Tuesday, June 5, 2012

Blame it on the genes..

It looks like it's official! Risk preferences are central to any model of human decision making but researchers are increasingly able to identify a link between our genetic makeup and our risk taking behaviour.

We've recognised for a long time that there are substantial differences in peoples willingness to trade off risk versus reward. Some of the variation in preferences can be explained by gender, race, culture, age, education and socioeconomic status but none of these differentiators were sufficient of themselves to explain the variation.  Research by Camelia Kuhnen and Joan Chiao of Northwestern University in the journal PLoS ONE, was able to link financial investment risk-taking to variations in certain genes that regulate chemicals in the brain.

In particular, it appears that those of use who enjoy risk taking, whether day-trading or motorcycling are likely to have specific differentes in our Dopamine Receptor D4 (DRD4) gene.  Without getting overly technical, it appears likely that 25% of the individual variation in risk taking can be explained by heritable differences.

It's early days yet of course, and risky to confuse cause with correlation but it appears that there is a definite genetic trait at play. For those of you who are really curious, you'll find more technical details in 'The 7R polymorphism in the dopamine receptor D4 gene (DRD4) is associated with financial risk taking in men' at Evolution and Human Behavior 30 (2009) 85–92.

For an easier read, New Scientist speculates that DRD4 could be responsible for the human migrated out of Africa around 50,000 years ago. Even to the point where DRD4 has moved us across the planet, thanks to a propensity for risk-taking and adventurousness. DRD4 comes in may shapes and forms whereby the 4R allele, is associated with being even-tempered, reflective and prudent. Ie. People who like to manage risk to be ALARP (as low as reasonably practicable).

Those of us more inclined to manage risk to be AHARP (as high as reasonably practicable) probably have the less common 7R and 2R versions, which by contrast have been linked to impulsive and exploratory behaviour, risk-taking and the ability to shrug off new situations. In short, the migrants with these versions were better able to deal with dangerous, fluctuating situations and more likely to survive and reproduce under those conditions.

So, before you have that risk conversation with your spouse or colleague at work, think about just how deep seated their risk attitude may in fact be.  Culture, perception, gender, education, age and many other factors are important but, in part at least, we can be pretty confident that it's hardwired.


Tuesday, May 22, 2012

Another view of a risk management framework


The previous blog entry on risk management frameworks, presented a relatively simple risk management framework but there are many ways to view risk and the interactions of the various elements involved. It’s not the intention to provide a single ‘perfect’ risk management framework – you need to work that out for yourself – but we’ll provide a couple of ideas to get you started.  

Figure 1 below (adapted from SRMBOK) presents a more complex example of a risk management framework.  In this model we break up the elements of risk management into six main categories:
Activity Areas
Practice Areas
Enablers
Strategic Knowledge Areas
Operational Competency Areas
Risk Treatments



Risk Management Framework
Figure 1: Risk Management Framework example


Looking at the above example, we can see a rough outline of how different elements of risk management support each other. For example:

  • Practice Areas – the activity groups that embody distinct areas of expertise. These areas can also be the scope of the risks to be managed, or primary area in which a risk practitioner is focused (eg: Safety, Finance, Enterprise risk, etc) 
  • Strategic Knowledge Areas – the four concepts which all risk practitioners must understand in order to achieve an optimal trade-off in support of risk treatments (Ref: The Quadruple Constraints of Risk Management)
  • Operational Competency Areas – a group of closely-related skill sets in which a risk practitioner needs to be competent in at least one of (if not all) in order to support effective risk management. 
  • Risk Treatments – the strategies that we put in place to support objectives. In the graphic above, ‘assets’ are placed at the center of concentric circles. These circles represent the layered approach known as hierarchy of controls (Ref: Slides 10 and 11) whereby multiple mutually supportive treatments are more effective than a single treatment (Ref: Swiss Cheese).
  • Activity Areas – principle risk countermeasure areas through the lifecycle from pre-incident prevention (planning and preparation) to post-event response (emergency management and business continuity). As indicated in the diagram, there should be a primary focus on various elements at the appropriate phase of a risk event (pre or post) but all four elements need to be considered at all times – albeit with varying levels of focus or priority.
  • Enablers – the underpinning elements required to ensure the application of risk management processes and activities in a sustained fashion (eg: Policies, training, etc) 

Why Build Such a Complex Model?

It’s important to remember that the model illustrated in Figure 1 is just one possible way to view how risk management fits together. It's useful nonetheless, to stimulate your risk thinking in three main areas:

  • GAP ANALYSIS. What elements aren’t happening right now in our organization and what do we need to do to fill in the gaps?
  • BENCHMARKING. If we had to measure the effectiveness of our risk management, which metrics would we choose and how do they relate to each other?
  • INTEGRATION. How does this model help us integrate various functions such as treasury, IT, emergency response, design, governance, assurance, policies etc?


Tuesday, April 10, 2012

First International Conference on ISO 31000

If you're looking for a good excuse to visit Paris in the spring, I can think of few better excuses than the First International conference on the ISO 31000 Risk Management Standard.
The conference will take place there on the 21st and 22nd of May 2012.



"This international conference on ISO 31000 is addressed for the first time to the global risk management community active across all fields, sectors, industries and services related to risk management. We have gathered together an outstanding panel of international experts and practitioners from your sector to share their current perspectives on the ISO 31000 Risk Management standard”, said Alex Dali, President of G31000, the international non-for-profit NGO based in France dedicated to raise awareness on ISO 31000 standard.

With more than 30+ speakers, 4 plenary sessions and 10 parallel sessions and a focus purely on applying ISO31000, this conference is the risk management event of the year.

Plenary sessions:
  • Why ISO 31000 will become the global Risk Management standard
  • 20 years of Risk Management Standardisation - Past, Present and Future 
  • Why every RM programme should be based on ISO 31000
  • How to implement or adapt your RM programme using ISO 31000
  • G31000 – the new Platform for ISO 31000
Parallel sessions:
  • Regulatory Authorities 
  • Business Continuity
  • Software
  • Security
  • Internal Audit
  • Finance and Banking
  • Moving from COSO ERM
  • Raising awareness, worldwide 
  • Education
  • Human Factors
More information and registration details can be found at http://www.G31000conference2012.org and a 10% discount is available if you use booking code: G7ACCX.


I'll be presenting there and will look forward to catching up with colleagues, and hopefully meeting a few readers of this blog at the conference.

Sunday, January 15, 2012

How to build a risk management framework


Section 4 of ISO31000 opens with the simple statement that "The success of risk management will depend on the effectiveness of the management framework providing the foundations and arrangements that will embed it throughout the organization at all levels."  The standard devotes about 5 pages to talking about what a framework requires and sums it up in the Figure 1 below.
Figure 1: Relationship between the components of the framework for managing risk (ISO31000)

We'll go even further, and say that the risk management framework is the heart of organizational risk management. It might be tempting to overlook this portion of ISO31000 or to downplay its significance and jump straight to Section 5: Process but that would be a mistake.  No matter how much you and your organization know about risk, no matter how excellent your latest risk assessment is and despite an outstanding risk treatment plan, unless an organization has a well structured and appropriate risk management framework it will not have a sustainable risk management system.

Of all the elements of ISO31000, building the risk management framework deserves primacy for this is where policy, mandate, organizational commitment and structure set the scene for ongoing successful application of risk management.  And it isn't a one-time event. Like most of risk management, it is an iterative, adaptive process and as you can see from Figure 1, the authors of ISO31000 clearly intended it to be a cyclical process.

At the very least a framework should provide you with guidance regarding how your organization manages risk and in particular provides:
A centralized and comprehensive source of risk policy, procedures and information.
A consistent taxonomy for classification and prioritization of risk.
Automated (or at least consistent) workflow for risk management.
Auditable paper trail of records, decisions made and changes.

Putting this into action however isn't a simple task but if you consider what actually needs to go into it, the following graphic and our next blog entry will offer a couple of suggestions. 

The three most important elements in actually turning risk management theory into risk management practice will inevitably be training, training and more training.  How you put together the underlying framework for your organization however, will depend on your context and existing management systems. Whatever result you end up with, It’s likely to include three common elements: Direction, Systems and Execution.  I built this framework for a large Commonwealth government department a few years ago, and part of the brief was that it had to be easy to grasp the underlying principle.

DIRECTION is set by the Executive management team and in order of priority is based on:
  • Organizational objectives vision and mission (ie. The reason for existence of the organization). 
  • A risk assessment based on those objectives
  • A risk treatment plan to support achievement of the objectives (which might also be known as a Strategic Plan, Operational Plan, etc)
SYSTEMS are the management infrastructure that provides technical and policy guidance for implementation of the organizations plans and uses four core elements:
  • Policies and Management Standards - set the high level expectations and guide decision making
  • Procedures and Guidelines - provide the step by step process flows to implement the policies as well as some general guidance about how to interpret high level policy or standards.
  • Work Instructions – provide task specific detailed instructions for each step in the process flow.
  • Forms, Templates & Tools – are the specific tools and documentation that people will use to identify, assess and document risks.
EXECUTION is the phase where the plans, policies, objectives that have been so carefully developed, are finally implemented using three phases of this process:
  • Training Needs Analysis – involves identifying what people need to know in order to implement the ‘Systems’ previously developed. 
  • Training & Implementation – involves delivering the training that your people will need so that they can begin to correctly implement the various elements that support organizational objectives.
  • Reporting, Monitoring & Review – are the final elements to close the feedback look, assess how effective the framework is and provide appropriate feedback for continuous improvement. 
You’ll find this concept illustrated in Figure 2 below. It’s a relatively simple example of a framework but is easy enough to explain to people and equally importantly is highly scalable. 
Figure 2: Illustrative Example of a Risk Management Framework
Figure 2 is a relatively simple risk management framework. There are of course, many ways to view risk and the interactions of the various elements involved. It’s not the intention of this book to provide a single ‘perfect’ risk management framework – you need to work that out for yourself- but we’ll provide a couple of ideas to get you started.

In the next blog article, we'll look at a more complex version of a risk management framework which might suit larger organizations.