I recently spoke with Jim DeLoach, a managing director with Protiviti Inc., about enterprise risk management (ERM) and the ways in which CEOs and board members can move beyond theory and develop actionable strategies. We began the conversation by referring to a statement made by our academic adviser, Dr. Paul Walker of St. John’s University, in the preface of our new ERM report:
Numerous academic studies have been showing that there’s a value side to ERM. And more companies today are examining the notion that excellence in ERM can do more than keep trouble at bay. Still, there are management teams stuck on doing compliance-focused ERM or, as one case study participant told us, “simply checking off the boxes."
Mary Driscoll: What’s your take on this? Do you think there is an emerging or clear trend in which companies that are enlightened about ERM and have sound ERM process models really hope to use ERM as a way to augment a competitive advantage or otherwise enable value creation?
Jim DeLoach: I agree completely with Dr. Walker’s point. The vision around ERM has always been to integrate it with strategy setting. Most companies don’t do that, making risk an afterthought to strategy setting and risk management an appendage to performance management. The challenge is to integrate ERM with what matters to establish sustainable competitive advantage, improve business performance and manage the inevitable tension between creating enterprise value and protecting enterprise value. Like everyone else, I am watching for trends and, frankly, see more companies in Europe focusing on these integration touch points than in the United States. The good news is I have been seeing more emphasis on integration in the States recently. As more companies demonstrate how it’s done and the merits of doing it, we’ll see more traction.
MD: What are the key pieces of information that boards need to carry out their oversight duties and assure investors and regulators that the company’s ERM model is sound?
JD: Boards have traditionally asked two questions: What are our risks and how are we managing them? Since the financial crisis, boards have sought answers to a third question: How do we know? In other words, directors have expressed interest in understanding whether there are effective processes informing management’s responses to the first two questions. From there, questions have started to become more refined. For example:
- Have we integrated risk management with the appropriate management processes?
- Is our risk culture encouraging the right behaviors?
- Are the board and executive management on the same page with respect to risk appetite?
- Are our risk management capabilities keeping pace with the changing business environment?
Answers to these questions go a long way toward providing insights that the ERM model is sound. Unfortunately, a lot of boards are simply asking, “What are we doing with respect to ERM?” By itself, that question can be a nonstarter as it often leaves executive management searching for clues as to what the board really wants them to do.
MD: What do you say to a CEO who says, “We do not get hard-dollar pay back from ERM spending, so we’re not going to put our decision makers through annoying risk assessments? These operating managers know the risks in their businesses and they know what to do about them. That’s what we pay them to do!”
JD: That’s a tough conversation. When you turn the covers back, there may be several reasons why a CEO would take this position. First, ERM may be applied with a focus on compliance or to check off the boxes, as noted in Dr. Walker’s statement, which means that ERM is a mere afterthought or appendage to the processes the CEO really cares about. Second, the risk assessment isn’t adding value the CEO can identify. And third, the board isn’t asking the tough questions.
A comment on the second reason: Traditional risk maps focusing solely on severity of impact and likelihood of occurrence have their flaws. For example, they often focus on known risks, foster group think and pre-empt out-of-box thinking; they require guessing at probabilities and may even lead to a false sense of security with respect to high-impact, low-likelihood risks. A critical flaw, in my view, is they don’t consider speed to impact and response readiness. While these maps may provide a “quick and dirty” view of a company’s risks, they often offer little insight as to what to do next.
So what do you say to the CEO? My line of inquiry would be to ask the CEO if we should focus less on ERM spend and more on enhancing our existing core management processes to make risk considerations more explicit in the strategy setting and business planning processes so we can understand what everyone is doing to manage risk rather than just assume it’s being done. I would also focus on two things: First, the critical enterprise risks that concern the CEO the most rather than the myriad day-to-day risks he believes he is paying people to manage; and second, how to shift the conversation to a business discussion rather than just a risk discussion.
MD: Lots of companies are good at risk identification and assessment, but they fail to effectively integrate ERM with strategic planning. What are the common impediments that prevent companies from influencing already-developed strategic plans so that the risks to the “must-win battles” are proactively managed?
JD: This is a complex but important question. A significant challenge in risk management is getting off the printed page of a risk assessment into actionable steps in a business plan. If the strategy is already developed and risk is an afterthought, ERM has a steep uphill battle to establish relevancy from a strategic standpoint. This positioning has plagued the traditional risk management model of mitigating insurable risk, treasury risk and operational risk through risk reduction and risk transfer strategies for a long time. For risk management to become strategic and focus on the “must-win battles,” it must be integrated with strategy setting — that is the most important impediment to overcome. Other impediments include lack of CEO support, excessive focus on the known risks, and gaining a mutual understanding on the part of the board and executive management on the importance of linking opportunity and risk.
MD: What can the ERM leader do to promote debate among boards, senior executives and operating leaders about new or emerging risks? How to set up the conditions for such debate so that executives don’t feel that admitting to having strategic risks is a sign of weakness?
JD: Some context may be useful here. I view strategic risks as the risks that the business model is not effectively aligned with the strategy and/or one or more future events may invalidate fundamental assumptions underlying the strategy. These risks can arise from myriad internal process issues leading to poor execution of the strategy as well as from disruptive change in the external environment due to actions of competitors, changing customer wants, technological innovation, changes in financial markets and the economy and the actions of regulators, among other things. If you adopt this point of view, it’s not difficult to get everyone to acknowledge that every strategy has risks.
Risk is a four letter word that is normally associated with uncompensated loss exposure, such as health and safety, warranty recalls, catastrophic losses, and environmental disasters. Strategic risks, on the other hand, are compensated risks, meaning the expected upside returns from executing the strategy are regarded as sufficient to warrant taking on the risks inherent in the strategy. Thus, strategic risks represent bets management decides to make in the pursuit of creating value. These are bets the board approves and, hopefully, investors support. This is the way businesses have always been run, so there is nothing offensive about it. Once everyone understands this important distinction, then it’s a matter of deciding how to evaluate these risks differently from the uncompensated risks that risk management has traditionally addressed.
The financial crisis demonstrated how lethal strategic risks can be. They are potential enterprise value killers. If change in the environment invalidates critical assumptions underlying the strategy, that’s something management and the board need to know. Otherwise, unknowingly, they may be playing out an obsolete strategy.
MD: You have written that it’s good practice to review risk assessments over the past 3-5 years and evaluate their effectiveness versus actual experiences. What are some reasonable ways to go about this? What are the common objections to doing this?
JD: I’d start by asking “What did we learn from our risk assessments?” and then “What did we do based on what we learned?” Then I would ask if there were any surprises that occurred subsequently that we didn’t expect. If there were, I’d then ask what could we have done differently in the risk assessment process that might have helped the organization prevent the incident from happening or improve its response readiness. The objective is to improve the risk assessment process continuously. Regarding objections, they typically boil down to time, cost and legal concerns.
Jim DeLoach is a managing director with Protiviti Inc. He writes regularly on the Protiviti blog. You can also follow him on Twitter @DeLoachJim.
To learn how successful ERM programs work at companies such as the LEGO Group, Rockwell Collins Inc., and Exxaro Resources Ltd., be sure to read our free Enterprise Risk Management Report Overview and listen to our free archived webinar: Enterprise Risk Management: A New Landscape Prompts Change.