Strategic risk management
|Strategic risk management|
|Methods and techniques|
Strategic risk management enables top management to link strategy with risk management in highly uncertain environment. Achievement of goals described in the strategy requires identification and dealing with risks. The strategic risk management is part of enterprise risk management (ERM) as defined by COSO (Committee of Sponsoring Organizations of the Treadway Commission) in Enterprise Risk Management—Integrated Framework in 2004.
As the environment becomes more and more turbulent, and long-term planning gets shorter and shorter due to inability to predict future, the strategic risk management becomes a necessary tool for managers. It helps extend planning and increase its accuracy, which translated into decline in losses related to bad strategic decisions.
6 principles of strategic risk management
M.L. Frigo and R.J. Anderson defined six principles of strategic risk management in relation to ERM:
- It's a process for identifying, assessing, and managing both internal and external events and risks that could impede the achievement of strategy and strategic objectives.
- The ultimate goal is creating and protecting shareholder and stakeholder value.
- It's a primary component and necessary foundation of the organization's overall enterprise risk management process.
- As a component of ERM, it is by definition effected by boards of directors, management, and others.
- It requires a strategic view of risk and consideration of how external and internal events or scenarios will affect the ability of the organization to achieve its objectives.
- It's a continual process that should be embedded in strategy setting, strategy execution, and strategy management.
Strategic risk management process
The strategic risk management process was proposed by M. Tonello:
- Achieve a deep understanding of the strategy of the organization
- Gather views and data on strategic risks
- Prepare a preliminary strategic risk profile
- Validate and finalize the strategic risk profile
- Develop a strategic risk management action plan
- Communicate the strategic risk profile and strategic risk management action plan
- Implement the strategic risk management action plan
See also: risk management process.
Implementation of SRM
Implementation of SRM in the enterprise requires to deal with four main issues:
- Corporate governance,
- Reward mechanisms,
- Organization size, structure and culture
If the goals of top management are different than those of enterprise owners, the increased exposure to risks is inevitable. The risk level accepted by managers can be lowered if they are also owners of the company. If the power of investors is low, the managers tend to take higher risks. Therefore, effective corporate governance is necessary for SRM to work properly.
The personnel should be prepared for risk events to avoid panic and wrong decisions. The managers should teach personnel how to behave in case of crisis situations. They should also create a set of procedures and risk management plans. The personnel and managers should be rewarded for good decisions related to risks. Some add that they should be also punished for bad ones.
The whole implementation of SRM usually requires change in the organizational culture. In case of risk management, the communication systems should be fast and reliable, personnel must not be afraid of taking about risks. This helps to identify all the risks related to enterprise strategy.
- COSO (2004) Enterprise Risk Management—Integrated Framework
- Frigo M.L., Anderson R.J. (2011), What Is Strategic Risk Management, Strategic Finance, April
- Tonello M. (2012) Strategic Risk Management: A Primer for Directors, Harvard Law School Forum on Corporate Governance and Financial Regulation, The Conference Board, August 12
- Damodaran A.Strategic risk management, Damodaran Online
Author: Slawomir Wawak