Take control of enterprise risk

1 June 2012 Security Services & Risk Management

Regulatory compliance has become of increasing importance in recent years, as a multitude of new regulations and legislation has forced the arm of businesses into obedience at the risk of hefty financial penalties. However, compliance is only one aspect of a wider field of enterprise governance, risk and compliance (GRC), a discipline that evolved as part of a growing global need to ensure sustainability, accountability and sound business practices.

Managing risk lies at the core of any GRC endeavour, since if risks are not managed adequately they have the potential to result in decreased profitability, non-compliance to regulations and laws and ultimately a failing enterprise. Enterprise risk management (ERM) is the pivot upon which GRC turns, facilitating both good corporate governance and compliance, and is a vital part of the agenda for businesses of all sizes, large and small.

“Managing risk does not mean eliminating risk, since without risk organisations could not exist and remain profitable. However, these risks do need to be taken on board and brought to an acceptable level. With every business in South Africa subject to at least 80 or more acts of parliament that must be complied with, ERM is vital to ensure compliance,” says Ben Pieters, executive at ESPconsult. “While large corporates and state-owned entities are able to employ teams of risk managers and legal experts to analyse the relevant acts and regulations, smaller businesses and micro enterprises simply cannot afford such luxuries.”

While having the funds to employ teams of full time risk managers and legal advisors can be of benefit, many large organisations still view ERM as a tick-box exercise. They regard it as something that must be done in order to comply and avoid penalties but not something which will contribute positively to the organisation.

“Nothing could be further from the truth, however,” says Greg Bogiages, MD of Cortell Corporate Performance Management. “The excuse that small organisations cannot afford risk management is negated when you view ERM as a vital business process that will not only facilitate compliance, but improve profitability. Businesses should align their strategic plans with their risk management disciplines. Managing risk is not a ‘one size fits all’ concept, since each organisation’s risk appetite differs, and ensuring that a risk management solution is tailored to the individual needs of the organisation is vital.”

The reality is that risk, while it is part of business, can be detrimental if it is not managed correctly. Risk management software is a useful tool as it assists with automating and creating workflow for procedures associated with risks and risk events. It also removes the risk of human error when it comes ensuring that processes are followed accordingly.

However, software alone is not sufficient to ensure risk is managed effectively. Once software has been installed, it is vital for risks to be identified and defined at various levels throughout the organisation, in order to create a risk framework. Consultants and experts in the field of GRC play an important role in ensuring that all risks are identified, incorporated into ERM tools, and processes around these risks have been defined and implemented.

“It is also necessary to workshop controls and identify the risk owners for each individual area. Without a risk owner, accountability cannot be assigned, which means that in effect the risk cannot be managed because it is not understood who is responsible for mitigating it,” says Pieters. “Software acts as an enabler that eases the risk management workload, but true ERM relies on a top-down, culture driven approach. Managing risk requires the people within the organisation to understand what the risks are and why they need to be mitigated and managed, which often involves a change management process,” he adds.

Only once risks have been identified and controls put into place can risk be mitigated. Implementing a real risk management discipline, with the necessary controls and procedures in place and the correct combination of software and organisational culture, ensures that an enterprise operates in an environment of sound governance. It also helps to identify legislation and regulations as areas of risk, helping to ensure compliance. Aside from these soft benefits, improved risk management means a lower risk profile, which typically leads to decreased insurance costs, which can directly benefit the bottom line.

“ERM has multiple benefits for organisations of all sizes, from improved governance and compliance to better accountability, improved profitability and increased shareholder confidence. The real question is not ‘can your organisation afford to implement ERM’, but can it afford not to,” Bogiages concludes.

For more information contact Cortell Corporate Performance Management, +27 (0)11 804 2412, [email protected], www.cortell.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

ArxTech: Over 30 years of evolving security solutions for South Africa’s toughest challenges
Security Services & Risk Management Integrated Solutions
[Sponsored] For over 30 years, a Centurion-based company has helped shape how security technology is designed, deployed, and supported in South Africa. Originally known as CellSecure, it now operates as ArxTech.

Read more...
Don’t Miss the Exclusive Launch of the AirXpress 3 SCBA
Security Services & Risk Management
Be the first to experience the all-new AirXpress 3 Self-Contained Breathing Apparatus (SCBA), designed and manufactured by MSA, and brought to you by PSA Africa.

Read more...
Transform WhatsApp chaos into real-time security intelligence
Security Services & Risk Management
The HYDRA AI security intelligence software plugs into existing guard chat groups to automatically convert voice notes, photos, and texts into structured, real-time security data and insights.

Read more...
SABRIC Annual Crime Statistics 2024
News & Events Security Services & Risk Management Residential Estate (Industry)
SABRIC has released its Annual Crime Statistics for 2024, reflecting a significant decline in financial crime losses, but also warning of the growing threat posed by artificial intelligence (AI) in fraud schemes.

Read more...
Health, safety, and environmental eLearning
Training & Education Security Services & Risk Management
SHEilds is a global leader in health, safety, and environmental eLearning, delivering internationally recognised qualifications such as NEBOSH, IOSH, IEMA, and ProQual NVQs.

Read more...
See crime stopped in seconds
Products & Solutions Security Services & Risk Management
Fog Bandit, a leader in security fog, is bringing its instant crime-stopping technology to Securex Cape Town 2025. Experience the innovation trusted worldwide to protect retailers, warehouses, and high-value sites.

Read more...
SA’s private security industry receives multi-million USD investment
News & Events Security Services & Risk Management
South Africa's private security sector has attracted significant international attention, with the world’s largest tactical flashlight manufacturer, Nextorch, announcing a major investment in its local operations, Nextorch Africa.

Read more...
Vetting people in security estates
iFacts Security Services & Risk Management Residential Estate (Industry)
In today’s security-conscious South Africa, estate management’s responsibility extends beyond gates and patrols; it involves ensuring that every resident, staff member, and service provider upholds the community’s safety standards.

Read more...
View from the trenches
Technews Publishing SMART Security Solutions Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
There are many great options available to estates for effectively managing their security and operations, but those in the trenches are often limited by body corporate/HOA budget restrictions and misunderstandings.

Read more...
IVA AI Pro Visual Gun Detection
Products & Solutions Surveillance Security Services & Risk Management Residential Estate (Industry)
Bosch has announced the launch of the IVA AI Pro Visual Gun Detection analytics based on deep learning. It is designed for automatic detection and classification of people and brandished firearms.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.