No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Featured

Is Your Risk Culture Aligned With the Realities of the Digital Age?

The Importance of Strategic Risk Management in Creating Enterprise Value

by Jim DeLoach
February 2, 2021
in Featured, Risk
illustration of businessman holding giant shield to protect him from falling arrows

How many senior executives and directors can name a chief risk officer who has advised them that the organization is too risk averse? In the digital age, not enough. Protiviti’s Jim DeLoach discusses.

The ground rules for risk and reward are well known. These rules hold that one must take risks to grow, and typically, the more risk one takes, the higher the potential return. They also suggest that a risk-averse mindset often leads to a lower return. These canonical laws have been embedded in business and finance since before any of us were born.

But in the digital age, these time-honored tenets must reflect more prominently the risks of inaction and organizational resistance to change. Given the pace of change in the digital economy, the realities are such that it’s not just a matter of taking risk to grow or generate greater returns, it’s also a matter of survival. Bottom line: Organizations must undertake more risk than they may be accustomed to taking if they are going to survive. Refusal to take risk means accepting the risk of growing stale and becoming irrelevant. This is no time to be comfortable with the status quo.

Key Considerations

Taking risk means more than introducing new products and entering new markets. It entails becoming more innovative in reimagining processes, disrupting business models and even reinventing the organization itself. In the digital age, executive management and the board have an important role to play in strengthening and nurturing the risk culture that facilitates the initiative, creativity and digital thinking so vital to success.

Over three decades, thinking around best-of-class risk management has evolved from a fragmented, siloed model focused narrowly on myriad risks to an enterprisewide approach focused on the most critical enterprise risks and integrated with strategy setting and performance management. Cultural attributes illustrating this transition are illustrated in the following table:

Risk Culture Attribute Traditional View Fit for the Digital Age
Attitude Avoid, Mitigate Risk

Reduce Downside

Take Risk Within Limits

Maximize Upside, Manage Downside

Management Style Manage

React

Ad Hoc

Master

Be Proactive, Agile

Continuous

Focus Present, Looking Backward Anticipatory, Looking Forward
Types of Risk Operational, Financial and Compliance Strategic, Disruptive Change and Digital Risk
View of Risk Profile List of Risks Variability of Outcomes
Risk Appetite Not Articulated Agreed by CEO/Board
Objective List Risks, Treat Risk Optimize Risk Profile

Facilitate Successful Outcomes

Measurement Heat Maps Monte Carlo, “What If” Analysis, Stress Testing
Strategy Setting Afterthought Integrated
Performance Management Appendage Integrated

In the digital age, risk management must be strategic. Traditional risk management applies an analytical framework to assess risks and opportunities with different characteristics and time horizon considerations in the same way, without considering multiple views of the future. This approach ignores the reality of uncertainties organizations face in the digital age and is often influenced by past experience and subjective assessments, fostering groupthink, pre-empting out-of-the-box thinking and offering little insight as to what to do about exposures to disruptive events. It also does not account for the increased velocity of change in the digital economy.

Many of the risks and opportunities unique to the digital age are “compensated,” meaning they are two-sided and present enormous potential for upside that compensates for the downside exposure. If all foreseeable future outcomes were listed as a result of undertaking a given risk or group of interrelated risks along with the expected net cash flows relating to each possible outcome and their respective probability of occurrence, a distribution of possible outcomes results with both net positive and negative cash flow results, giving rise to performance variability. Therefore, compensated risks are inseparable from setting and executing the organization’s strategy.

This is why traditional risk management often does not influence strategy, as it often focuses on mitigating and avoiding uncompensated risks. Such risks are often one-sided, because they offer the potential for downside with little or no upside potential (i.e., every foreseeable outcome results in net cash outflows, creating a loss exposure). These risks include environmental, health and safety risks.

That said, when managing such loss-exposure risks, care must be taken not to ignore interrelationships with other risks that offer upside potential, because they are compensated risks. For example, there is no upside if a cyber or privacy incident were to occur. However, an overly cautious approach that eliminates too much risk might limit or delay innovation opportunities that offer significant upside. Therefore, managing cyber and privacy risk in isolation may not be in the best interests of the business. If a company is evaluating whether to apply digital technologies to enhance its processes, launch a new product or service or differentiate customer experiences, it also needs to consider how much exposure to cyber and privacy risk it is willing to accept. With today’s optics on managing the reputational fallout of security breaches, this question requires careful consideration.

In the digital age, risk management must help leaders make the best bets from a risk/reward standpoint that have the greatest potential for creating enterprise value. This means that the creation and protection of enterprise value in the digital age depend on the organization’s ability to pursue compensated risks and opportunities successfully and either avoid or transfer uncompensated risks or reduce them to an acceptable level. A risk-informed approach fit for the digital age is one that is strategic in considering the impact of risk on strategy and performance; balanced in evaluating both opportunity and risk; integrated with strategy setting, planning and business execution; and customized, reflecting organizational business needs, expectations and cultural attributes.

As the keystone that balances the inevitable tension between (a) creating enterprise value through strategy and driving performance on the one hand and (b) protecting enterprise value through risk appetite and managing risk on the other hand, risk culture balances the push between strategy and risk appetite – an essential goal in the digital age.

Digital Leaders proactively take risk, whereas Digital Skeptics do not (see my article on assessing an organization’s digital readiness). Additional aspects of the risk culture relevant to the digital age are illustrated in the following table:

Risk Culture Attribute Traditional View Fit for the Digital Age
Digital Maturity Skeptic or Beginner Agile Follower or Leader
Customer Orientation Passive Awareness Passionate Focus
Decision Making Get All the Facts First

Lack of Real-Time Intelligence

High-Velocity, High-Quality

Informed, Intelligent

Innovation Failure Impedes Careers Failure Celebrated, Fail Fast
Line of Sight Make the Numbers

Pursue Commodities

Seek Opportunities

Pursue the Possible

Industry Vision Watch the Wallet Watch the Disrupters
Leadership Style Conformist, Catch Up Contrarian, Set the Pace

In the digital economy, risk management must contribute to reshaping strategy in advance of disruptive change. Integrating more sophisticated quantification and monitoring capabilities into the day-to-day activities of the business in executing the strategy and focusing on the risks and opportunities that matter can help management frame a composite risk profile fit for the digital age and provide more granular information on key aspects of the strategy as well as costs and benefits expected from alternative scenarios.

Market-changing organizations are built differently. It is our view that a Digital Leader has a very different approach to risk management than a Digital Skeptic or Digital Beginner. In the digital age, it is all about maximizing the upside while managing the downside, thus fitting the profile of companies best positioned to compete, thrive and win with an obsessive focus on growth and improving the customer experience. If the organization does not advance its digital maturity, another risk arises. We call it “digital risk,” or the risk of choosing not to get uncomfortable in the digital age. Accordingly, a traditional approach to risk management might be the biggest risk that an organization faces when it seeks to grow and defend share against new entrants.

In the digital age, becoming a leader entails revisiting risk mitigation strategies with an eye toward accepting more risk and exploiting the upside potential of market opportunities. For example, rather than merely mitigating risks to the execution of the strategy, companies should also use scenario analysis (Monte Carlo and/or “what if” analysis) to assess the impact on the achievement of strategic objectives and desired corporate risk profile of alternative scenarios. This analysis contributes to a more robust strategic decision-making process.

Our advice to executive management and boards: It is time to change the corporate risk culture, and digital-savvy executives and directors should lead the way.

Questions for Executive Management and Boards

Following are some suggested questions that executive management teams and boards of directors may consider, based on the risks inherent in the organization’s operations:

  • Is the organization’s risk culture enabling its advancement in digital maturity? Or is it a barrier requiring executive management’s and the board’s attention from a change management standpoint?
  • Does the board possess the digital savviness to provide leadership and support the CEO? Is there sufficient digital savviness on and available to the executive team?
  • Is executive management and the board satisfied that the company understands the digital economy and is embracing the market differentiation possibilities in its strategic thinking? Do senior executives and the board receive risk-informed insights, competitive intelligence and opportunities to secure early-mover positioning in the marketplace, fostering more effective dialogue in decision-making processes and improved anticipation of future exposures and vulnerabilities?

Tags: Board of DirectorsBoard Risk Oversight
Previous Post

NICE Launches Next-Gen Compliance Solution

Next Post

Deloitte: Global Risk Management Survey, 12th Edition

Jim DeLoach

Jim DeLoach

Jim DeLoach, a founding Protiviti managing director, has over 35 years of experience in advising boards and C-suite executives on a variety of matters, including the evaluation of responses to government mandates, shareholder demands and changing markets in a cost-effective and sustainable manner. He assists companies in integrating risk and risk management with strategy setting and performance management. Jim has been appointed to the NACD Directorship 100 list from 2012 to 2018.

Related Posts

boards

Moving on Up? Before Reaching for a Board Seat, Make Sure You Understand Public-Private Nuances

by David Roberson
March 28, 2023

Compliance is a huge part of the job description for any member of the board of directors, so it’s no...

svb_f

Risky Business: Important Lessons From SVB’s Demise

by Atul Vashistha
March 28, 2023

When all is said and done, it’s likely that Silicon Valley Bank’s failure will be traced back to one serious...

risk tunnel

From Regulation to Volume, There Is No Light at the End of the Data Privacy Tunnel

by Jim DeLoach
March 15, 2023

Data proliferation and data privacy regulatory activity across the globe have created the need for focused boardroom discussions. An underpinning...

shifting sands risk

Shifting Sands: Leaders Are Feeling the Pressure of an Uncertain, Dynamic Risk Landscape

by Jim DeLoach
February 22, 2023

The global risk landscape has rarely been more unsettled over the past half-century than it is right now, and a...

Next Post
Deloitte: Global Risk Management Survey, 12th Edition

Deloitte: Global Risk Management Survey, 12th Edition

Compliance Job Interview Q&A

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Code of Conduct Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2022 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe

© 2022 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT