SlideShare a Scribd company logo
Enterprise Risk Management
Prof Akram Hassan SME@PMI
1980 Johnson & Johnson Story
Reputation risk
Someone poisoned
bottles resulting in
several deaths
100% 100%
Honest open
communication
Recovery of
share value
The company reacted quickly, removing
and replacing its products at retail outlets,
cooperating fully with law enforcement
authorities, and keeping the media (and,
hence, the public) informed throughout.
2020 Wirecard Group Story
Fraud risk Corruption Case
0% 97%
Honest open
communication
Failure of
share value
Wirecard acknowledgesfor the first time
from 2015 the potential scale of a multiyear
accounting fraud, warning that the €1.9bn
of cash probably does “not exist”. Wirecard
says it will file for insolvency.
“The primary purpose of
ERM is the creation and
protection of value.” ©2019 PMI
What constitutes "best
practices" in ERM has yet
to be defined. ©2020 Investopedia
Enterprise Risk Management
01
Identify Enterprise Risk
02
Analyze Enterprise Risk
03
Respond Enterprise Risk
04
Agenda
ERM Maturity Model
05
01 Enterprise Risk Management
M I L I TA R Y
Traditional Risk Management Vs ERM
Tactical
Reactive
Silo-based processes
RM ERM
Unlinked to decision makers
Supported by rules
WHY ?
Strategic
Proactive
Integrated processes
Linked to decision makers
Supported by risk culture
Chief Risk Officer (CRO)
to coordinate ERM efforts.
M I L I TA R Y
Risk Culture
Tailoring risk effort.
Open and honest
communication.
Recognizing the value of
risk management.
Individual commitment/
responsibility.
Organizational
commitment.
Integration with OPM.
1
2
3
4
5
6
Executive Role
A chief risk officer (CRO) is an
executive in charge of managing
risks to the company.
High Experience
It is a senior position that
requires years of experience in
accounting, economics, legal, or
actuarial backgrounds.
CRO
ERM provides
decisionmakers with a
realistic picture of likely
outcomes to their
strategic initiatives by
integrating risk into the
cost-benefit analysis of
all strategic
investments.
ERM Proactive Approach
ERM is an approach for:
1. Identifying major risks that
confront an organization.
2. Forecasting the significance of
those risks to business processes.
3. Responding to create or protect
the value.
Forecast
Identify Respond
E R M
I n t e g r a t i o n
C o n s o l i d a t i n g & C a s c a d i n g
Plan Risk Responses
Implement Risk
Responses
Plan Risk Management
Identify Risks
PerformQualitative
Risk Analysis
01
06
03
04
07
ERM Life Cycle Framework
05
02
PerformQuantitative
Risk Analysis
Monitor Risks
Source: The standard for Risk Management ©2019 PMI
PLAN RESPONSE
IMPLEMENT
RESPONSE
INITIAT RISK
IDENTIFY RISKS
ASSESS RISKS
01
02
03
05
ERM Life Cycle Framework
04
Source: The Project Risk Analysis and Management (PRAM) Guide 2nd edition, written by the APM
ERM Life Cycle
Source: ISO 31000 standard Risk management: principles and guidelines
ERM Plan Success Factors
Acceptance
Bias correction
Alignment
Balance
Completion
02 Identify Enterprise Risk
01
02
03
04
People
Processes
Information
Technology
Risks permeate…
M I L I TA R Y
Risk Classification
There is knowledge to
identify probability and
impact.
Known–Unknown
(Classic risk)
Knowledge exists in
community but not with
the entity working on
the endeavor.
Unknown–Known
(Hidden fact)
Managed as a part of scope.
Not a risk.
Known–Known (Facts)
Knowledge does not exist within the sphere of
influence.
Unknown-Unknown (Emergent Risk)
Cause – Risk – Effect
FACT
RESULT
RISK
CAUSE
EFFECT
As a result of cause
risk may occur
which lead to effect
Ishikawa Diagram
Example of a Cause and Effect
ERM Identification Success Factors
Early identification
Iterative identification
Comprehensive identification
Emergent identification
M I L I TA R Y
ERM Identification Tool
Technology
Regulatory/legal
Uncertainty
Market
Socio-cultural
Political
Economic
Competitive
Prompt List
SPECTRUM
ERM Identification Tool
Competition, Social trend, Capital
availability.
Strategic Risks
Customer satisfaction, Product
failure, Integrity, Reputational risk;
Knowledge drain.
Operational Risks
Pricing risk, Asset risk,
Currency risk, Liquidity risk.
Financial Risks
Liability torts, Property damage,
Natural catastrophe
Hazard Risks
Source: The Casualty Actuarial Society (CAS)
03 Analyze Enterprise Risk
ERM Criteria
5 4 3 2 1
60% 40%
Heat Map
Exposure = Impact × Probability
ER Prioritization
Proximity. The period of time
before the risk might have an
impact on one or more project
objectives. A short period indicates
high proximity.
Detectability. The ease with which
the results of the risk occurring, or
being about to occur, can be
detected and recognized. Where
the risk can be detected easily,
detectability is high.
ER Forecasting
04 Respond Enterprise Risk
Thomas Stanton (Feb 18, 2017).
"Enterprise Risk Management".
The point of ERM is not to
create more bureaucracy,
but to facilitate discussion
on what the really big risks
are.
ERM Strategies (Threats)
Mitigate
Avoid
Escalate
Transfer
Accept
ERM Strategies (Opportunities)
Share
Exploit
Enhance Accept
Escalate
ER
Response Tool
Force Field Analysis
Balance of Forces for
and against Change
05 ERM Maturity Model
ERM Model
ERM Stakeholders
ERM Maturity Model
Be Safe…
Manage the Risks…
Protect Your Business…
Prof Akram Hassan SME@PMI
akramkram@yahoo.com +201014356420

More Related Content

PPTX
Enterprise Risk Management
DOCX
Enterprise risk management
PPTX
Enterprise Risk Management and Sustainability
PDF
Enterprise Risk Management & Organizational Excellence
PPTX
Strategic Risk Management as a CFO: Getting Risk Management Right
PDF
ERM-Enterprise Risk Management
PDF
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management
Enterprise risk management
Enterprise Risk Management and Sustainability
Enterprise Risk Management & Organizational Excellence
Strategic Risk Management as a CFO: Getting Risk Management Right
ERM-Enterprise Risk Management
Enterprise Risk Management - Aligning Risk with Strategy and Performance

What's hot (20)

PPTX
Risk management
PPT
Risk Management Fundamentals
PDF
Risk Assessment PowerPoint Presentation Slides
PDF
Risk appetite
PPTX
Integrating Risk into your Balanced Scorecard
PPTX
Risk Culture, Risk What?
PDF
Risk management concepts and learning
PDF
Shaping Your Culture via Risk Appetite
PDF
How to Build an Enterprise Risk Management Framework
PPTX
Integrating Strategy and Risk Management
PPT
The importance of risk management in business
PPTX
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
PPTX
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
PDF
Sharing Practice on Enterprise Risk Management (ERM)
PPTX
Key risk indicators shareslide
PPTX
Organizational Risk Management
PDF
Risk Management Overview Powerpoint Presentation Slides
PPTX
Risk culture presentation
PDF
Managing with KPI's and KRI's
PDF
Enterprise Risk Management (ERM) Framework 2020
Risk management
Risk Management Fundamentals
Risk Assessment PowerPoint Presentation Slides
Risk appetite
Integrating Risk into your Balanced Scorecard
Risk Culture, Risk What?
Risk management concepts and learning
Shaping Your Culture via Risk Appetite
How to Build an Enterprise Risk Management Framework
Integrating Strategy and Risk Management
The importance of risk management in business
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Sharing Practice on Enterprise Risk Management (ERM)
Key risk indicators shareslide
Organizational Risk Management
Risk Management Overview Powerpoint Presentation Slides
Risk culture presentation
Managing with KPI's and KRI's
Enterprise Risk Management (ERM) Framework 2020
Ad

Similar to Enterprise Risk Management (20)

PPTX
Enterprise Risk Management
PDF
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...
PPTX
Erm talking points
PDF
An approach to erm in the insurance industry apria 2002 rama warrier&preeti
PPT
enterprise risk m training awaereness.ppt
PDF
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) model
PDF
Presentation Makes the Case for Enterprise Risk Management
PPT
Enterprise Risk Management : Hollow Tree Giant Redwood.ppt
PPT
files_maf_gorvett.ppt-managementt_risiko
PPTX
DiSerafino - ORSA_insurance_conference
DOCX
I need a response to the discussion in APA format.docx
PPT
The role of auditing in the erm process
PPTX
ERM.pptx Erm ERM Erm Erm Erm Erm Erm Erm
PPTX
Risk Management ERM Presentation
PDF
The Role of Data Science in Enterprise Risk Management, Presented by John Liu
PDF
Role of Data Science in ERM @ Nashville Analytics Summit Sep 2014
PPT
Coso Erm(2)
PDF
Enterprise risk management summary approach guide
PPTX
Enterprise risk management summary approach guide
PDF
Enterprise tools and_techniques
Enterprise Risk Management
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...
Erm talking points
An approach to erm in the insurance industry apria 2002 rama warrier&preeti
enterprise risk m training awaereness.ppt
ThinkGRC justifying the transition to an Enterprise Risk Management (ERM) model
Presentation Makes the Case for Enterprise Risk Management
Enterprise Risk Management : Hollow Tree Giant Redwood.ppt
files_maf_gorvett.ppt-managementt_risiko
DiSerafino - ORSA_insurance_conference
I need a response to the discussion in APA format.docx
The role of auditing in the erm process
ERM.pptx Erm ERM Erm Erm Erm Erm Erm Erm
Risk Management ERM Presentation
The Role of Data Science in Enterprise Risk Management, Presented by John Liu
Role of Data Science in ERM @ Nashville Analytics Summit Sep 2014
Coso Erm(2)
Enterprise risk management summary approach guide
Enterprise risk management summary approach guide
Enterprise tools and_techniques
Ad

More from Prof. Akram Hassan PhD,MBA,PMP,OPM3 (20)

PDF
PDF
ادارة تحديات المستقبل
PDF
Essential Skills for 2023 Engineers
PDF
مقدمة لدورة الهوية المؤسسية
PDF
المشاريع المتعثرة
PDF
اخلاقيات البحث العلمى
PDF
Resilient Project Managers
PDF
BMO Integration with PMO
PDF
PDF
برنامج مستقبل وطن
PDF
حوكمة المؤسسات غير الربحية
PDF
الشراكة - دروس وعبر من التاريخ
PDF
التنمر الوظيفي
PDF
إعادة الإعمار بعد الحروب
PDF
Business Sustainability
PDF
Governance, Risk management and Compliance Integrated Systems
ادارة تحديات المستقبل
Essential Skills for 2023 Engineers
مقدمة لدورة الهوية المؤسسية
المشاريع المتعثرة
اخلاقيات البحث العلمى
Resilient Project Managers
BMO Integration with PMO
برنامج مستقبل وطن
حوكمة المؤسسات غير الربحية
الشراكة - دروس وعبر من التاريخ
التنمر الوظيفي
إعادة الإعمار بعد الحروب
Business Sustainability
Governance, Risk management and Compliance Integrated Systems

Recently uploaded (20)

PDF
PMI UK 31st July 2025 Presentation...pdf
PPTX
Mastering-Event-Management-A-Comprehensive-Guide.pptx
PDF
OBSTRUCTIONS OF TURKISH PUBLIC ORGANIZATIONS GETTING ISO/IEC 27001 CERTIFIED
PDF
Asia’s Healthcare Power Players - The Visionary CEOs Reshaping Medicine for 4...
PDF
Handbook of Procurement (Nicola Dimitrig
PPTX
Active listening skills for school education
PDF
The Hive Mindset_ What School Leaders Can Learn from Beekeeping by Dr.pdf
PPTX
Letter of credit which matters to Import and Export policy
PDF
2024_10 Approach to selecting a CPM Application
PPTX
AAccounts Prepration for Public Limited Companies
PPTX
School Annual day Presentation, Logo, Animation
PDF
Asia’s Health Titans - Meet the Hospital CEOs Revolutionizing Care Across the...
PDF
Guide to the contract management (CMBOK)
PPTX
Consulting on marketing-The needs wants and demands are a very important comp...
PDF
The Crystal Ball Chronicles - Battle of the Healers - Tran Quoc Bao the winner
PDF
Situation Managment - Lesson in Krishna Way.pdf
PDF
SpatzAI Micro-Conflict Resolution Toolkit - Fairer Teamwork Globally
PDF
How does risk management integrate with project control?
PDF
40.-Rizal-And-Philippine-Identity-Formation.pdf
PPTX
Hutt_Speh_Chapter2_Organizational_Buying.pptx
PMI UK 31st July 2025 Presentation...pdf
Mastering-Event-Management-A-Comprehensive-Guide.pptx
OBSTRUCTIONS OF TURKISH PUBLIC ORGANIZATIONS GETTING ISO/IEC 27001 CERTIFIED
Asia’s Healthcare Power Players - The Visionary CEOs Reshaping Medicine for 4...
Handbook of Procurement (Nicola Dimitrig
Active listening skills for school education
The Hive Mindset_ What School Leaders Can Learn from Beekeeping by Dr.pdf
Letter of credit which matters to Import and Export policy
2024_10 Approach to selecting a CPM Application
AAccounts Prepration for Public Limited Companies
School Annual day Presentation, Logo, Animation
Asia’s Health Titans - Meet the Hospital CEOs Revolutionizing Care Across the...
Guide to the contract management (CMBOK)
Consulting on marketing-The needs wants and demands are a very important comp...
The Crystal Ball Chronicles - Battle of the Healers - Tran Quoc Bao the winner
Situation Managment - Lesson in Krishna Way.pdf
SpatzAI Micro-Conflict Resolution Toolkit - Fairer Teamwork Globally
How does risk management integrate with project control?
40.-Rizal-And-Philippine-Identity-Formation.pdf
Hutt_Speh_Chapter2_Organizational_Buying.pptx

Enterprise Risk Management

  • 1. Enterprise Risk Management Prof Akram Hassan SME@PMI
  • 2. 1980 Johnson & Johnson Story Reputation risk Someone poisoned bottles resulting in several deaths 100% 100% Honest open communication Recovery of share value The company reacted quickly, removing and replacing its products at retail outlets, cooperating fully with law enforcement authorities, and keeping the media (and, hence, the public) informed throughout.
  • 3. 2020 Wirecard Group Story Fraud risk Corruption Case 0% 97% Honest open communication Failure of share value Wirecard acknowledgesfor the first time from 2015 the potential scale of a multiyear accounting fraud, warning that the €1.9bn of cash probably does “not exist”. Wirecard says it will file for insolvency.
  • 4. “The primary purpose of ERM is the creation and protection of value.” ©2019 PMI What constitutes "best practices" in ERM has yet to be defined. ©2020 Investopedia
  • 5. Enterprise Risk Management 01 Identify Enterprise Risk 02 Analyze Enterprise Risk 03 Respond Enterprise Risk 04 Agenda ERM Maturity Model 05
  • 6. 01 Enterprise Risk Management
  • 7. M I L I TA R Y Traditional Risk Management Vs ERM Tactical Reactive Silo-based processes RM ERM Unlinked to decision makers Supported by rules WHY ? Strategic Proactive Integrated processes Linked to decision makers Supported by risk culture Chief Risk Officer (CRO) to coordinate ERM efforts.
  • 8. M I L I TA R Y Risk Culture Tailoring risk effort. Open and honest communication. Recognizing the value of risk management. Individual commitment/ responsibility. Organizational commitment. Integration with OPM. 1 2 3 4 5 6
  • 9. Executive Role A chief risk officer (CRO) is an executive in charge of managing risks to the company. High Experience It is a senior position that requires years of experience in accounting, economics, legal, or actuarial backgrounds. CRO
  • 10. ERM provides decisionmakers with a realistic picture of likely outcomes to their strategic initiatives by integrating risk into the cost-benefit analysis of all strategic investments. ERM Proactive Approach
  • 11. ERM is an approach for: 1. Identifying major risks that confront an organization. 2. Forecasting the significance of those risks to business processes. 3. Responding to create or protect the value. Forecast Identify Respond E R M I n t e g r a t i o n C o n s o l i d a t i n g & C a s c a d i n g
  • 12. Plan Risk Responses Implement Risk Responses Plan Risk Management Identify Risks PerformQualitative Risk Analysis 01 06 03 04 07 ERM Life Cycle Framework 05 02 PerformQuantitative Risk Analysis Monitor Risks Source: The standard for Risk Management ©2019 PMI
  • 13. PLAN RESPONSE IMPLEMENT RESPONSE INITIAT RISK IDENTIFY RISKS ASSESS RISKS 01 02 03 05 ERM Life Cycle Framework 04 Source: The Project Risk Analysis and Management (PRAM) Guide 2nd edition, written by the APM
  • 14. ERM Life Cycle Source: ISO 31000 standard Risk management: principles and guidelines
  • 15. ERM Plan Success Factors Acceptance Bias correction Alignment Balance Completion
  • 18. M I L I TA R Y Risk Classification There is knowledge to identify probability and impact. Known–Unknown (Classic risk) Knowledge exists in community but not with the entity working on the endeavor. Unknown–Known (Hidden fact) Managed as a part of scope. Not a risk. Known–Known (Facts) Knowledge does not exist within the sphere of influence. Unknown-Unknown (Emergent Risk)
  • 19. Cause – Risk – Effect FACT RESULT RISK CAUSE EFFECT As a result of cause risk may occur which lead to effect
  • 20. Ishikawa Diagram Example of a Cause and Effect
  • 21. ERM Identification Success Factors Early identification Iterative identification Comprehensive identification Emergent identification
  • 22. M I L I TA R Y ERM Identification Tool Technology Regulatory/legal Uncertainty Market Socio-cultural Political Economic Competitive Prompt List SPECTRUM
  • 23. ERM Identification Tool Competition, Social trend, Capital availability. Strategic Risks Customer satisfaction, Product failure, Integrity, Reputational risk; Knowledge drain. Operational Risks Pricing risk, Asset risk, Currency risk, Liquidity risk. Financial Risks Liability torts, Property damage, Natural catastrophe Hazard Risks Source: The Casualty Actuarial Society (CAS)
  • 26. 60% 40% Heat Map Exposure = Impact × Probability
  • 27. ER Prioritization Proximity. The period of time before the risk might have an impact on one or more project objectives. A short period indicates high proximity. Detectability. The ease with which the results of the risk occurring, or being about to occur, can be detected and recognized. Where the risk can be detected easily, detectability is high.
  • 30. Thomas Stanton (Feb 18, 2017). "Enterprise Risk Management". The point of ERM is not to create more bureaucracy, but to facilitate discussion on what the really big risks are.
  • 33. ER Response Tool Force Field Analysis Balance of Forces for and against Change
  • 38. Be Safe… Manage the Risks… Protect Your Business… Prof Akram Hassan SME@PMI [email protected] +201014356420