Key Risk Indicators Case Study Analysis
Key Risk Indicators Case Study Analysis
Introduction___ ____________________________________________________________ 1
Case Illustration #1: Midwestern Utility Company, Inc. ______________________________ 2
Case Illustration #2: Wimbledon Investments ____________________________________ 13
Case Illustration #3: Discovery Health Group _____________________________________ 23
Conclusion ________________________________________________________________ 31
About the Authors _________________________________________________________ 32
Introduction
The main purpose of this case study is to take a closer look at risk reporting metrics and key risk
indicators (KRIs). KRIs are metrics used to provide an early signal of increasing risk exposure in various
areas of the organization. This study is based on three different companies in different industries
illustrating the overall Enterprise Risk Management (ERM) process and the role that risk reporting and
KRIs play in that process. For each company, the study provides examples of how risk metrics can be
developed, monitored, and reported. The main goal of the research is to provide examples that could
be used as a guideline to help other organizations implement risk metrics and indicators to effectively
monitor major risks. In addition, this case study may also provide insights on the structure of the ERM
function and the operation of the ERM process at the three different companies.
ERM PROCESS
The Company has always had a strong focus on risk management given the nature of its business and
the fact that it faces extensive regulation. However, it had not taken a structured enterprise-wide
approach to managing risks until it began a formal Enterprise Risk Management (ERM) program after
the Sarbanes-Oxley Act of 2002 was passed. The CFO of the Company initiated the process by selecting
a director of ERM. The newly appointed director of ERM consulted two other utility companies that had
more mature ERM processes to identify best practices that are important for a successful ERM launch.
The ERM director began the ERM process by going to each of the senior vice presidents of the major
departments of the Company to request participation in the development of the initial inventory of
risks. Each senior vice president then selected one individual at the director or general manager level to
represent them in the ERM function. After collecting all of the key people from each department, the
ERM director organized a series of brainstorming workshops. Starting at the enterprise level and
working down into the department level, the workshops focused on the major corporate risks. The
workshop started with the scenarios that would be the most severe if they were to occur. Next, the
workshop determined which scenarios would have the greatest likelihood of occurring. Finally, the
workshop determined which scenarios would be more controllable by the Company. When this process
was completed, the ERM director had a list of 14 major corporate risks that were spread out among all
of the departments in the Company. For each of these risks, a person within the responsible
department was named the risk owner and was given the responsibility of managing the risk. The risk
owners continued to work under the senior vice presidents in their departments while also working
with the ERM director to manage the risks. All of the risk owners collectively constitute the corporate
risk committee, and each serve the ERM function in addition to the current position they hold in their
respective departments.
The bowtie analysis (see illustration below) starts with the risk at the “knot” of the tie, and then
describes the events or circumstances that may cause the risk event to occur, paying particular
attention to root causes. Once those causes have been identified, the analysis then identifies
preventive measures that could be implemented. At this point there could be an evaluation of the
actual preventive measures that the organization has in place to determine whether additional
measures should be put in place. The analysis then moves to the right to look at the potential
consequences that would result after the risk event happens, and the plans the organization either has
or should have in place to minimize the negative effects of the risk.
“Causes” “Consequences”
What would cause Risk What would the
this event to
Event consequences be if
happen? this event occurs?
The root causes that have been identified in the box on the upper left of the bowtie analysis become
the focus of the development of KRIs. With the goal being to identify metrics that track those root
causes.
At the Company, the bowtie analysis was completed through a series of workshops organized by the
ERM director. Each workshop included the risk owner as well as subject matter experts from each
Each risk owner was asked to pull together information on their risk in advance of the meeting in order
to optimize time in the workshop. Once the cause events are identified, subject matter experts help the
group by providing relevant information for each cause event. With that information in hand, the group
can look more closely at potential cause events and discuss differences of, all of which sharpens the
group’s focus. The risk owners worked together to decode the root causes of the identified risks by
discussing what combination of events would lead to the occurrence of each risk. Then, they seek to
understand the issues which cause the event to occur. This requires the involvement of subject matter
experts who are well versed in the fields relating to each identified risk. Next, they consider the
potential consequences of the event. Then the Company reviews mitigation strategies that are either in
place or need to be developed for each cause.
CAUSES CONSEQUENCES
The causes identified in the bowtie analysis are then evaluated to identify predictive metrics that could
be used as KRIs. The risk owners were asked to define one key data point which could be linked to each
of the identified causes, and then gather three years of historical data on that data point. The ERM
director at the Company found that the key component of this process is to develop KRIs that look at
metrics in different ways. There should be at least one or two KRIs for each risk that go beyond pure
numbers. The reasoning behind this strategy is that some KRIs are effective predictors but are not
easily measured by numbers. These KRIs must be utilized in some way in order to effectively monitor
the risk. The subject matter experts help to develop metrics which are then used to monitor each KRI.
The process was made easier because the data for most risks was already being monitored either
within the Company or externally. In the example given, “state economic conditions” is a metric that is
measured externally by many independent sources, and this allows the risk owner a means to gather
metrics for this KRI.
Next, the subject matter experts determine a weight for each KRI, and this is a scale of high, medium,
or low. The process of determining the weighting is subjective based on the subject matter experts’
opinion of the influence of that factor on the likelihood of the risk occurring. The weighting of KRIs
brings a more specific approach to monitoring the risk associated with them. Each KRI represents a
trigger event which has a proportional impact on the likelihood of the identified risk occurring. For
example, if a KRI like “energy commodity prices” with a high weighting, moves above the red threshold,
it would make regulatory risk more likely to occur than if a KRI like “state regulatory success rate for
prior 12 months” with a low weighting moved above the red threshold.
The result of this process for regulatory risk at the Company is illustrated in the table below.
For energy commodity prices, a ratio showing the percentage change from the previous month is used
and thresholds are set. Red is set at greater than 1, yellow between 0.9 and 1, and green at anything
below 0.9 and the weight given is high. For example, a change in energy commodity prices above 1%
would be reflected in the red area.
The final two KRIs that are used for regulatory risk are performance threshold exceedance which
relates to reliability metrics and the regulatory success rates which relates to regulatory decisions.
These KRIs are measured and monitored like the three KRIs discussed above.
At the end of each quarter, the ERM director works with each risk owner individually and compiles a
KRI summary dashboard for the risk in that risk owner’s department. A comprehensive KRI report is
prepared by compiling the KRI summary dashboards for all the 14 major corporate risks facing the
Company. This report is distributed to the 45 senior officers of the Company, and provides a high level
overview of each risk and the current status of the KRIs in relation to the risk. The report is organized in
such a way as to allow each senior officer easy access to the KRI summary dashboards which directly
relate to the department he or she manages.
The KRI summary dashboard contains metrics comparing the current quarter measurements against
the previous quarter as well as the previous years’ matching quarter. The metrics show the changes
between the current quarter and the other two quarters in order to give the senior officers an idea of
the direction in which the KRI is heading. The dashboard is organized as a chart that lists the risk owner,
the risk, and each KRI along the top portion. Measurements for the three quarters are listed
underneath each KRI for easy reference. The dashboard also includes a KRI overall color assessment,
which is taken from the risk owner’s KRI graph for that particular KRI. Underneath each KRI summary
dashboard, a short narrative is provided that describes any changes in the colors of the KRIs. This
summary describes the change, what specifically occurred to cause the change, and whether this
change was an improvement or a setback. This narrative gives the senior officer enough information to
be able to have a discussion with the risk owner in regards to any actions which may need to be taken
to address the status of the KRI. These discussions occur regularly between the risk owner and the
senior officer, so if there is any unexpected change the narrative will be descriptive enough to inform
the senior officer of why it occurred.
Performance Overall
Advocacy
KRI’s Threshold
Energy Typical State Success Rate Risk
Number of
Commodity Customer Economic Regarding Assessment
Times
Prices Bill Conditions Regulatory
Exceeded in
Issues
Last Year
Regulatory
Risk
In this example, the prices of energy commodities are given a high weight, therefore if this KRI goes
into the red threshold it signals that the likelihood of the risk event occurring has significantly
increased. In the Regulatory Risk row, the boxes for each KRI will be filled with the color in which it is
plotted on the graph. Thus, the senior officer is alerted to the situation and will have a discussion with
the corresponding risk owner to discuss what mitigation strategies are in place and how they can be
adjusted to decrease the KRI to an acceptable level or begin to prepare the organization for the risk
event.
The ERM director at the Company understands that some KRIs are within the organization’s control and
some are not. The reason for employing KRIs is to help determine whether the mitigation strategies
being employed by each department for managing risks are effective. The ERM director does not own
the risks being managed, but they do own the process of managing the risk. This is essential to the
success of the process, and the team continuously monitors the effectiveness of KRIs. They do this by
meeting quarterly with the corporate risk committee and challenging the data being presented to them
by the risk owners from each department.
COMPANY BACKGROUND
Wimbledon Investments (WI) is a leading investment and financial services company based in the
United States with investments across the globe, but focused primarily in the United States, Canada,
and Europe. WI has been in business for over 50 years and has survived numerous market downturns
including the most recent global financial crisis. The Company had assets valued at approximately
US$100 billion at December 31, 2015.
A significant portion of WI’s business consists of investments in mortgage loans. The company focuses
on maintaining a diversified portfolio of mortgage investments and tries to be forward-looking when
assessing the risks of investing in particular markets. One of the challenges for any international
company is to design an effective Enterprise Risk Management (ERM) program that is common across
all of its global businesses, yet is flexible enough to work in different environments. The markets in
these different areas around the world may act and are regulated differently, which is why an ERM
program cannot be too rigid. WI’s strategy for making investments in new markets has been to look for
areas with growing home ownership, a solid legal and regulatory framework for mortgage lending, and
people who are home ready. It believes that this strategy has contributed to the company’s successful
growth and performance.
Another key component of the ERM process is monitoring and communication, which is performed on
a continuous basis throughout the organization. In addition, risks are also reassessed as a part of the
company’s annual business planning process. During the business planning process, the Executive
Management Risk Committee assesses its investment portfolio and prepares three to four year
forecasts of changes expected in its portfolio and in the markets in which it invests. The committee
then creates three to four scenarios with increasing stress to evaluate the events that may happen and
how the portfolio would be affected. The committee also assesses the probability of these events
happening. To understand how the business will be affected by deeper levels of stress, the committee
will run a deep downside scenario analysis looking at economic capital along the probability
continuum. The Executive Management Risk Committee will then present its findings to the Board Risk
Committee and gain approval over its risk appetite and tolerances. Wimbledon Investments’ ERM
process helps to ensure that the company remains vigilant as risks are constantly changing. Below is an
illustration of WI’s ERM process:
Core Drivers
WI’s Corporate Chief Risk Officer (CCRO) is appointed by and reports to both the Board Risk Committee
as well as the CEO. The CCRO chairs the Executive Management Risk Committee and is the
management liaison to the Board Risk Committee. As such, the CCRO regularly attends meetings of the
Board Risk Committee. Reporting to the CEO are the heads at each of the United States, Canada, and
Europe business units. Each business unit has a business-level Chief Risk Officer (CRO) that reports
directly to the business head and indirectly to the enterprise-level CCRO. Each business unit also has an
ERM Team that includes an ERM Lead and Analytics lead, reporting directly to the business-level CRO.
Below is an illustration of the company’s reporting line:
Board of
Directors
Compensation Audit
Committee Committee
Nomination and
Board Risk
Governance
Committee
Committee
CEO
Capacity: The first hurdle for WI is the capacity of the borrower and ultimately the company’s
portfolio. This principle can be expressed through the question “Does the borrower have the ability to
pay back the loan?” If the borrower makes $900 per month and the mortgage is for $1000 per month,
the company knows that the borrower does not have capacity. But if the borrower makes $2000 per
month, the transaction may be possible. Therefore, the company evaluates potential mortgage
investments for sufficient capacity. One metric that WI uses to monitor the capacity of the borrowers
in its portfolio of mortgage securities is Debt to Income (DTI). Therefore, the question for developing a
KRI could be, “What event(s) could have a significant impact on the Debt to Income ratio across my
portfolio?” and “What is the earliest indicator that such an event or events is starting to occur?”
Credit: Once the first condition is met, the next step for WI is to look at credit. This principle asks, “Is
the borrower willing to pay back the loan?” Some borrowers may satisfy the first principle and have
the capacity to pay, but they don’t pay their bills on time or they don’t manage their finances very well.
These types of habits can be reflected in a borrower’s credit score, and ultimately in the company’s
investment portfolio. Credit scores are easy to obtain and the company has found them to be very
predictive of default. The scores may also show the company if the borrower has any liabilities that
have not been disclosed, because most loans in most mature markets will show up on a borrower’s
credit report. The company’s portfolio risk increases as its borrowers’ credit scores decrease.
Therefore, WI may develop a KRI by asking the question, “What event(s) may decrease borrowers’
credit scores?” and “What indicator will precede such an event?”
Collateral: After WI has confirmed the borrower’s credit position it will assess its collateral. If the
borrower defaults on the loan, the first step would be to work with the borrower to try to remedy the
situation through a loan workout process. If this process is unsuccessful, the property securing the
mortgage would likely be sold to recover the value to pay off the loan. One of the key measures of
involving collateral is the Loan-to-Value (LTV) ratio. The LTV ratio is a key measure that banks and
mortgage lenders use that describes the relationship between the loan amount and the value of the
property. A higher LTV will mean that there is less equity in the loan, which makes it riskier. Some loans
may have a 95% LTV, which means that the borrower only made a 5% down payment. These loans are
payments, WI will have more cushion to recover the value needed to pay off the loan. Therefore, WI
would use LTV to develop a KRI by asking, “What would increase our portfolio’s LTV?” and “What
indicator could show when LTV is about to increase?”
Documentation may also be added to these principles. Although it does not relate to KRIs, all of the
three above steps rely on good documentation by the company and by the loan originators. The 3Cs
underwriting principles have been used for many years and were implemented long before the global
financial crisis of 2007. Even so, one can easily map deficiencies that resulted in the crises to one of
these three key principles. For example, some mortgage investors had purchased 100% LTV loans,
which were very vulnerable to potential losses in the event of a market decline. If WI can develop KRIs
that are tied to these 3Cs, the company might mitigate its exposure to a risk event in the future. Below
is an illustration of how Wimbledon Investments linked its objective to strategies to risks and
ultimately KRIs:
Risky Credit
Profitability Credit Credit Score KRIs
Score
Controllable risks: Controllable risks are managed on the front end of business decisions to decide
whether or not to take certain risks based upon limits that have been put in place.
1. For capacity, the lender can make sure that it has reasonable DTI by putting a cap on the
measure of, for example, 45%. The company can monitor and manage the loans that are
coming so that they don’t exceed this metric.
2. For credit, the company may look at its portfolio to see how many loans are coming in below a
certain threshold. It may also look at the average and see how it is moving up and down.
For collateral, the company may put a cap on LTV and say it wants 95% maximum and 90% average for
its portfolioTo monitor these controllable risks, the company uses multiple dashboards and analytical
data. When a measure is triggered, it forces a refreshing of the company’s analysis and an escalation to
higher committee levels. However, the company realizes that its geographical diversification allows it
to experience stress events without always having to create a
deviation from its business plan.
Controllable risks of new
Uncontrollable risks: Even if WI has all three principles in place, investments: High Debt-
there are many factors in the mortgage industry that could influence to-Income, Low Credit
its risk position. The company cannot control macroeconomic shifts, scores, and High Loan-to-
but it can prepare itself to be more agile and resilient when these Value.
events do occur. This is where risk indicators can be very effective
and useful. To monitor the macroeconomic environment, WI may Uncontrollable risks
look at indicators such as Gross Domestic Product (GDP) growth, managed by KRIs: Low
interest rates, unemployment, and inflation. To monitor the housing GDP, Low Growth rates,
environment, the company may look at mortgage originations, home High Interest rates, High
price appreciation, affordability, and housing supply and demand. All Unemployment, and High
these indicators may cause changes in a portfolio’s 3Cs principles. Inflation.
In the past, WI simply established trigger levels related to the key drivers of each significant risk, and if
the trigger level was reached the company would take action according to a defined action plan for
that risk. Over time, WI realized that this process was too mechanical and automated. It decided to
focus on creating a more proactive approach to risk oversight and management so that the process
shows a continuous evolution of approaches. For WI, the goal is to be able to show that the business
has been monitoring the risk before any metric was triggered. Negative trends should be talked about
and discussed at regularly scheduled risk review meetings, before it escalates to a trigger point. The
company still relies on the required action plans when metrics are triggered, but now it also has
incorporated qualitative measures into its ongoing risk oversight process. Every month, the CRO of
each business will review its portfolio and document some qualitative analysis which he communicates
to the business unit head and the enterprise level CRO. This step gives the business unit CRO an
opportunity to communicate the positives and negatives regarding the level of risk the business is
taking on. It also gives the CRO an opportunity to step away from the metrics and to voice his concerns
early, so that they are talked about long before any metrics are triggered. Therefore, WI includes these
qualitative measures as leading indicators for the company.
WI has built many sophisticated leading indicators for its uncontrollable risks. One of WI’s six leading
indicators for the mortgage industry is oil prices. The company identified this indicator when it asked
itself, “What uncontrollable event might affect the capacity of borrowers in the markets where we
have made investments?” It realized that when unemployment was high, borrowers may not have the
income to pay their mortgages, resulting in potential losses for WI. Therefore, the company asked
itself, “What is a leading indicator of when unemployment is about to rise in each of the markets
where we have made investments?” To evaluate unemployment, the company first identified the
largest employers or most significant industries in each area where it had investments. In one area, the
economy was very dependent on the oil and gas industry. WI realized that when oil prices decline, oil
companies may react by laying off employees which would affect not just the oil company’s employees
but also the broader economy in that area. These actions would not only affect the borrower’s ability
to pay but also could have cascading effects on the value of property in that area, increasing the LTV
ratios.
On the other hand, if the same area experiences an increase in oil prices, it could improve the
borrower’s capacity to repay as well as increase property values. The process is illustrated below:
Risk Event:
Asset Quality
Declines
Mortgage
Delinquencies
Increase
Unemployment
Increases
Root Cause
Event: Fall in Oil
Prices
Some investors have searched for measures that would predict a decrease in new business for the area
because a decrease in new business could be an early warning sign of a decline in existing business and
employment. They discovered that by monitoring the number of shipments coming into the area, they
could predict business activity. If there was a decline in scheduled shipments coming into an area it
was a sign that business activity was slowing and therefore the workforce would no longer be growing,
thus there would be less demand for mortgages which would result in a potential decrease in the
capacity of existing borrowers to meet their loan obligations. On the other hand, this
leading indicator may also be turned around and used to predict future opportunity events by
monitoring an increase in number of shipments coming into an [Link] another area where WI has a
concentration of mortgage investments the dominant industry is mining and the KRI is China’s
economy. Similar to the oil manufacturing example, the company recognized that the health of the
mining companies was crucial to the continued employment of the borrowers in this area. The
company then asked itself, “How can we predict when mining companies will experience a downturn?”
Going further down the chain, WI determined that mining companies in the area were highly
dependent on exports of raw materials to the Chinese market, and therefore it could predict a decline
in demand for raw materials when China’s building infrastructure slowed down. Therefore, WI began
monitoring the Chinese economy, which ultimately would affect WI’s mortgage investments in the
area.
SUMMARY
WI uses a significant amount of data and predictive modeling in monitoring both controllable and
uncontrollable risks. It constantly analyzes data and trends looking for an edge on any variable that
may help the company predict business performance in the future. It may take months or even years
for WI to realize whether a certain mortgage investment was a good or bad decision. Therefore, the
company believes that the more important part of its business is to make sure that the quality and
profitability of new investments are sound. Where KRIs have been most helpful for the company is
when they are used to manage uncontrollable risks. WI uses the root-cause analysis to tie indicators of
risk events to the 3Cs principles that will ultimately determine the risk position of the company’s
existing portfolio as well as help to shape the strategy for making new investments. In this way, WI
seeks to use risk indicators not just for the risks in its existing portfolio but also to be more forward-
looking as it seeks out new investments.
ERM PROCESS
The process of building out the ERM function at DHG began in 2008. Since then, the organization
believes their ERM process has gradually gained greater acceptance at all levels of the organization.
DHG believes that maintaining an ERM framework is critical for the long-term success and sustainability
of its ERM process.
According to the ERM Framework developed by DHG, the organization begins by developing and
deploying a risk strategy. The overall risk strategy is connected to individual risk objectives that pertain
to each area of the organization. The following defines the roles of each participant in the ERM process:
Risk Governance: Composed of the Audit Committee, the Board of Trustees and the Senior
Leadership Team (SLT).
Risk Oversight: Composed of the Enterprise Risk Committee (ERC) within Audit and Risk
Management (ARM). The ERC is responsible for ensuring the ERM process is effectively executed
across the organization. ARM collaborates across silos and communicates cross-departmentally to
ensure risk response plans have been implemented and are effectively operating.
Risk Infrastructure: Consists of competent individuals with proper training, effective risk
management procedures, and appropriate technology to analyze and communicate risk exposures.
Risk Management and Ownership: Consists of business unit leaders (risk owners) accepting
responsibility for managing risks within their control in the risk universe.
The objective of the ERM framework, depicted below, is to sustain and continuously improve the
effectiveness of the ERM function at DHG. The ERC is responsible for developing enterprise wide
DHG employees are encouraged to follow certain key Enterprise Risk Management Steps. These steps
are typically communicated through ERM workshops. All individuals in leadership/management
positions are required to attend informal training on risk mitigation and ERM fundamentals. The
following steps are included in the organization’s ERM process:
Identify Risks: Understand what could prevent a department from achieving the corporate goals
Assess and Evaluate Risks: Understand the impact of risks and provide key information for cost-
effective decision-making
Respond to Risks: Understand and prepare for circumstances impacting risk response
Design and Test Risk Mitigation
Monitor, Assure, Escalate and Report: Provide management with a comprehensive view of
business unit risks
Each business unit has a risk owner responsible for ensuring that ERM plans are properly established
and operating as intended. Risk owners are accountable for developing relevant success measures,
Tier1 risks are routinely re-evaluated and plotted on a MARCI chart. The MARCI chart (for Mitigate,
Assure, Redeploy, and Cumulative Impact) plots risks along the two axes of impact and vulnerability
and indicates each risk’s speed of onset by the size of the data points. The chart particularly useful
when the primary purpose of the prioritization exercise is to highlight those risks for which an
appropriate risk response is most needed. Risks plotting the farthest in the upper right quadrant
represent the highest impact and vulnerability and would benefit the most from additional
management effectiveness in managing the risks. Tier 2 risks are managed at a slightly less robust level,
and Tier 3 risks typically
do require the attention
of the ERM team. The tier
three risks are still in the
risk universe managed by
business units, but they
are not brought to the
attention of the ERC un-
less they subsequently
arise to tier 1 or tier 2
status.
The ERM function at the company is a part of the Audit and Risk Management Department along with
the company’s Internal Audit Function. The ERM team has found success in monitoring the risks facing
the organization through its association with the Internal Audit Team. This link allows the organization
to improve its assessment of mitigation strategies with regards to individual risks being managed by risk
leads. An example of this would be the outsourcing of certain functions of the operations of the
company to external vendors. Since the company needs to have the assurance that the risks inherent in
vendor outsourcing are managed effectively, the company uses its internal audit function to assess the
controls of those vendors. Also, the vendor management function is audited to determine the
effectiveness of overseeing the company’s managing of relationships with vendors. During this audit
process of vendor management, information received from the Internal Audit team by the ERM team
prompted the discovery that risk mitigation strategies needed to be reviewed and revised to better
handle the risks involved with outsourcing operational functions to vendors. The internal audit function
was able to communicate this to the ERM team, who in turn worked together with the risk leads and
the ERC to develop increased and improved risk mitigation activities to better manage the risk.
However, the ERM team is not always involved in the decision-making process from the beginning. In
some cases, after the decision has been made to launch a significant enterprise initiatives, the ERM
team may assist the business unit management in completing the ERM steps to increase the likelihood
of success in accomplishing the initiative’s objective.
The development of KRIs occurs in tandem with the reporting of key emerging risks expressed above.
The difference is the KRIs associated with those risks are developed, documented, and presented to the
ERC but are not reported on the company’s ERM Dashboard. What goes on the ERM Dashboard are
only the risk description, success measures, risk scores, and mitigation strategies. The success
measures are the high-level objectives and outcomes that would demonstrate that the risk is
satisfactorily mitigated and opportunity optimized.
These reports begin with a risk description which details the risk and what it involves. The next item is
the background of the risk, which discusses the root causes and consequences involved. The report also
includes success measures and the mitigation strategy.
Secondly, the ERM team engages the risk lead in determining success measures for the optimal
management of the risk. The success measures are the high-level objectives and outcomes that would
demonstrate that the risk is being satisfactorily mitigated and the opportunity optimized. The ERM
Team seeks to have management define quantifiable success measure statements, but will allow
qualitative statements. With respect to regulatory risk, a simple qualitative success measure statement
could be: Regulatory requirements that could be problematic onto the company’s strategy, business
performance, or ability to implement are avoided or kept to a minimum. Essentially, the success
measures for all risks help establish and align the risk mitigation strategies in place or planned by DHG
to manage the risk exposures or opportunities they present.
The report next focuses on risk mitigation strategies being employed for the risk. The mitigation
strategies include current and proposed mitigation strategies. The strategies are listed in rank order
starting with the most impactful mitigation strategy. Each risk mitigation strategy has a detailed
description of the strategy, a high-level action item to implement the strategy, the status of the
strategy, and an impact statement that corresponds to the risk. The purpose of the status is to show
whether or not the strategy to combat a risk is actively being employed. When mitigation strategies
simply are not reducing the risk impact or likelihood, the risk lead informs the ERM Team and, at times
the ERC. In this situation the risk lead will typically be advised to develop additional or revised
mitigation strategies as well as facilitate reporting the risk exposure to the Risk Governance level (i.e.
Executive Risk Committee and Audit Committee).
While the company has developed Key Risk Indicators (KRIs) for its tier 1 risks, it has not yet
incorporated KRIs into its ERM dashboard reports. The ERM Team began developing the KRI concept for
usage in the DHG enterprise risk management processes in 2011. The ERM Team worked with the Tier
1 Risk leads to identify and incorporate KRIs into their ERC presentations beginning in 2012. The KRIs in
the ERC presentation are specific to each risk, however there is not a formal process surrounding their
development. The ERM Team facilitates consultative meetings with the Risk Lead and other subject
matter experts engaged by the Risk Lead to identify suitable KRIs. The ERM Team advises the Risk Lead
to self-report the available KRI information along with other factors/sources of information that
management may be using to intuitively ‘know’ when the risk is increasing/decreasing/holding steady
(i.e. the basis for management’s “gut” feeling). The majority of the KRIs used by the company are not
The reporting of KRIs to the ERC has been limited to the self-reporting done by the Risk leads. DHG is
working towards having a more formalized, transparent process to allow the ERM Team, the ERC, and
management beyond the Risk Lead’s business area to gauge the movement of the risk and the
effectiveness of the associated risk mitigation strategies.
Emerging Risks
Since the inception of an ERM framework in the company, DHG has been primarily focused on
developing robust reporting of tier 1 risks. The reporting on emerging risks and their associated KRIs
and risk mitigation strategies has lagged behind. However, the ERM team and the CRO are currently
developing robust emerging risk identification and reporting processes that should bring additional
value to the ERM process by ensuring that significant emerging risks are included in its risk inventory,
and that related KRIs have been identified to monitor these risks.
Emerging risks, similar to the other risks, are primarily managed by the risk leads with regular dialogue
with the ERM team. The Risk leads generally identify these emerging risks from a combination of
discussions with external parties, industry news, and review of internal information. When risk leads
identify these risks, they try to get as much information as possible to track the risk, particularly to
determine the velocity at which the risk is approaching. The risk leads and the ERM team meet every
six months to discuss and document those emerging risks that appear to be approaching the most
rapidly. An example of an emerging risk is biological and chemical terrorism. This is a risk that could
originate and play out in the company’s service area resulting in a large scale disaster response
impacting members, employees, business partners, and surrounding community. A key risk indicator
related to this risk could be to tracking threat levels from emergency management and federal
homeland security officials. Another KRI could be monitoring news reports of reported attempts that
involve the company, the health insurance industry, and the communities situated near the company.
Each company has taken a slightly different path in the development of key risk indicators, tailoring the
approach to fit the needs and capabilities of each organization. Some companies use more analytical
data to monitor the major risks facing them, and some use more qualitative analyses in their approach.
Some are more focused on gathering data to develop their leading indicators, and others are focused
on maturing other areas of their ERM program before tackling more quantitative indicators. Even
though the companies have varying levels of developing KRIs, they all find value in the processes they
use. Although the development process may need to be different for different companies, the key steps
outlined in this report illustrate effective practices. The case studies in this report should serve as a tool
for ERM practitioners that are looking for guidance on risk reporting and the development of key risk
indicators.