What's Hot

Nassim Nicholas Taleb's blog, an inspiring read | Incerto


Showing posts with label ISO 31000. Show all posts
Showing posts with label ISO 31000. Show all posts

Tuesday, June 27, 2017

ERM Decision Trees and ISO 31010

Over the years we have written numerous blogs that share in-depth presentations on different risk modelling methods and in the coming months ahead, Causal Capital is going to increase the number of these technically natured risk management articles.

Today we are going to focus on Decision-Trees from the ISO 31010 Risk Assessment standard, and if you are interested in downloading the presentation associated with this posting, please do continue reading.

Sunday, May 21, 2017

Risk Management Interconnectedness

Recent correspondence with a client drew me into a debate on ‘Interconnectedness’ or specifically: It would be good to get your thoughts on the second bullet point – Interconnectedness?


Saturday, August 29, 2015

Assessing uncertainty is full of error

Our recent article on the risk matrix [LINK] is all fine but the concept of a risk matrix from the outset seems to embody much of what is wrong in risk management today, let me elaborate on all of this for a moment.


Friday, July 31, 2015

Australian and Canadian Bank Risk Culture Examined

An interesting study on the internal "Risk Governance Culture and Behaviour" of Australian and Canadian banks has recently been published by Elizabeth Sheedy and Barbara Griffin from the Faculty of Business and Economics at Macquarie University [LINK].

There are some curious insights to be found after surveying 22,145 employees of 222 various business units in six major banks headquartered across two countries and, I have plucked out some of these findings or perhaps their interpretations in this short blog posting.


Wednesday, September 18, 2013

31000 Frameworks for Market Risk

A recent discussion on the G31000 risk forum opened up an interesting debate that ISO 31000 doesn't really include explicit detailing on how to treat market risk, credit risk or whether it is or should be enterprise risk wide at all.

We have taken to write this posting as a complete whitepaper that shows how to apply ISO 31000 to a firm wide market risk requirement.

In this blog we share the 31000 Risk Framework whitepaper for market risk [LINK].

Friday, August 2, 2013

Can risk models predict the future?

Back at camp G31000 we have another provocative debate raging on with "can we say that risk management helps to predict the future?LINK ] ... Let's ruminate on this statement for a moment.

Prediction and forecasting are a long standing deliberation but one that many people from the risk profession will ponder on at some point in their careers and it all ends up being partly philosophical but definitely paradoxical as we shall see.

Surely the more accurate we are in predicting something, the better off we become? ...

Tuesday, July 30, 2013

A Failure To Define - Part I

Risk managers and consultants often facilitate "risk management workshops" in an effort to capture a registry or list of threats that their businesses may face. The way these workshops are delivered can vary substantially between practitioners but all that aside, a common problem found by many risk managers is; How to propose the likelihood of occurrence for a specific incident and how to identify its unbiased impact.

Let's take a look at this.

Tuesday, July 23, 2013

Extending Ishikawa with PLS-PM

In a recent article on this blog site we looked at how Ishikawa diagrams can be used to represent the causal drivers or factors for risk. However, these schematics lack the statistical models necessary for quantifying which factors are contributing most to the top event.

Perhaps one of the biggest problems with all causal analysis techniques are the conclusions that risk analysts draw from their assumptions, yet they often fail to test these postulations. In this blog we are going to look at how causal factors in a Bowtie or Ishikawa diagram can be investigated by "adding-in" the relevant statistical models. Our aim here is to identify which factors contribute most to a top event by considering both their frequency of occurrence as a driver but also how each variable intertwines and correlates in a network of factors to spawn an outcome.

Tuesday, July 16, 2013

Ishikawa Diagrams Explained

Several risk analysts have asked me how difficult Ishikawa Diagrams are to build and in this short article we are going to quickly construct one of these schematics.

"In ISO 31010 Fishbone Diagrams and Root Cause Mapping are recommended techniques for structured analysis techniques, section B.12.4 of ISO 31010. Do you have an example of such a Fishbone Diagram and are there any software tools that can assist with these techniques?"

Sunday, January 13, 2013

ISO 31000 supporting Basel II

On the G31000 LinkedIn risk forum, we have decided to open up a new "chat room" that is dedicated to the application of the ISO 31000 enterprise risk management standard in Banking, Insurance, Supply Chain Finance, Markets and Investment.
The link for the new group can be found by clicking on the logo here 

In this blog posting we are going to consider whether ISO 31000 is compatible with Basel II from the outset.

Sunday, January 6, 2013

Five thorns of ISO 31000

Anyone following the G31000 forum closely will come to realize that there are some continual inconsistencies of opinion which raise their head when ISO 31000 is discussed broadly. I call these debates of contention, the Five Thorns of ISO 31000.

In this blog posting, we are going to look at these Five Thorns in more detail. The aim in the end, is to put a structural emphasis on attempting to resolve them.

Tuesday, October 30, 2012

Importance of risk categories

So much inspiration for articles in this blog seems to originate from reading what risk practitioners are writing about on the G31000 linked-In portal. One recent debate restarted an old angst on enterprise risk categories.

Personally I am a big believer in the categorisation of risk events and while this may not be popular among many of the non-banking members of the risk community, even more so with ISO 31000 practitioners it seems, I still believe it is an important exercise to carryout. Either way, I have taken to list ten reasons why causal event categorisation is crucial for the operation of a sound enterprise risk management framework.

Wednesday, October 24, 2012

Inherent vs Residual Exposure

A recent debate on the G31000 Linked-In forum around the gap between Inherent versus Residual exposure has shown that there is a large deviation on opinion, not only with what these terms actually stand for but why it is important to measure inherent risk as a value in the first place.

Inherent Risk is actually not a new concept to risk management and is captured in many other risk standards such as COSO but for ISO 31000, the term has uniquely been excluded. This omission adds to the confusion on whether it should be used at all, let alone why someone would want to understand their Inherent and Residual risk side-by-side.

In this short blog, we are going to investigate these two terms and how they interrelate with each other, why and importantly how inherent risk can be estimated. 

Monday, August 6, 2012

ISO 31010 and Loss Modeling

One of the most concerning trends that continually persists in operational risk management, is the lack of interest analysts have for attempting to quantify this risk exposure coherently.

In this blog we look at operational risk from the perspective of the normal and the extreme.

Thursday, July 26, 2012

ISO 31000 for Property Development

It states in the ISO 31000 standards guide, that organisations of all types and sizes face internal and external factors as well as influences that make it uncertain whether and when they will achieve their objectives.

If we were to look at property development or the construction industry for example, we know that these types of issues are also likely to be evident. So, would ISO 31000 be of benefit to the construction sector?

In this short journal post, we share a presentation that reviews some of the problems of risk management in property development, how risk management currently functions in this industry sector and why it would be advantageous to adopt ISO 31000 in property development.

Friday, July 13, 2012

Retrofitting ISO 31000

There have been some interesting discussions on the G31000 forum over the last week which allude to a future of potential conflict for ISO 31000.

In this short post, we look at some of the headwinds that ISO 31000 is going meet, as the adoption of the standard ramps-up across multiple industries.
  

Thursday, June 28, 2012

ISO 31004 Wishlist

The International Organisation for Standardization [ ISO ] is about to enter into a trial review for its ISO 31004 guide.

Being an active risk manager, I believe it is important to highlight potential key topical points for inclusion in the ISO 31004 program. This is all in the hope that the final ISO 31004 document will address some of the open ended elements that ISO 31000 seems to omit. The risk community at large seems to struggle with some of the items listed in the attachment that is linked to this post and more information, example case studies and critique on these areas of risk measurement specifically, would be welcome from the ISO body.

This blog lists 50 key aspects of commercial enterprise risk management which are not only common practice in some cases, but are also important for evolving the enterprise risk management field today.

Saturday, June 2, 2012

Perception in Objectives

Over the last two years alone, we have seen some incredible risk events across the planet. 

These disasters have not only been extremely high profile but also massively impacting and questions are now emanating from all quarters, that risk management as a commercial discipline of planning control is missing the mark.
  
What is wrong with risk management?

Thursday, May 17, 2012

ISO 31000 for banks

ISO 31000 is a risk management standard that provides generic guidelines for the design and operation of an enterprise risk management framework. Released in 2009 by the ISO standards board, the standard itself has been crafted in such a manner that it makes ISO applicable for any organisation type. Theoretically banks to manufacturing firms can benefit from implementing ISO 31000.

What we are exploring in brief today is: Should the banking sector entertain ISO 31000 when it already has an established global risk standard of its own?

The presentation for this posting can be found by following this [link]

Saturday, March 10, 2012

ISO 31000 and Objectives

ISO 31000 is becoming a popular risk framework, a credible alternative for COSO and many organisations across the planet are now selecting this approach for formalizing their internal risk programs directly. Actually, ISO 31000 is probably taking the lion's share of market interest for risk management at present and that isn't such a bad thing.

One aspect that sets ISO aside from many other risk frameworks in use, is its clear delineation yet connection between an objective and the objectives uncertainty. In this article we take a brief look at this relationship.