The COSO Framework for Internal Control
February 12, 2025
The general public is not very fond of the financial services industry. Whenever any crisis breaks out, the financial services industry is one of the first ones to bear the brunt. The fact that AIG, which is one of the largest insurance companies in the world, needed a bailout during the 2008 crisis does not […]
A conflict arises when individuals have different opinions, thought processes, attitudes, interests, needs and find it difficult to adjust with each other. When individuals perceive things in dissimilar ways and cannot find the middle way, a conflict starts. No organization can survive if the employees are constantly engaged in fights and conflicts. The individuals have […]
Culture and Group Behavior It is a known fact in management theory and practice that culture has a direct impact on group behavior. To elaborate, groups in organizations are comprised of individuals belonging to a common or a different culture. Therefore, it can be expected that the behavior of these individuals would depend a lot […]
The Forces of Chaos The business landscape of the 21st Century is characterized by increasing complexity, disorder, intense competition, hyper speed pace of change, and above all, a 24/7 “always on” culture. This means that chaos is inevitable in such a landscape because of the confluence of all these factors. Therefore, managers and leaders cannot […]
Corporate decision making happens at various levels in organizations and can be top down or bottom up. The difference between these two styles of decision making is that the top down decision making is done at the higher levels of the hierarchy and the decisions are passed down the corporate ladder to be implemented. On […]
Undertaking financial and non-financial risks is the basic job of any business organization. In fact, profit is considered to be a reward for efficiently bearing risks. Since risk-taking is so crucial, It is for this reason that every organization needs to create a framework that needs to be followed in order to manage risks in an effective manner.
The corporate risk governance framework is the organization’s way of institutionalizing the risk management process. In the absence of this governance framework, the organization’s approach will be driven by a handful of individuals instead of being driven in an institutional manner.
This article outlines some of the steps which are commonly taken by organizations in order to ensure that they have the appropriate corporate risk governance policy in place.
Risk governance is the process of setting up rules, regulations, procedures as well as norms related to the decisions which involve risk-taking across the organization. Risk governance is broader in scope as compared to the risk policy. This is because risk governance considers the impact as well as the point of view of all stakeholders. It also considers wider political, social, and legal ramifications of the risky decision.
The best way to understand risk governance is to think of it as an architecture that enables all other risk management activities in the organization. Risk governance also encompasses the formation of communication lines between various organizational stakeholders.
It is important that all the steps related to risk governance should be in compliance with the Enterprise Risk Management (ERM) framework. It is the job of the risk governance committee to ensure that the tenets laid down by the ERM framework are carefully followed during the risk governance process.
The first step in building a corporate risk governance framework is the establishment of a risk committee. The steps to form this committee and ensure its efficient functioning have been mentioned below:
The amount of capital being allocated for various risk management activities also needs to be approved by this committee. If the company is part of a larger framework of organizations, then it would be better if the committee is formed at a higher level and uses the enterprise risk management framework instead of managing the risks at an individual level. This helps in ensuring that the risk management practices being followed across the firm are not contradictory in any manner.
Industry-wide best practices dictate that the minutes of these meetings must be communicated to the board of management. These minutes should also be included in the quarterly report which is generally sent to all shareholders. The idea is to ensure that all the shareholders are made aware of the risk governance practice.
The central idea behind the establishment of the risk governance committee is that the risk management practices must remain more or less standardized even if the management of the company changes.
Hence, attempts are made to codify and standardize the risk management practices. However, it is important to realize that the risk management practices vary across organizations depending upon their size and complexity of the business.
Your email address will not be published. Required fields are marked *