Decoding Uncertainty by Measuring the Risk

An ideal risk management process contains various phases including Risk Identification, Risk Assessment, Risk Mitigations, Risk Monitoring and Risk Reporting. This article is focused on the Risk Assessment phase, where the risk professionals strive to measure the risks which enable the organizations to make informed decisions. Risk Assessment can be done both objectively and subjectively. It is based on the organization\'s maturity in the risk management process. Organizations new to risk management tend to prioritize qualitative risk measurement, while more established ones employ sophisticated methodologies to assess risks and uncertainties. Whether the risks are measured qualitatively or quantitatively, the only goal is to facilitate the board to make informed decisions. This article covers the concepts of \'why\' vs 'how' to measure the risks, basic tools, and techniques to measure the risks and broader implications.

Measuring a Risk - \"Why\" Vs \"How\"

Understanding \"why\" we measure risk is important before we think about \"how\" to do it. In everyday life, we constantly measure things to help us make smart choices. Let\'s say someone needs to be at a meeting by 11:30 AM, and it\'s currently 8:00 AM. To make sure they\'re not late, they need to figure out how long it takes to get there. ("Why")

Now, let\'s talk about how we measure risk. In our example, we use a clock to measure time. While measuring the time, several considerations/scenarios are considered to have an approximate measurement of time. In our example, let\'s say it\'s the rainy season. The person might check the weather forecast to see if rain could slow them down and adjust their travel time accordingly. They could also use maps on mobile phones to check traffic conditions. They might decide to measure time down to the minute or even seconds, depending on how precise they want to be. Gathering this extra information helps make their travel time prediction more accurate. (\"How\")

In risk management, people use different methods to measure risk. Is that okay? Instead of saying if it\'s right or wrong, we should ask if these methods help organizations make informed decisions. Organization needs to focus on optimized efforts in quantifying the risks.

Enablers that assist in gauging the risks

Before diving into the quantification models, let\'s discuss \"what\'s next?\" i.e., what is the actual outcome of the quantification of risks involved? Yes, we discussed this earlier saying that quantification helps organizations to make informed decisions. But how does this quantification exactly help in making informed decisions?

Organizations need certain \"enablers\" to make informed decisions. For example, the CRO of Company X has reported to the board saying that a potential cumulative financial risk would hit the profit and loss account adversely by ~INR 50 lakhs if it materializes. What does that INR 50 lakhs mean to Company X? How does Company X decide whether to mitigate or accept the risk?

The following are the enablers that assist the organizations in making informed decisions:

  1. Risk Appetite Statements
  2. Risk Assessment Scales

1. Risk Appetite Statements

Risk Appetite statements are the amount and the type of risks that an organization is willing to accept. Risk appetite tends to change from time to time to reflect the organization\'s strategic objectives.

In continuation to the above example, let\'s assume (Scenario 1) that Company X has planned to significantly invest in new markets/products in multiple regions as a part of its aggressive growth strategy. In this scenario, Company X would have made multiple debts, made aggressive recruitments, and spent on heavy research and marketing, impacting its cash flow statement adversely and in such situations when the risks are assessed, financial risk would be in the company\'s risk priority radar.

An appetite statement is framed on how willingly an organization can accept the risk. In the above example, as the organization is currently operating in a cash crunch situation, the financial risk would be on the company\'s radar with a medium to low-risk appetite. Thus, a potential financial impact of INR 50 Lakhs would be considered by the board and try to mitigate the same.

Below is the sample Risk Appetite Statement of Company X for Financial Risk (Scenario 1):

The organization remains vigilant on the financial aspects to enable it to serve its purpose and value. Currently, to serve its strategic objective, Company X remains a low-risk appetite for financing activities.

Sample Metric: Any potential impact over and above Y% on revenue is considered to be a serious financial impact for Company X.

2. Risk Assessment Scales

Risk Assessment Scales help the organizations to measure the risks in multiple parameters (i.e., impact, likelihood, velocity, etc.) and define what is high/medium/low scales for each parameter.

Risk Assessment scales serve as a gauge for measuring risk. In terms of risk appetite, organizations define the amount and types of risks they are willing to accept. In risk assessment, we establish scales for parameters such as impact, likelihood, and others, which help determine whether the identified risks fall with the organization\'s acceptable risk appetite.

Similar to Risk Appetite Statements, Risk Assessment Scales require a periodic revision based on the strategic objectives and appetite levels of the organization. In general, most of the organizations prefer a 5-rating scale, however, there is no hard and fast rule for the same.

Impact Scales

The impact scale in risk assessment measures the potential consequences or severity of a risk event if it were to occur. It helps to evaluate how significantly the risk could affect an organization, project, or process. The impact scale typically ranges from low to high, with a metric that quantifies its effect.

Impact/Consequence is defined by ISO 31000 as \"Outcome of an event affecting objectives. A consequence can be certain or uncertain and can have positive or negative direct or indirect effects on objectives. Consequences can be expressed qualitatively or quantitatively. Any consequence can escalate through cascading and cumulative effects.\"

Risk CategoryMetricQuantitative Impact Scales
  1 (Very Low)2 (Low)3 (Medium)4 (High)5 (Very High)
Financial RiskRevenue1%2%3%5%7%

In the above example, as the Risk Appetite for the company is already defined and the metric says Y% as the cap for potential impact, the scales are defined on the higher cap. Below could be the sample scale for the financial risk: (Assuming Y as 7%)

The above table can be developed for all the risk categories that the organization is willing to assess. For example, SEBI provides a guideline for the risk domain coverage to include financial, operational, sectoral, sustainability, environment, social and governance, information, cyber security etc.

In instances where financial metrics may not apply, such as in the case of Reputational Risks, it becomes imperative to define metrics based on the organization\'s operations. For instance, a key metric could be the reduction in market share or share price resulting from reputational impact or any inadvertent events.

Risk CategoryMetricQuantitative Impact Scales
  1 (Very Low)2 (Low)3 (Medium)4 (High)5 (Very High)
Reputational RiskAdverse newsNews column in a district newspaperNews columns in a few to multiple district newspaperNews column in a state newspaperHeadlines in National newsMultiple allegations/acquisitions in National news on the company and its Board
  No impact on the share priceNo to very minor impact on the share priceMinor fluctuations in share priceSignificant fluctuations in share pricePermanent reduction in share price

Likelihood Scales

The likelihood scale in risk assessment measures the probability or frequency with which a particular risk event is expected to occur. It helps to evaluate how likely it is that a specific risk will materialize. The likelihood scale typically ranges from low to high, with different levels representing the probability of the event happening.

Likelihood/Probability is defined by ISO 31000 as \"chance of something happening, whether defined, measured or determined objectively or subjectively, qualitatively or quantitatively, and described using general terms or mathematically (such as a probability or a frequency over a given time period).\"

Now, why do we require the likelihood scale? Is the impact scale and measuring the impact is not sufficient? As the risk is assessed always as a futuristic event, we need to assess how probable this impact might be, i.e., if an event is certain to occur, it transitions from being a risk to a certainty of loss. Conversely, when the probability of an event occurring is zero, it ceases to be a risk altogether. Therefore, the probability of occurrence lies between 1% to 99%! The scales can be defined after assessing the historic events and other considerations from the Small Modular Reactor (SMR\'s).

The Likelihood scales, similar to the Impact scales, can be qualitative and quantitative:

Quantitative likelihood Scales
12345
<=19% chance of occurance>=20% and <=49% chance of occurance>=50% and <=69% chance of occurance>=70% and <=89% chance of occurance>=90% chance of occurance
Qualitative likelihood Scales
12345
Rare (OR) Once in every 30 to 50 yearsUnlikely (OR) Once in every 15 to 30 yearsPossible (OR) Once in every 5 to 15 yearsLikely (OR) Once in every 2 to 5 yearsFrequent / Almost Certain (OR) Annually or more than once annually

Impact and likelihood are the fundamental scales adopted by organizations to assess the risks and make informed decisions. This is called a \"two-dimensional\" assessment of risks. However, other dimensions like \"Velocity\", and \"Controllability/Vulnerability\" can also be a part of risk assessment scales.

Velocity Scale

Paul Hopkins refers to velocity as the \"speed at which the risks become significant\". The assessment of velocity happens only after the event has occurred. In our example, we assumed that Company X has the potential financial risk of INR 50 Lakhs to achieve its strategic objective of aggressive growth. In this example, Company X would incur a heavy cash crunch due to its activities but does that impact the company immediately? NO! This impact might take a few months, unlike a financial risk due to a sudden crash in the stock market, which has an immediate effect.

So, velocity can also be defined as \"the time between the risk event and the actual impact the company experiences\". Below is the sample Risk Velocity scales:

Velocity Scales
12345
Company experiences the impact in a few years post the event occursCompany experiences the impact in a year post the event occursCompany experiences the impact in few months post the event occursCompany experiences the impact in few weeks post the event occursRapid onset of risk impact

Vulnerability/Controllability Scales

The controllability scale in risk assessment measures the extent to which an organization can influence, manage, or mitigate a risk once it occurs. It evaluates how much control the organization has over the risk event, including the ability to prevent, reduce, or manage its impact.

Control is defined by ISO 31000 as \"measure that maintains and/or modifies risk. Controls include, but are not limited to, any process, policy, device, practice, or other conditions and/or actions which maintain and/or modify risk. Controls may not always exert the intended or assumed modifying effect.\"

In the context of scales, Vulnerability/Controllability is defined as the \"Organisations preparedness towards the risks or the strength of the controls\". Below are the sample scales for vulnerability or controllability:

Controllability Scales
12345
Strong controls designed and implemented & Controls testing happens frequentlyStrong controls designed and implemented & Very minor deviations or lapses in controlsModerate controls designed and implemented & Few deviations or lapses in controlsFew controls designed and implemented & Major deviations or lapses in controlsNo controls in place

The above scales assist organisations in gauging the risks, and now let\'s dive into the tools that assist in measuring the risks.

Risk Quantification Models

There are several tools and techniques that help the organizations in measuring the risks. Below are a few examples:

  1. PI Matrix
  2. FAIR Methodology
  3. PERT analysis
  4. VaR - Monte Carlo simulation
  5. Scenario analysis etc.,

In any quantification method, having accurate data is crucial. Without reliable data, the results won\'t be accurate.

PI Matrix (Probability - Impact Matrix)

After assessing the risks, the PI matrix helps the organizations in prioritizing the risks. Once the risks are prioritized, it becomes clear to the organization that what risks it has to invest resources and plan for mitigations. Below is the methodology:

Calculate Risk Exposure = Probability X Impact

For example, if a particular risk is rated as 3 on the impact scale and 4 on the probability scale, the risk exposure is $3 \\times 4 = 12$.

The PI matrix is a 5X5 matrix (if the probability and impact scales are 5 pointers), below is the sample PI matrix post-computation of all risk exposures:

Risk#Risk NameProbabilityImpactRisk ExposurePriority
R1Financial Risk34121
R2Safety Risk2483
R3Compliance Risk25102

The Red, Amber, and Green colours in the PI matrix resemble the risk appetite of an organization. Different organizations adopt different prioritization methodologies. The above risks are prioritized based on the \"Risk Exposure\". If Velocity and Controllability scales are also considered, then the prioritization varies. Simply put, all risks that fall under the red colour represent the organization\'s top priority, while others are assigned lower priority accordingly.

FAIR (Factor Analysis of Information Risk) Methodology

FAIR methodology deconstructs the uncertainty inherent in risk into manageable elements. FAIR methodology mostly focuses on Cyber and Operational Risks. Its fundamental components, Loss Event Frequency (LEF) and Probable Loss Magnitude (PLM), play key roles. LEF assesses the frequency of potential loss events occurring within a specific timeframe, while PLM evaluates the likely financial impact of each event. This structured approach enables organizations to comprehensively analyze and address their risk landscape.

The entire flow of FAIR methodology ranges from designing scenarios, FAIR factors, Expert estimation, PERT analysis, and Monte Carlo.

PERT Analysis

The FAIR methodology has suggested the PERT analysis to estimate the uncertainty. As per this methodology, one should have 3 values for a risk i.e., minimum, most likely, and maximum. Along with this, organization has the highest confidence value among the three.

For example, in case of financial risk, organizations should consider the maximum loss, most likely loss, and minimum loss if the risk materializes. Also, by expert judgement or by any past data, organizations should be a little surer about either of the 3 values. Below is the computation:

  • Expected Value = [Min + (4 x Most likely) + Max] / 6 - If organization is little surer on Most likely value
  • Expected Value = [(4 x Min) + Most Likely + Max] / 6 - If organization is little surer on Minimum value
  • Expected Value = [Min + Most Likely + (4 x Max)] / 6 - if organization is little more sure on the Maximum value

VaR - Monte Carlo Analysis

Monte Carlo is the most commonly and widely used risk analysis methodology, mostly used in finance fields. Below are the steps followed to apply Monte Carlo simulation:

  1. Determine the impact of the potential risk event, based on expert judgement or brainstorming. A range of the outcome can also be considered as an input to the simulation.
  2. Run the Monte Carlo simulations with the available data by running around ~1000 iterations.
  3. For a simulation of ~1000, Mean and Std Deviation are calculated by the tool.
  4. The output of Monte Carlo, provides multiple possible outcomes and the probability of each from a large pool of data.

The output generated will usually be a normal distribution or bell curve, with the most likely value in the middle of the curve i.e., There is almost an equal possibility that a risk impact could be higher or lower. Users may obtain the results such as the minimum value, which is the lowest value generated by the Monte Carlo simulation, a maximum value, which is the largest generated value, as well as an average and most likely value.

Now as the results have been narrowed down, expert judgement can be utilized to quantify and rate the risks.

Scenario Analysis

Scenario analysis refers to defining one or more risk scenarios with utmost detail that could impact the strategic objectives. The details of the scenarios can boil down to the severity of risk, time duration, mitigation efforts, etc.

However, this analysis cannot be done to all the risks of the organization. Before getting into scenario analysis, the organization should already have a high-level top 15-20 risks. The scenarios can be developed by a combination of risk experts, process owners, and SMRs.

Below is the sample Scenario analysis: (While there can be base case, worst-case, and best-case scenarios, only the worst-case scenario is considered here for illustration purposes)

Risk DescriptionStrategic ObjectiveMetricDetailed ScenariosImpactExisting ControlsAdditional actions to be taken
Strategic Risk - The risk that the organisation cannot achieve its strategic objectives1B$ company by 2030Revenue
  1. New market player with innovative product
  2. Failure of current R&D project
  3. Technology Shift
  4. Competitor pressure
  5. Supply chain issues
  6. Failure to scale
  7. Attrition/ loss of talent
  1. Decline in market share by 30%
  2. Loss of INR 50 Lakhs quarterly
  3. Increase in R&D expenses by INR 20 Lakhs
  4. 15% price reductions / discounts
  5. 12% price increases / inflation
  1. Marketing Campaigning at core markets - Detailed plan attached
  2. FMEA in place
TBD

Conclusion

In conclusion, risk quantification is an indispensable process for organizations seeking to navigate the complexities of today\'s dynamic business environment. By systematically assessing, analyzing, and assigning numerical values to various risks, businesses can make informed decisions, allocate resources effectively, and mitigate potential threats to their objectives.

However, it\'s crucial to recognize that risk quantification is not a one-time exercise but an ongoing practice that requires continuous monitoring, evaluation, and adaptation to evolving circumstances. By embracing a proactive and data-driven approach to risk quantification, businesses can better anticipate, respond to, and ultimately thrive in an ever-changing landscape, safeguarding their sustainability and success in the long run.

References:

  • Measuring and Managing information risk (A FAIR Approach) by Jack Freund and Jack Jones
  • 5th Edition of Fundamentals of Risk Management by Paul Hopkins
  • ISO 31000: 2018 Risk Management - Guidelines (ISO 31000:2018(en), Risk management - Guidelines)
  • COSO 2017: Enterprise Risk Management integrating with Strategy and Performance - Executive Summary (https://aaahq.org/portals/0/documents/coso/coso_erm_2017_-_exec_summary.pdf)
  • Monte Carlo Simulation and Risk Management: An Easy Explanation - IRM India Affiliate (theirmindia.org)
Author may be reached at varanasi.kishore9308@gmail.com and eboard@icai.in