Risk Trends 2025 – IRM
Driven by the explosion of technological advancements and increasing global uncertainties, we need to look at what the key shifts in risk are and how practitioners should prepare themselves, and their organisations, for the future. The ability to anticipate and respond to these fast moving developments will be crucial for risk practitioners in 2025.
Organisational Resilience Building in Small and Micro Enterprises under the VUCA Environment
Small and micro enterprises (SMEs) encounter big blows while operating in VUCA (Volatility, Uncertainty, Complexity, Ambiguity) environment as a result of their resource constrains and external dependencies. This study build a conceptual model that links organized performance to the elements of external environmental factors, internal resources, resilience capabilities, and the contribution of resilience building to SMEs. From systematically reviewing literature on VUCA and organisational resilience theories, the model specifies the pathways of how SMEs adapt and thrive in continuously changing (VUCA) conditions.
Integrating ESG and Organisational Resilience through System Theory: the ESGOR matrix
This paper aims to develop a conceptual framework that jointly considers Environmental, Social and Governance (ESG) factors and organisational resilience (OR) components to ameliorate organisations’ understanding of sustainability’s overall requirements and related decision-making processes.
When Risk Maps become Risk Traps
Let us step back and consider the process of collecting risk information for the purpose of communicating to senior management and the Board about the most important threats to their organization (that they may or may not be currently aware of) with sufficient credibility to cause them to sponsor further action.
Risk Appetite and Risk Tolerance
George Bernhard Shaw has been quoted to state that “The English and Americas are two fine people, separated by a shared language”. It appears the drive to increase confusion has not stopped yet. Personally, having English as my second language, I mentally like the ISO vocabulary better than the COSO – but I can easily live with either. So:
Dear ISO and COSO organisations. Get together and agree on terminology.
Leverage your ERM as a powerful Decision Tool
Many companies and organisations have an Enterprise Risk Management (ERM) program where they identify, evaluate and decide on action to take on key risks to the company/organisation. For some this is a very systematic and well documented approach using scientific methodologies etc. – for others it is a collection of managerial perceptions. In most all process, some decisions are taken, and the organisation believes it executes well on ERM.
Managing Legal Risks
The other day, I had a chat with a risk management consulting colleague who was working with and focusing on legal risks. He had trouble doing this well as he found that people with a legal background:
• Have limited or no insights into statistics
• Rarely, if ever, work with a spreadsheet
• Find it hard to quantify risks and opportunities
Heat Maps and Risk Management
Heatmaps are commonly used as reporting and discussion tools in risk management. However, there are two different types/categories of heatmaps, only one of which is useful.
Dangerous Data
Over the years, I have advocated vigorously for the use of facts and data when analysing and assessing risks, uncertainties and levers. I fully stand by this and will continue advocating for using data as well as I firmly believe there really is no such thing as “qualitative analysis”.