Why Value Investing is Not for Everyone

There are several reasons:

  • They are not aware of it
  • They do not believe in it
  • They need results quickly.  This is especially true for fund managers who are under pressure to not only show results every quarter, but not be at the bottom rank of performers for that quarter.
  • It is not very exciting.  Value investing requires copious amounts of research and patience.  Many people enjoy the thrill of day trading.

Value investing may work, but it is not the only one that works. 

Kahnemann, Empricial Data on BCP for Small Businesses

Roundup
 
- Daniel Kahnemann has a new book titled "Thinking Fast and Slow".
 
- Someone in LinkedIn group "Business Continuity Management & Risk" is asking where to find metrics that show BCP is "worthwhile" for small businesses.  Suggestions were to look at regulators and government offices set up to help small business (offices such as http://www.sba.gov/).  Others are convinced no such empirical data is available, after having spent time looking for them previously. 
 
Someone questions the question.  Why the need for empirical data when it is clear that a catastrophe means end of the company?. Someone suggested looking at 9/11 as proof of the value of planning for disaster (mostly in convincing people that disaster CAN strike). But the original poster thinks more 'normal' disasters can be more compelling than extreme (and rare) ones such as 9/11.  Someone suggests that the Bishopgate Bomb can provide a useful resource in comparing the impacts between those with BCP and those without.
 
The Waffle House apparently lives in hurricane country and has a very simple and effective BCP plan in place.  More details in http://online.wsj.com/article/SB10001424053111904716604576542460736605364.html.  The company is famous locally for their very quick Return to Operations ability (when the shops are still closed, locals know the danger is not yet over) and uses this to their advertising advantage.
 
Finally Tim Cousins from Australia makes a suggestion to read "The Risk/Earnings Ratio - New Perspectives for Achieving Bottom-Line Stability." (http://www.fmglobal.com/assets/pdf/P09232.pdf).  Tim seems to be also the author of another recommended paper "Organisational Resilience Position Paper", available here:  http://www.emergency.qld.gov.au/publications/pdf/Organisational_Resilience.pdf
 
Someone from the US recommends a read of "The Impact of Catastrophe on Shareholder Value" by Knight and Pretty and says he often uses this paper as a seling point.  (This paper is mandatory reading in the IRM Risk Diploma, so I am quite familiar with it).
 
Dori makes the stunningly obvious (but forgotten!) point that insurance companies would have the best emprical data.
 
The silver lining in disasters is that they often provide the opportunity to restructure (re-engineer), using the sudden infusion of cash from insurance (such as Business Interruption Insurance). 
 
In addition to empirical data, someone suggested to personalise the effects of a disaster.  What would be the impact to you, Mr / Ms Business Owner, what is the cost of lost sales, claims, etc.?
 
 
 
 
 

ModelRisk

VOSE Software provides a software tool called ‘ModelRisk 4’ which allows analysts to run Monte Carlo simulations within Microsoft Excel.  The software is able to display the results in graphics format.   The ‘Standard’ version of the product is free and is not time-limited.   You can download it and use it for as long as you like.  If you need more powerful features, the company sells the ‘Professional’, and ‘Industrial’ version of the products.

The software is supported by a very comprehensive help file which goes beyond merely explaining how to use the software, but also gives a brief explanation of the various data analysis functions and their purpose.    But for more in-depth analysis, you can turn to David Vose’s book ‘Risk Analysis: A Quantitative Guide’.   David runs VOSE Software out of Belgium. VOSE Software also provides risk consulting services.

Likelihood of an Event

The biggest constraint in risk management, indeed the very reason for the existence of the discipline, is our inability to foresee what will happen next. In most cases where people have to manage the risk of an event, it is very common to rely on subjective estimates of the likelihood that an event will happen. It may be easy to deliver criticism of this approach, but alternative options are limited.  An improvement over such a simplistic 'gut feel' approach is to incorporate the phenomenon that events of a smaller scale occur at a higher frequency than similar events of bigger scale.  Earthquakes of low magnitude occur very frequently. Killer earthquakes occur far less frequently. The relationship of the frequency between the two types of events is described a the Power Law Distribution.  If we keep track of smaller scale events, we will be able to predict with a certain degree of confidence the frequency of the bigger scale events.

Deciding That a Crisis is Upon Us

A key challenge that needs to be met in the face of a serious situation is determining whether we are in a crisis or not? Whence is the transition from non-crisis to crisis? Is it time to initiate the crisis management plan, or not yet?

The US military gives us a good model of crisis with the DEFCON
status. It allows a staged reaction to a crisis that may be impending
or may not be impending.  It allows the military to prepare and also not to over-prepare.

As facts become known, and the understanding of the situation becomes more solid, the authorities are able to step up or step down preparations
and mobilisations for handling the crisis.

Business organisations would to well to think about a staged approach to
their crisis management plans.

Some Regulatory Business Continuity Links

By no means a complete list...

Australian Prudential Regulatory Authority

Guidance Note GGN 222.1
Risk Assessment and Business Continuity Management
http://www.apra.gov.au/General/loader.cfm?url=/commonspot/security/getfile.cfm&PageID=8532.

Guidance Note AGN 232.1
Risk Assessment and Business Continuity Management
http://www.apra.gov.au/Policy/loader.cfm?url=/commonspot/security/getfile.cfm&PageID=8529

Prudential Standard APS 232
Business Continuity Management
http://www.apra.gov.au/Policy/loader.cfm?url=/commonspot/security/getfile.cfm&PageID=8528

Prudential Standard GPS 222
Business Continuity Management
http://www.apra.gov.au/General/loader.cfm?url=/commonspot/security/getfile.cfm&PageID=8531


Commission of the European Communities (2005): Green paper on a
European programme
for critical infrastructure protection, November
http://eur-lex.europa.eu/LexUriServ/site/en/com/2005/com2005_0576en01.pdf

De Nederlandsche Bank (2004)
Business Continuity Planning
http://www.dnb.nl/en/payments/bcp/index.jsp

Beyond the Risk Register

A few months ago, someone in a program management office noticed that a new employee had taken a master's degree course in risk management.
A brief cackle burst forth, asking: "why would someone need a master's degree in risk management?"

It's a good question.

Risk management is, for many people in projects, one of the very basic things that anyone can do. It's not rocket science. To most people,
risk management is simply the risk register - often created because it
is a mandated part of the project management procedures - and not much
else.

And anyone can create a risk register. All you need is an Excel
spreadsheet and a template of the right headings, or a risk management
software, and start populating it.

Even the risk management framework is simple enough: identify the
risks, give an estimate of the likelihood, determine consequences,
identify controls, estimate residual risk, identify who is
responsible, and then rank the risks for prioritisation.

Brain surgery is equally simple: identify the area to be incised,
determine the likelihood of success, determine the risks, etc. People
know that not all surgeons are equally qualified to do brain surgery.
Even among brain surgeons, there is a qualitative difference in
experience and consqeuently, results.

Riding a bicycle is also equally simple, but everyone knows there is a
magnitude of difference in the performance of a rider at a Tour de
France level, and someone who rides for leisure.

But what about risk management? While anyone can come up with a risk
register, there can be a serious difference in the results.

Some areas where competence in risk analys would produce a marked
difference in results

* Risk identification - are we identifying the right risks? Are we
missing any? Are putting in risks that aren't risks? Missing a
critical risk can prove catastrophic to a project.

* Risk likelihood - are our estimates any good? Is there available
data we should be using? Overestimating can prove costly.
Underestimating can prove disastrous.

* Risk consequences - how credible are our estimates of consequence?
How complete is it? An inept analysis of the consequences will mean
poor preparation and mitigation of the consequences.

* Risk control - how realistic are the controls and mitigations we
have identified? How good is our decision-making on which controls to
implement? What is the impact of our controls

* Risk prioritisation - are using the right prioritisation approach?

Checklists

Checklists and questionnaires belong in the toolbox of risk professionals. A checklist works best when used by the risk professional while interviewing an information source, whom we’ll call an interviewee. 

The checklist becomes far less effective when simply handed over to the interviewee because when you let the interview work by himself,  it raises new undesirable dynamics:

  • First, the interviewee loses the chance to ask questions about the questions being asked.  He may misunderstand what is being asked, but unaware of it.  In such a case, even if you informed the interviewee that they should ‘feel free’ to ask if they have questions, will not help much, because in this case, the interviewee is not even aware that they misunderstand.
  • Second, the interviewee may not have as much interest as the interviewer in the process of gathering data.  In cases like this, you can expect that only the minimum amount of information will be written down in the checklist.
  • Third, the interviewee may not see the whole point of the interview, and why they must fill in the checklist. As in the second dynamic above, this results in lacking information.
  • Fourth, a large number of checklists and forms are very badly designed, which can easily lead an interviewee to confusion. Many forms ask for too many things. The interviewer may have energy to fill in the first few entries, but a noticeable drop in energy due to a drop in interest can often be seen.

A well designed form helps much toward eliciting good information.  At the very least, the following should be addressed when designing questionnaires and checklists:

  • Who is going to use the contents of the checklist?
  • To what purpose are they going to use the contents?
  • Who is going to provide information to the checklists? (That is, who are the interviewees)
  • What kind of questions and prompts should the checklist contain in order to elicit the information required?
  • What kind of information does the current version of the checklist contain that are not needed?
  • In what ways can the questions and prompts be misunderstood?

It is vital that a checklist be tested on several interviewees first before finalising it use.

Risk Management Software Packages

In a LinkedIn discussion someone asked for recommendations on a web-based risk management software package that’s suitable for a SME (small to medium enterprise).  The key need was for managing a risk register and for tracking risks.  Some of the recommendations were:

This is quite a handful of choices. I’m hoping to be able to spend some time lokking into each one.

What is the difference between an impact and a risk?

Sit at any Risk Management 101 class or Risk Management introductory workshop and you will most certainly be introduced to the risk register. And in that risk register, you will be introduced to two columns: the Risk, and the Impact. 

You will be told that the Risk is an event that may or may not happen.  You will also be told that Impact is what will happen if the Risk occurs (or ‘eventuates’). Sounds clear, simple, direct. 

Now let’s apply what we’ve learned.  You are concerned (rightly) about crashing your car. Is that a risk? Or is it an impact?  (Avoiding the pun on crash and impact). It is not certain that your car will crash, so that is a risk.  What will be the impact?  Easy: you may experience fatality.  Or you may experience serious injury, or you may experience light injury. 

But why isn’t crashing the car an Impact? 

What caused the car crash? Did your brakes malfunction?  Was that a risk?  Was there a risk that your brakes would malfunction?  Were you hit by a drunken driver? Was that a risk you faced when you were driving? Absolutely.

So let’s say: Risk = Possibility of being hit by a drunker driver.  What is the impact?  Crashing your car.  What was the risk earlier is now the impact.

The distinction between risk and impact is not so clear.  What is a risk from one perspective is an impact from another.  But which perspective is the right one to take? And which perspective should you be taking when you fill in the risk register?  Do you put “Car crash” under Risk or under Impact?

Winning and Risk Management

There’s a highly-regarded self-coaching book called “Sail, Race, and Win”, by Eric Twiname and Cathy Foster. In the book is a neat description of how to win in a race.  They ask the reader to imagine a descending escalator, with lots of people, representing the competitors, walking up the escalator.  The goal being to remain in the same spot they started in as much as they could manage to. They can walk up to the same pace that the escalator is going down, but they can't walk up faster than that.

  images

Since no one’s allowed to go faster than the pace of the escalator, the would-be winner will have to focus on not making mistakes rather than walking faster than the pace of the escalator.  Any mistake, no matter how momentary, will set you back a little, possibly allowing someone behind to move out in front of you.  The more mistakes and lapses you make, the more you are pushed back relative to your starting position, and relative to the other competitors.

Now since you can't go faster than the pace of the escalator, you can't make up the distance you lost by putting in extra effort. The best you can do is to make no more mistakes.  The only way you can get ahead of those in front of you is if they make mistakes.

escalator

I haven’t seen winning explained in this manner before, and despite its oddness, it has a certain valid point.  Twiname and Foster come from the world of sailing.  Perhaps the idea of not being able to outpace the escalator comes from their world, where your progress depends on the winds and the tides -- you can't go faster than what the elements or the environment allows.

The image seems rather useful when thinking about how risk impacts business.  A company cannot make more money than what its environment allows.  For example, if you are a consumer goods company, how much you can sell is moderated by the size of your market, the demand for your product, and the competitive dynamics of the industry you are in. In a market with 10,000 customers and 5 competitors, you just cannot make sales equivalent to a market of 20,000 customers.

And while you can't get ahead, you can definitely be set back.  The key to winning then becomes minimising the setbacks. From an operational basis, you are constantly being set back if your production costs are more than the competition’s. From a discrete and pulsating basis, you are set back each time a risk eventuates which impacts you negatively.  The longer and more expensive it takes you to recover, the more you are set back.  The key to winning in this case is to ensure that you minimise your risk eventuations and minimise their impacts.

You can look at risks as these setbacks.  It is in your interest to avoid them as much as possible, and to be able to recover as quickly as possible.  Even then, you can only recover to a point less better than where you started. Hence, reducing the occurrences of risks become a key factor in winning.

Risk - What Can Go Wrong

There is so many definitions of risk. The newer versions include 'positive risk' and variations thereof. These definitions try to be very inclusive, to make sure they cover all possible perspectives and manifestations of risk. It can be a bit confusing. Some days I am tempted to find a simple, clear, usable definition of risk.

I am not yet convinced that 'positive risk' should have the word 'risk' appended to it. On those days when I look at risk management as 'the management of uncertainty' I have no problem accepting that positive risks belong to this domain.

But for now, I will use as the most basic definition of risk:

Risk = what can go wrong.

Risk management = managing what can go wrong

The ‘wrong’ already implicitly includes a reference to our objectives.  If something can go wrong from our point of view, it means something going wrong in relation to our interests.  Something that doesn’t affect us is not something going wrong. So I don’t have to extend it to ‘something that can go wrong with regard to our objectives’  (in any case, I prefer to use ‘interests’ rather than objectives).

The ‘managing’ in ‘managing what can go wrong encompasses identification, assessment, and mitigation.

Let’s see how far these definitions will let me go.

Review of "The Failure of Risk Management: Why It's Broken and How to Fix It" Part 2

In Chapter two of his book, Douglas Hubbard's discusses where the risk
management industry has been and where it currently thinks it is.

The chapter starts out with a very brief history of risk management
('800 words' according to the author), tracing the route from the
discovery of mathematical probabilities, to its initial commercial
application in insurance, and finally down to the modern day emerging
'new character' or risk management, incarnated in regulations like
Basel II, and in applications like Enterprise Risk Management. His
history is not very complimentary, comparing today's state of risk
management as similar to the Old West gold rush towns, where things
look brightly painted and pretty, but built on shaky foundations and
filled with snake oil peddlers.

His history aligns quite well with Peter Bernstein's own summary,
although at a very very high level and, I suspect, very much framed to
support his thesis (which I suppose is what the rest of the book is
about).

Hubbard then makes a brief discussion of the common risk assessment
approaches (expert intuition, weighted scoring, probabilistic models,
etc) and suggests that some of these are not up to par for the role
risk management is playing (corporate growth survival, after all) and
will probably need to be dispensed with.

The next section covers risk mitigation approaches. He has a brief
treatment of the common approaches (what risk management book
doesn't?): avoid, reduce, transfer, retain. The most interesting part
of this section is his list of examples of concrete manifestations of
risk mitigation approaches (in contrast to the abstract approaches of
avoid, reduce, etc. His list includes selection processes, contractual
risk transfer, insurance, liquid asset position, etc.).

In the final section, Hubbard discusses 3 major surveys of enterprise
risk management, conducted by Aon, The Economist, and Protiviti. The
surveys show what the executives in these companies thought about what
their top risks are (reputation, market, human capital, and regulatory
environment figure very high). The surveys indicate that risk
management is present in those companies primarily because they are
being required to have it (a necessary evil). It also shows that risk
management is well represented and increasingly so at the board level.
The executives seem pretty confident that they are doing risk
management well.

Hubbard suggests that that is not the case at all.

Risk Versus Risk

One of the most critical processes in managing projects are those addressing project risks.  Some writers go so far as to call risk managent 'project management for adults'.  The implication being that if you’re not doing risk management in your project, then you’re just a kid, you haven’t grown up yet, and have no place among grown-ups (I agree with this view, by the way).

When asked what risk is, quite a few will give an answer that goes something like: 'a risk anything that can go wrong.'  In this view, a risk is something that can go wrong, and therefore risk management is about addressing those things that can go wrong.

But there is another, less commonly known, view of risk.   In this view, risk is something uncertain that may affect the project.  Not something necessarily bad, but something uncertain. 

Let's suppose you are planning a picnic for tomorrow.  Being an adult, you have prepared a risk management plan (your picnics may be boring, but they are predictable).  You have an entry for weather in your risk plan.  In the first view of risk, you look at the weather and look for something that could 'go wrong' that could negatively affect your picnic.  Is it going to rain tomorrow?  If there's a chance of rain, what can we do to mitigate the effects of this rain on the picnic? Perhaps bring an umbrella.  Perhaps plan to hold the picnic nearby an accessible shelter, to make escaping from the rain easier.

In the second view, we look at the weather not as something that is the harbinger of something that can go wrong, but simply something uncertain.  So there's a 50% chance of rain.  Let's prepare for that eventuality.  But there's also a 50% chance of no rain. Let's also prepare for that happy eventuality as well -- perhaps plan to go to a place with a nicer view if the weather clears up.

With this second view, risk is not simply viewed as about bad circumstances that can happe, but simply about all uncertain circumstances. Circumstances which can indeed turn out bad (and whose effects we should be ready to address), but which can also turn out good (which we should be ready to take advantage of).

In the first view, we simply prepared ourselves for the worst.  But in the second view, we also prepared ourselves for the best.

Assumptions

Until we develop the ability to see the future, projects and programmes will have to be run in the face of uncertainty.

In the absence of complete information, assumptions will have to be made. Otherwise decisions cannot be made and activities will stall. At least some of these assumptions are documented in the projects. In the more badly run projects, the assumptions are there uncritically reviewed. Because a project is proceeding as if these assumptions are valid, it is critically important to review the assumptions.

You are trying to cross a bridge and making the assumption that the floor is sound. You have several choices: make the assumption, and proceed to walk normally as if the assumption is correct. You can also make the assumption, keeping in mind that you could be wrong, and proceed with caution, testing every step to see if the assumption holds. You can also, before, proceeding, inspect the bridge, and gather more information about the assumption. How likely is the assumption to be correct? How likely is it wrong? Apart from
physical inspection you can observe the environment. Are locals crossing the bridge? Are there local experts who know if the bridge is sound?

Because the assumptions are the 'floor' on which the programme will be proceeding, it is critical to review these assumptions to see how sound they are. These assumptions should be looked at with the following filters:

  • Are they complete? Are these the only critical assumptions?
  • Are they valid? Are we making assumptions about things that are not already known to be false?
  • Do we have a plan for reviewing the assumptions at a later date, when we may have more information and able to verify or reject the assumptions.
  • Have we identified the risks that will arise if the assumptions on which we are proceeding are proven false?

Ten Rules of Effective Language

One of the challenges risk professionals wrestle with is how to convince stakeholders to take specific actions,  such as proactively identifying risks. These stakeholders can be individuals, or they can be organisations.  While these stakeholders are not necessarily reluctant to comply with the requirements of proper risk management, they do have to deal with their own realities, including other demands on their energy,  or simply a perception that risk management is a waste of time.

Perception is reality, as the saying goes.  If you want to change reality, you have to change perception.  And one way to change perception is through communication.  A risk professional often needs to organisational action through reports and recommendations and also through interpersonal communication.

Dr. Frank Luntz, who apparently is a highly sought political speech writer, provides ten rules for effective language in his book, “Words that Work”.   I think when he came up with these rules, he was thinking in the in the context of public speeches, political messages,  and media relations.  But his rules seem a useful guide for a launching  a coordinated approach to getting your message across. 

In summary his rules are:

  1. Use Small Words.  Use only words that you are certain your audience understands.  Don’t risk getting your message misunderstood. 
  2. Use Short Sentences. If you can deliver the same message using a dozen words, do not do so with a thousand.  Not only are fewer words easier to remember, you stand a better chance at having your writing  read.
  3. Credibility is as Important as Philosophy. Make sure you are telling the truth.  Very catchy marketing of something false will fool some people for a little while, but not for long, and not again. 
  4. Consistency Matters. This is a nice way of saying: repeat the message over and over, using the same words if possible.  Drill the message in. Repeat until it becomes the truth.  And don’t change your message. Don’t change what you are trying to say.
  5. Novelty: Offer Something New. Add a new twist on the language or coin a new phrase that capture the message vividly and clearly and memorably.  Definitely avoid clichés. Avoid it like the plague ;-).
  6. Sound and Texture Matter. A slogan that makes sound (like ‘Snap, Crackle, Pop!’) helps make the slogan memorable.  Alternatively, come up with combinations of words that make a distinctive sound (‘Melts in your mouth…’)
  7. Speak Aspirationally. Show the way to an ideal place. He gives the example of Crest toothpaste’s “Look ma, no cavities”. Tap into the audience’s aspirations and ideals.
  8. Visualize.  Paint a picture with your words.
  9. Ask a Question. Engage the listener by asking a relevant and memorable question.  Note that it is a single question, not several.
  10. Provide Context and Explain Relevance. Make it very clear ‘why’ you are telling them what you are going to tell them. Give context to your message.

Luntz summarises these ten rules with ten words: simplicity, brevity, credibility, consistency, novelty, sound, aspiration, visualisation, questioning, and context.

You don’t have to follow all his rules for every message you want to get across.  I don’t think that’s possible, nor is it Luntz’s intention.  However, the list is useful as a guide for formulating a memorable message.

ERM is an Integrative Approach to Risk Management

Risk management as traditionally practiced in organisations tended to be silo-based.  Risks originating from one area is expected to be managed in that area which is assigned the responsibility for managing, while risk originating from another area is managed by that area.  

One of the reason Chapman gives to why this approach developed is our tendency to compartmentalise. Our analytical mindset approach to problem solving lead us to split things apart into their basic components to make them easier to manage.  

Over the years, there had been a growing recognition that a silo-based approach is flawed.  The impact of risks span across silos - a breakdown in manufacturing leads to impacts well beyond the manufacturing department.  Mismanagement of risk in one silo affects other silos, which may not be prepared for that risk because they had assumed that other area was managing that risk.  

ERM is a new approach to managing risk.  The thrust is of ERM is the integrative management of risks, understanding the interedependencies, their impacts, and areas where they can be leveraged so that addressing a single cause can prevent multiple risks.

Reference: Chapman, Robert. Simple Tools and Techniques for Enterprise Risk Management 2006.

Tools and Techniques of Enterprise Risk Management, Part 1

I’m going to go through Robert Chapman’s ERM book.  Based on the table of contents, the first part of the book what ERM is. Part II is about ‘The Appointment’ or what I think is a discussion of the engagement process.  The table of contents covers topics about interviewing the client, preparing the proposal, and implementation (of what, I am not sure yet).

Part II covers the Risk Management Process.  It seems to be about a fairly standard process: Analysis of the Business, Risk Identification, Risk Assessment, Risk Planning, and Risk Management.

Part IV covers ‘Internal Influences’ which I think is about internally generated risks.  The table of contents says it covers Financial Risk Management, Operational Risk Management, and Technological Risk.

The final part covers ‘External Influences’ which seems like about risks generated externally.  It discusses Economic, Environmental, Legal, Political, Market, and Social risks.

Finally there are 14 short Appendixes which discuss techniques like SWOT, PEST, VRIO analysis, Change Management, among other topics.

Corporate Social Responsibility as Risk Management: A Model for Multinationals

Kytle & Ruggie

Ideas:

Globalization

Large Enterprises

CSR – what you do with your money

How you make your money

Conceptual Framework

Greater interdependencies

Hidden vulnerabilities

Significant shift in market power

Social risk

Own behaviour or actions of others create vulnerabilities

CSR Programs

Global operating environment: networked operations, empowered global stakeholders, dynamic tension between stakeholders

Supply chain components bring their own individual vulnerabilities. Risk in one can ripple through supply chain

Being large being global makes you a platform for stakeholders

Other country issues – weak regulatory frameworks, means of enforecement, high levels of corruption inadequate provision of local service.

Social issues stakeholder interests are not profit motivated\

A Framework for Risk Management

Froot, Scharfstein, and Stein

The purpose of risk management for an organisation is to ensure availability of funds for financing investments.  Risk management does not create new wealth; investment does. Wealth-creating investment is only possible if there are funds available to finance it. Risk management must be used to ensure the organisation has enough funds to finance its wealth-creating investments should events arise that threaten the availability of funds.

The best funds to use for funding investments are funds created internally.  Funds obtained through debt make the company less attractive for further debt, which may result in a dangerous spiral where it cannot obtain debts when it needs them.  Funds raised from equity raise the problem of investors knowing that organisations sell equity when they know it is overpriced.  So despite Modigliani and Miller, who posited that how the funds are obtained is generally irrelevant, internally generated cash is best for funding further investments.

Hedging is one way to insulate the organisation from fluctuations of funds availability.

To determine what to hedge, think about events you wish to hedge against, and understand the impact of that event to your cashflow requirements for funding wealth-creating investments.  For example, if your company manufactures in Europe (Euro) and sells in the USA. Suppose the Euro appreciates thus making sales in the USA slower. Then cashflow is lessened because a) there is less product demand in the USA and b) the value of dollar sales has decreased comapred to Euro, therefore, there is little incentive to further increase production capacity in Europe, therefore there is lessened need for cashflow during the time.  Thus there is little need to hedge.

However, if opposite occurs, and the Euro depreciates, then sales to the US can be expected to increase (cheaper products), however,

Risk management “lets companies borrow from themselves” by shifting funds to when they are more needed.

The goal is to align the internal supply of funds with the demand for funds. The goal is not to insure against the events (such as exchange rate fluctuations) but to ensure the company has the cash it needs during such times.

The company shouldn’t need to worry much about its own stock prices.  That is a problem for individual investors. They can mitigate that risk through diversification.

Choices of which financial instrument to use must not be left to financial engineers. Managers must align the instrument to the corporate goal – which is to ensure availability of cash appropriate to the environment it is hedging against.

Two key issues in derivative features is mark-to-market vs over the counter. In the former, you need to top up daily to compensate for short term losses. In the latter you only need to pay at maturity date.  The other feature is linearity vs non-linearity. Futures and forward contracts may have no floor. There is symmetry in your gain or loss. Options allows setting a floor to loss, while keeping the option to benefit from the event.