280 likes | 447 Views
Equity Housing Group. Risk Management. Agenda. Introduction: what is Risk Management? The Building Blocks Practicalities: Who does what? Feedback and conclusions. Introduction. What is Risk Management?. Risk - Definition. RISK is :
E N D
Equity Housing Group Risk Management
Agenda • Introduction: what is Risk Management? • The Building Blocks • Practicalities: Who does what? • Feedback and conclusions
Introduction What is Risk Management?
Risk - Definition RISK is : “…..the chance of something happening that will have an impact on objectives.” Risks may be • events with the potential for adverse effects (e.g. risk of fire) • events which provide opportunity to achieve better outcomes (e.g. risk of not changing the way things are done to be more efficient)
Wrong assumptions about Risk • Something for finance and insurance to worry about • Risk is an annual compliance issue • Just another corporate initiative • Risk Management is about downside (i.e. bad things), not creation of value
Why bother with Risk Management? • Compliance with law and regulations • Helps with the business planning process • Reduced “fire-fighting”
There are two types of Risk • STRATEGIC RISK • Risks which need to be taken into account in judgments about the medium to long term goals and objectives of the organisation • BOARD FOCUS SHOULD BE ON THESE RISKS • OPERATIONAL RISK • Hazards and risks which managers and staff will encounter in their daily course of work
What is Risk Management? Risk Management is about asking three questions: • What might stop Equity from achieving its objectives (i.e what is the risk?) • How big is the risk? • What are we doing about the risk, and what else should we be doing about the risk?
Basic Steps towards Risk Management Risk Identification Risk Quantification Risk Management
Step 1 - Risk Identification There are many different ways of categorising risks... Governance and mgmt External People Types of Risk Financial I.T. Operations Hsg/ Maint
Step 2- Risk Quantification • Impact - a measure of the potential impact or damage a risk will cause. • Likelihood - a measure of the likelihood of a risk occurring.
Step 2 - Risk Quantification HIGH Likelihood LOW LOW Impact HIGH
The Building Blocks • Risk management strategy • Risk register • On-going review of risks
Risk Management Strategy • Board’s policy on risk • Considers what the organisation is doing to manage risk • Considers responsibilities for risk • Requirements to review risk assessment by relevant groups
Risk Register • This is used to document: • Identified risks, and their effect on Equity • how the risks are controlled • responsibility for each risk • actions required • progress
Risk Businessoperations 1st line of Defence Risk 2nd lineof Defence Risk Internal and External Audit 3rd line of Defence Three Lines of Defence Model Operational processes, project risk and control activity, business level monitoring Executive Managers Audit Committee Board Business planning, policy and procedure setting, functional oversight - Finance, Environment, Health & Safety, IT Divisional, Corporate Oversight Functions Monitor compliance and provide independent challenge and assurance
Practicalities: Who does what? • First line – day to day • Second line – oversight functions • Third line – independent assurance
Practicalities: Who does what? • First line • Rests with the business operations which perform the day-to-day risk management activity • Control through established processes and project management controls
Practicalities: Who does what? • Second line • Provided by oversight functions for Equity, currently at corporate level, e.g. Standards and Innovation, Finance, HR… • They provide assurance by ensuring that policies or procedures issued are followed.
Practicalities: Who does what? • Third line • Internal Audit and External Audit • Offering independent challenge to assurance provided by business operations and oversight functions
Practicalities: Who does what? • Role of the Board: • Overall responsibility • Role of Audit and Risk Committee • Review strategic risk regularly • Receive report on risk action plans • Question the executive team • Provide assurance to Board
Practicalities: Who does what? • Head of Risk (David Fisher): • Oversight of maintenance of risk map • Produce updates for Board on strategic risks • Other as per his role?? • Risk owners (operational management): • Discuss risk register and progress on action regularly at team meetings