Using Controls to Manage Risk

The concept of using control processes to manage risk is really common, sort of intuitive.   You will remember from childhood how you were schooled in checking in both directions before crossing the street (well most of us do).

This is a control process.  For the expenditure of a little effort, that is moving your neck to the left and then to the right (or vice-versa) you reduce the risk of being hit by a car.

Over the years, I have found there is a tendency to put more rigid  controls in place (more costly, more effort) than needed for the same resulting reduction in risk.

For example consider three houses in a row.  The first house has no specific burglar protection (relying on neighborhood watch), the second home has a dog and the third a fully monitored alarm.   The control practice (alarm, dog, rely on neighborhood watch) is designed to increase the likelihood of detection/reaction to a robbery and thus will decrease the likelihood of being robbed or the losses if a robbery occurs.  The cost rises with each control improvement.

Consider the burglar, it is kind of intuitive (all other things being equal) he/she is probably going to go after the house with no dog or alarm.  In this example (assuming a dog is cheaper than a fully monitored alarm) the middle house is getting the best risk reduction for the lowest cost – the best value.

What Level of Control is Appropriate?

Control assessment starts with risk assessment.  What is the likelihood and the impact if the risk occurs?  Intuitively it’s fairly obvious it’s probably a reasonable business decision for less likely low impact risks to be mitigated with less rigorous controls  (i.e, lower cost/effort )

How about an example?

Say your organization has a public web site and 10 people can access and change the content and publish the changes immediately.  The content is informational and while it impacts the organizations reputation there is no pricing, products for sale or legal agreements.  A person working for the organization is unlikely to post negative content and when they leave a good control is to make sure their access is removed immediately.

Now consider the content has financial implications or products/services are sold on-line, in this case the impact of a mistake or malicious manipulation of the content is greater and it might make sense to have a control such that no content changes are published unless approved by a second person.  Automating or manually implementing this control is more expensive but given the greater risk probably makes sense.

IN SUMMARY

It’s recommended careful analysis be undertaken when considering control implementation to ensure the level of control is balanced against the level of risk for both cost effectiveness and efficiency.

Leave a Reply

Your email address will not be published. Required fields are marked *