1/37
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Risk (King IV definition)
The uncertainty of events, including the likelihood of such events occurring and their effect (positive or negative) on the achievement of the organisation's objectives; includes uncertain events with potential positive effect (opportunities) not being captured or not materialising
Risk (simple formula)
Risk = Probability × Impact
Sources of information on risk
Reports from departmental managers, whistle-blowers, reports on key projects/new business areas, internal audit review results, customer feedback, performance monitoring systems, directors' own observations, and external sources
The five main risk categories (King IV)
Strategic risk, Operational risk, Financial risk, Information risk, and Other risks (e.g. reputational, compliance, sustainability)
Strategic risk
Risk that a company takes on voluntarily to increase returns; cannot be avoided by a rule-based control model, since high expected returns inevitably require accepting a high level of risk
Strategic risk — drivers
Strategic direction set by entity's strategy, state of the economy, intensity of industry competition, M&A activity, over-reliance on certain resources/clients/products, products in decline or introductory phase, insufficient new products/R&D funding, high breakeven due to high operating/financial/combined leverage
Operational risk
Internal risk that arises within the company; usually avoidable, as the company does not benefit strategically from taking it on (e.g. risks from unauthorised/unethical staff actions or interruptions to operations)
Operational risk — drivers
Weak or absent internal controls/internal audit function, technology or information system failures, poor asset maintenance, lack of skilled staff, over-reliance on key staff, human error, fraud, labour unrest, non-compliance with laws or financial reporting requirements
Financial risk — external drivers
Currency risk, interest rate risk, market risk, inflation risk
Financial risk — internal drivers
Liquidity risk, credit risk, refinancing risk, regulatory/legal risk
Information risk
Risk from failures in technology/information systems, poor asset maintenance, unskilled staff, human error, or fraud, that can interrupt operations or cause loss of information with serious adverse effects
Reputational risk
Risk of incurring losses due to damage to a firm's reputation — e.g. losing income, increased working capital or regulatory costs, or destruction of shareholder value due to an unfavourable event, even without a guilty finding
Compliance risk
Risk that a company is exposed to legal fines and material losses due to not adhering to laws, industry rules and regulations, internal policies, or best practices
Sustainability risk
Risk that influences an organisation's capacity to create value in the short, medium, and long term; assessed directly via the Six Capitals, SWOT strengths/weaknesses, and stakeholder analysis, and indirectly via SWOT threats, PESTEL, and stakeholder group analysis
ESG (in a sustainability risk context)
Environmental, Social, and Governance — the JSE's 'triple bottom line' principles considered alongside financial performance when assessing sustainability risk (e.g. climate change, population/health & safety, corporate governance/compensation/privacy)
Enterprise risk management (ERM) — COSO 2004 definition
The process affected by an entity's board of directors, management, and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity and manage risk to be within its risk appetite, to provide reasonable assurance regarding achievement of entity objectives
Enterprise risk management — COSO 2017 definition
The culture, capabilities, and practices that organisations integrate with strategy-setting and apply when carrying out that strategy, with the purpose of managing risk in creating, preserving, and realising value
Risk appetite
The level of risk the board of directors is willing to take to achieve the organisation's objectives and increase stakeholder value
Risk appetite — determining factors
Current risk profile (level and spread of risk across categories), risk capacity (level of risk the company can take and remain solvent), management's attitude to risk, risk tolerance, and the required level of risk/return
Risk tolerance
The specific quantified level of risk an entity can tolerate in pursuing its objectives without jeopardising its sustainability; represents the maximum acceptable variance from determined risk levels, based on the company's risk appetite
Risk management strategy
A structured and coherent approach to identifying, assessing, and managing risk, which builds in a process for regularly updating and reviewing the assessment based on new developments or actions taken
COSO ERM framework — components
Internal environment, Objective setting, Event identification, Risk assessment, Risk response, Control activities, Information & communication, and Monitoring
COSO ERM — Internal environment
The tone of the organisation, including its risk management philosophy, appetite, and tolerance levels
COSO ERM — Event identification
Identifying positive and negative, internal and external events that can influence the realisation of the organisation's objectives
COSO ERM — Risk assessment
Analysing risks in terms of the probability of the risk event occurring and its impact, to determine how the risk should be managed
COSO ERM — Risk response
Management's decision on how to react to each risk (accept, transfer, reduce, etc.), aiming to align actions with the organisation's risk appetite and tolerance
Risk response options
Avoid (don't undertake the activity), Reduce/mitigate (limit exposure or impact), Transfer/share (e.g. insurance, joint ventures), Tolerate (accept the risk and its consequences, usually where impact isn't material), Exploit (use the risk to the company's benefit), Terminate/abandon (stop the activity giving rise to the risk)
Residual risk
The risk that still exists even after management has implemented a risk response
Key Risk Indicators (KRIs)
Criteria used to measure potential risks — contrasted with Key Performance Indicators (KPIs), which measure performance
COSO
The Committee of Sponsoring Organizations; provides thought leadership through comprehensive frameworks and guidance on enterprise risk management, internal control, and fraud deterrence to improve organisational performance/governance and reduce fraud
Interest rate risk
A company's exposure to changes in interest rates (greater with more debt/investments); measured via sensitivity analysis; managed via a mix of fixed/floating rate debt, avoiding concentration of interest rate renewals, and hedging
Refinancing risk
The risk that a loan or bond matures when the economy is weak or interest rates are high, making refinancing unavailable or only available at high cost; managed by spreading loan/bond expiry dates, diversifying finance sources, and maintaining a high credit rating
Liquidity risk
The risk that a company does not have enough funds to meet its short-term obligations; managed through planning, sufficient cash reserves or unused overdraft facilities, and communication with the bank via cash budgets
Exchange rate risk
The possibility of profit or loss due to changes in exchange rates; measured via sensitivity analysis and managed via hedging
Credit risk
The risk that a counterparty to a contract will be unable to fulfil their obligation (e.g. a debtor not paying); managed via debtors' age analysis, strict creditworthiness evaluations, avoiding concentration of credit in one client, insurance, and dealing only with well-rated counterparties
Market and commodity price risk
The risk of unfavourable price changes in inputs or outputs (or the company's own share price) that reduce profitability; measured by understanding the cost structure and sensitivity analysis, and managed by hedging inputs
Exam technique for risk identification questions
Always provide a reason for your answer — state the risk, then explain why the company is exposed to it and its specific effect on that company, rather than naming the risk in isolation