Changes to the governance code will compel companies to think more seriously about risk management, says Vijay Krishnaswamy
The Financial Reporting Council’s (FRC) consultation paper – Risk Management, Internal Control and the Going Concern Basis of Accounting – is designed to strengthen the risk assessment and reporting requirements applied to UK companies. This initiative comes in the wake of the failure of several large financial institutions, during the global financial crisis – often only months after auditors had given them a clean bill of health.
Changes to the governance code will compel companies to think more seriously about risk management, says Vijay Krishnaswamy
The Financial Reporting Council's (FRC) consultation paper – Risk Management, Internal Control and the Going Concern Basis of Accounting – is designed to strengthen the risk assessment and reporting requirements applied to UK companies. This initiative comes in the wake of the failure of several large financial institutions, during the global financial crisis – often only months after auditors had given them a clean bill of health.
The paper is primarily addressed at companies subject to the UK Corporate Governance Code but it serves as useful guidance to all organisations. Past experience suggests that it may become a 'soft' requirement for even medium-sized companies not subject to the Code. Any changes resulting from this consultation are expected to apply to reporting periods starting 1 October 2014.
The FRC paper is a massive cultural and technical challenge to finance functions in companies and auditors because the risk management domain has been dominated by box ticking. It almost requires a rewiring of brains to think about what is not yet on the balance sheet. It requires an ability to look ahead and understand business models and the economic environment while many currently have internal controls and compliance checklists which are backward looking.
Overall, the proposals contribute to strengthening the robustness of risk management and the quality of information provided to investors which should help with potential investment decisions. However, the annual reports of large companies now typically contain several hundred pages and adding more content may not help to make them easier to use. Initiatives are in place to reduce the size of these reports and make them focus on the most important issues but it remains to be seen how greater transparency can be achieved.
Implications for companies
The board must determine its willingness to take on risk and the desired risk culture within the company. It must undertake a robust assessment of the principal risks to the company's business model and ability to deliver its strategy, including solvency and liquidity risks. In making that assessment, the board should consider the likelihood and impact of these risks materialising in both the short and longer term. This assessment of risks and associated controls should be an ongoing process, not just an annual exercise.
Once those risks have been identified, the board should agree how they will be managed and mitigated, and review the company's risk profile. It should satisfy itself that management's systems include appropriate controls, and that it has adequate assurance.
It is also important then to decide what arrangements are being made to ensure that there is a robust risk framework in the company and that it is embedded within normal management and governance.
The risk management process should inform a number of disclosures in the annual report: the description of principal risks and uncertainties facing the company in the strategic report, disclosures in the financial statements on the going concern basis of accounting and material uncertainties, and the review of risk management and internal controls.
More specifically for auditors, they ought to consider whether they have anything material to add to what the directors' have included in the annual report and accounts in relation to solvency and liquidity risks, and going concern.
Raising the bar
While the focus is on boards, in practice it is expected that CFOs and accountants will need to play a key role in implementing the guidance. There are four elements which raise the bar for the work they will need to undertake:
far more engagement and challenge by the board than has been the case in the past;
there will be an explicit link between risk management and the company's business model and strategy;
auditors will be much more intense in reviewing the company's risk management practices; and
better quality of disclosures results in more external scrutiny and peer benchmarking.
Following the gap analysis, a coherent and comprehensive set of actions should be put in place to address them.
The journey of financial institutions has shown that the task of embedding risk management within a business has not been straightforward. The upside is that done well risk management can add real value for investors, while giving all stakeholders greater confidence in sustainable corporate performance over the long term. It can also act as a 'language' to align investor expectations and company objectives.
The scale of the challenge facing UK plc must not be underestimated given the 1 October 2014 implementation target.
CFOs and companies would do well to start early down the journey of implementing the FRC's guidance.
Risk management system
UK companies that are obligated to comply with the Code will need to strengthen their risk governance, assessment, management, mitigation processes and disclosure – an excellent starting point would be an enterprise-wide approach to risk management (ERM) system.
Identification and evaluation of existing and emerging risks: building a strategic risk register by identifying all principal risks in the business model can help identify future issues.
A clear definition of risk appetite and tolerance that is balanced against return, takes into account the expectations of various stakeholders, is embedded in decision making throughout the organisation and underpins the risk culture of the company. This should then drive the risk strategy.
Risk assessment, models and stress testing to support decision making by quantifying the likelihood and impact of key business risks on an ongoing basis. Reverse stress testing can help to identify latent but severe vulnerabilities.
Mitigation and management: some risks are difficult to avoid but it is often possible to take mitigating or contingency actions to reduce their impact, should they materialise.
Forecasting and planning: including forward-looking assessments of the company's risk profile implied in the strategy versus stated risk appetite, regular reviews of activities and management actions.
Risk reporting and monitoring: engaging risk management information – for example, heat maps – can help boards and management prioritise their time on the most important risks, visualise them and critically challenge the business model.
Risk culture and governance: developing and nurturing the right behaviours by linking business objectives, performance measurement and incentives with risk management.
Vijay Krishnaswamy, Partner and head, enterprise risk management, Hymans Robertson