Risk rarely comes from one source. A new investment may involve financial and operational concerns, while an expanding organization may face weaknesses in its procedures, responsibilities or internal controls.
Global Screenings provides risk consulting support for organizations that need to identify potential threats, understand where losses may arise and review how those risks are currently managed. The scope can be shaped around the organization, project, business venture or specific area of concern.
Risk Consulting for Better Business Decisions
A risk assessment is most useful before an important decision is made, but it can also help an organization review an existing operation, project or business activity.
The purpose is to consider:
- What could affect the organization or project
- Which business functions may be exposed
- How serious the potential impact may be
- Which controls or procedures are already in place
- Where responsibilities may be unclear
- Which matters require further attention or monitoring
The review should be proportionate to the size of the organization, the activity involved and the possible consequences of the risk being considered.
Organizations That May Require Risk Consulting
Risk-management requirements differ between industries. The service may support:
- Non-profit organizations
- Insurance companies
- Investment businesses
- Healthcare organizations
- Banks and financial institutions
- Companies reviewing a new business venture
- Organizations planning or assessing an investment project
- Businesses reviewing their corporate risk procedures
A bank may be concerned with financial, customer and third-party exposure, while a healthcare organization may place greater emphasis on people, records, service delivery and operational responsibilities. The assessment should reflect the organization rather than apply the same plan to every industry.
Corporate Risk Assessment
A corporate risk assessment reviews the areas that may affect the organization’s objectives, operations, people, assets or business relationships.
Depending on the agreed scope, the assessment may consider:
- Organizational structure
- Management responsibilities
- Business functions and operating activities
- Existing risk-management procedures
- Internal reporting and escalation
- Potential hazards
- Areas of possible financial or operational loss
- Projects, investments and business ventures
- Third-party or external dependencies
- Weaknesses identified during a survey or review
The assessment can help management understand where the organization is most exposed and where existing controls may need clarification or further development.
Risk Assessment Strategic Planning
A risk strategy should explain how risks are identified, assessed, assigned and reviewed. It should also show which issues require immediate action and which can be monitored over time.
A strategic risk plan may include:
- The purpose and scope of the assessment
- The business functions included in the review
- The risks identified
- The possible impact of each risk
- The people responsible for managing the issue
- Existing procedures and controls
- Recommended areas for further review
- Priorities and proposed review periods
The plan should be practical enough for management and operational teams to use. A risk register or report that is never reviewed will have limited value.
Reviewing Business Functions and Responsibilities
Risk can increase when responsibilities are unclear or when several departments assume that another team is managing the issue.
A functional review may examine:
- How responsibility is divided between teams
- Who approves important decisions
- Who monitors the risk after approval
- How concerns are reported
- Whether procedures are applied consistently
- How management receives information
- Which activities depend on outside parties
Mapping these functions can help identify gaps, duplicated responsibilities and areas where an issue could remain unaddressed.
Risk Surveys and Information Gathering
A risk survey can help build a clearer picture of the organization, project or activity under review. The survey may involve available documents, operating information, management input and other records included in the agreed scope.
The review may consider:
- The organization’s objectives
- The nature of its activities
- Important business processes
- Existing controls and procedures
- Known incidents or previous concerns
- Management and employee responsibilities
- Possible financial, operational or business consequences
The information collected should be relevant to the assessment. A longer questionnaire does not necessarily produce a better understanding of risk.
Identifying Hazards and Potential Loss
Risk assessment involves more than listing possible problems. The organization also needs to understand how a risk could affect its operations and what type of loss may result.
Potential consequences may include:
- Financial loss
- Operational disruption
- Loss of business or investment value
- Damage to assets or projects
- Weaknesses in service delivery
- Management or governance concerns
- Reputational impact
- Additional investigation or corrective costs
The likelihood and possible impact of each issue should be considered separately. A low-frequency event may still require attention if the potential loss is significant.
Procedures, Standards and Risk Controls
Once a risk has been identified, the organization should consider whether its existing procedures are suitable for managing it.
The review may examine:
- Current policies and procedures
- Approval and authorization controls
- Management oversight
- Internal reporting
- Review and monitoring arrangements
- Documentation and recordkeeping
- Escalation of serious concerns
- Standards applied by the organization
Where the concern relates specifically to governance, policies or regulatory responsibilities, the assessment may also be supported through Regulatory Compliance Support.
Investment Projects and Business Ventures
An investment project or new business venture may involve assumptions about costs, ownership, partners, market conditions, operations and expected returns. If those assumptions are incomplete or inaccurate, the project may carry risks that were not visible at the planning stage.
A risk review may consider:
- The organizations and people involved
- The purpose and structure of the project
- Available financial and operational information
- Important dependencies
- Potential hazards and losses
- Management responsibilities
- Existing controls
- Issues requiring further due diligence
Where a project requires a broader review of its practicality or supporting information, the work may also include Feasibility Intelligence.
If the main concern relates to a proposed business partner, investor or transaction party, the review may require Third-Party Integrity Due Diligence.
Maintaining the Risk Assessment
A risk assessment reflects the organization and information available at a particular point in time. Business activities, management, regulations, investments and external conditions can change.
Ongoing maintenance may involve:
- Reviewing the assessment at agreed intervals
- Updating information when the business changes
- Recording new incidents or concerns
- Checking whether recommended actions were completed
- Reassessing risks after a new project or investment
- Reviewing changes in responsibility or management
Regular review can help prevent an old risk plan from being relied upon after the organization or project has changed.
Common Risk Assessment Weaknesses
A risk assessment can lose value when it is too broad, based on incomplete information or disconnected from day-to-day operations.
Common weaknesses may include:
- Using the same assessment for every business activity
- Failing to identify who owns each risk
- Relying on assumptions that have not been reviewed
- Listing risks without considering possible impact
- Ignoring external parties or dependencies
- Creating procedures that are not followed in practice
- Failing to update the assessment after a material change
- Reporting issues without a clear follow-up process
Reviewing these weaknesses can help an organization improve the way it conducts and maintains future risk assessments.
International and Cross-Border Risk
Organizations operating across several countries may face different business conditions, record systems, operating practices and regulatory requirements.
A cross-border risk review may need to consider:
- The countries involved
- Local operating conditions
- Business partners and suppliers
- Management and ownership structures
- Available records and information
- Differences in procedures and responsibilities
- Risks created by distance, language or local dependencies
The same risk-management approach may not be appropriate for every jurisdiction. Regional differences should be considered when the scope and recommendations are prepared.
Reporting the Findings
The completed review may identify:
- Risks that appear to be adequately controlled
- Risks requiring further management attention
- Procedures that may need clarification
- Responsibilities that are not clearly assigned
- Information that could not be confirmed
- Areas requiring specialist or additional review
The report should make a clear distinction between an identified risk, a possible concern and a confirmed incident.
Important Limitations
Global Screenings provides risk-assessment and consulting support within the agreed scope. The service does not eliminate every business risk, guarantee that a loss will not occur or replace legal, financial, insurance, medical, technical or regulatory advice.
Final decisions on risk acceptance, investment, controls, procedures and implementation remain with the client and its responsible management and professional advisers.