2022 OnRisk Report

Page 26

RISK STAGES MODEL

Figure 8: RISK STAGES MODEL

In today’s dynamic, technology-driven world, risks can emerge and mature, sometimes at breakneck speeds. The risks discussed in this epo r rtaregroupedintoeoffourstages—Recognize,Exple, or Develop, or Maintain — as they relate to the potential impact on organizations and what actions organizations should be taking to address them. The Risk StagesModel(Figuer 8)eflect r showriskmanagementevolveswithne organization on the same scale as the risk rankings — Personal Knowledge andOrganizationalCapabi. lity Additionally, the relevance of each risk should be understood as unique to each organization. Where each risk ranks in relevance depends on various factors, including the organization’s size, industry, and type, as well as competition, maturity, position in the marketplace, supply chain, liquidity, and others. As noted earlier, there are likely risks not included in this analysis that haveparticularelr evancetosomegan or izationsdependingontheirspecific circumstances. Because of this unique aspect, risk relevance is not depicted in the Stages of Risk.

Stages of Risk Explanation RECOGNIZE

EXPLORE

DEVELOP

MAINTAIN

A risk is perceived as emerging and knowledge of the risk among stakeholders is low. Risk response strategies are not implemented or are not assumed to be effectively designed given the low understanding of the underlying risk. Monitoring processes have not been contemplated. Inherent risk levels are not well understood.

Knowledge of the risk is growing among some stakeholders, but not by all. The risk may be perceived as emerging or dynamic. Risk response strategies have been contemplated, but not fully implemented. Monitoring processes have not been contemplated or are not implemented. Inherent risk levels are generally understood.

Risk knowledge is high, at least with executive management teams. Risk response strategies may be developed or in process of being implemented. Monitoring processes may be in contemplation but are not likely to have been fully implemented. Residual risk is generally understood.

Risk is well understood by all relevant stakeholders and is not perceived to bechangingsignifican. tly Risk response strategies have been developed and implemented consistent with the perceived relevance of the risk. Monitoring processes are utilized to ensure risk response strategies are operating effectively as designed. Residual risk levels are understood and believed to be at an acceptable level for the organization.

Personal Knowledge – Low Organizational Capability – Low

Personal Knowledge – Mid to High Organizational Capability – Low

Personal Knowledge – Mid to High Organizational Capability – Low to High

Personal Knowledge – High Organizational Capability – High

www.theiia.org 26


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

Supply Chain Disruption

1min
page 41

Social Sustainability

1min
page 40

Environmental Sustainability

2min
pages 42-44

Disruptive Innovation

1min
page 39

Supplier and Vendor Management

1min
page 38

Change in Regulatory Environment

1min
page 37

Economic and Political Volatility

1min
page 36

Culture

1min
page 35

Data Privacy

0
pages 33-34

Organizational Governance

1min
page 32

Talent Management

1min
page 31

Cybersecurity

1min
page 30

The Risks

0
pages 28-29

Risk Stages Model

2min
pages 26-27

How to Use This Report

2min
page 25

Senior executives and boards desire broader scope for internal audit services

5min
pages 18-19

Methodology

1min
page 24

Perceptions of risk relevance vary greatly across ESG components

3min
pages 14-15

Pandemic revealed opportunities to improve organizational risk management

2min
pages 16-17

Insights and Actions – C-suite

1min
page 22

Insights and Actions – Board

1min
pages 20-21

Insights and Actions – CAEs

1min
page 23

Top Risks, 2022

3min
page 5

Introduction

1min
page 3

Key Observations Explained

0
page 7

several risks

1min
page 10

The OnRisk Approach

1min
page 4

Key Observations

1min
page 6

Notable variations in capability and relevance for certain risks

2min
pages 8-9
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.