Business Continuity Tip of the Month - March 2019
A healthy appetite
Every one of us has our own personal appetite for risk. Some people think nothing of taking huge risks, both in their business and personal lives, whilst others are far more reserved, to the point of being almost totally risk averse. Most of us fall somewhere in between.
Similarly, all organisations have a ‘corporate’ risk appetite, which dictates the types and levels of risk that the organisation, or at least the senior management team that directs it, are willing to take or to accept. The problem is that it can be very difficult to pin them down and get them to define the corporate risk appetite, partly because it’s actually quite difficult to put into words. So few organisations bother to do so, and fewer still actually document and publish a formal statement of risk appetite to their managers and staff, which can make life a bit difficult for them in terms of their risk management efforts.
But if our risk management programmes are to be effective, we really need those at the helm to give us a clue as to the levels of risk that they’re willing to accept and those that they aren’t. For instance, a high level of strategic or equipment risk may be acceptable, whereas the opposite may well be true of health and safety or reputational risk – so one approach may be to ask for clarification of the acceptable levels of risk in each of the various categories.
Another approach might be to ask, after your risk assessments have identified and quantified what you consider to be the most significant risks, for confirmation (ideally in writing as this always helps to focus the mind!) of those that they’re willing to accept and those that they want to address in some way.
Whatever approach is taken, getting a steer from those at the top can be hugely beneficial. It helps get their buy-in, ensures a consistent approach, makes the risk assessment process more productive and can potentially save a significant amount of wasted time and effort by preventing managers and staff from barking up the proverbial wrong tree.
This tip first appeared in Andy Osborne’s book ‘Risk Management Simplified‘ (ISBN 978-1-906316-48-8) – available in paperback or as an e-book, along with Andy’s other books, from the Acumen Shop.
Did you know that Acumen’s Consultancy Director, Andy Osborne, publishes an expert tip each month for people with an interest in developing a business continuity capability?
Why not subscribe now and have Andy’s ‘Tip of the Month’ delivered to your inbox.
Andy also writes the occasional blog, which is somewhat more light-hearted, but with a serious business continuity message. Subscribe to ‘Oz’s Blog’ instead and receive an email notification when Andy posts a blog, in addition to the Tip of the Month emails.