Managing risk through process

By Peter Franz, Founder of bpmd

Managing risk through process

Business risks and the controls used to manage these can be challenging to articulate to employees. Companies often lack a centralised, consistent way to document business risk. Those that do record it, often do so differently across functions and departments, leaving them without a common, organisation-wide view. In an ideal risk management framework, a company would document risk in a way that gives a cross-company view of all risks. It would also be available in a digestible format that is accessible to employees as they carry out the relevant tasks. A robust BPM practice is a powerful mechanism for managing risks across an organisation. Well-documented processes give employees a single point of truth that they can visit to understand how the organisation functions and what their responsibilities are. A process explains not only tasks (i.e. what must be done and the order it must be done in), but also who the stakeholders are, what systems are used, and the flow of data.

Identifying risks and controls

This understanding of the business can enable the capture of risks across its processes – by understanding what is done, you can pre-emptively identify potential risks and assign controls to these.

Further, by visualising your risks across your processes you can begin to identify those risks which are uncontrolled – i.e. they have no (or insufficient) mitigating actions assigned to them. This helps organisations focus their risk management efforts on those areas which most critically need attention. On most good BPM platforms, this is supported by reporting features which extract risk reports and show areas of concern.

You can therefore extract cross-functional risk reports and quickly analyse which areas of your organisation manage risk well and which areas are lagging behind.

Assigning controls – static or process-dependant

There are two options when assigning control to risks. The traditional way is to have controls assigned to risks in a “static” manner. This means that the same controls are assigned to a risk, regardless of the process or parties involved. This works well initially but when scaled up can cause a proliferation of risk records, with unique risks created for every occurrence of a potential risk. Ultimately this causes an extensive, over-long risk register which can be effort intensive to maintain.

The benefit of managing risks through a BPM lens comes when the same risks occurs in multiple processes/functions. With a BPM-centric risk management approach you can assign different controls to the same risk dependent on the process (or even the task) in which it occurs. For example, the risk “Inaccurate Customer Data Recorded” could occur in numerous processes, but the controls assigned would depend on the specific process – if it occurred in a marketing process, the control may be focused on CRM data cleansing, whereas if it occurred in the sales cycle then the control may be focused on matching customer information across different documents (Purchase Order, Invoice, Delivery Note, etc). This means that a rationalised risk register can be maintained, with the most relevant controls applied dependent on the process in which a risk occurs.

Getting visibility of risks

Risk information should be highlighted on business process models. By describing a risk and control in a process model, you are increasing its visibility to the organisation and therefore helping to mitigate its potential negative impact. If people refer to process models to understand how to do their jobs, storing risk information here ensures that managing risk becomes an inherent part of their day-to-day practices.

Digitising the process data also makes it far easier to produce risk management reports and support audits. This is crucial both to manage risk within the company and to satisfy regulatory requirements.

Reusing information and reducing effort

Documenting risks and their associated controls represents a significant effort in investment. By using a centralised BPM repository as your source for risk information, you enable reuse of risk and control information across similar functions/processes. This also introduces new risk concepts to functions/teams which might have not previously considered them and helps develop a better understanding across the organisation.

Maintaining process and risk information

Good process models are regularly updated to ensure the information stored reflects current practices; if this is not done, then you run the risk of “process drift” where the directions do not match business needs. If risks are stored alongside processes, this ensures that they will be reviewed regularly too and kept current. This stops one of the biggest dangers in BPM: process drift. Updating process and risk information is important to ensure that the BPM repository always reflects reality.

Automation and data analysis

Digitising risk in a process repository introduces automation opportunities. There are a multitude of GRC software available which allow you to manage and record control actions. By maintaining risk information in a process repository, you create a structure which enables these GRC tools to use consistent, comprehensive information and therefore provide sustainable value.

By storing information in a BPM-tool, you can leverage other workflow/project management tools. You could, for example, integrate your process repository to push risk information to a tool like JIRA, where you could then manage control tasks.

Process can function as the medium for combining data from your source systems with risk information to monitor performance, with both the risk records and data assigned to a common process. Tools like process mining extract data from your source systems and use this to paint a picture of how your processes are actually performing. By using this data, you can identify in near-real-time whether risks are being effectively managed and when there are instances of potential non-compliance arising.

When should companies manage risk through process?

There’s never a wrong time to improve a company’s documentation of risk and its relation to business processes. The more intelligence an organisation has on risk management, the better prepared it will be. Nevertheless, there are some critical events that demand a tighter, more mature approach to risk management through process.

One of these is when there are changes to the regulatory landscape. If a company’s sector is likely to come under more scrutiny based on messaging from the regulator, then documenting processes and their associated risks will help it to prepare ahead. Similarly, any forthcoming changes to regulations represent a good opportunity to level up risk management through BPM.

Process-based risk management can also prove effective when revising or changing strategic direction. This will often spark a flurry of process activity and a series of new risks. A formal modelling and documentation process creates a strong platform for transformation while helping management to articulate the associated risks.

The business environment is more volatile than ever, with external events calling for greater flexibility and agility as companies prepare to mitigate risk. Using process management as a discipline to support risk management is a clear path to a competitive advantage.

Share the Post: