What are “emerging risks”?

A commonly cited “emerging risk” is “climate change”, with risk functions advocating that the firm create policies around minimising the firm’s footprint on climate-sensitive areas, establish climate risk assessment processes, implement climate risk-specific control mechanisms and include climate risk metrics in a variety of risk reports. Yes, the ongoing environmental damage and disruption that is fuelling climate change is critical and needs to be addressed, but is this an “emerging” risk?

As far back as January 2016, The Risk Universe, an operational/non-financial risk publication, included “climate change” amongst its top ten business concerns for the year ahead – that is, a decade ago, ten years ago. How long should an identified issue remain an “emerging” risk?

Similarly, cash-related crimes were major concerns pre the widespread adoption of electronic cash transfers and payment methods. Specific crimes that concerned banks were forged bank notes, forged cheques/checks presented for payment, robberies and misuse of another’s identity so as to access and drain funds from an account.

But the magnitude of these risks faded over time as more and more people moved to online payments, card payments, phone payments and electronic wire transfers, coupled with the large-scale closure of retail banking branches by most major banks globally. But, if we suddenly see in the mainstream press or social media that “payment fraud” is on the increase, that there has been a significant uptick in forgery, should we consider this an emerging risk?

Or is it simply the reoccurrence of known and existing risks which we have not experienced for some time, irrespective of whether it is using slightly different techniques for the same end consequences?

At a recent workshop involving some 19 internationally active firms and facilitated by RiskBusiness, a standard definition for emerging risks was agreed – a risk never seen before, but which has actually manifested itself somewhere in the world. Three key criteria here – something new, something which has happened and something which has affected some firm, not necessarily in the same industry as that of your own firm, but which could be relevant for your firm.

This definition of emerging risks would automatically exclude “climate risk”, “geopolitical risk”, “AI risk”, etc, as none of these are new. Similarly, it would exclude what-if scenarios, as these may not have manifested themselves anywhere, but would include events affecting other industry sectors (for example, oil and energy, aviation, manufacturing, etc.) which have experienced such events.

Gaining an awareness of such emerging risks at the earliest opportunity is a crucial component of any firm’s defensive risk management activities – firstly, it allows relevant functions and individuals within the firm to be made aware of the emerging threat so that they can include the threat in their risk management activities.

But secondly, and at least equally as important, is that it allows the firm to consider its controls, safeguards and operating procedures to assess potential gaps or improvement opportunities so as to safeguard against any such threat manifestation.

While being aware of and assessing the firm’s exposure to emerging risks is a critical managerial function, the inevitable question is likely to arise once the risk has been quantified, namely, what do other firms think about this emerging risk? Are our estimates appropriate, over-inflated or inadequate? Should we allocate budget for remedial action, or do we take a chance that the risk never materialises for us?

Without comparative industry or peer data against which our assessments and remedial spend can be compared, management will never know, and potentially, just maybe, the firm will be ill-prepared should the emerging risk actually manifest itself.

Stay up to date with the latest stories from the world of governance, risk, audit and compliance >>>

Facebook
Twitter
LinkedIn