Hidden Strategic Risk

strategic riskHow is it that strategic risk assessment misses the obvious?  It seems the most fundamental risks, although right out in the open, are not recognized as risks.

How to Identify Strategic Risk
First, the basic process: As discussed in previous posts, strategic risk assessment should be a review of goals, objectives and corporate values, as expressed in a plan. Risk assessment benefits from a multi-disciplinary round table reviewing the schedule of intended action. The risk lens brings to light the things that may prevent the successful execution of the plan.

Tracing through all stages of the plan, ask the question: What could hinder or prevent the accomplishment of this particular objective?; or, What could compromise the safeguarding of this professional value? In the broadest analysis, it is a matter of identifying phenomena that call into question the strategic direction, approach to a project, or feasibility of a program. The mitigation of such risk involves action on the same scale: to shift the planned direction; to build up one aspect of the business; to attenuate another.

Systemic Risk – Challenging Assumptions

Risk managers should contribute to long range planning and analysis. They can cause planners and modellers to recast their assumptions. In a recent workshop, participants and I were discussing risk assessment of the firm’s strategic plan, and considered wider systemic risk and emerging risk, that could undermine the organization.

On the issue of strategic risk, I first draw the reader’s attention to my 6-part series in which I discussed high quality risk assessment and future scenarios; strategic identity; stakeholders; and environmental scan. The essential point in that series is that risk assessment should be part of a complete research and planning process, including methods to deal with “black swan” risks and high uncertainty.

In this post, I want to elaborate on the idea of risk managers questioning assumptions that typically go unchallenged.

Reprint – Risk Analysis for Tough Issues

Edward Robertson-article-risk-management-magazineThe Economist’s risk management study in 2010 found that there is a continuing perception of risk management as: “…support function staffed with narrowly focused specialists, such as business continuity planners, insurance buyers, or health and safety officers…” (Fall guys – risk management in the front line). Then Forbes/Deloitte reported in 2012 that a significant sector of corporate employees are “unaware of what they need to do concerning risk”. (Aftershock: adjusting to the new world of risk management).

Back December 2006 I published an article with Risk Management Magazine. It is relevant to the question of broadening the risk manager’s role to bring risk assessment to strategic planning and policy. I wouldn’t change a word of it today.

Definitions: ERM and Risk Assessment – Part 2/2

definition enterprise risk management risk assessmentIn this second post, I give my proposed definition of both Enterprise Risk Management and Risk Assessment.  They are not a reflection of the actual usage of the terms; instead, they are recommendations for what the terms should denote:

Definition of Enterprise Risk Management

Enterprise Risk Management: A distributed process of risk assessment applied to strategy and operations, in all domains, in support of corporate goals and values.
Definitions: ERM and Risk Assessment – Part 1/2

definition enterprise risk management, risk assessment Enterprise Risk Management is a relatively young discipline. There is no universal agreement on what it really consists of. In some of the academic literature, the definition is assumed. Authors don’t bother with it, and yet actual practice of what people call ERM is varied.

I want to give a critique of some of the definitions of Enterprise Risk Management having currency in management discourse, and then propose my own definition of ERM. Standards such as ISO or AS/NZ 4360 do not define or even contain the term Enterprise Risk Management. But they do define risk itself consistently as being associated with the organization’s goals and objectives.

ERM Case Study – Part 5/5

Entrepreneurial universityHere are links (some not appearing in previous posts) germane to the case study of Enterprise Risk Management implementation at Camosun College.

New Employee Manual

President’s Welcome Message

ERM Case Sudy – Part 4/5

Entrepreneurial universitySo far in this series of posts, we have seen the genesis of the ERM program in the decision by the Board of Governors; the project team’s review of background materials; and the decision to begin with a trial risk assessment applied to the strategic plan. Now we consider how ERM was developed and rolled out to the rest of the organization.

Conclusions Drawn from Initial Risk Review
The trial risk assessment of the strategic plan yielded a risk register addressing all the main strategic objectives. The plans for mitigation developed by the executive were, for example, to adjust program…

ERM Case Study – Part 3/5

Entrepreneurial universityThis is the next post in the Enterprise Risk Management implementation case study of Camosun College, B.C., Canada.

Project Approach – Key Players

As mentioned previously, the idea for enterprise risk management came from the Board of Governors, who were keen to participate in the provincial government’s foray into the new practice. While many public sector executive seemed at least intellectually to accept the idea of applying risk methods to strategy, the Board wanted to see it done and effect some real changes.
