Risk Culture Resources for Practitioners the Institute of Risk Management (IRM) Is the World’S Leading Enterprise-Wide Risk Management Education Institute
Total Page:16
File Type:pdf, Size:1020Kb
The Institute of Risk Management Risk culture Resources for Practitioners The Institute of Risk Management (IRM) is the world’s leading enterprise-wide risk management education Institute. We are independent, well-respected advocates of the risk profession, owned by our members who are practising risk professionals. IRM passionately believes in the importance of risk management and that investment in education and continuing professional development leads to more effective risk management. We provide qualifications, short courses and events at a range of levels from introductory to expert. IRM supports its members and the wider risk community by providing the skills and tools needed to put theory into practice in order to deal with the demands of a constantly changing, sophisticated and challenging business environment. We operate internationally with members and students in over 100 countries, drawn from all risk-related disciplines and a wide range of industries in the private, third and public sectors. A not-for profit organisation, IRM reinvests any surplus from its activities in the development of international qualifications, short courses and events. Protiviti (www.protiviti.com) is a global consulting firm that helps companies solve problems in finance, technology, operations, governance, risk and internal audit. Through our network of more than 70 offices in over 20 countries, we have served more than 35 percent of FORTUNE 1000 and Global 500 companies. In the UK we have worked with over 30% of the FTSE 100. We also work with smaller, growing companies, including those looking to go public, as well as with government agencies. Protiviti is a wholly owned subsidiary of Robert Half International Inc. (NYSE: RHI). Founded in 1948, Robert Half International is a member of the S&P 500 index. ©2012 The Institute of Risk Management. Chapter 11 is copyright Protiviti. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording or otherwise without the express permission of the copyright owner. Permission will generally be granted for use of the material from this document on condition that the source is clearly credited as being the Institute of Risk Management and, in the case of chapter 11, Protiviti. IRM does not necessarily endorse the views expressed or products described by individual authors within this document. Foreword For over 25 years the Institute of Risk Management has provided leadership and guidance to the emerging risk management profession with a unique combination of academic excellence and practical relevance. Problems with The Institute’s profile continues to grow internationally with heightened interest in the management of risk risk culture are across government, public and business domains. often blamed for Our work on risk culture is our latest contribution to thought leadership in the field. The continuing parade of organisational catastrophes (and indeed some notable successes) demonstrates that frameworks, organisational processes and standards for risk management, although essential, are not sufficient to ensure that organisations reliably manage their risks and meet their strategic objectives. What is missing is the difficulties but, behavioural element: why do individuals, groups and organisations behave the way they do, and how does this affect all aspects of the management of risk? until now, there Problems with risk culture are often blamed for organisational difficulties but, until now, there was very was very little little practical advice around on what to do about it. This paper seeks to give guidance in this area, drawing upon the wealth of practical experience and expert knowledge across the Institute. It aims to provide advice practical advice to organisations wanting greater understanding of their own risk cultures and to give them some practical tools that they can then use to drive change. It should be of interest to board members, executive and non- around on what executive, risk professionals, HR professionals, regulators and academics. to do about it. This document - Risk Culture: Resources for Practitioners – is aimed at those working as risk professionals and brings together work on the concepts and models that we have found to be useful. It has been published concurrently with a short document summarising our approach to risk culture for those working at board level. Risk culture remains a developing area and we do not consider that we have written the last word on the subject – we expect to see more models and tools and, in particular, sector and issue-specific work emerging in the future. I am particularly grateful to Alex Hindson, my immediate predecessor as IRM chairman, who has been the driving force behind this work and who has brought together the wide ranging thoughts of a diverse project group plus a global consultation into a coherent paper. I would also like to thank our sponsor Protiviti, for supporting the design and print of this document, as well as contributing to the content. IRM is a not-for-profit organisation and such support is invaluable in helping us maximise our investment in the development and delivery of world class risk management education and professional development. Our thanks also go to those other organisations and associations from around the world who are endorsing this document and commending it to their members. Richard Anderson Chairman The Institute of Risk Management These days it feels as though we read about another failing in corporate standards almost every day. Maybe it has always been the case but it appears that when the dust settles and the enquiry is over the causes of the failure boil down more often than ever to culture. The term risk culture is bandied about by regulators, politicians and the media. Why does it appear so hard to get risk culture right and what does it look like when we do? Protiviti is delighted to support this new piece of thought leadership from the IRM and looks forward to engaging in the resulting debate with its members and with the wider business community to bring solutions to this topic to the front of the business agenda. Peter Richardson Managing Director Protiviti Our supporters The IRM’s paper focuses attention on an important governance issue that is relevant across all sectors. By helping the understanding of how culture impacts on risk management, the paper will help risk managers, governance practitioners and those charged with governance to be more aware of the contribution of effective risk management to good governance. The questions for the board will support organisations seeking to improve their risk culture and we look forward to exploring these issues further with our members. Ian Carruthers Director Policy & Technical Chartered Institute of Public Finance and Accountancy The Institute of Risk Management South Africa (IRMSA) is looking forward to being part of this initiative and to assist members, within South Africa and Africa, better understand risk culture and the constant debate within their organisations. IRMSA supports this initiative by the IRM and we look forward to continuing the discussion amongst our members and seeing the feedback from our global peers. Gillian le Cordeur Chief Operations Officer The Institute of Risk Management South Africa (IRMSA) The Business Continuity Institute (BCI) welcomes this exceedingly thorough contribution to the subject of risk culture from IRM and its partners. The BCI is confident that this will become the definitive guide on the subject for years to come. Culture has a significant impact on how organisations prepare for and successfully deal with unexpected crises and their consequences, whether it is in supporting communication up and down the organisation or ensuring that employees are motivated to work through a crisis. It is therefore a key determinant of an effective business continuity capability and organisational resilience. This paper provides some excellent diagnostic tools for practitioners to better understand the risk culture in which they are implementing a BCM programme, and how they can take the initiative to advocate changes to attitudes and behaviours that can deliver more effective business continuity. Lee Glendon Head of Research & Advocacy Business Continuity Institute IRM’s guidance on risk culture offers a crisp and thought provoking discussion of the importance and difficulty of determining the desired culture and making it stick. We recommend it as a valuable resource for anyone in any organization who is striving to understand and improve risk culture as a critical step in achieving principled performance. Carole Stern Switzer, Esq Co-Founder and President Open Compliance & Ethics Group Alarm, now in its 21st year of being the UK voice for public service risk management is pleased to support this latest publication from the Institute of Risk Management. Culture is a complex structure with many elements feeding it from the objectives of an organisation, the tone at the top through to the way we always do things here, as a few examples. All organisations will have a culture - the challenge is to ensure that this culture supports the management of risk rather than working against it. This publication gives real practical guidance and tools that managers of risk can use to drive change towards a positive risk culture. Mandy Knowlton-Rayner Chairman Alarm While much progress has been made in recent years in developing risk management frameworks and standards, recent events have shown that there needs to be more focus on the behavioural aspects of governance and risk management, including the creation of a robust risk culture. CIMA therefore welcomes this new report as a valuable contribution to helping organisations to succeed with plenty of practical tools to support putting the concepts into practice. Gillian Lees Head of Corporate Governance Chartered Institute of Management Accountants (CIMA) The Federation of European Risk Management Associations (FERMA) is pleased to endorse this authoritative work.