Tuesday, April 10, 2012

First International Conference on ISO 31000

If you're looking for a good excuse to visit Paris in the spring, I can think of few better excuses than the First International conference on the ISO 31000 Risk Management Standard.
The conference will take place there on the 21st and 22nd of May 2012.



"This international conference on ISO 31000 is addressed for the first time to the global risk management community active across all fields, sectors, industries and services related to risk management. We have gathered together an outstanding panel of international experts and practitioners from your sector to share their current perspectives on the ISO 31000 Risk Management standard”, said Alex Dali, President of G31000, the international non-for-profit NGO based in France dedicated to raise awareness on ISO 31000 standard.

With more than 30+ speakers, 4 plenary sessions and 10 parallel sessions and a focus purely on applying ISO31000, this conference is the risk management event of the year.

Plenary sessions:
  • Why ISO 31000 will become the global Risk Management standard
  • 20 years of Risk Management Standardisation - Past, Present and Future 
  • Why every RM programme should be based on ISO 31000
  • How to implement or adapt your RM programme using ISO 31000
  • G31000 – the new Platform for ISO 31000
Parallel sessions:
  • Regulatory Authorities 
  • Business Continuity
  • Software
  • Security
  • Internal Audit
  • Finance and Banking
  • Moving from COSO ERM
  • Raising awareness, worldwide 
  • Education
  • Human Factors
More information and registration details can be found at http://www.G31000conference2012.org and a 10% discount is available if you use booking code: G7ACCX.


I'll be presenting there and will look forward to catching up with colleagues, and hopefully meeting a few readers of this blog at the conference.

Sunday, January 15, 2012

How to build a risk management framework


Section 4 of ISO31000 opens with the simple statement that "The success of risk management will depend on the effectiveness of the management framework providing the foundations and arrangements that will embed it throughout the organization at all levels."  The standard devotes about 5 pages to talking about what a framework requires and sums it up in the Figure 1 below.
Figure 1: Relationship between the components of the framework for managing risk (ISO31000)

We'll go even further, and say that the risk management framework is the heart of organizational risk management. It might be tempting to overlook this portion of ISO31000 or to downplay its significance and jump straight to Section 5: Process but that would be a mistake.  No matter how much you and your organization know about risk, no matter how excellent your latest risk assessment is and despite an outstanding risk treatment plan, unless an organization has a well structured and appropriate risk management framework it will not have a sustainable risk management system.

Of all the elements of ISO31000, building the risk management framework deserves primacy for this is where policy, mandate, organizational commitment and structure set the scene for ongoing successful application of risk management.  And it isn't a one-time event. Like most of risk management, it is an iterative, adaptive process and as you can see from Figure 1, the authors of ISO31000 clearly intended it to be a cyclical process.

At the very least a framework should provide you with guidance regarding how your organization manages risk and in particular provides:
A centralized and comprehensive source of risk policy, procedures and information.
A consistent taxonomy for classification and prioritization of risk.
Automated (or at least consistent) workflow for risk management.
Auditable paper trail of records, decisions made and changes.

Putting this into action however isn't a simple task but if you consider what actually needs to go into it, the following graphic and our next blog entry will offer a couple of suggestions. 

The three most important elements in actually turning risk management theory into risk management practice will inevitably be training, training and more training.  How you put together the underlying framework for your organization however, will depend on your context and existing management systems. Whatever result you end up with, It’s likely to include three common elements: Direction, Systems and Execution.  I built this framework for a large Commonwealth government department a few years ago, and part of the brief was that it had to be easy to grasp the underlying principle.

DIRECTION is set by the Executive management team and in order of priority is based on:
  • Organizational objectives vision and mission (ie. The reason for existence of the organization). 
  • A risk assessment based on those objectives
  • A risk treatment plan to support achievement of the objectives (which might also be known as a Strategic Plan, Operational Plan, etc)
SYSTEMS are the management infrastructure that provides technical and policy guidance for implementation of the organizations plans and uses four core elements:
  • Policies and Management Standards - set the high level expectations and guide decision making
  • Procedures and Guidelines - provide the step by step process flows to implement the policies as well as some general guidance about how to interpret high level policy or standards.
  • Work Instructions – provide task specific detailed instructions for each step in the process flow.
  • Forms, Templates & Tools – are the specific tools and documentation that people will use to identify, assess and document risks.
EXECUTION is the phase where the plans, policies, objectives that have been so carefully developed, are finally implemented using three phases of this process:
  • Training Needs Analysis – involves identifying what people need to know in order to implement the ‘Systems’ previously developed. 
  • Training & Implementation – involves delivering the training that your people will need so that they can begin to correctly implement the various elements that support organizational objectives.
  • Reporting, Monitoring & Review – are the final elements to close the feedback look, assess how effective the framework is and provide appropriate feedback for continuous improvement. 
You’ll find this concept illustrated in Figure 2 below. It’s a relatively simple example of a framework but is easy enough to explain to people and equally importantly is highly scalable. 
Figure 2: Illustrative Example of a Risk Management Framework
Figure 2 is a relatively simple risk management framework. There are of course, many ways to view risk and the interactions of the various elements involved. It’s not the intention of this book to provide a single ‘perfect’ risk management framework – you need to work that out for yourself- but we’ll provide a couple of ideas to get you started.

In the next blog article, we'll look at a more complex version of a risk management framework which might suit larger organizations.


Friday, December 16, 2011

The role of the business case in risk management


Well-conceived and thoroughly researched business cases can play a pivotal role in improving the quality of organizational decision-making. The business case does not however, stand by itself as a risk management tool. It is simply part of a toolbox for analyzing and making decisions about proposed risk treatments.

Whatever risk treatment you’re considering, and whatever means you used to identify it, the business case is designed to determine and enunciate the value of that treatment. In Figure 1, we’ve used the ISO31000:2009 Risk Management Standard process to illustrate the role of the business case. Quite simply, it supports analysis, selection and implementation of risk treatments.
Figure 1: The Role of Business Cases in the context of ISO31000 Risk Management Process
At the risk of stating the obvious, lets go back to basics for a moment. Any proposed risk treatment should relate directly to a specific risk or risks. For example, if risk number one in your risk register is “Failure to deliver organizational outcomes within budget due to inadequate financial reporting” you might end up with a range of risk treatments, each of which will have different merits.  It’s worth pointing out at the moment that ‘risk’ includes both opportunities and threats (benefits and costs). Accordingly, you might also choose to rephrase the above risk in as an opportunity, such as “Increased profitability due to cost reductions resulting from improved financial reporting”.

Irrespective of how you phrase this risk, lets say that in our hypothetical example, you have identified two main treatments to address it. You’ll note from the examples in Table 1, that we’ve included a reference to which risk(s) each treatment addresses.

Table 1: Example of Risk Treatment Plan
In this hypothetical treatment plan (Table 1) each treatment has a reference to the risks it addresses. Risk Treatments number 1 and 2, primarily address risk number 1 but they also contribute to reducing the risks associated with risks 5 and 8. It’s not important what risks 5 and 8 actually are (it’s a hypothetical example remember). Risk number 8 may in fact be addressed primarily by Treatment number 4 and potentially also be improved by Treatments 1 and 11. It’s a complicated scenario but it’s worth remembering when you are defining the benefits of treatment number one, that you should consider it’s impact on risks number 5 and 8. You never know, it could be the indirect benefits of your proposed risk treatment that sways the decision makers in favor of supporting it. Add in ALL the intangible and indirect benefits. They all count.

Thursday, December 15, 2011

The Evolution of Risk Management...


It is sometimes tempting to respond to a risk or an incident, with a knee-jerk response by throwing time, money and effort at a quick fix.  That’s entirely understandable, given that our risk management decision-making evolved from a fight or flight response.  As Daniel Kahneman says in his latest book, "Thinking, Fast and Slow"we have two risk management decision making processes. Our ancient limbic brain is largely unconscious and it makes rapid decisions based on memory and emotions. Our more recently developed mammalian brain (neocortex) has the capacity for detailed analysis, abstract thought and logical inquiry. Unfortunately our logical brain is easily distracted, painfully slow and hard to engage, while our Limbic brain is (in todays modern world) wrong as often as it is right.

So, as it turns out, despite millions of years of evolution, we still make the majority of our risk management decisions in the emotional center of our brains.   This was fine when we lived in small Paleolithic communities, but the complexity of the modern world means we need better approaches to decision making.  Fortunately, we do have the capacity for analysis, and with hundreds of years of research in science, finance and engineering to name but a few, we have a pool of knowledge to draw on.

Until recently, when ISO31000 Risk Management Standard defined risk as “the effect of uncertainty on objectives”, risk management focused on negative risks. In this scenario, risk was bad, and had to be avoided, mitigated or to be transferred to another party through outsourcing or purchasing insurance. This led to risks being addressed as separate compliance issues and not integrated or managed broadly across the organization. Only comparatively recently has the role of Chief Risk Officer been created with the main focus (as it needs to be) on business integration, enterprise risk management and value creation.


Effective implementation of risk management into organizations and projects is not common.  Organizations that have tried to integrate risk management into their business processes have reported differing degrees of success and some have given up the attempt without achieving the potential benefits.  Aligning risk management with standard management systems including financial systems, workplace health and safety (WHS) and human resources is a key element of success in this area.  Existing platforms such as ISO9000 Quality Management and Balanced ScoreCards also help to demonstrate alignment with the business and are a key element of the process.

Linking business management to strategic risk management means setting up the corporate "infrastructure" for risk management. The evolving risk management function is designed to enhance understanding and communication of risk issues internally, to provide clear direction and demonstrate senior management support.  To be effective, this risk management framework needs to be aligned with the organization’s overall objectives, corporate focus, strategic direction, operating practices and internal culture.  Additionally, in order to ensure risk management is a consideration in priority setting and budget allocation, it needs to be integrated within existing governance and decision-making structures at the operational and strategic levels.