You are on page 1of 5

Global CEO October 2001 Enterprise Risk Management

A Strategic Approach to Enterpise


Risk Management
- by A V Vedpurishwar

Risk Management has become a favorite topic As the Economist (February 10, 1996) put it: "Top
of discussion these days. Bankruptcies and managers often fail to understand properly the firm's
huge losses have reemphasised the importance sensitiveness to different types of risk. This is
of identifying corporate risks and dealing with because the technology for identifying risk
them effectively. Companies such as Procter & exposures in non financial firms is as yet fairly,
Gamble, investment banks such as Barings and primitive, but more fundamentally because
government organisations like the Orange managers and boards too often regard risk
County, have all burnt their fingers due to faulty management as a matter for financial experts in
risk management practices. Closer home, we the corporate treasury department rather than as
have seen many Non Banking Finance an integral part of corporate strategy."
Companies (NBFCs) winding up after taking
risks totally inconsistent with their resources or
capabilities. Exploding some myths about risk
management
Organisations face various types of risks. While on the subject of risk management, four points
Unfortunately, much of the focus of risk management need to be made at the outset. Risk is not
has been on the financial aspects. Just like the field something new. One of the earliest examples of
of Knowledge Management has been dominated by risk management features in the Old Testament.
IT companies, risk management has been strongly An Egyptian Pharaoh had a dream which was
associated with treasury, forex and portfolio interpreted as seven years of plenty to be followed
management. The risk management agenda has been by seven years of famine. To deal with this risk,
hijacked by investment bankers and corporate the Pharaoh purchased and stored large quantities
treasurers and dominated by the use of financial of corn during the good times. As a result, Egypt
derivatives. This is not quite the way it should be. prospered during the famine.

Risk is all about vulnerability and taking steps to The second point is that risk can neither be
reduce it. Several factors contribute to this avoided nor eliminated completely. Indeed,
vulnerability. So, it is obviously incorrect to equate without taking risk, no business can grow. And if
risk with fluctuations in financial parameters such there were no risks, managers would not be needed.
as interest rates, exchange rates or stock indices. The Pharaoh in the earlier example was obviously

© ICFAI PRESS. All rights reserved.


- 47 -
Enterprise Risk Management Global CEO October 2001

taking a risk in the sense that his strategy would Capital Management. Similarly, many companies
have proved counterproductive, had there been no have been ruined by the reckless plans of CEOs
famine. obsessed with growth.

This leads us to the third point. Risk management Understanding uncertainty


is all about making tradeoffs. These tradeoffs Organisations face various types of uncertainty.
are closely related to a company's assumptions
A. State Uncertainty: This refers to
about or interpretation of the developments in the
unpredictability about the environment. Causes
external environment. Consider two leading global
of state uncertainty are:
pharmaceutical companies, Merck and Pfizer.
a) Volatility in the environment
Merck is betting on a scenario in which Health
Maintenance Organizations (HMOs) rather than b) Complexity in the environment
doctors will dominate the drug-buying process. c) Heterogeneity in the environment
Hence its acquisition of the drug distribution
company Medco. On the other hand, Pfizer has B. Effect Uncertainty: This is the uncertainty
invested heavily in its sales force on the assumption about the impact of developments in the
that doctors will continue to play an important role.
environment on the organisation.
Each company is working out its strategies based
on an assumption and consequently taking a risk.
Similarly, a company which bets on a new C. Response Uncertainty: This refers to the
technology could be diverting a lot of resources from unpredictability about the options available to an
its existing business. If the new technology fails to organisation and their outcome. Even after an
take off, it may become a severe drain on the option is selected, the speed at which it will
company's finances. But, if the firm decides not to respond depends significantly on how deeply
invest in the new technology and it does prove entrenched are the company's processes and
successful, the very existence of the company cultural traits.
becomes threatened. So, what it means is that in
many cases, not taking a risk may turn out to be a Integrating risk management into corporate
risky strategy. strategy
Quite obviously, risk management has to mesh with
A fourth point, which is often overlooked, is that the ultimate goal of the organisation, which is to
risk may not arise only because of environmental maximise the shareholders' wealth. That means
changes. Many of the risks which organizations maximising earnings through judicious investments,
assume have more do to do with their own which in turn necessitates adequate cash flows.
strategies, processes and culture than any external Firms typically run into cash flow problems because
factors. For example, the collapse of Barings Bank they fail to anticipate or handle risks efficiently.
had as much to do with poor management control These include huge R&D investments which do
systems as unfavourable developments in the not pay off, excessive premium paid for an
external environment. An excessive risk taking acquisition, costly litigation (especially class action
culture contributed to the downfall of Long Term law suits) by aggrieved stakeholders, excessive

- 48 -
Global CEO October 2001 Enterprise Risk Management
dependence on a single or few customers and which are unmanageable. They also usually cover
suppliers and vulnerability to interest rate, stock one time risks rather than recurrent risks typically
index and exchange rate movements. In March through insurance. Companies also usually carry
1997, the chemicals giant, Hoechst incurred those risks which are closely connected to their
expenses of about $400 million due to product recall core competencies. Thus, software companies
and unexpected restructuring charges. would in normal circumstances, not transfer
Metallgesellschaft tried to cover the risk associated technology risk. Self retention makes sense when
with its long term contracts through oil futures. It the cost of insuring the risk is out of proportion to
ended up losing a huge amount. Philip Morris had the probability and impact of any damage.
to cut prices of Marlboro sharply due to However, there is no hard and fast recommended
unexpectedly stiff competition from cheaper private rule. What risk to keep and what to transfer has to
labels. be determined on a case to case basis.

Thus for any company, the sources of risk and the Types of risk commonly encountered
ways to deal with the risk are closely linked to A firm can be exposed to various types of risk.
business strategy. We need to examine how some Let us now look briefly at some of the risks
strategies create risks while others mitigate them. commonly faced by organisation.
Any company needs to grow and generate adequate
profits to survive in the long run. Unprofitable or
stagnating companies are doomed to failure. So, Strategic risks arise from the firm's core business
per se, companies have to make investments. All strategies. Excessive dependence on a single or
investments carry some risk. Indeed, if investments few products or a single or a few regions for
did not carry risk, the field of financial management generating revenues leads to vulnerability. A
would not exist. Thus, risk cannot be eliminated diversified product portfolio or geographical base
entirely. On the other hand, a prudent risk can lend a degree of stability to revenues and profits.
management strategy would result in sufficient cash This may mean moving into new businesses or
flows which can keep the company going even if expanding capacity to serve new markets. Major
some of the investments run into rough weather. capacity expansion, vertical integration and
And it would ensure that the company holds only diversification projects all involve risks. Quantifying
such risks it is comfortable with and transfers the the risks involved and taking a view on whether
remaining risks to other parties. such risks can be borne is hence crucial.

How does a company decide what risk to keep The most commonly discussed form of risk is
and what to hedge? By classifying risks, managers financial risk. When interest or foreign exchange
can decide what risks to carry and what to transfer rates fluctuate, there is an impact on cash flows
by taking a suitable insurance. Often, companies and profits. Risk also increases as the debt
are comfortable with outsourcing risk caused by component in the capital structure increases. This
external factors. This is probably why financial is because debt involves mandatory cash outflows
risk management has caught on quite well in recent while dividends in the case of equity can be paid at
times. Companies also tend to transfer those risks the discretion of the company. Today, sophisticated

- 49 -
Enterprise Risk Management Global CEO October 2001

Environmental Strategic
Risks Risks

Risk Management :
Legal & A holistic Technology
Ethical Risks perspective Risks

Political Financial
Risks Risks
M&A
Risks

hedging tools like derivatives are available to Political risk refers to actions of governments that
manage financial risk. interfere with business transactions, resulting in loss
of profit or profit potential. In extreme cases,
political risk results in confiscation of property.
Technology risk has become a major factor these
More commonly, governments change policies from
days, especially due to the growing importance of
time to time and put restrictions on the way
software as opposed to hardware. Innovations are
businesses operate.
more frequent and regular in the area of software.
Consequently, companies which, do not have a
strategy to cope with changing technology may find Another type of risk is environment risk. If
themselves at a disadvantage. Very often, companies fail to put in place policies which ensure
successful and well established companies fall by that the environment in which they operate is not
the wayside in the wake of an innovative and damaged, they face the risk of resistance and
disruptive technology introduced by a startup. hostility from the society. In some cases, the very

- 50 -
Global CEO October 2001 Enterprise Risk Management
existence of the company may be threatened, as India's leading companies is in ruins because of poor
well illustrated by the example of Union Carbide in corporate governance practices. In the mid 1990s,
Bhopal. Similarly, oil companies like Exxon have ITC ran into big problems because of poor corporate
faced major crises due to oil spills from their governance.
tankers.

In their seminal paper, "The Balanced score card -


Many companies today look at mergers and Measures that drive performance" (Harvard
acquisitions as a way of generating fast growth Business Review, January - February, 1992) Robert
by gaining access to resources such as people, Kaplan and David Norton emphasised the need for
products, technology and facilities. Yet, mergers
assessing the performance of an organisation from
and acquisitions have to be planned and executed
four different angles - customer perspective, internal
carefully. The premium paid by the acquiring
perspective, innovation and learning perspective and
company should reflect the synergies which can
be realised. Poorly executed acquisitions prove to shareholder perspective. Their Balanced score
be a severe drain on the existing resources and card considers financial measures that indicate the
even ruin a company in some cases. results of actions already taken. At the same time,
it incorporates operational measures on customer
Today, legal risk has also become important. Class satisfaction, internal processes and attempts at
action suits by employees or shareholders can pose innovation and improvement, all of which drive
grave concerns. Similarly anti trust proceedings future financial performance. Similarly, the various
by the government can distract a company so much business risks which an organisation faces must be
that it may not have enough time for its core considered along with the financial risks. Ultimately,
business. Microsoft, till the recent judgement has financial risks are the outcome of business
been heavily burdened in this respect. On the other strategies. If the role of financial risk management
hand, Intel seems to have managed its antitrust risks is to minimise uncertainty regarding cash flows, the
well through various proactive measures personally
very source of these cash flows is the type of
overseen by Andrew Grove.
business which the company operates and how well
it manages them.
More and more importance is being paid to high _______________________________________
standards of ethics and corporate governance.
The author is Dean, ITUC School of Management, an
Unethical practices and low standards of corporate ICFAI affiliate.
governance can severely damage the reputation of ----------------------------------------------------------
Reference #15-01-10-06
a company. In such circumstances, the share price
and consequently the market capitalisation may
As corporations go global, the importance of
plunge dramatically. A good example of a company,
which has seen a severe decline in its business enterprise wide risk management is realized.
owing to unethical and illegal disclosure practices We would address various facets of this
is the famous insurance company, Lloyd's of emerging field in our forthcoming issues.
London. In India, Shaw Wallace, once one of

- 51 -

You might also like