Notes
Notes
Notes
Frameworks’.
In this session
By the end of this session, you should be able to:
organisation
Examine how organisations can better identify opportunities and threats, and
Introduction to Risk
Management Frameworks
“It is not the beauty of a building you should look at; it's the
Throughout our lives, we learn many lessons, study new concepts and
experiences are dependent upon the firmness of our foundation, that is, our
fundamentals.
learnt the meaning of a framework and saw the widely used ERM
common methodology, which one can follow and use for developing a risk
management process.
the COSO and ISO 31000 frameworks are used most widely.
The COSO ERM and ISO 31000 frameworks cover, in great detail, all the
COSO
ISO 31000
The ISO 31000 framework was developed by the International Organization
for Standardization.
planning.
In addition to COSO and ISO 31000, you also learnt about COBIT and saw its
Having learnt the meaning of a framework and have also learnt about COSO
and ISO 31000, the two widely used ERM frameworks, in the next segment,
you will learn about the differences between COSO and ISO 31000
COSO
✓ Correct
Feedback:
The board of directors and the senior management are extremely involved in the risk
management process of the company; this helps them in improvising their strategic
planning. Info Globe has an integrated risk management framework that is used
across the business units of the organisation.
To which framework is Info Globe Ltd.’s risk management process more inclined?
ISO 31000
✓ Correct
Feedback:
frameworks cover all the aspects of ERM in great detail. Organisations can
But which framework is the most suitable for an organisation’s ERM process
In the forthcoming video, you will learn about the key differences between
No single framework is right for a company. Many companies, thus, take the
31000 frameworks, in the next segment, we will look at the ISO 31000
process.
At H&M, the Swedish retail brand, the board of directors handles the company’s
internal control and risk management. The overall aim of the internal control is to
safeguard the company’s assets and, consequently, its shareholders’ investment. This
is to ensure that the business is managed in the most appropriate and effective
manner possible, that there is reliable financial reporting and compliance with
applicable laws and regulations.
Based on the given information, H&M’s risk management process is more inclined
towards the ____________ framework.
COSO
✓ Correct
Feedback:
H&M’s risk management process is targeted at internal audit and accounting and
has a broad focus on corporate governance, which is a characteristic of the COSO
framework.
Fill in the blank with the correct option from those given below.
COSO
✓ Correct
Feedback:
advantages and disadvantages. Now, in this segment, you will learn more
about the ISO 31000 framework, which is used worldwide and by different
organisations.
But before proceeding further, why do you think these organisations use this
framework? How can organisations of different types benefit from the same
framework?
This boils down to all the organisations having a common base to risk
management, and this base is created through the process of the ISO 31000
framework.
ISO 31000
After tests revealed high levels of lead and MSG, India's Food Safety Administration
(FDA) instructed Nestlé India to recall its famous 2-minute Maggi noodles by the end
of May 2015. The company was aware of the repercussions of having higher than
permissible levels of these components in its product.
The multinational FMCG company initially denied the allegations that the noodles were
unsafe, stating on their official social media pages that no request to recall any goods
had been issued.
Lead content found in Maggi samples sent in the consumer market for consumption is
a sign of ___________ failure.
Fill in the blank with the correct option from those given below.
Risk monitoring
✓ Correct
Feedback:
Maggi did not perform accurate quality checks of its product samples. Even
though the risk had been identified, it was not monitored properly, which led to
the huge debacle.
Implementation of an
ERM framework: Case
Study
“If knowledge is not put into practice, it does not benefit one.”
- Muhammad Tahir-ul-Qadri
Now that you have gathered knowledge on the different ERM frameworks, in
this segment, we will analyse them through a case study. Such an analysis
ERM process.
Process design: It developed a global risk process using the attributes of the
During the implementation of the ERM process, the company faced two main
challenges:
It faced difficulty coordinating among different time zones for
scheduling meetings since all of its employees were scattered around the world, due
One key rebuttal that the concerned stakeholders raised was to question the need of
using an ERM framework given the company had been able to succeed so far without
it.
emerging risks.
assessments were conducted annually. The required information was reported to the
global risk committee for review purposes and assessment of corporate risk profile
Session Summary
This session covered the following topics:
business. The COSO and ISO 31000 frameworks cover all the aspects of ERM in
exposed to.
2. COSO
3. ISO 31000
The ISO 31000 framework was developed by the International Organization for
Standardization.
4. The ISO and COSO ERM frameworks have certain advantages and
1. The session also discussed the ISO 31000:2009 process, which is depicted
below.
ISO 31000
ISO 31000
1. Through a case study, you learnt how an ERM process is implemented. In the
Education: It educated the senior management on the need for an integrated ERM
process.
Process design: It developed a global risk process using the attributes of the ISO
Stakeholder buy-in: It presented the process to various global operation groups for
brainstorming sessions.
emerging risks.
Global ERM plan: It implemented a global ERM plan wherein risk assessments
were conducted annually. The required information was reported to the global risk
committee for review purposes and an assessment of the corporate risk profile was
also undertaken.
Graded Assessments
Q1) Healthcare Group, a pharmaceutical firm, takes a methodical outlook to enterprise
risk management. Throughout its value chain, from the early identification of new,
promising compounds to the manufacture and distribution of drugs to patients, it is
constantly exposed to risks. In the pharmaceutical industry, certain uncertainties are
inevitable, such as delays or failures of promising new drugs in the R&D pipeline.
Other challenges, such as supply disruptions and competitive threats, are well known
to every global manufacturing organisation.
R&D risk, supply chain risk, safety and quality risks, commercialisation risk, security
risk, financial risk and regulatory risk are some of the most significant threats that it
faces.
Based on the given information, which framework is Healthcare Group more inclined to
use as a base in its risk management process?
ISO 31000
✓ Correct
Feedback:
They have an internal risk committee that is responsible for financial risk and
implemention of the risk management strategy, which is created based on discussions
with the board of directors and the senior management.
Based on the given information, which framework is Honeywell more inclined to use as
a base in its risk management process?
COSO
✓ Correct
Feedback:
COSO is targeted at internal audit and accounting and has a broad focus on
corporate governance. Honeywell International’s risk management process is
targeted at internal audit and accounting and has a broad focus on corporate
governance.