Risk Management: A Complete Introduction To Managing Enterprise Risk

Global pandemics such as the scale of Covid-19 or the Spanish Flu have an annual occurrence probability that varies between 0.27% and 1.9%. And while organizations with robust enterprise risk functions had identified pandemics as one of their risks, the low probability meant that few had put in place measures to mitigate against the potential occurrence.

Safe to say, we have all been schooled at the moment.

From cyberattacks to air crashes, third party compromise to regulatory changes, employee unrest to economic downturn, the business environment is rife with uncertainties. Having an approach to anticipate and limit the impact should such materialize is critical for any enterprise that wants to remain.

As an organization defines its strategic goals and objectives, a realistic look at threats to success can go a long way in enabling the enterprise to remain on track. Investing in a risk management approach is the mark of mature companies who are well aware that the path to their vision is not always straightforward.

Let’s look at some of the key aspects define risk management.

What is risk?

The ISO 31000 standard for risk management guidelines defines a risk as:

The effect of uncertainty on objectives.

The outcome of the uncertainty can swing in either a positive or negative manner. If the risk is negative, then the uncertain outcome results in harm or loss for instance lost customers, regulatory penalties being imposed or reduced business revenue. On the other hand, if the risk is positive, the uncertain outcome can result in benefits if exploited e.g., regulation changes can be favorable in terms of new business opportunities.

Elements of risk

To fully express a risk, one has to consider the following elements:

Responding to risk

In order to effectively respond to risks, an approach is required. That’s where risk management comes into play.

Defining risk management

ISO 31000 defines risk management as

Coordinated activities to direct and control an organization with regard to risk.

ITIL® 4 outlines the purpose of the risk management practice is to ensure that the organization understands and effectively handles risk to guarantee ongoing sustainability and value co-creation.

Principles for effective risk management, as outlined in ISO 31000 include, ensuring that your risk management practice:

  1. Creates and protects value.
  2. Is made an integral part of all organizational processes.
  3. Is made part of decision making.
  4. Explicitly addresses uncertainty.
  5. Is systematic, structured, and timely.
  6. Is based on the best available information.
  7. Is tailored.
  8. Takes human and cultural factors into account.
  9. Is transparent and inclusive.
  10. Is dynamic, iterative, and responsive to change.
  11. Facilitates continual improvement of the organization.

(Learn more about risk management in ITIL 4 & ITIL v3 environments.)

Risk management steps

Let’s look at a couple well-known frameworks.

Management of Risk framework

At a high level, the risk management process can be broken down into five iterative steps as outlined by Axelos’ Management of Risk (M_o_R) framework:

M o R Risk Management Process

M_o_R Risk Management Process

1. Identify

The organization identifies its strategic and operational context, and then identifies the risks based on that context. The context leads to a determination of the organization’s capacity and tolerance to risks should they materialize. Risks identified are documented in a risk log or register.

2. Assess

The risks identified are then assessed to determine the likelihood and consequence. This then leads to an evaluation of the assessment to rank the risks from a priority perspective, where risks with higher consequence and likelihood are prioritized higher. A risk heat map is a tool that can be used to visualize risk prioritization.

3. Plan

Planning involves identifying and evaluating the appropriate risk response to remove or reduce threats, and to maximize opportunities. Responses can be categorized as follows:

4. Implement

Here the planned risk responses will be actioned, their effectiveness monitored and corrective action taken where responses do not match expectations.

5. Communicate

This is a standalone step that occurs concurrent to the previous four. Risk information and treatment status is reported to key stakeholders based on agreed channels. This step is also very relevant whenever an identified risk materializes.

NIST risk management framework

The NIST risk management framework (RMF) provides a comprehensive, flexible, risk-based process that integrates security, privacy, and cyber supply chain risk management activities into the system development life cycle through 7 steps outlined below:

NIST RMF Steps

NIST RMF Steps

  1. Prepare. Carry out essential activities to help prepare all levels of the organization to manage its security and privacy risks.
  2. Categorize. Determine the adverse impact with respect to the loss of confidentiality, integrity, and availability of systems and the information processed, stored, and transmitted by those systems.
  3. Select. Select, tailor, and document the controls necessary to protect the system and organization commensurate with risk.
  4. Implement. Implement the controls in the security and privacy plans for the system and organization.
  5. Assess. Determine if the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security and privacy requirements for the system and the organization.
  6. Authorize. Provide accountability by requiring a senior official to determine if the security and privacy risk based on the operation of a system or the use of common controls, is acceptable.
  7. Monitor. Maintain ongoing situational awareness about the security and privacy posture of the system and organization to support risk management decisions.

Risk Management Roles

Now that we understand the purpose and steps in any risk management practices, let’s look at the people involved. Key roles required for effective risk management in an organization include:

Success factors in risk management

Success in risk management is a chance in itself—that’s because you can never plan perfectly (unless you can see the future). However, having a robust yet flexible framework can be the difference between successfully navigating through a challenging risk or seeing your enterprise going under.

Key elements required in successful risk management according to the ITIL 4 practice guide include:

Related reading