The Art of Risk Management (2017)

Risk management has evolved from a financial sector concern to a top-management priority across all industries, requiring a shift from technical models to a strategic mindset.
The Art of Risk Management*, which discusses the ten principles that should govern an approach to risk management, is part of a publication series by BCG on CFO excellence.* The Art of Performance Management looks at the critical components of a best-in-class performance management system and operating model. The Art of Planning examines the ten principles driving best practices in corporate planning.
In the aftermath of the global financial crisis, companies worldwide have become more focused on risk management. What was once a concern primarily of senior executives in the financial services sector has now become a top-management priority in nearly every industry.
In a global survey of close to 1,500 C-suite executives conducted in the summer of 2011 by Harvard Business Review Analytic Services, more than two-thirds of respondents said that risk management had become somewhat or significantly more important over the previous three years. And in a March 2012 survey of finance executives by CFO magazine, 72 percent of respondents said their companies had increased the amount of time and resources devoted to risk management over the previous two years, with 23 percent calling the increase “significant.”
Risk management is essential in today’s volatile economy. And yet many of the very financial firms that took such dangerous risks before the financial crisis had some of the most sophisticated risk-management operations around. What’s more, some of the very few financial companies that had been praised for their deft risk management before the financial crisis have since gone on to make major errors. One dramatic example is JPMorgan Chase, which suffered a trading loss of $2 billion in 2012 due to trades that its CEO Jamie Dimon has termed “flawed, complex, poorly reviewed, poorly executed, and poorly monitored.”
We worry that in their headlong embrace of formal systems of risk management, many companies are making the same mistakes that companies in the financial sector made. Put simply, they are pursuing a highly technical approach to risk management—characterized by complex financial models and elaborate, formal risk-management systems—in isolation from the day-to-day activities of the broader organization. The result, as was the case at many banks, is that risk management may exist as a formal function, but it is not really embedded in the “mindset” of the broader organization and, therefore, is not shaping behavior and informing decision making.
To be sure, metrics, systems, and processes are important. And for the vast majority of companies, it probably does make sense to create a formal risk-management function. But developing the right risk-management mindset and organizational culture is even more important—and, in our experience, far more difficult to implement.
Companies need a new approach. They need to stop thinking of risk management as primarily a regulatory issue and to reconceive risk management as a value-creating activity that is an essential component of the strategic debate inside the company. The goal of that discussion should not be to eliminate risk, or even to minimize it, but to use it to create competitive advantage. And doing that effectively depends upon a far more dynamic interaction between risk management experts and the line organization.
Ten Principles of Risk Management
Creating a more dynamic managerial system for risk management is as much an art as it is a science. In working with our clients to develop this new approach, BCG has identified ten principles that should govern the art of risk management. (See “Ten Principles of Risk Management.”) We describe these principles below.
Ten Principles of Risk Management
- Risk management starts at the top.
- Risk cannot be managed from an ivory tower.
- Avoid relying on black boxes.
- Risk management is strategy, and strategy is risk management.
- Risk management is more than a policy; it is a culture.
- A risk-aware culture requires the free flow of information.
- What matters is the “talk,” not the “report.”
- The path is the goal.
- It is possible to prepare for unknown risks.
- Avoid the downside, but don’t forget the upside.
1. Risk management starts at the top. Most managers are eager to talk about ambitious plans and favorable results. They are generally far less enthusiastic, however, when it comes to discussing potential—let alone actual—losses that affect the business. For this reason, risk management has to be a high-priority topic with a dedicated owner—either the CEO or some other senior corporate executive. Otherwise, the impulse will be to “kill the messenger” whenever lower-level executives raise sticky questions about potential risks or obstacles to an ambitious business plan.
One approach that many companies are taking to emphasize the importance of risk management is to appoint a chief risk officer (CRO). According to the 2011 Harvard Business Review survey, roughly 42 percent of companies with 10,000 employees or more have such a position—compared with only 11 percent three years previously. Companies with a CRO typically have more advanced planning tools in major risk areas, such as cost of capital, financial regulations, information security, and internal planning and reporting.
But just because a company has appointed a CRO doesn’t necessarily mean that it has made risk management a high priority. The critical factor is to have a highly visible commitment on the part of the senior executive team to make risk management an integral part of the managerial decision-making process.
At General Electric, for example, the board of directors and senior management annually develop a list of the priority risks the company will face in the coming year. The list is public and available throughout the organization. The CRO, who leads the company’s risk function, has the responsibility of coordinating GE’s risk practices with the line organization and business units, including identifying and appropriately managing specific risks and ensuring the enforcement of companywide risk policies. The CRO also reports back frequently to the CEO, CFO, and board in order to discuss the latest trends and any changes in the company’s risk scenarios.
Without this kind of active senior involvement and a management process that links high-level considerations of risk with practices at the frontline of a company’s businesses, a CRO will have limited effect. Responding to the Harvard Business Review survey, about 41 percent of the CROs said that the lack of strong senior-management support was the primary barrier to embedding risk management deep in the company.
2. Risk cannot be managed from an ivory tower. As a company elevates the importance of risk management through the creation of, for example, board-level committees and a dedicated risk-management function, it also needs to be careful not to turn the risk management organization into a kind of ivory tower. Too often, the bigger and more centralized a company’s risk-management function, the more likely it exists in isolation from the rest of the organization, with an insufficiently granular understanding of the actual business-specific risks the company faces. To avoid this outcome, risk management needs to be integrated into all of the company’s routine management processes, including planning, capital allocation, controlling, and reporting. This integration needs to be done collaboratively with the operating management in order to secure buy-in at all levels of the organization. Simply imposing a process from the top rarely works.
BCG has developed a framework that uses the metaphor of a house to describe a truly integrated enterprise risk management (ERM) system. (See Exhibit 1.) Under the “roof” of strong senior-corporate leadership, and built on a “foundation” of appropriate metrics and tools, cross-functional processes and rules for governance, and a companywide risk mindset and c
Source: Hacker News















