Some thoughts on best practice risk management

Risk management is simple.

It just takes 12 easy steps to achieve effective risk management in your organisation.

Truly.

So what is the simple 12 point method to best practice risk management.

But before we get to that, why is it important to be best practice risk management?  The primary reason is it provides management with the full understanding of the risks of the business and therefore should allow the business to make even more informed and balanced decisions.  You know when you have a great risk management framework when everyone in your business is talking risk and making considered decisions based on the risks.

Essentially a good risk management framework has the following key aspects:

  • A well understood view of the risks of the business;
  • A process of ongoing update of the risks but also some form of periodic review;
  • An analysis of other organisations events and incorporating them in your risk assessment process;
  • Reporting includes risks, events and key risk indicators (KRIs);
  • A process of root cause analysis such as using 5 Whys and Six Sigma techniques;
  • All business events cover who, what when and how;
  • Any actions that are required after an event are effectively managed;
  • Committees have an effective charter and accountability, and understand the risk appetite;
  • Committee actions are effectively managed;
  • Members of the committee attend all meetings; and
  • Risk owners present all papers.

Using these 12 key points and ensuring that the individuals in the organisation understand that the most important person in risk management is them, should provide your business with a great risk management framework.

Cheers,

More from the Reading Room

AI Agents, Non-Human Identity Risk, and the Transparency Problem Leaders Cannot Ignore

A practical AI risk governance article focused on AI agents and non-human identity risk, evidence, ownership, challenge and maturity assessment.

Shadow AI and uncontrolled usage is not leveraging AI

A practical AI risk governance article focused on Shadow AI and uncontrolled staff usage, evidence, ownership, challenge and maturity assessment.

APRA calls for a step-change in AI-related risk management and governance

APRA has flagged a need for a step-change in AI-related risk management and governance across banks, insurers and superannuation trustees, indicating a sharper prudential focus on emerging technology risk.

Effective Risk Committees

The practice of effective risk management requires the management team to take ownership for the risks of their business through an effective and efficient decision making process.