Thursday, February 25, 2010

Strategic Risk

Risk management has a history of sloshing about in the nether regions of the organisation: focussing on operational type risks, processes, insurance, that type of thing. Don't get me wrong, I think those things are important, but shouldn't we be dealing with the strategic issues? You know, M&A, what is the future of the organisation? What is coming at us over the horizon?

I have a view that we should be looking a lot more at strategic risk, and I like to tie it back to value drivers (via objectives?) such as those that drive shareholder value (or whatever your equivalent might be for our organisation).

This leads me to pose several questions:
  • Do we as a profession have enough face time with the CEO and Chairmen of our organisations?
  • Do we get involved in strategic plans before or after they happen? eg, do we get involved in risk based due diligence after the transaction is announced, or when options for acquisitions are being discussed?
  • How often do we, as a profession, facilitate board awaydays focussing on more distant strategy (say 5 to 10 years out)?
  • Does anyone have any really good war stories on this that you are happy to share on line?

Thanks

Richard

Wednesday, February 17, 2010

Ethics and Risk Management

It is my contention, as I have often said, that Corporate Ethics is one of four key attributes of Risk Management, and that is is often in tension with a performance culture (another of my four key attributes).

A number of things have cropped up over the recent years:
  • Clearly Toyota has some "ethical" questions to answer with regard to brakes, accelarators and now steering systems.
  • It seems unutterbaly proven that there were dubious (at best) ethics in banking which allowed the situation to arise for the financial crisis.
  • A few politicians in the UK have exhibited less than the highest standards in the ethical field.
  • Greece (aided and abetted by at least one bank) appears to have been cooking the books, with disastrous consequences for other Eurozone countries.
  • BAe has paid a stinging penalty to the US and a modest one in the UK.
  • We have a new bribery act coming onto the statute book in the UK (if it gets through before the election).

I believe that risk management can ONLY work where there is an ethical dimension to the organisation. And yet, perversely, this allows free-riding unethical corporations to duck and weave unhindered and leave the ethical corporation trailing - at least for a period of time.

I would welcome people's views on the interaction of ethics and risk management.

As ever, I am likely to turn the discussion into a paper in due course, summarising the contributions - if you are uncomfortable with that, let me know in your response.

Thanks

Richard

Monday, January 25, 2010

Management Rheumatism

I have been thinking about the need for a cure for what I describe as Management Rheumatism: a disease that typically occurs in older organisations, where the need for security (and therefore control) far outweighs the ability to embrace and implement change. For more see here...

Feedback welcome, as always!

Risk Appetite - reality v. aspirations

I have a new paper on risk appetite which has been written following on from a discussion on LinkedIn about Risk Appetite. The on-line discussion was followed by a real discussion at the Institute of Risk Management (www.theirm.org). The aim is to develop some practical guidance on the subject, which will be the subject of a follow on paper in due course. I am truly grateful to all those who took part in the discussion and especially to those who have allowed me to quote them in the paper. The paper is here...

I look forward to feedback: I thrive on feedback!

Thanks

Richard

Tuesday, December 15, 2009

I have recently added a new section to my website, where I will publish a series of "Working Papers" on topical risk management subjects. The first of these is on Target Risk, others will follow.

Target Risk was written following a recent enquiry about the subject. In particular I was asked whether I knew of any other organisations that was using the concept of target risk, and if so how were they defining it? In essence I was asked whether my client was being consistent with best practice and with general usage. Given that this exercise was done by talking to other clients, contacts and consultants, I am now sharing the results of that exercise. To see a copy of the paper, click here.

Governance article: while I am writing, you might be itnerested to see a very short article that was published in "Governance" recently on my views as to whether the Walker Report will make the slightest difference to the state of Corporate Governance in the UK. To see a copy click here.

I thrive on feedback - let me know what you think.

Thanks

Tuesday, October 13, 2009

Three Lines of Defence - Dead or Alive?

I went to a hearing at the European Commission yesterday. They wanted to know what professionals, experts, regulators, bankers and others thought about Corporate Governance, the role of shareholders, and risk management. There were three panels, but the one that I participated on, and which is prompting this post, was the one on risk management. One of the panelists put forward the view that internal control and risk management really needs the Three Lines of Defence (1: Line Mangers manage risks, 2: Risk Managers set policy, 3: Internal audit confirms compliance with policy etc).

I argued that Three Lines of Defence (TLD from now on) had not worked... witness RBS and HBOS and others in the States etc. To which this participant replied, but had it been done better it would have provided clear guidance on what should have been done.

My contention is that TLD allows assurance (actually that should be Assurance with a capital A) should not be divided. What we need is: a balanced view to risk, ethical programmes, mature risk management, a risk management and assurance framework, and an organisational structure that works. Now TLD might do that, but it is not the only way at all.

So I am arguing that TLD is fine if you really want it, but don't depend on TLD to protect you next time round. It wasn't that we were slightly wrong in our approach to risk management, we were fundamentally inadequate and TLD did not spot that...

I would welcome your comments, either here, on LinkedIn, or via my website.

Regards

Richard

Friday, October 2, 2009

Risk oversight committees in Banks and Other Financial Institutions

You will all be aware that Sir David Walker issued his consultation paper on Corporate Governance in UK Banks and Other Financial Services Entities (BOFIs for short) on 16 July. There may well be some overlap here with the SEC recommendations. In my view there is a lot to be welcomed in Sir David's report, however there are a few areas where further fresh thinking would be merited.

My main recommendations are fourfold (excuse the numbering...):
  1. I continue to believe that we need to see a paradigm shift in Corporate Governance. In order to make incumbent boards and individual directors take this seriously we need to see new fiduciary duties relating to Corporate Governance responsibilities, which should be discharged with due and diligent care.
  2. I applaud the recommendation to create effective board risk oversight committees. I happen to believe that the remit as described in Sir David's paper is insufficient for the purpose. The remit and mechanics should:
  • Encompass the development of a balanced view of risk;
  • Include the oversight of the development and implementation of a robust ethics programme;
  • Encompass the periodic assessment of the maturity of risk management maturity;
  • Include the development of a risk management and assurance framework that is fit for purpose; and
  • Address the development of an appropriate risk management organisation.
  1. Although it may well be difficult, in the context of the worst dereliction of Corporate Governance responsibilities of recent economic history, I continue to believe that we should find ways to make a form of permanent, full time non-executive director role work in BOFIs (and other organisations) that have a major societal impact.
  2. I continue to believe that the most important attribute of a non-executive director is an ability to act in a challenging, and yet supportive manner. Akin to risk management, the role of such directors is to periodically pierce the “perfect place arrogance” that develops in large corporate organisations. I am therefore less interested in the sectoral background, while of course acknowledging the need for a number of the directors to have BOFI backgrounds.

I set out more detail supporting my recommendations in my letter to Sir David, a copy of which can be found at http://randerson-assocs.co.uk/WalkerConsultationPaper.aspx. I would be pleased to hear what you think of (a) Sir David's consultation paper, (b) my responses and whether you believe Corporate Governance will improve as a consequence of his work.

Kind regards

Richard