Identifying and taking opportunities to improve performance as well as taking action to avoid or reduce the chances of something going wrong

Similar documents
ENTERPRISE RISK MANAGEMENT (ERM) GOVERNANCE POLICY PEDERNALES ELECTRIC COOPERATIVE, INC.

Escorts Limited. Risk Management Policy

INFIBEAM INCORPORATION LIMITED

Risk Management Policy

CERA Module 1 Exam 2015

Risk Management Strategy January NHS Education for Scotland RISK MANAGEMENT STRATEGY

Overview of ERM Assessment Viewpoints (June 2016) Overview

MEMORANDUM. To: From: Metrolinx Board of Directors Robert Siddall Chief Financial Officer Date: September 14, 2017 ERM Policy and Framework

BERGRIVIER MUNICIPALITY. Risk Management Risk Appetite Framework

RISK MANAGEMENT POLICY OF HEXA TRADEX LIMITED (W.E.F )

MINDA INDUSTRIES LIMITED RISK MANAGEMENT POLICY

The Central Bank of Ireland Risk Appetite: A Discussion Paper

Bournemouth Primary MAT Risk Management Policy

Risk Management Policy

Ingenious Capital Management Limited: Pillar III Disclosure

University Risk Management Policy

Risk Management. Policy No. 14. Document uncontrolled when printed DOCUMENT CONTROL. SSAA Vic

ENTERPRISE RISK MANAGEMENT (ERM) POLICY Republic Glass Holdings Corporation. Purpose. Goals

RISK MANAGEMENT POLICY

Enterprise Risk Management Integrated Framework

Risk Management. Seminar June Compiled by: Raaghieb Najjaar, Yaeesh Yasseen & Rashied Small

Kidsafe NSW Risk Management Plan. August 2014

An Overview of the Enterprise Risk Management Process

INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS

INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS

Managing risk appetite for operational and non-financial risks

Merrill Lynch Kingdom of Saudi Arabia Company. Pillar 3 Disclosure. As at 31 December 2017

Risk Management. Webinar - July 2017

Botswana Building Society Basel II Pillar III disclosure for the year ended 31 March 2016

SOL PLAATJE MUNICIPALITY

Summary of Risk Management Policy PT Bank CIMB Niaga Tbk

Merrill Lynch Kingdom of Saudi Arabia Company. Pillar 3 Disclosure. As at 31 December 2016

APPENDIX 1. Transport for the North. Risk Management Strategy

Procedure: Risk management

ENTERPRISE RISK MANAGEMENT Framework

Practical aspects of determining and applying a risk appetite for SMEs

Master Class: Construction Health and Safety: ISO 31000, Risk and Hazard Management - Standards

Risk Management: Principles, Methodologies and Techniques. Peter Getugi Internal Audit Manager ILRI

RISK MANAGEMENT FRAMEWORK

Risk Management Framework

Capital Requirements Directive Pillar 3 Disclosure. June 2017

RISK MANAGEMENT POLICY

ก ก Tools and Techniques for Enterprise Risk Management (ERM)

GOV : Enterprise Risk Management Policy

Goodman Group. Risk Management Policy. Risk Management Policy

Botswana Building Society Basel II Pillar III disclosure for the year ended 31 March 2017

RISK MANAGEMENT POLICY

JAY BHARAT MARUTI LIMITED

Risk Management Strategy Draft Copy

CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY GROUP RISK AND ASSURANCE SERVICES GROUP RISK MANAGEMENT POLICY

Risk Management Plan for the <Project Name> Prepared by: Title: Address: Phone: Last revised:

Risk Management Relevance to PAS 55 (ISO 55000) Deciding on processes to implement risk management

Procedures for Management of Risk

Project Management for the Professional Professional Part 3 - Risk Analysis. Michael Bevis, JD CPPO, CPSM, PMP

Subject SP9 Enterprise Risk Management Specialist Principles Syllabus

RISK MANAGEMENT ON USACE CIVIL WORKS PROJECTS

An Introduction to Risk

Risk Management Strategy and Board Assurance Framework

General Risk Control and 20/10/15

Meeting of Bristol Clinical Commissioning Group Governing Body

Fundamentals of Project Risk Management

Risk Management Strategy

1. Define risk. Which are the various types of risk?

HEALTH RESEARCH CAPACITY STRENGTHENING INITIATIVE. Program Risk Management Policy. September Imperial : +265 (0)

RESERVE BANK OF MALAWI

Chapter 7: Risk. Incorporating risk management. What is risk and risk management?

An Introductory Presentation for ECU Staff

AIA Group Limited. Terms of Reference for the Board Risk Committee

Nagement. Revenue Scotland. Risk Management Framework

Applying COSO s Enterprise Risk Management Integrated Framework. September 29, 2004

Risk Management Guideline

Approved by: Diocesan Council 17 December 2015

Risk Management Policy

INTERNAL CAPITAL ADEQUACY ASSESSMENT PROCESS GUIDELINE. Nepal Rastra Bank Bank Supervision Department. August 2012 (updated July 2013)

REGULATION. on Internal Governance Arrangements, the Management body and the Internal Capital Adequacy Assessment Process for Banks and Savings banks

RISK MANAGEMENT POLICY

GUIDELINE ON ENTERPRISE RISK MANAGEMENT

HUBTOWN LIMITED REVISED RISK MANAGEMENT POLICY. (Effective from December 1, 2015)

West Coast District Municipality. Risk Management Policy

Pillar III Disclosures

Applying COSO s Enterprise Risk Management Integrated Framework

GENERAL RISK CONTROL AND MANAGEMENT POLICY

PILLAR 3 DISCLOSURE AS AT 31 DECEMBER 2017

THE INVESTOR FOR SECURITIES COMPANY. PILLAR III DISCLOSURE As of 31 December 2017

Subject ST9 Enterprise Risk Management Syllabus

ENTERPRISE RISK MANAGEMENT (ERM) The Conceptual Framework

RISK MANAGEMENT POLICY

Nagement. Revenue Scotland. Risk Management Framework. Revised [ ]February Table of Contents Nagement... 0

PILLAR 3 DISCLOSURE As at 31 December 2017

Tilman Brewin Dolphin Limited Pillar 3 Disclosures

RISK ASSESSMENT, MANAGEMENT & MITIGATION POLICY AND PROCEDURES

RISK MANAGEMENT POLICY

Basel II Pillar 3- Qualitative Disclosure

28 July May October 2016

Business Auditing - Enterprise Risk Management. October, 2018

Risk and Risk Management. Risk and Risk Management. Martin Schedlbauer, Ph.D., CBAP, OCUP Version 1.1

4. Outline of EIA for Development Assistance

SOLVENCY & FINANCIAL CONDITION REPORT. SureStone Insurance dac

The Importance Of Risk Management In An Organizations

PILLAR 3 DISCLOSURE As at 31 December 2018

Transcription:

Risk Management Policy PREAMBLE: Risk management is an approach to decision-making and accountability. Risk management comprises the culture, processes and structures that are directed towards the effective management of potential opportunities and adverse effects within Company's operational environment. The manner in which the Company performs this important role can significantly affect national reputation and national interests. Risk is inherent in all functions. All personnel are responsible for managing the risks that relate to their particular area of work. Risks should be managed in a way that derives the best outcomes for Company and its stakeholders. The aim of this policy is not to eliminate risk. It is to assist personnel to manage the risks involved in all activities to maximize opportunities and minimize adverse consequences. Effective risk management requires: Identifying and taking opportunities to improve performance as well as taking action to avoid or reduce the chances of something going wrong A systematic process that can be used when making decisions to improve the effectiveness an efficiency of performance Forward thinking and active approaches to management Effective communication Accountability in decision making Balance between the cost of managing risk and the anticipated benefits. The purpose of this Policy is to ensure that each of you are aware of the company s standards for risk taking while conducting business and to provide an easy-to-access guide any time you have a question. The Risk Management Group will currently cover Market Risk, Credit Risk, Process Risk and other risks as detailed in these documents. Each risk is covered within this Policy. This Policy will apply across all products, throughout the firm. Policies with respect to specific risks arising out of a particular product or product groups will be covered in the annexture or in documented process notes with appropriate sign-offs, or in the relevant New Product Review documentation, and filed by Risk Management. (A) Definitions 1) Risk: Risks are events or conditions that may occur, and whose occurrence, if it does take place, has a harmful or negative impact on the achievement of the organization s business objectives. The exposure to the consequences of uncertainty constitutes a risk.

2) Risk Management Risk Management is the process of systematically identifying, quantifying, and managing all risks and opportunities that can affect achievement of a corporation s strategic and financial goals. 3) Risk Strategy The Risk Strategy of a company defines the company s standpoint towards dealing with various risks associated with the business. It includes the company s decision on the risk tolerance levels, and acceptance, avoidance or transfer of risks faced by the company. 4) Risk Assessment Risk Assessment is defined as the overall process of risk analysis and evaluation. 5) Risk Estimation Risk Estimation is the process of quantification of risks. 6) Risk Tolerance/Risk Appetite Risk tolerance or Risk appetite indicates the maximum quantum of risk which the company is willing to take as determined from time to time in accordance with the Risk Strategy of the company. 7) Risk Description A Risk Description is a comprehensive collection information about a particular risk recorded in a structured manner. 8) Risk Register A Risk Register is a tool for recording the risks encountered at various locations and levels in a standardised format of Risk Description. (B) Objectives of the Policy: The main objective of this policy is to ensure sustainable business growth with stability and to promote a pro-active approach in reporting, evaluating and resolving risks associated with the business. In order to achieve the key objective, the policy establishes a structured and disciplined approach to Risk Management, including the development of the Risk Matrix, in order to guide decisions on risk related issues. The specific objectives of the Risk Management Policy are: 1. To ensure that all the current and future material risk exposures of the company are identified, assessed, quantified, appropriately mitigated and managed 2. To establish a framework for the company s risk management process and to ensure company wide

implementation 3. To ensure systematic and uniform assessment of risks related with construction projects and operational power stations 4. To enable compliance with appropriate regulations, wherever applicable, through the adoption of best practices 5. To assure business growth with financial stability. (C) Risk Management Policy: In order to fulfill the objectives of this policy and lay a strong foundation for the development of an integrated risk management framework, the policy outlines the following guiding principles of Risk Management: (D) Risk Management Policy Statement: The policy statement is as given below: 1. To ensure protection of shareholder value through the establishment of an integrated Risk Management Framework for identifying, assessing, mitigating, monitoring, evaluating and reporting of all risks. 2. To provide clear and strong basis for informed decision making at all levels of the organization. 3. To continually strive towards strengthening the Risk Management System through continuous learning and improvement (E) Scope and extent of application: The policy guidelines are devised in the context of the future growth objectives, business profile envisaged and new business endeavours including new products and services that may be necessary to achieve these goals and the emerging global standards and best practices amongst comparable organizations. This policy is meant to ensure continuity of business and protection of interests of the investors and thus covers all the activities within the company and events outside the company which have a bearing on the company s business. The policy shall operate in conjunction with other business and operating/administrative policies (F) Risk Assessment: The process of Risk Assessment shall cover the following: a) Risk Identification and Categorisation the process of identifying the company s exposure to uncertainty classified as Strategic / Business / Operational. b) Risk Description the method of systematically capturing and recording the company s identified risks in a structured format c) Risk Estimation the process for estimating the cost of likely impact either by quantitative, semi-

quantitative or qualitative approach. Name of Risk Scope of Risk Nature of Risk Stakeholder Quantification of Risk Risk Tolerance and Trigge Risk Treatment & Control Mechanism Potential Action for Improvement Short description by which the risk may be referred to Qualitative description of the events by which the occurrence of the risk may be identified, any measurement indicating the size, type, number of the events and their related dependencies Strategic/ Business/ Operational List of stakeholders affected and impact on their expectations Cost of impact, if risk materialises Loss potential and financial impact of risk on the business Value at Risk Probability of occurrence and size of potential losses Objective(s) for control of the risk and desired level of performance to assimilate Risk Trigger Primary means by which the risk is currently being managed Levels of confidence in existing control system Identification of protocols for monitoring and review of the process of treatment and control Recommendations to reduce the occurrence and/or quantum of adverse impact of the risk Strategy and Policy Development Identification of function responsible for developing the strategy and policy for monitoring, control and mitigation of the risk (G) Risk Strategy : The following framework shall be used for the implementation of the Risk Strategy: Avoid Reduce Based on the Risk Appetite/Risk Tolerance level determined and reviewed from time to time, the company should formulate its Risk Management Strategy. The strategy will broadly entail choosing among the various options for risk mitigation for each identified risk. The risk mitigation can be planned using the following key strategies: a) Risk Avoidance: By not performing an activity that could carry risk. Avoidance may seem the answer to all risks, but avoiding risks also means losing out on the potential gain that accepting (retaining) the risk may have allowed. b) Risk Transfer: Mitigation by having another party to accept the risk, either partial or total, typically by contract or by hedging. c) Risk Reduction: Employing methods/solutions that reduce the severity of the loss e.g., shot create being done for preventing landslide from occurring.

d) Risk Retention: Accepting the loss when it occurs. Risk retention is a viable strategy for small risks where the cost of insuring against the risk would be greater over time than the total losses sustained. All risks that are not avoided or transferred are retained by default.