Immediate Vault

The Case for Strategic Risk Management

At last week’s RIMS 2019 in Boston, a group of risk professionals got together for the panel session “NextGen ERM: Strategic Risk Management” to discuss the advantages of strategic risk management (SRM) and the challenges to successfully integrating it into organizations.

buy reglan online medilaw.com/wp-content/uploads/2015/03/jpg/reglan.html no prescription pharmacy

The panel examined several major organizations that have taken shortcuts with training or even rushed to out-duel a competitor, failing to consider the long-term impact on strategy, reputation and market-share. Blockbuster, Kodak and Sears failed to innovate, and these once-thriving name brands are now prime examples of SRM’s benefits.

“Blackberry is one such company, but there are countless examples of organizations that have overlooked the long-term strategic impact of their actions,” said Marian Cope, owner of CopeRisk LLC.

Despite recent corporate missteps tied to failures in long-term strategic analysis, as recently discussed in Risk Management, risk professionals still face resistance to their SRM initiatives. “Demonstrating the value of SRM has to be a priority for risk professionals if they hope to gain buy-in from leadership,” said Rick Roberts, director of risk management and employee benefits at Ensign-Bickford Industries and a former RIMS president.

One of the value propositions of SRM—and an easy one for leadership to support—is the focus on taking advantage of risks that can accelerate the achievement of strategic objectives. “Artificial intelligence is an example of a disruptive technology that is impacting many industries. But, if your organization is aware of it, understands its usefulness and has developed a plan for it, it can give you a competitive edge,” said Marian Cope, owner of CopeRisk LLC.

But the case for an SRM initiative should not just be made with cautionary tales of organizations that did not use SRM. “Don’t just share failures, it’s also important to share SRM successes,” said Ellen Dunkin, senior vice president, general counsel and chief risk officer at Amalgamated Life Insurance Co. “Even Amazon and their business model that gives consumers almost instant access to their purchases has adjusted its strategy and started to open brick-and-mortar shops.”

According to the panel, the risk professional should ideally be involved in strategic planning from the get-go. “Some organizations have a chief risk officer that participates in the preparation as well as the strategic planning and decision-making discussions. Unfortunately, that’s not the norm,” Cope said.

The panel identified the next-best option for risk professionals, which is to work from the strategic objectives established by the organization. From there, they need to analyze the business model, identify, assess, and prioritize the risks that can derail or accelerate achieving the strategic objectives, facilitate the development of appropriate risk responses, and then align such objectives, risks, and risk responses with operations.

An effective SRM program will incorporate plans for a risk strategy, communications strategy, implementation, and training with the goal of integrating strategic risk management into decision-making processes. “The risk professional is going to require support from others in the organization too.

buy cymbalta online medilaw.com/wp-content/uploads/2015/03/jpg/cymbalta.html no prescription pharmacy

They’re going to need risk champions to vouch for them, as well as a final presentation that includes achievable and measurable deliverables that demonstrate the value of the process,” Roberts said.

SRM can be a stand-alone program or a component of ERM. Regardless, the panel noted that SRM is vital to the long-term success of organizations as alignment of strategy and operations results in the identification of opportunities to accelerate achievement of strategic objectives and prevents operational blunders that will trigger strategic risks (e.g., substantial reputational harm). Accordingly, SRM as a stand-alone program allows risk professionals to add more value while streamlining the process.

“SRM is the next generation of ERM and identifies external and strategic risks as opposed to the more granular view for ERM. It allows the team to bring the top 10 key risks to leadership, with a focus on the top two to three as opposed to overwhelming them with the full risk register that could include 100,” said Ellen Shew Holland, higher education practice leader for Hanover Stone Partners LLC and president of Strategic Risk Frameworks LLC.

Ultimately, the group agreed, SRM will help fully integrate risk management programs into an organization’s business model and the value should be evident in each positive step the business takes toward achieving its strategic objectives.

buy xifaxan online medilaw.com/wp-content/uploads/2015/03/jpg/xifaxan.html no prescription pharmacy

Saint Joseph’s University Wins Spencer-RIMS Risk Management Challenge

BOSTON—Students from Saint Joseph’s University won the Spencer-RIMS Risk Management Challenge at RIMS 2019. Comprising team members Joseph Angelina, Katherine Branson, Ashley Myers, Daniel Tan, and academic advisor Michael Angelina, the winners earned $4,000 for the risk management program they developed and presented at the conference here in Boston this week. Second and third place went to St.

buy symbicort inhaler online meadfamilydental.com/wp-content/uploads/2023/10/jpg/symbicort-inhaler.html no prescription pharmacy

Mary’s University and Butler University, which won ,000 and ,000, respectively.

buy oseltamivir online meadfamilydental.com/wp-content/uploads/2023/10/jpg/oseltamivir.html no prescription pharmacy

The case study for this year’s challenge came from Robert Zhang, RIMS board director and the risk and compliance director for IKEA China. Zhang tasked the students with identifying the top five risks of integrating new physical and digital commerce options for customers.

In determining a winner, the fine print proved critical, with the best presentations specifically focusing on the core part of the prompt: given digital transformation and shifting consumer preferences, what are the key risks involved as such a massive company innovates and evolves?

The winning team took a useful, strategic approach to risk management that could be flexible for the company to adapt and use going forward.

“They provided a true strategic view of IKEA’s risks as they transition from traditional brick-and-mortar into a multi-channel retailer, and they provided IKEA with a strategic framework that can be built out with tactical options,” said Andrew Bent, risk director at Sage and one of the challenge judges.

This year’s Spencer-RIMS Risk Management Challenge drew more entries than ever before, with teams from 28 schools initially submitting papers on the case study. And the competition was strong—according to Louis Drapeau, who served as a judge, they could not pick a top eight submissions, as anticipated, so they invited nine teams for the in-person presentation rounds here in Boston.

buy tamiflu online meadfamilydental.com/wp-content/uploads/2023/10/jpg/tamiflu.html no prescription pharmacy

Poise and pertinent PowerPoint slides reflected the strong presentation skills of the top three teams, Drapeau noted. RIMS CEO Mary Roth had a similar impression, praising all of this year’s participants as impressive aspiring additions to the risk management community. “Beyond the remarkable presentations delivered by each university team, our Spencer-RIMS Risk Challenge students continue to demonstrate the highest-degree of professionalism and an exceptional grasp of sophisticated concepts,” she said.

Understanding Insurance Coverage for Traveling Employees

BOSTONThe odds of dying in a terrorist attack: 1 in 9.3 million. The odds of getting sick while traveling: 1 in 2. But both should concern companies sending their employees around the world for business, panelists Kathleen Ellis of CNA International, Erin Wilk of Facebook and Andrew Miller of International SOS said at a RIMS 2019 panel titled “Is Insurance Enough When Employees Travel?”

The answer to this question, the panel agreed, was emphatically “no.” But, as Ellis and Wilk noted, insurance coverage is an important part of the equation for many of the biggest things that do go wrong. Even though the risk of catastrophic incident is minor compared to seemingly mundane travel concerns like weather and petty theft, companies should still prepare for the worst in advance.

This is true whether employees are going to common destinations within the United States traditionally thought of as safe or to less familiar places. It is also true, Wilk said, whether the employee is an experienced traveler (who can be over-confident) or a novice (who can over-prepare and miss warning signs around them).

The panelists repeatedly stressed that companies should approach travel risk with protecting employees as their priority. Not only do companies have a “duty of care” (a legal responsibility to mitigate the risks traveling employees face), but they also need to be cognizant of the “standard of care” and “duty of loyalty.” Standard of care is the industry standard for employees’ travel risk protection, and companies’ obligation to meet that standard. Duty of loyalty is the employees’ responsibility to abide by the safety measures the company has put in place. As recently discussed in Risk Management, this is largely on the employee, but the panel noted that employers also have a critical role to play in creating a culture that enables and encourages their people to take the necessary steps to protect themselves while traveling. As Wilk said, “Policy is a piece of paper. Employee practice is what actually matters.”

When it comes to insurance, companies should make sure they are covered, but not over-covered. For example, Miller discussed cases in which companies’ benefits, HR and legal department have all purchased travel coverage without communicating their purchases to the other departments. Businesses may also be unfamiliar with the coverage they have and pay to remediate travel problems themselves when their insurance policies would actually cover those issues.

Key insurance options include:

  • Foreign voluntary workers compensation, which covers workers traveling on business in a way similar to traditional workers’ comp, paying for disease, or repatriation or evacuation
  • Business travel accidental death and dismemberment coverage, which works like life insurance and covers both work-related and non-work-related incidents, and is an option for covering employees’ spouses and dependents
  • Kidnap and ransom coverage, which provides pre-trip support, crisis management services during an incident, and reimburses for ransoms paid for kidnapping extortion, wrongful detention and hijacking
  • Expatriate medical, which is an option for employees who are traveling long-term, and
  • Defense base act coverage, which handles government contractors overseas at embassies and military bases

The panelists also emphasized that travel risk not only endangers employees’ well-being, but also the company’s bottom line. If an employee gets sick while traveling for business, for example, the company’s investment in the trip can be wasted. Additionally, traveling employees who feel unsafe or unprepared for the risks they are facing feel less loyal to their company, and can also be distracted, potentially derailing the important business they are traveling to conduct. The panel urged that pre-trip training and a thorough understanding of the company’s existing coverage are the best ways to mitigate these risks and help employees succeed when traveling for work.

Q&A: 2019 Risk Manager of the Year Luke Figora

Luke Figora, senior associate vice president and chief risk and compliance officer at Northwestern University, was named the RIMS 2019 Risk Manager of the Year today.

With annual revenues of approximately $2.5 billion (reported in 2018) and nearly $700 million in sponsored research annually, Northwestern is among the country’s leading research universities. Figora has risen quickly through the ranks at Northwestern, where his enterprise risk management (ERM) framework has elevated its risk culture across three campuses—two in Illinois and one in Qatar.

Figora spoke with Risk Management Monitor about his experience as one of the youngest stakeholders among Northwestern’s leadership, his process of customizing an ERM matrix and his reaction to the recent college admissions scandal.

Risk Management Monitor: You and your department created an ERM matrix in the past year that united Northwestern’s compliance owners and that may even set a precedent in higher education. What went into its creation?

Luke Figora: We spent a lot of time defining risk appetite statements and tried to make our program a little more outcome-based and actually show how we’re moving the needle on uncertain key risks for Northwestern. And we avoided spending too much time aligning perfectly to one of the ERM frameworks like COSO or ISO. So I think if someone looked at our program from the outside, it might not check all the boxes from a typical model perspective, but it’s driving action here at Northwestern and it seems to be the right level for engagement with our stakeholders.

I think one of the biggest challenges for ERM at Northwestern—and maybe this is true across the industry—is that we don’t necessarily have one strategy right now. We have some pillars and values that Northwestern follows, but we’re ultimately a very decentralized institution that has a number of schools, and a number of units in each one of those have slightly different objectives and goals.

RMM: It seems that there is a degree of transparency, but not full transparency.

LF: Right. For example, athletics and the School of Medicine have very different risk profiles and neither one of them should know the other’s risks or operations. And it would be hard for someone in athletics to speak about the risks of animal research within the School of Medicine. I think that’s where our risk office plays a role in right-sizing the expectations and taking the feedback from all the units, but trying to do some triage through that.

RMM: Many of your colleagues are several years your senior—how has that impacted your work?

LF: I am probably the youngest person on the leadership team across the institution, but it has probably been beneficial. I have tried to bring different ideas and update the ways in which we think about risk. I’m not jaded by the insurance industry, and I think people are receptive because of that.

RMM: Since arriving at Northwestern nearly five years ago, you moved up the ranks relatively quickly, although you’ve maintained that was not your goal. How would you advise young risk professionals as they get their feet wet?  

LF: I think all of us at early stages in our careers can’t wait to be a manager and want that vertical growth and the chance to lead a team, but the bigger driving factor for me has been horizontal growth and expanding the portfolio. After that, I believe the other opportunities will come. That is a belief I try to hammer home in my work and when I make industry presentations.

RMM: The college admissions system is a hot topic due to the major scandal that broke in March. How might that have affected where the admissions process is on Northwestern’s risk register?

LF: Last year at this time, fraud in the admissions cycle wouldn’t have been one of our top 10 enterprise risks. But when things like this break, there is a tendency to go into reaction mode and examine whether we have similar issues. I always try to keep people level-headed and remind them that just because this hit doesn’t mean it moves to number one on our crisis management list for the year. It is worth doing a deep dive into the question or topic that’s in the news, but whenever scandals hit, I think we’ve tried to approach them with a rational view.

RMM: It sounds like the knee-jerk reaction is to go into crisis communication mode, even though it’s not your crisis.

LF: We know we’re going to get questions from our trustees, so there’s an initial all-hands-on-deck mentality. You have to make sure you have talking points that outline how we’ve thought about it because we know we’re going to get questions from the media. We do focus on crisis communications, but it becomes more about knowing if we have the right controls that could protect the institution from something like this happening to us.  

Figora was also the special guest on this week’s RIMScast, which you can download here.