Перейти к содержанию
Association of Insurance Services Consumers
Бесплатно для потребителей +7 (727) 224 28 28
RU KZ EN

Creating a risk map

26 June 2011 Reading: 14 min Views: 10 826

Risk Map: an Effective Management Tool

Representatives of various sectors of the economy, including our clients, often ask us, as risk management consultants, whether there are simple and visual methods, accessible even to non-specialists, that would help at least roughly assess risks when developing new strategic business lines, major investment plans and the like. During strategy development, up to ten possible strategies may be evaluated, and each of them carries its own set of risks, often catastrophic ones. So is there a way to display, quickly and concisely, the business risks that prevent your organisation from achieving its strategic goals? How can the details of these risks, as well as the actions to mitigate or eliminate them, be described on a few pages, and how can timeframes, measures of success and the persons responsible for successful delivery be set and assigned?

This can be done by building a risk map of your organisation or of a specific strategic line of business development.

What is a risk map and why is it useful?

A risk map is a graphical and textual description of a limited number of an organisation's risks arranged in a rectangular table, with one "axis" showing the impact or significance of the risk and the other showing the probability or frequency of its occurrence. Figure 1 shows a specific example of a risk map.

 

What you can do yourself: the process of building a risk map.

In general, risk mapping is part of a systematic methodology covering all aspects of a company's activities that makes it possible to identify, prioritise and quantify (classify) the organisation's risks. The methods consultants use when compiling a risk map include interviews, structured and unstructured questionnaires, industry reviews and studies, analysis of the company's documentation, numerical assessment methods and so on. It should be noted that when financial risks are being assessed, quantitative analysis of the company's financial statements is particularly important. Of course, the individual characteristics of the client company and its needs dictate the appropriate method of data collection and analysis.

We will describe an example of a self-performed risk mapping process aimed at identifying risks that are critical for the organisation (those threatening its very existence), highlighting only the main steps. These steps include initial training, defining the scope of analysis, forming the team, time horizons, scenario analysis and ranking, defining the risk tolerance boundary, drawing up an action plan, and quantitative assessment and modelling techniques.

Initial training.

When compiling an organisation's risk map, it is very important that at least one or two of the company's employees receive training in the fundamentals of risk management. They will then help establish dialogue among team members and guide the whole team through the mapping process. This requires preliminary training, which may last from one to five days. In our experience, the best results are achieved with introductory seminars lasting two to three days. The role of such a trained employee is that of an in-house risk mapping process manager who keeps the team focused on the right goal. Where special subject-matter expertise is required, an expert may be brought into the team. Naturally, if your organisation has a large number of competent specialists, this will strengthen the team.

Do not entrust the work to amateurs. If you do not intend to engage consultants, train your own staff.

Scope of analysis.

The scope of analysis, which determines which areas of business decision-making the mapping covers, is set at the initial stage of the process. Risk management consultants also do this at the first stage of examining an organisation. In our example, we define the scope as identifying, prioritising and understanding all risks that prevent the achievement of corporate strategic goals in implementing a specific strategic plan. Note that the scope of analysis may be as broad or as narrow as the organisation wishes. However, a balance must be struck between the breadth of the scope, the depth of information and the value of the information obtained from the risk mapping process. For example, a single risk map for the entire company may be worth considerably less than risk maps for each business division or a particular business unit of the company, or it may be the other way round.

Decide on your goals and on the availability and cost of information. Only then outline the scope of analysis for building the risk map.

Team composition.

The composition of the team is critical to the success of the risk mapping process. When the work is carried out by professional consultants, the team (working group) usually includes the company's top management, i.e. those specialists who have experience and expert knowledge. In the case of self-performed risk mapping, the consultant is essentially the "collective mind" of the organisation's top management, guided by the trained employees. Experience shows that a team works effectively if it consists of six to ten people.

Only once the scope of analysis has been defined can you decide who joins the team. When compiling a map of a company's strategic risks, for example, the team includes the chief executive, the head of finance, the head of treasury, the heads of the legal, control and IT departments, and the head of strategic planning if the company has such a department. If the company already has a risk management department, its head is, of course, included in the working group.

For a narrower scope, such as identifying and mapping the risks of a specific division or operating business unit, the team will consist of the top members of that division's management team. Or, if the risks of a particular area of activity such as e-commerce are being analysed, the team will be formed from senior representatives of the relevant functional areas and of the divisions whose interests are affected.

Most importantly, the team should represent the institutional knowledge of its company as fully as possible and include top management.

Scenario analysis and ranking.

At this step the team conducts a guided brainstorming session to identify all of the company's potential risks under the given development strategy and the scenarios accompanying their occurrence. Once they have been identified, the risks and scenarios are discussed, consensus is reached and a written description of the scenarios is prepared. The key elements of each scenario are the company's "vulnerability" (the object of risk), the "trigger mechanism" (risk factors) and the "consequences" (the size of potential losses).

A vulnerability, or object of risk, is an asset of the company that is exposed to potential threats. Trigger mechanisms (risk factors) cause adverse consequences for the objects of risk. Consequences are expressed in terms of the nature and size of the loss resulting from the vulnerability of the object of risk and the nature of the trigger mechanism. It sometimes happens that seemingly dissimilar scenarios and trigger mechanisms leading to the same consequences for the object of risk are merged into one scenario when viewed from a bird's-eye perspective. Already at this stage, you should try to understand whether the many minor risks that employees usually identify when working on their own can be combined into groups, and on what basis this can be done.

Once a limited number of scenarios has been identified and consensus reached, the team should rank the scenarios in terms of "impact" and "probability". The team defines both impact and probability in terms relevant to the organisation. For example, in qualitative terms, four levels of impact can be defined in descending order as (1) catastrophic, (2) critical, (3) significant and (4) marginal. The probability levels, of which there are six on our map, are also defined in qualitative terms, ranging from "almost impossible" to "almost certain to occur". In principle, both probability and significance can also be assessed by the company quantitatively. The team may use any quantitative definitions; however, this procedure is much more complex and requires considerable time for analysis.

 

Defining the risk tolerance boundary.

The critical risk tolerance boundary, a bold broken line, separates the risks that are currently tolerable from those that require constant monitoring right now. Business risks located above and to the right of the boundary are considered "intolerable" and require immediate management attention. When developing an organisation's strategy, it is advisable to understand, before the strategy is adopted, how to manage or eliminate them, and whether doing so would reduce the profitability of the business to the point where the strategy becomes unattractive. The threats located below and to the left of the boundary are currently considered tolerable (this does not mean that they will not need to be managed at all).

The risk tolerance boundary changes depending on the organisation's risk appetite. When risks are classified by significance/probability, even without a numerical assessment it is possible to roughly estimate the amount of financial loss from a particular risk, which makes it possible to determine, to some extent, the organisation's risk appetite and to draw the risk tolerance boundary on the map.

And here is the risk map!

The final step in building the map is placing the business risks on the risk map according to their impact level and probability level, i.e. essentially classifying the risks by two parameters. In the general, more complex case there may be three or even five such parameters, and then mathematics becomes indispensable. In our example there are two parameters, and the team seeks to place each risk in the appropriate impact/probability cell. Only one risk goes into each cell.

It is important to understand that the ultimate value of an organisation's risk map lies not in determining the exact impact or probability level of a specific threat, but in the relative position of one threat in relation to the others and in their position relative to the risk tolerance boundary. Now, in order to adopt this strategy, provided it suits us in terms of profitability, it is important to understand how to move all the risks lying in the red-and-purple "intolerance" zone into the green zone.

Action plan.

Risks lying above the tolerance boundary require immediate attention right now. It is therefore important to develop specific action plans to reduce the size or probability of losses from each such risk. It is also necessary to define targets and measures of success in managing the risk, set dates for achieving the targets and appoint the persons responsible. The purpose of the action plan in this case is to understand how to move each "intolerable" risk to the left and down into the "tolerable zone". It should be noted here that the costs of such a move must be weighed against its benefits, and that a sharp reduction in the company's risks may also cause it to lose most of its profitability.

 

Quantitative assessment and modelling.

The degree of detail required in the analysis is specific to each risk and varies from one risk to another, depending mainly on the goals pursued by the organisation. While Western banks often fight over fractions of a percent when estimating potential losses, such precision is not yet needed even by our banks, let alone by enterprises in the real sector of the economy. In general, when assessing a fairly wide range of business risks, significant detail is either not required or cannot be achieved. Other risks and action plans will require more detailed research and quantitative assessment than can be achieved through questionnaires, brainstorming or the study of industry data and the like.

For risks requiring additional analysis, sophisticated quantitative assessment and modelling methods should be used.

A risk map: a picture or a process?

From the standpoint of risk management technology, building a risk map does not complete the management process; it only begins it. Moreover, your company's risk map is a "living organism" that responds to the decisions made and the operations carried out. It lives and evolves as your business develops: new opportunities bring new risks, while some of the old risks lose their relevance and become insignificant for your business. It is therefore important that the process of risk mapping and refining the map be built into the organisation's activities.

This will make it possible to update the company's risks as often as necessary. The "scheduled update" period is usually one year; sometimes it is tied to seasonal cycles if the business has them, and so on. However, as soon as even weak signals appear about events that could strongly affect the company's objects of risk, their impact on the company's risk map should be assessed regardless of any schedule.

Creating value for the company.

Risk mapping should be used to test existing strategies in the context of realised and unrealised risks and the company's opportunities to generate returns, as well as to support management decisions on developing new strategic lines.

Let us consider traditional approaches to strategic planning. While most companies carry out some type of formal strategic planning (all of which are well known), companies lack a business process for identifying, assessing and integrating opportunities and risks, i.e. a kind of "learning strategy". This is easily illustrated by the example of e-commerce, where traditional strategic planning methods cannot keep up with the pace of change. The nature of technological change shows that the assumptions (returns and risks) considered correct for many of today's decisions are very likely to no longer hold in six months' time and will bear no resemblance to those that will apply in three years.

There is a gap between those who usually run the strategic planning process and those who interact with clients and are responsible for the gains or actual business losses in day-to-day operations. Traditional "strategic planners" rely on knowledge available at a particular point in time, whereas line management relies on "live" knowledge based on actual market dynamics, which can be called a "learning strategy". Business success depends on the quality of decisions made in the dynamic present. A permanent risk mapping process focused on the company's strategy can eliminate or narrow the gap between "strategy planners" and line managers by incorporating "live" market information about where the company's competitive advantage can actually be realised.

Thus, risk mapping is a powerful analytical tool for understanding a company's business risks and prioritising them. In addition, in many cases the risk map is a source of economic value creation for the company, since it is already clear that this methodology can be applied beyond the risk management process as such. It plays an important role in strategic and operational planning, in implementing existing business strategies and in evaluating future ones.

More on this topic