INSIGHT
In conversation with Sanjay Mehta, Senior Advisor, KPMG
As a concept, Enterprise Risk Management (ERM) has been around in some form just as long as business itself has existed. After all, managing risk is fundamental to any firm’s survival. Yet, with intangibles now dwarfing physical assets as a share of the firm’s overall ‘value’, and given the spate of recent high-profile governance failures, the principles guiding ERM are shifting. Risks to cash flows, reputation, or other intangibles today have the potential to wipe out billions in investor wealth overnight. The Enron/Anderson and Satyam debacles are cases in point. The regulatory response – SOX in America, and Clause 49 and a new Companies Act in India – has been definitive. More recently, the Global Financial Crisis redefined risk management in the financial sector, while in India, the IL&FS crisis promises to raise new questions. CFOs, clearly, are at the forefront of managing all sorts of risks, and they would be well advised to institutionalise rigorous ERM processes. At its core, ERM seeks to preserve and enhance enterprise value, and it rests on some basic principles. At a recent India CFO session in Mumbai, Sanjay Mehta, Senior Advisor at KPMG, who has studied risk management processes at the world’s leading companies, laid out what exactly what it entails.
Diverse risks…. |
|
From safety issues… |
In seeking to understand how world-class businesses manage risk, Mr Mehta closely studied a whole gamut of industries. What he found was that each sector faces its own unique risks, demanding different types of ERM programmes. For example:
|
…but a common aim: Making risks visible |
|
One goal to guide them all |
The risks they face vary, but a common goal guides many of the world’s most sophisticated companies: making risks – whether current or future, hidden or in plain sight – visible. This includes evaluating impact, readiness, and the quality of decision-making in the organisation. In parallel, it means creating a strong awareness of where the company stands, in the most efficient manner possible, and getting both managers and the Board to respond. On a related note, leading firms have done away with the old ad-hoc approach to risk, towards one that is more systematic and institutionalised. Instead of a pure art, ERM must be strongly backed by science. Today’s computing power allows for insights that are derived from billions of data points, and endless correlations between causal factors – something that was previously impossible. Multiple scenarios can be built, though ultimately, a human being must choose between these scenarios. |
Proactive, reactive, or compliance-driven? |
|
Compliance lies at one end of the scale… |
Broadly, there are three approaches to risk management. At one end of the scale is a tick-box style, compliance-driven ERM, which is usually of limited value. Choosing between a proactive and a reactive approach is less clear-cut, and one is not necessarily ‘better’ than the other. Dominant firms – Microsoft, say, or Coca-Cola – lean towards being proactive, but this also tends to slow down decision-making. Since the value at risk is huge – one bad decision can destroy years of hard work – it breeds caution. On the flip side, disruptive businesses tend to be more reactionary about managing risk. A new entrant in the Indian telecom industry, for example, will be faster to react to evolving situations, but even faster to reverse bad decisions. Taking a risk without understanding all of the underlying factors is acceptable only so long as it is possible to quickly change tack. A failure on this count can destroy value, and damage the business model no end. |
Varying focus areas |
|
Strategy is foremost for certain types of companies… |
Companies vary also in where they focus their ERM programmes. Some concentrate only on strategic risks, while for others, it is mainly about operational/financial ones. The choice depends on where the company stands in its life-cycle, and the nature of its business. ‘Steady state’ firms like Pepsi – they know what to produce, how to produce it, and where to sell it – are concerned mainly with strategic and emerging risks. In contrast, project-based companies like GE or Bechtel keep an eye on softer issues as well as financial risks. There is also a third category of firms – those like Cisco, which outsources much of its manufacturing to contractors, who further outsource to sub-contractors, including in other countries. This extra layer of intermediation makes it hard to monitor quality, or to assure supply-chain continuity. It also brings strategic risks, such as when a trade war erupts. To overcome this challenge, Cisco mapped its supply chain from end to end, determining precisely where the disruption risks lay. In general, financial and operational risks are easier to quantify, and usually also less ‘damaging’ to a company’s long-term health than strategic ones. That said, for start-ups, they are actually more important: until an organisation has its house in order, and has scaled up sufficiently, strategic issues are secondary. Finally, ERM programmes can be either enterprise-level or enterprise-wide. Firms that focus on strategic risks usually tilt towards the former, while those focused on financial and operational risks are more inclined to the latter. |
ERM implementation: guiding principles |
|
There is no one-size-fits-all, but… |
An ERM programme and risk culture are two sides of the same coin. Indeed, a risk manager’s primary role is to build or strengthen a risk culture, by fostering awareness, starting conversations, and breaking down silos. While there are no silver bullets, a number of principles might guide ERM implementation in any situation:
|
The contents of this paper are based on discussions of The India CFO Forum in Mumbai with Sanjay Mehta, Senior Advisor, KPMG in January 2019. The views expressed may not be those of IMA India. Please visit www.ima-india.com to view current papers and our full archive of content in the IMA members’ Knowledge Centre. IMA Forum members have personalised website access codes.
INSIGHT