ISO 31000:2009 The Effect of Uncertainty on Objectives

For several weeks, I had been consumed with trying to understand what the new definition of risk really means.

As anyone involved in risk management knows, the ISO late last year published the new Risk Management Standard known as ISO/IEC 31000:2009.  One of the innovations in this standard is a new definition of risk -- a rather oddly phrased definition, in my view. The new definition says that risk is "the effect of uncertainty on objectives."

Clear as mud?  Compare that with the previous definition used by a de facto worldwide standard.  AS/NZS 4360:2004 defined risk as "the chance of something happening that will have an impact on objectives."  Here it’s clear that risk is clearly tied to "something happening".  Risk is an event or a circumstance (together with its chance of happening).

In the new ISO definition, risk is the "effect of uncertainty".  This is quite unfortunate because “uncertainty” is not about how things will happen, but is more about our state of knowledge.  Our lack of knowledge about how things will turn out.  Events will happen, we just don't know which and when.  Uncertainty is our ignorance.   Even ISO is aware of this, and notes that uncertainty is "the  state, even partial, of deficiency of information related to understanding or knowledge of an event, its consequence or likelihood."

If I replace this meaning of uncertainty in the definition of risk, we come up with:

  • Risk = the effect of ignorance on objectives.

Clear as Florida swamp water.

But what about "effect"? What does this word mean? Well ISO 31000 defines effect as "a deviation from the expected -- positive or negative". So if we use that definition, and
insert it into the definition of risk, we get:

  • Risk = the deviation from the expected, due to our ignorance, on objectives.

Which is now really realy murky.

An inadvertent clarifying light came last night while I was re-reading Elaine Hall's "Managing Risk: Methods for Software Systems Development".  Hall notes that risk is “potential loss.” Since potential means possible, which can be another definition of “uncertain” (not certain = possible = uncertain), and since I know the ISO 31000 wants to incorporate "positive risks" into the new definition of risk, then maybe ISO is trying to say that risk is "loss or gain on our objectives due to events which may occur".

If we rephrase it this way, then it becomes clearer that risk is the loss or the gain  (rather than the event).

This is a conceptual shift from the previous definition used in 4360:2004 in which risk is the event and its likelihood ("the chance of something happening")

Let's apply these new definitions to an example risk. Suppose we have to deliver a product by March 30, 2010, and if we fail to deliver it, our client loses $30,000 per day.

Then by 4360:2004's definition that the risk is the event that has an impact on objectives, we have the risk as "risk that product will be delivered late."  And the impact / consequence will be that the client stands to lose $30,000 per day.

And by 31000:2009's definition where the risk is the effect of the event, we have the risk as "risk of losing $30,000 per day" and the consequence is whatever the impact of that impact.  What about the event of failing to deliver on time?  Then that is a cause of the risk.

Both standards recommend qualification (or if applicable, quantification) of the likelihood of the event, so we should apply some description of likelihood to the risk. Let's say the likelihood of meeting the deadline has been assessed at 90%. So our risks are:

  • Risk as per 4360: 10% chance that the product will be delivered late.
  • Risk as per 31000: 10% chance that the client will lose $30,000 per day.

The definition of risk as per 31000 is consistent with their note: "Note 4: Risk is often expressed in terms of a combination of the consequences of an event (including changes in circumstances) and the associated likelihood (2.21) of occurrence."

I think I have finally nailed to my satisfaction what the drafters of ISO 31000 mean when
they say risk is "the effect of uncertainty on objectives". I still do not like their definition, and I think it is muddled (primarily because of the desire to incorporate positive risks), but I have a workable meaning now, which I can use for further work.

Example of a Decision Tree

A simple example of using a decision tree to help us with decision-making.

A couple renting an apartment and is wondering whether they should sign a 1-year contract on the rent.  If they sign a contract, their rent is guaranteed not to increase during the 1-year period. If they don’t sign a contract, their rent will increase by about $20 after 6 months.

This seems like a simple decision.  But there is a drawback to signing the contract. If the couple decides to terminate the contract before the end of 1 year, they are liable to pay up to 25 weeks worth of rent to the landlord, unless the landlord is able to get someone else to rent the place earlier. 

The couple intends to buy their own home if the right opportunity comes, so there is a chance that they would need to terminate any contract they sign.

Supposing the initial rent is $900 per month, what is the couple’s best option?

Let us choose the simplest situation first.  Let’s assume there is zero chance that the couple will terminate the contract.  So the decision tree looks like this:

DecisionTree01

The tree says that the option to sign a lease contract will result in a total 1-year rent of $10,800 ($900 * 12 months), while not signing a lease contract will result in a total 1-year rent of $11,800 ($900 * 6 months + $900 * 1.2 * 6 months).

But what happens if the couple finds their dream house and moves out of the house after 8 months?

The Essence of Risk Management

All of man’s activities is fraught with uncertainty and risk.  When he undertakes something, he faces uncertainty and risk and loss.  Even when he does not undertake anything new, but simply goes on with life as normal, he still faces uncertainty and risk and loss.

Therein lies the essence of risk management, to which man runs to, to seek an answer to his question: in the face of this uncertainty, what should we do?

Operations Risk

Every company faces risks as it goes about its day-to-day operations.  A bank branch could find itself in the midst of a robbery.  A fastfood restaurant could suddenly have a cook badly burned by an overturned pot filled with boiling water.  A shipping company may have one of its ships boarded by pirates.  A veterinary clinic may have one of its staff or customers bitten by a dog. A data centre may find the building it is located in collapsing due to an earthquake. These risks are called ‘Operations Risk’, or alternatively ‘Operational Risk’. 

The types of operations risk a company faces depends heavily on its line of business, although the nature of risk is that it is often unexpected: the bank could suddenly discover that the pirates who boarded the ship in the above example are actually the bank’s customers.  The shipping company may find its cook burned badly while preparing food.

Operations risk is different from the other types of risks that companies face.  It is not credit risk, which is the risk related to debtors not paying the company.  It is not strategic risk.  It is not market risk.  It is not reputation risk.  Nevertheless, risks arising from operations can cascade into these types of risks.  The revelation that a pirate has been hoarding its loot in your bank can rapidly discredit the bank (reputation risk). 

Concatenation of Risk

Currently reading J. Davidson Frame’s “Managing Risk in Organizations”.  Great example of a seemingly insignificant event cascading into a major headache.  The printing press experiences a fire and will not be able to deliver brochures expected to be that were supposed to come today.  These brochures are needed for a client’s conference in two weeks time. All the arranged plans to sort, label, and send them out have to be replanned.

Seeing Tomorrow, III

Continuing book review of Dembo & Freeman’s “Seeing Tomorrow: Rewriting the Rules of Risk”

In chapter 2, the authors introduce four elements they consider to be core to any forward-looking approach to risk management:

  • Time horizon
  • Scenarios
  • Risk measure
  • Benchmarks

Time horizon refers to the future period that we are interested in.  It is a distinct period (with a distinct begin and end, as opposed to simply ‘the future’).  An investor who wants to assess the risks involved in an investment needs to think about the timeframe of his investment.  This timeframe (or time horizon)  is very different for someone who wants to cash in in two years than for someone who plans to cash in 15 years into the future.

Of the four elements, the authors give the longest treatment to scenarios.  A scenario is a projection of what could possibly happen in the future.  The purpose of creating scenarios is to help us plan for that event if it occurs. 

The key here, the authors say, is not merely generating a scenario but several scenarios.  These set of scenarios will help us gain a clearer understanding of the range of dangers (and opportunities) we might face. 

If a scenario eventuates, and we had anticipated that scenario, and made plans for it, then we are in a better position to react and perhaps exploit the new situation.  We will be better placed, relative to our competitors and relative to where would be had we not planned for it.

The third element of risk management is deciding on a risk measure. This is about deciding we measure riskiness.  Apparently this is very tricky, since choosing a measure like Value at Risk (VaR) could protentially produce similar values to very different risk situations, effectively obscuring the reality that they are very different propositions.

The final element is Benchmark, or having something to compare with.  Choosing the appropriate benchmark is key to understanding how well we are managing our risks.  Do we choose to benchmark our investment performance relative to Warren Buffet’s or the DOW index or something else?

After the discussion on the four elements, the authors also touch on Risk-Adjusted Valuation.  This is the ‘real’ pricetag of something and is almost always ignored.  For example, suppose you buy an expensive ring for $20,000.  Now, you would want to insure something that valuable since you cannot afford to self-insure it (absorb the loss if it gets lost).  So let’s say you pay $100 per year to insure that ring.  That total amount (comprised of the original amount of the ring, plus its ongoing insurance) is the Risk-Adjusted Value of that ring.  The authors want the reader to begin thinking always about the Risk-Adjust Value of everything.

The chapter ends by tying up all the four elements in a short example using a model called Marking-to-Future, a model developed by one of the authors.

Seeing Tomorrow, II

Book review of Dembo & Freeman’s “Seeing Tomorrow: Rewriting the Rules of Risk”

In chapter 1, the authors give more details about the Soros/Reichmann deal gone wrong which they hinted at in the introduction.   It seems the reason for the deal was that Reichmann camp considered only one possible risk event (that would be a windfall for them), got fixated on that and wouldn’t budge in the negotiations.  They (inadvertently?) preferred to risk losing the whole deal rather than giving up a small portion of the profit.

Demob & Freeman writes that the way to think about risk not to consider one possible event, but to look at several different possible outcomes, explore how each event will make use react .

The chapter then very lightly mentions considerations about risk. That we all have different views of risk, that what is attractive to one is repellent to another, that risks have positive and negative aspects, that doing nothing can be risky as well. 

The one interesting notion I hadn’t come across before stood out briefly: “an acceptable risk one day might appear a foolish gamble on the next day.”  But after further reflection, this is very common in hindsight, when events that we weren’t able to consider during decision time unfold.

The second half of the chapter consist of continuing remarks about flawed and outdated approaches to risk management, examples of failures in managing risk: Orange County, the very biggest banks, etc.   They also picked up on Peter Bernstein’s notion on whether modern man has replaced his earlier superstitions of the fates and the gods with new superstitions about the magic of statistics and quantifications of risk.

The topic then shifts to the idea of sharing the risk, with a story about a group of women involved in charity, who without realising it, bought futures contracts on grains. 

They reveal a little more about their soon-to-be-explained  framework, by noting that risk sharing (distributing the risk) is an important concept of the framework.

The last few paragraphs of the chapter – oddly - begin sounding like a marketing brochure on reinsurance. Words like catastrophe reinsurance, catastrophe insurance bonds, pure risk, packaging of business risk and so on are spoken about (with a bit of a hint of glee?)  Some of the final paragraphs in this chapter may be more opaque  for readers not yet familiar with insurance terms as they are used without definition.

A review of chapter 2 will come next.