Risk management and compliance are part of the critical Board functions. The Board also oversees strategy and its execution. Risk monitoring plays a central role in effective governance. For this to be successful, you need a risk management framework, strategic plan, budget, and structure for effective strategy implementation. The Board cannot execute its role without these critical documents. And this is where risk management becomes imminent for the success of any organization.
Risk is about being alert to the environment, scanning to see and prepare for what could go wrong. The Coronavirus pandemic is an event that nobody could have anticipated. Even the superpower countries, and all organizations with sophisticated models and technology were caught unaware. An event of this nature and global impact just happened and took the world by surprise. Two years on, the pandemic continues to wreak havoc, killing dreams, livelihoods and disrupting everything in its wake.
According to ISO 31000:2018, “risk is the effect of uncertainty on the objectives.”
Like any disaster, the pandemic was uncertain. No leader or country or organization knew how and when it could occur, at least based on the available reports. It suddenly happened and became a global health threat to the human race.
When you are moving on the road, be it walking, cycling, or driving, anything could happen. You could hit a pothole, and get a flat tire. This happens without your prior knowledge. If you knew about it, maybe you could have managed it. This is why some people are prudent enough to have a spare tire on the car. The risk of an event is a probability of occurrence and its impact. As a leader, you must anticipate these kinds of happenings in a way that is scientific and proactively manage them. That is why we have insurance companies. People buy health, motorcycle, fire insurance, etc to prepare for the bad times. They are recognizing that anytime, anything could happen to them. The question is how do you get back on your feet and move on? How do you automate your risk management process and stay at the top of things?
To swiftly implement your Enterprise Risk Management (ERM) and facilitate the automation of the process, begin by understanding the guiding principle of your risk process. This guides the organization on how risks are identified and assessed. You must have a common risk language. Everybody in the organization has the responsibility to remain alert of what could go wrong. They should be able to identify the risk, assess it, and immediately report to management for action to be taken.
Most organizations have a risk management framework that is aligned to the ISO 31000 2018, and comprehensive risk registers. That’s a plus. However, most of the time, the risk register is kept in MS Excel and manually updated. Usually, the Risk Manager is the custodian of the document. S/he moves around various departments to update it say at the end of the month or quarter. The challenge with this kind of risk management style is organization loses critical value in terms of risk assimilation, it takes a lot of time to get management’s attention. Such a process is prone to bureaucracy yet leadership is about being swift in decision-making based on facts on the ground. Organizations look at risk management as an event. They only have a risk report when the Board is sitting. As you noticed, the Coronavirus pandemic did not wait for the board or management to sit. It just happened. Organizations with high maturity for risk management were able to let know the people who matter get a sense of what the issue was when the pandemic has just started. For some organizations, it took a long time. The more agile you are, the more chances of staying relevant and creating value.
If you are operating in the new era of the digital agenda, means that when any staff identifies a risk, logins into the risk system and updates it regardless of where you are. From a leadership perspective, you want as much as possible information to reach the critical person responsible for the decision, ie the decision-right owner. When you operate manually, critical information is buried and doesn’t get to the right people. Sometimes, it goes to the wrong people. Such people may not assimilate to appreciate the impact of what they are holding, they end up undermining it. By the time, the right person who should make the call gets the information, it is too late. That is why some companies are penalized just because the information went to the wrong person.
Risk automation is the recommended approach.
It provides for agility, adaptability and responds to the everchanging business environment in the risk management agenda. Technology and automation are like oxygen to the business, you must embrace them to support critical functions across the organization. This ensures risk management is no longer a manual process but becomes part and partial of the entire enterprise risk governance.
Need to automate your ERM to comply with the requirements of the, contact Summit Consulting Ltd for a demo on actionTEAM GRC, a governance system that automates risk management, strategy execution, and compliance.
Copyright Mustapha B Mugisa, Mr Strategy, 2021. All rights reserved.
