Risks

How to Consider Controls in a Risk Management Strategy

Written by

Controls in the risk management strategy

All organizations should develop, maintain, and update a corporate risk map whose objective is to provide the company with the status of the situation regarding events that may impede the development of business processes.

Basically, this status comprises the level of detection, prevention, and response to the occurrence of an event that may impact the business.

Responding to risks: controls based on their effectiveness

Based on knowledge of this status, decisions can be made to try to mitigate the risks that have an unacceptable value for the organization. The objective is to be able to prioritize the available resources to improve the risk response.

This process is known as risk analysis. It must be consistent with a previously established methodology for calculating risk levels.

Control measures, or controls, are the way to respond to risks. Every organization has different controls in place that we must identify and assess in the analysis.

The assessment of controls must be based on their effectiveness; we must know whether the control really helps us mitigate the risk and to what degree it does so. With this effectiveness value, we obtain the current risk levels we have in the organization.

If we have obtained a high risk level, it will mean that the control measures existing in the organization are not effective or are insufficient. If the risk level is low, we have sufficient and effective measures.

The importance of the risk management strategy and the implementation of controls

It is essential to define the acceptable risk level based on the risk appetite that the organization has.

All risks whose obtained level is above the acceptable risk level must be evaluated, and a strategy for their management must be defined. One possible strategy is to establish an action plan to improve the high-risk situation by implementing new control measures or improving existing ones.

We must obtain senior management’s approval of the results of the risk analysis, since management must be aware of the organization’s situation, and obtain approval of the acceptable risk level, since whether a risk can be accepted or must be treated will depend on the definition of this level.

 

Under no circumstances should a risk with a level above the acceptable risk level be left unevaluated.

 

Controls are usually preventive or corrective; that is, they help us prevent the risk from affecting us — in which case they reduce its probability — or they help us reduce the impact the risk causes once it has materialized, which are the corrective controls.

Action plan: controls to mitigate risks

The action plan or risk treatment plan will contain all the control measures necessary to reduce high risk levels to an acceptable level. It may happen that for one risk we have to implement more than one control, and that a single control helps us mitigate more than one risk.

We must select the controls to include in the treatment plan, depending on whether we need to reduce the probability or the impact of each risk.

Once the plan has been drawn up, it must be approved by the organization’s senior management, thereby ensuring the availability of resources to carry it out and the assumption of responsibility by the people designated as responsible for the projects to be undertaken.

We must carry out the corresponding monitoring of the plan’s execution and, once it is completed, assess the effectiveness of the new controls and update the entire risk map in order to obtain the new situation in the organization.

Whenever there is a relevant change, and periodically, the risk analysis must be updated since, among other considerations, the effectiveness of controls can change; if their follow-up and monitoring are not adequate, we may lose effectiveness over time.

This process, called risk analysis and management, must be considered within a risk management system implemented in the company. An international standard such as ISO 31000 can serve as a guide to understand the components of this management system.

At GlobalSuite Solutions, we have a consulting area that will advise and help you implement a corporate risk management system that helps you understand the level of protection your organization has against the possible risks that affect its business processes.

Additionally, we offer you the GlobalSuite Risk Management application — a tool that makes it easier to implement the system and provides us with automation and traceability throughout the entire risk analysis and management process.

Tabla de contenidos