will shape the compliance agenda
IFCA Congress How the post-pandemic will shape the compliance agenda
 
CISSPills #3.04
CISSPills #3.04CISSPills #3.04
CISSPills #3.04
 
Practical approach to security risk management
Practical approach to security risk managementPractical approach to security risk management
Practical approach to security risk management
 
Risk Assessment And Management
Risk Assessment And ManagementRisk Assessment And Management
Risk Assessment And Management
 
Centralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and ComplianceCentralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and Compliance
 
Building an Effective AML Program
Building an Effective AML ProgramBuilding an Effective AML Program
Building an Effective AML Program
 
Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA
Security and Governance Done Right - Prof. Hernan Huwyler MBA CPASecurity and Governance Done Right - Prof. Hernan Huwyler MBA CPA
Security and Governance Done Right - Prof. Hernan Huwyler MBA CPA
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Risk management
Risk managementRisk management
Risk management
 
Management of risk introduction
Management of risk introductionManagement of risk introduction
Management of risk introduction
 
ISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final VersionISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final Version
 
Ballot: Risk Assessments Made Simple
Ballot: Risk Assessments Made SimpleBallot: Risk Assessments Made Simple
Ballot: Risk Assessments Made Simple
 
The importance of risk management in business
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in business
 
CISSPills #3.03
CISSPills #3.03CISSPills #3.03
CISSPills #3.03
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 

Similar to Dimensions in Risk Measurement

Risk management Phase 1-5 Individual Project.docx
Risk management Phase 1-5 Individual Project.docxRisk management Phase 1-5 Individual Project.docx
Risk management Phase 1-5 Individual Project.docx
joellemurphey
 
IntroductionThe standards of venture risk administration can be .docx
IntroductionThe standards of venture risk administration can be .docxIntroductionThe standards of venture risk administration can be .docx
IntroductionThe standards of venture risk administration can be .docx
mariuse18nolet
 
Table of ContentsIntroduction3P.docx
Table of ContentsIntroduction3P.docxTable of ContentsIntroduction3P.docx
Table of ContentsIntroduction3P.docx
mattinsonjanel
 
In the risk prioritization step, the overall set of identified risk .pdf
In the risk prioritization step, the overall set of identified risk .pdfIn the risk prioritization step, the overall set of identified risk .pdf
In the risk prioritization step, the overall set of identified risk .pdf
annaelctronics
 
RISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdf
RISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdfRISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdf
RISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdf
olabisiali
 

Similar to Dimensions in Risk Measurement (20)

Risk management Phase 1-5 Individual Project.docx
Risk management Phase 1-5 Individual Project.docxRisk management Phase 1-5 Individual Project.docx
Risk management Phase 1-5 Individual Project.docx
 
IntroductionThe standards of venture risk administration can be .docx
IntroductionThe standards of venture risk administration can be .docxIntroductionThe standards of venture risk administration can be .docx
IntroductionThe standards of venture risk administration can be .docx
 
Table of ContentsIntroduction3P.docx
Table of ContentsIntroduction3P.docxTable of ContentsIntroduction3P.docx
Table of ContentsIntroduction3P.docx
 
In the risk prioritization step, the overall set of identified risk .pdf
In the risk prioritization step, the overall set of identified risk .pdfIn the risk prioritization step, the overall set of identified risk .pdf
In the risk prioritization step, the overall set of identified risk .pdf
 
Quantification of Risks in Project Management
Quantification of Risks in Project ManagementQuantification of Risks in Project Management
Quantification of Risks in Project Management
 
RISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdf
RISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdfRISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdf
RISK TEMPLATE FORMATE GOOD-ALIU OLAB.pdf
 
Project/Program Risk management
Project/Program Risk managementProject/Program Risk management
Project/Program Risk management
 
RISK MANAGEMENT Essays
RISK MANAGEMENT EssaysRISK MANAGEMENT Essays
RISK MANAGEMENT Essays
 
Lecture 6 Managing risk.pptx
Lecture 6 Managing risk.pptxLecture 6 Managing risk.pptx
Lecture 6 Managing risk.pptx
 
The incorporation of sustainability risks into the risk culture | Albert Vila...
The incorporation of sustainability risks into the risk culture | Albert Vila...The incorporation of sustainability risks into the risk culture | Albert Vila...
The incorporation of sustainability risks into the risk culture | Albert Vila...
 
Risk management
Risk managementRisk management
Risk management
 
Crisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdfCrisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdf
 
Crisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdfCrisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdf
 
Crisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdfCrisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdf
 
Crisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdfCrisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdf
 
Crisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdfCrisis Management for Events How to Handle Unexpected Challenges.pdf
Crisis Management for Events How to Handle Unexpected Challenges.pdf
 
ERM -01- Introduction 06-10-2022.pptx
ERM -01- Introduction 06-10-2022.pptxERM -01- Introduction 06-10-2022.pptx
ERM -01- Introduction 06-10-2022.pptx
 
12-RISK-MANAGEMENT-PROCEDURES-METHODS-AND-EXPERIENCES-RTA_2_2010-09.pdf
12-RISK-MANAGEMENT-PROCEDURES-METHODS-AND-EXPERIENCES-RTA_2_2010-09.pdf12-RISK-MANAGEMENT-PROCEDURES-METHODS-AND-EXPERIENCES-RTA_2_2010-09.pdf
12-RISK-MANAGEMENT-PROCEDURES-METHODS-AND-EXPERIENCES-RTA_2_2010-09.pdf
 
Project risk management - Methodology and application
Project risk management - Methodology and applicationProject risk management - Methodology and application
Project risk management - Methodology and application
 
Risk Management Essay
Risk Management EssayRisk Management Essay
Risk Management Essay
 

More from Hernan Huwyler, MBA CPA

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Hernan Huwyler, MBA CPA
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Hernan Huwyler, MBA CPA
 
Model to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdfModel to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdf
Hernan Huwyler, MBA CPA
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Hernan Huwyler, MBA CPA
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler, MBA CPA
 

More from Hernan Huwyler, MBA CPA (20)

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
 
Model to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdfModel to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdf
 
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsProf Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
 
The Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfThe Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdf
 
R is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using RR is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using R
 
Compliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerCompliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan Huwyler
 
DPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksDPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy Risks
 
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerMaster in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
 
Cyber Laundering and the AML Directives
Cyber Laundering and the AML DirectivesCyber Laundering and the AML Directives
Cyber Laundering and the AML Directives
 
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
 
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
 
10 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 3730110 Mistakes in Implementing the ISO 37301
10 Mistakes in Implementing the ISO 37301
 
Qa Financials - 10 Smart Controls for Software Development
Qa Financials  - 10 Smart Controls for Software DevelopmentQa Financials  - 10 Smart Controls for Software Development
Qa Financials - 10 Smart Controls for Software Development
 
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
 
Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks
 
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized World
 
Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340Hernan Huwyler MetricStream German Law idw ps 340
Hernan Huwyler MetricStream German Law idw ps 340
 

Recently uploaded

Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
amitlee9823
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
daisycvs
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
dollysharma2066
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
Renandantas16
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
lizamodels9
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
Matteo Carbone
 

Recently uploaded (20)

Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 

Dimensions in Risk Measurement

  • 1. It is widely accepted that risk is calculated by multiplying the impact of an event by its probability of occurrence. Here, Hernan Huwyler has a look at some alternatives for measuring risk and how they fit into the day-to-day risk management framework THE AUTHOR Hernan Huwyler is a risk management and internal control specialist. His background includes management positions with Veolia, Tenaris, Baker Hughes, ExxonMobil and Deloitte Enterprise Risk Services where he has served in financial, audit and compliance leadership roles. He teaches postgraduate courses in risk, audit and compliance at Instituto de Empresa, Universidad Complutense de Madrid, the Comillas Pontifical University and the Centro de Estudios Financieros. n the early days of enterprise risk management as a discipline, it was widely accepted that risk was calculated by multiplying the impact of an event by its probability of occurrence. Over time, risk professional circles developed several concepts to provide ever greater insights to the actuarial approach based on impact and frequency. Heat maps and risk dashboards gradually integrated additional measurement variables by using colors, symbols and dot sizes. These new concepts had not yet developed to standard definitions and uses; and terms are often mixed up by risk practitioners. This article is aimed at clarifying common definitions and specific benefits of additional dimensions for measuring risks. It allows customization of risk methodology and registry to accommodate wider stakeholders’ needs. Velocity This refers to the time elapsed from the event occurrence until the performance is impacted by a gain or a loss. It assesses how fast the chain of events will actually affect the business, in other words, the speed of onset. For instance, a high-risk velocity is a situation in which the consequences are immediately reflected into the business objectives such as a fire, an earthquake and many other natural hazards. Diseases caused by decades of exposure to asbestos and the many resultant legal claims are good examples of low velocity risks. Understanding the velocity of events is a key step in measuring the impact of risks. The velocity of risk can be linked to the need for effective crisis management with early detection and urgency for developing action plans. It helps to assess how much time will be available to prepare a response and the number of warnings the company will receive before a risk strikes. Even the time elapsed to reflect the impact of risk is discounted by calculation methodologies, such as value-at-risk. Showing this variable in risk maps helps managers to prioritize action plans. A related dimension, ‘risk persistence’, may also show how long the effects of the risk event are expected to last. Some ERM practitioners divide risk velocity into the time to impact from the occurrence to when the consequences are felt and the time to react, from the occurrence to when the contingency actions should start. Vulnerability This refers to the tendency of assets to be affected by risks. It assesses how well the assets of a company are prepared to react to risks, including the mitigation plans and the crisis management skills. This variable is highly popular in information security, health and disaster risk assessments. A highly vulnerable asset increases both the impact and the frequency of risks. For instance, a high vulnerability risk is a situation in which there are deficiencies or a lack of capacity exposing assets to threats. Examples include, coastal areas in a tsunami risk, unvaccinated people in an epidemic, or unsecured servers in a hacking attack. Understanding the drivers of vulnerability is 30 The Risk Universe May 2017
  • 2. a key step in identifying mitigation plans. The vulnerability of a risk can be linked to business resilience. Risk managers make better unbiased assessments when identifying the underlying vulnerabilities of the physical and intangible assets under evaluation. This dimension also allows for monitoring the evolution of residual risks after implementing the mitigation factors, strategies and controls which build resilient companies. Effectiveness This refers to how effectively the underlying processes and assets are controlled by the company. For instance, a robust control and compliance environment helps in the effectiveness of risk management plans. High effectiveness reduces the probability Measuring risk volatility allows identification of needs for horizon scanning, Monte Carlo simulations, stress testing and other scenario-based analyses Measuring risk of a risk occurring. Measuring the confidence in the effectiveness of controls helps to integrate risk into comprehensive GRC initiatives. Preparedness This refers to how effectively the company reacts once an event occurs, for instance by having implemented contingency plans, cost and schedule reserves or incident management tools. This dimension assesses the capacity to respond to and recover from a risk event. It measures the ex-ante investments in implementing early warnings, emergency and contingency measures and business continuity plans. High preparedness reduces the impact of a risk, particularly for high-velocity risks. The preparedness dimension can be linked to the risk communication, the training program and the need for testing and improving contingency plans for disruptive risks. The analysis of this dimension is relevant for operational and compliance risks, but critical for strategic risks. Volatility This refers to the stability of a risk over time, which makes its measurement difficult. The nature of emerging risks and unfamiliarity with new and undefined risk factors increases volatility. For instance, ever-changing compliance regulations increase the risk of receiving sanctions and litigation. Risks cannot be properly modelled and measured when the volatility in their factors is high to extreme. Measuring risk volatility allows identification of needs for horizon scanning, Monte Carlo simulations, stress testing and other scenario-based analyses. Risk programs adapt expeditiously in a more uncertain and volatile world. In this context, enterprise risk management should improve the continuous process to predict how the reputational and financial performance will be impacted by different variables. Risk managers should be pragmatic when deciding what dimensions are cost-effective to support the decision- making process of their companies. May 2017 The Risk Universe 31