Business processes, structures, knowledge, and outcomes can be improved when risks are identified and managed properly. While risk doesn’t have a single definition, it can be described as the likelihood of an event happening and its potential consequences. It may also refer to the lack of knowledge or expertise, or in the context of project management, as the “standard deviation of free cash flows.” Risk management has various aspects, including social, operational, technical, and management factors, and it can apply across all areas of a business, including its customers, markets, and suppliers. It can also cover intangible elements like reputation, brand, and image.
CMI 518 Managing Risk has been designed to help learners understand the scope and purpose of business risk management. This includes evaluating different types of business risks, the governance structures and strategies for managing them, and how to effectively implement risk management practices within organisations.
Table of Contents
Thorncliffe Chemicals Limited is a specialist distributor of industrial chemicals supplying water treatment, food processing and surface engineering customers from two licensed storage and blending sites in the North West, employing 290 people. Both sites hold environmental permits and one operates under upper tier major accident hazard controls. The author is Head of Operations and Compliance. Organisational detail is illustrative and anonymised.
Task 1: Report on the scope of business risk management
AC 1.1 Evaluate business risks in relation to the organisation, its customers and suppliers
Risks to the organisation. Thorncliffe’s defining exposure is a major accident: a loss of containment, fire or reaction event at a site holding substantial quantities of hazardous substances. Evaluating this against every other risk on the register, it has a low likelihood and a consequence that includes fatality, criminal prosecution of individuals and directors, permit revocation and the end of the business. Evaluating what follows from that profile, conventional likelihood-times-impact scoring understates it, and the exposure has to be managed on the basis that it must not happen rather than that it is unlikely to.
Regulatory risk runs alongside it. Operating under major accident hazard controls means the safety report, competent authority intervention and permit conditions govern what the business may do. Evaluating its character, this is not an external threat but a licence condition, and losing the permit removes the business rather than damaging it.
Financial risk arises from commodity price volatility on imported feedstocks and from working capital tied up in bulk stock. Cyber risk is material because the warehouse management and tank gauging systems are networked.
Risks in relation to customers. Evaluating product liability exposure, a mis-specified or contaminated delivery into a food processing customer could enter a food chain, and the consequential loss vastly exceeds the value of the consignment. Concentration risk is significant, with the three largest customers representing 38 per cent of revenue, so the loss of one is a material event rather than a setback. Evaluating credit risk, customers in sectors under margin pressure extend payment terms, and a customer failure removes both a receivable and a revenue stream.
Risks in relation to suppliers. Evaluating the dominant supplier exposure, two key products are single-sourced from overseas manufacturers, and a plant outage or export restriction stops Thorncliffe supplying its own customers. Haulage is contracted, and evaluating that arrangement, the business retains duty of care for the safe transport of dangerous goods regardless of who drives the vehicle, so a haulier’s compliance failure becomes Thorncliffe’s incident and Thorncliffe’s prosecution.
n this sector that responsibility is personal as well as corporate: directors can face individual prosecution following a major incident. Analysing the effect, this concentrates board attention on safety risk in a way that commercial risk rarely achieves, and the practical challenge is preventing that focus from crowding out strategic exposures entirely. An integrated framework rather than a register. Analysing what mature governance requires, the recognised enterprise risk management frameworks treat risk as integral to governance, strategy, objective-setting and performance rather than as a compliance exercise conducted alongside them. Their components typically span governance and culture, strategy and objective setting, performance, review and revision, and information and communication. Analysing the practical implication, risk considerations belong in the decision to enter a new market, not in a register reviewed after the decision. Risk appetite and tolerance. Analysing the distinction, appetite is what the organisation is willing to accept in pursuit of its objectives and tolerance is the outer boundary. Thorncliffe’s appetite is close to zero for process safety and environmental compliance, low for product quality, and moderate for commercial and credit risk. Analysing why the asymmetry must be explicit, without it a commercial pressure to accept a marginal delivery window gets argued on its own terms rather than against a stated boundary. Committee struct...
Subscribe to Unlock
Subscribe to unlock full access and draft feedback support.
Subscribe to UnlockAlready subscribed? Sign in
Why Choose Us?
- GPT Zero
- 100% Non-plagiarised Papers
- Dedicated human resource writers
- 24/7 /365 Service Available
- Affordable Prices
- Money-back and Privacy guarantees
- Unlimited Amendments upon request
- Satisfaction guarantee