Yahsat, the leading global satellite communications solutions provider from Abu Dhabi (a Mubadala company) has been revising its risk management approach. From a rather traditional approach to a more customised approached for a SME sized company.
Every approach comes with their own unique opportunities and challenges, strategies and process
People talk about having an organisational culture that recognises risks, and where risk management is embedded throughout the layers of the company.
But what does that actually mean?
A strong ‘Risk Culture’ has often been identified as a pre-requisite for improving risk management in resilient organisations. ‘Risk culture’ denotes: “The norms of behavior for individuals and groups within an organisation that determine the collective ability to identify, understand, openly discuss, and act on the organisation’s current and future risks”
It is a way of thinking and embedded within the organisation’s DNA through core values, patterns of behaviour, involvement, empowerment, transparency and tone at the top. Risk culture is a key component of integrated risk management focusing on the behavior of individuals with respect to risk. Embed & simplify risk management practices to be into normal business operations, planning and budgeting processes, and organizational culture. It is no longer an add-on or a management fad.
ESG initatives have never been more important for organisations. Research has shown a direct relation between both financial and reputational performances to that of organisations ESG practices. Investors, suppliers, external stakeholders and employees, all have started to pay close attention to organisation’s ESG practices as indicators of future performance and safety.
Cyber risks
Amongst all risks to watch out for in this year, cyber crime and risks come out on top. With technology advancing, cyber crime and activities advance at the same pace, sometimes faster. Risk and IT leaders need to have the right infrastructure, know-how, trainings and incident response plans at all times to ensure their organisation can refrain themselves from a cyber attack which can damage reputation, cost millions of dollars and create legal issues.
Cyber attacks take place every day, for different purposes. As attacks grow in intensity, there has been a resurgence in SOCs because of their role indetecting and neutralising threats. According to a recent report by Gartner, by 2022, 50% of SOCs will integrate with threat intelligence and incident response tools, putting risk leaders in a better position to protect their valuable data.
Executives and boards of directors have one of the most demanding jobs today. Each board committee face its own challenge, with the audit committee facing its own rising challenges. Corporate failures and scandals across countries and industries have raised concerns and debates on the audit and governance function, exposing serious governance and audit failures.
Audit committees, the board and the management all have a collective responsibility for the integrity and accuracy of an organisation’s reporting.
With the increased uncertainty in geopolitical, business and regulatory environments, audit committees today have their hands full.
A classic topic of discussion is the ever evolving relationship within an organisation’s internal audit and risk management departments and practices.
Key risk indicators (KRI`s) are vital predictors of unwanted events which can impact organisations in a negative way.
Understanding the power of the key risk indicators, how to define and develop them leads to the increase of the organisation’s risk appetite.
Key question – Do you know key indicators combined with risk appetite can contribute to make better decisions?
As organisations continue to navigate rapidly changing business environments, regulatory requirements, technology disruptions, and more, the need for IA to be agile and help organisations respond to risks is ever-increasing. To provide the greatest value, IA must find opportunities to add value and make improvements in organisations’ controls, risk management and governance while aligning itself with the organisational strategies and goals.