Managing Risks in Corporate World
What this session covered
This webinar formed part of NISSMAT's continuing seminar series and was chaired from the floor, with introductory remarks followed by three invited presentations and a question session. The opening remarks set out the institute's work in security training, risk mitigation audits and its research cell, and described the general sequence of a risk mitigation audit: identifying vulnerabilities, whether generic or specific and whether arising from natural hazards or human action; reviewing key business areas, internal controls, compliances and any existing business continuity plan; and drawing in additional subject-matter expertise where the audit team's own coverage is inadequate. An illustrative audit was recounted in which every stage of raw material reconciliation at a printing and packaging operation appeared sound until the waste management stage, where the volume of material handed over did not reconcile with the quantity shredded and incinerated; rejected printed material had passed into unauthorised hands and was subsequently used in the manufacture of spurious products.
The first presentation argued that risk management is less a specialist mystery than an exercise in structured common sense, and distinguished preventable risk arising within the organisation, external risk over which the organisation has no control, and strategy risk deliberately accepted in pursuit of return. Cyber risk was described as still at an early stage rather than approaching its peak, with state-sponsored activity noted alongside criminal activity, and reputational damage treated as the common consequence. The speaker set out the options of avoiding, reducing, transferring and accepting risk, outlined enterprise risk management in terms of risk appetite, governance, reporting lines and controls, and described scenario planning, war-gaming and stress testing as means of assessment. A leadership challenge was raised: that executives are seldom held accountable for insufficient foresight, and that risk management, being concerned with threats and failures, sits uneasily with a growth-oriented culture and with time horizons shorter than those over which the risk may materialise. The second presentation focused on communicating risk rather than identifying it, drawing on the management of a large federal records facility project. It covered risk modelling on impact and probability, the limits of colour-coded risk matrices, and the need to translate model scores into the terms a decision-maker actually uses — delay, cost and resources foregone elsewhere. The speaker recommended arriving with a mitigation plan rather than only a problem, and warning other parts of the organisation before naming their area as a risk factor, so that they can respond rather than be surprised.
The third presentation addressed business continuity, concentration risk and resilience. It traced two decades of disruptive events — natural, technological, financial, public health and security-related — to argue that such events increasingly occur in combination and at national or global rather than local scale, and that continuity planning should be driven by impact rather than by probability, since a low-frequency event of severe impact still requires a solution. Concentration risk was described as an unintended by-product of centres of excellence and clustering across sectors and geographies, and the speaker outlined resilience models varying by how concentrated and time-sensitive a delivery unit is, including multi-shoring, diversification and cross-region capability. In the question session, speakers were asked how medium-scale enterprises without resilience infrastructure should proceed; the response suggested a basic annual risk assessment framework tied to risk appetite and the risks applicable to the region and sector, a crisis management framework naming who takes decisions, and crisis simulation exercises to surface gaps. A question comparing the armed forces' willingness to prepare regardless of cost with commercial constraints drew the responses that military standards do not transfer directly to business, that calculated risk-taking is inherent to business and no assurance is complete, and that prioritisation is set against annual budgets, with regulatory pressure and scenario walkthroughs an additional driver in the financial sector. A further question on disruption by new entrants drew observations on firms defining their business too narrowly, on acquisition as a response, and on consistency of delivery. Closing remarks proposed that the institute consider guidance on how often risk assessments should be undertaken, whether by sector or by other criteria, and whether assessment capability should be in-house or external.
Key points raised
- Risk was categorised in the discussion as preventable risk internal to the organisation, external risk beyond its control, and strategy risk accepted deliberately in pursuit of return, with the options of avoiding, reducing, transferring or accepting it.
- One speaker argued that identifying risk is only part of the task, and that the value of risk modelling lies largely in the discussion it forces; scores must be converted into delay, cost and resource terms before they mean anything to a decision-maker.
- Continuity planning was described as differing from risk management in that it prioritises by impact alone rather than by impact multiplied by probability, so that severe but infrequent events still warrant a solution.
- Concentration risk was presented as an unintended consequence of centres of excellence and sectoral clustering, requiring different levels of resilience preparation depending on how concentrated and time-sensitive a delivery unit is.
- For medium-scale enterprises, the suggested approach was a basic annual risk assessment tied to risk appetite and locally applicable risks, a crisis management framework identifying decision-makers, and crisis simulation exercises.
- A risk mitigation audit was described in which reconciliation failed only at the waste management stage, with rejected printed material passing into unauthorised hands and being used to produce spurious goods.



