Friday, November 5, 2010

Risk Smile


by Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

I bet when you clicked on this link you thought there would be something about volatility smiles.  Probably not for a couple of weeks though (that is when I discuss that topic with my MBA Derivatives class).  Nope, this blog is about smiling.  That is the thing that you do when you are happy and cheerful.

In this blog I would like to ask you if your risk department, or your risk consultants make you smile.  Do they?  If you are a risk manager, or a risk consultant, do you make other people in the organization smile?  That is, while you are doing your job.

I think that risk managers should be making people smile.  Risk management is about getting things done in a prudent manner.  Risk management is about creating peace of mind.  Risk management is about creating opportunities.  Risk management is about increasing the probability and magnitude of good risk events happening (while decreasing the probability and severity of bad risk events happening).  All of these are good things.  Good things make people smile.  (….with apologies to Martha Stewart).

Wednesday, November 3, 2010

Fighter Jets and Chaos


by Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

I was doing a bit of studying lately on Chaos, which is a field of science that has interested me since I was in high school.  As a field of study it is really quite neat, but not as practical as complexity.  The issue is that it is harder to get academic papers published in complexity and thus the scientific establishment pushes forward with chaos.

One of the things I learned earlier this week in my readings was that fighter jets are designed to be chaotic.  That is they are specifically designed to be unstable.  While this might be an undesirable trait in a commercial airliner, it is very attractive for fighter planes.  The instability – chaos – allows the plane to be much more maneuverable in crisis situations.  The instability actually serves a useful and valuable purpose.

This led me to consider the use of risk systems by most firms.  The goal in risk management – to my chagrin – has been to create ever more inflexible risk systems and frameworks.  The thinking goes that building a rock solid stable risk framework leads to a rock solid firm.  However I think a lesson can be taken from the design of fighter jets.  Perhaps a rock solid risk system is putting too much rigidity into the firm’s culture and thus when a crisis does occur the firm does not have the degrees of freedom necessary to take effective action.  The inertia of the firm’s risk system does not protect, but actually makes the firm more vulnerable. 

Perhaps it is time to add more chaos to get less chaos.  After all, isn’t business just like war?

Monday, October 18, 2010

Rethinking Risk


by Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Seems like I’ve been on airplanes a lot lately.  That means reading too many magazines and other mindless drivel while waiting to get into the air.  (It is impossible to read anything of seriousness while everyone tries to carry their “piece of luggage plus briefcase” down the aisle.  They never fail to bang the arms of every passenger who has boarded before them.  As an air-warrior I get to board first with the other air-warriors, and I do so solely so I can get my own “piece of luggage plus briefcase” into the overhead bin.)

In any case I have been reading a lot of magazines lately which means that I have been reading a lot of print advertising.  This in turn means that I have been reading a lot of words about rethinking this or rethinking that.  Rethinking the car!  Rethinking the TV!  Rethinking the bar of soap – or whatever.

Reading the business press we also have a lot of articles about rethinking ethics, rethinking capitalism, rethinking banking rules, rethinking risk, rethinking business.

What if we simply stop rethinking, and instead start thinking?

Wednesday, October 13, 2010

Humans Are Special


by Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Read an article on Jarion Lanier recently – one of the fathers of virtual reality amongst other things.  Certainly not a Luddite when it comes to computers and such.

A quote that he made caught my attention. 

“Human’s are special, they’re not computers.”

Hmmmm.  Profound or obvious? 

Now, is your company run by computers or humans?  (Would you prefer that it was run by computers or humans?)  Is the world run by computers or humans?  (Would you like it to be run by computers or humans?)

Is your risk management run by computers or humans?  (Would you like it to be run by computers or humans?)

Thursday, October 7, 2010

5 Minute Risk Audit


by Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Met with a senior risk manager last week for breakfast.  They have a very hectic job.  Lots of reports and analysis to do for the quarterly report for senior management and then an annual report for the Board.  Lots and lots of reports and analysis.  Templates to fill in, data to collect, charts to be drawn, results to be collated, definitions to be defined and disseminated etc. etc. etc..  24/7 job.

What if things change?  What if a paradigm changing event happens whereby management and / or the Board needs a risk status now?  Can your firm do a 5 minute risk audit?  Will your firm know where it stands on a real-time basis, or do you need to wait to see the quarterly report (or perhaps even the annual report)?  What is in the 5 minute report?  Will your 5 minute risk audit be up to the task?

Monday, October 4, 2010

Rejigging COSO (Vicente Series Part 6)


by Rick Nason, PhD, CFA
RSD Solutions Inc.

I have never been a huge fan of the COSO framework (or any framework for that matter – see my presentation Get Creative or Take the Risk, which was presented at the 2008 Treasury Management Association of Canada’s annual conference  http://www.rsdsolutions.com/rick-nason039s-presentation-slides-tmac-annual-conference-2008 ).  Despite that, the COSO framework is still the basis for most Enterprise Risk Management systems. 

Admittedly, the COSO framework is one of the best frameworks out there, and it certainly is comprehensive.  (That tends to happen when a system is designed by a committee of consultants who do not have to worry too much about implementation.)

We are all familiar with the three-sided COSO cube.  One side of the cube of course has the delineations of; 1. Entity Level, 2. Division, 3. Business Unit and 4. Subsidiary, for which each of the functions of risk management are to be examined and implemented.

In the Human Factor, author Vicente offers up what he calls the “Human-Tech Ladder”, which are the ways that humans interface with technology.   Vicente’s steps are; 1. Physical, 2. Psychological, 3. Team, 4. Organizational, and 5. Political.  I propose that these are much better delineations for consideration for the COSO framework than the ones presented in the previous paragraph.

A risk system should be usable (Physical), deal with the individual (Psychological), deal with group interactions (Team), and organizational factors (Organizational), and as well incorporate factors from the broader aspects of the marketplace and society (Political). 

For most organizations this is a much more effective conceptual framework of risk units, and much more implementable.  Perhaps it is time to form another working committee.

Friday, October 1, 2010

Low Tech or High Tech (Vicente Series Part 5)


by Rick Nason, PhD, CFA
RSD Solutions Inc.

We all have seen high tech risk management systems (and processes).  Every risk conference has software vendors all putting forth the latest and greatest in terms of systems that will put your firm in complete control.  These systems are truly impressive in terms of their scope and their attention to the state of the art in risk management.

We also know firms that manage their risks through “low-tech”.  Very simple systems that are perhaps captured solely on a sheet of paper, perhaps in an Excel template, or in the simplest cases perhaps in a senior executive's head (and with significant gut-feel).

Many firms have a hybrid form of risk management system.  They have a high-tech system, but rely on the low-tech decisions of senior managers.

As Vicente puts forth in his book, perhaps it is time that we spent more time thinking about Human Tech risk management systems.  That is, risk management systems and processes that use the best of technology and techniques, but also engage the people who have to implement them, and make decisions based on their output.  These are the types of risk management systems that are not only practical, but also efficient and effective.

Which type of risk management system does your firm use?  Which type of risk management system should it use?  How many people in your organization have considered that question?