Take control of enterprise risk

1 June 2012 Security Services & Risk Management

Regulatory compliance has become of increasing importance in recent years, as a multitude of new regulations and legislation has forced the arm of businesses into obedience at the risk of hefty financial penalties. However, compliance is only one aspect of a wider field of enterprise governance, risk and compliance (GRC), a discipline that evolved as part of a growing global need to ensure sustainability, accountability and sound business practices.

Managing risk lies at the core of any GRC endeavour, since if risks are not managed adequately they have the potential to result in decreased profitability, non-compliance to regulations and laws and ultimately a failing enterprise. Enterprise risk management (ERM) is the pivot upon which GRC turns, facilitating both good corporate governance and compliance, and is a vital part of the agenda for businesses of all sizes, large and small.

“Managing risk does not mean eliminating risk, since without risk organisations could not exist and remain profitable. However, these risks do need to be taken on board and brought to an acceptable level. With every business in South Africa subject to at least 80 or more acts of parliament that must be complied with, ERM is vital to ensure compliance,” says Ben Pieters, executive at ESPconsult. “While large corporates and state-owned entities are able to employ teams of risk managers and legal experts to analyse the relevant acts and regulations, smaller businesses and micro enterprises simply cannot afford such luxuries.”

While having the funds to employ teams of full time risk managers and legal advisors can be of benefit, many large organisations still view ERM as a tick-box exercise. They regard it as something that must be done in order to comply and avoid penalties but not something which will contribute positively to the organisation.

“Nothing could be further from the truth, however,” says Greg Bogiages, MD of Cortell Corporate Performance Management. “The excuse that small organisations cannot afford risk management is negated when you view ERM as a vital business process that will not only facilitate compliance, but improve profitability. Businesses should align their strategic plans with their risk management disciplines. Managing risk is not a ‘one size fits all’ concept, since each organisation’s risk appetite differs, and ensuring that a risk management solution is tailored to the individual needs of the organisation is vital.”

The reality is that risk, while it is part of business, can be detrimental if it is not managed correctly. Risk management software is a useful tool as it assists with automating and creating workflow for procedures associated with risks and risk events. It also removes the risk of human error when it comes ensuring that processes are followed accordingly.

However, software alone is not sufficient to ensure risk is managed effectively. Once software has been installed, it is vital for risks to be identified and defined at various levels throughout the organisation, in order to create a risk framework. Consultants and experts in the field of GRC play an important role in ensuring that all risks are identified, incorporated into ERM tools, and processes around these risks have been defined and implemented.

“It is also necessary to workshop controls and identify the risk owners for each individual area. Without a risk owner, accountability cannot be assigned, which means that in effect the risk cannot be managed because it is not understood who is responsible for mitigating it,” says Pieters. “Software acts as an enabler that eases the risk management workload, but true ERM relies on a top-down, culture driven approach. Managing risk requires the people within the organisation to understand what the risks are and why they need to be mitigated and managed, which often involves a change management process,” he adds.

Only once risks have been identified and controls put into place can risk be mitigated. Implementing a real risk management discipline, with the necessary controls and procedures in place and the correct combination of software and organisational culture, ensures that an enterprise operates in an environment of sound governance. It also helps to identify legislation and regulations as areas of risk, helping to ensure compliance. Aside from these soft benefits, improved risk management means a lower risk profile, which typically leads to decreased insurance costs, which can directly benefit the bottom line.

“ERM has multiple benefits for organisations of all sizes, from improved governance and compliance to better accountability, improved profitability and increased shareholder confidence. The real question is not ‘can your organisation afford to implement ERM’, but can it afford not to,” Bogiages concludes.

For more information contact Cortell Corporate Performance Management, +27 (0)11 804 2412, [email protected], www.cortell.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Risk management and compliance enforcement
Security Services & Risk Management
Having a risk management and compliance programme (RMCP) is not just a procedural formality; it is a legal requirement under Section 42 of the Financial Intelligence Centre Act (FICA).

Read more...
The dangers of poor-quality solar cables
Security Services & Risk Management Smart Home Automation
Reports indicate that one in six fires attended by South African firefighters is linked to substandard solar installations, often due to faulty wiring or incompatible components.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it is a gamble.

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it’s a gamble.

Read more...
Managing mining physical security risks
Zulu Consulting Security Services & Risk Management Mining (Industry) Facilities & Building Management
[Sponsored] Risk-IO, a web app from Zulu Consulting, is designed to assist risk managers in automating and streamlining enterprise risk management processes, ensuring no steps are skipped and everything is securely documented.

Read more...
SAFPS issues SAPS impersonation scam warning
News & Events Security Services & Risk Management
The Southern African Fraud Prevention Service (SAFPS) is warning the public against a scam in which scammers pose as members of the South African Police Service (SAPS) and trick and intimidate individuals into handing over personal and financial information.

Read more...
Rewriting the rules of reputation
Technews Publishing Editor's Choice Security Services & Risk Management
Public Relations is more crucial than ever in the generative AI and LLMs age. AI-driven search engines no longer just scan social media or reviews, they prioritise authoritative, editorial content.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.