10 Principles of Effective Risk Management | AACSB (2024)

Academic leaders should never waste a crisis. Rather, they should view every crisis as an opportunity to improve their schools’ risk management systems.

Business schools are paying more attention to risk than ever before, especially now that Standard 1.2 in the 2020 AACSB Business Accreditation Standardsasks schools to “conduct formal risk analysis and … mitigate identified major risks.” The COVID-19 pandemic made it clear that such analysis is essential to an institution’s long-term survival. Nevertheless, many schools are only beginning to design state-of-the-art risk management systems that measure up to those used by business organizations.

What are the different pieces of the puzzle that, together, provide a tool academic leaders can use to better predict risks and prepare for crises? Here, I outline 10 principles of good risk management—and point out common fallacies that can limit the effectiveness of risk management programs.

Principle 1: Think broadly about risk.

Corporate risk managers interpret risk with a probabilistic approach, using statistical indicators such as standard deviation, skewness, and others that characterize the likelihood of extreme, undesirable outcomes. Unfortunately, most business schools not only lack the data required to carry out such detailed calculations, but they too often restrict their attention to financial impacts, which are relatively easy to measure (or so they believe).

But other less tangible risks can be just as devastating. Think of what happens to an institution’s reputation when its staff members exhibit criminal sexual behavior against students or when its faculty are accused of adopting fraudulent research practices.

And then there are the risks linked to opaque “sources of randomness”—these are crises that are difficult for leaders to understand given their current knowledge, tool sets, and professional experiences. We saw such a crisis in the COVID-19 pandemic, which was a sudden, singular disturbance that affected every aspect of business school operations.

It is not advisable to delay mitigation of these random uncertainties until they have materialized. By then, it is often too late. It is far better to prepare for a broad range of risks before they manifest as substantial problems, losses, or missed opportunities.

Principle 2: Understand your risk landscape.

Crises can result from several things going wrong simultaneously, but leaders too often ignore such co-movement. Compartmentalizing risks into separate silos might help leaders avoid ad hoc reasoning, but also can lead them to assume, incorrectly, that every unfavorable risk will occur in isolation, unaffected by other influences.

Once again, take COVID as an example. Before the pandemic, higher education already had been exposed to a multitude of “gray rhino” risks, a term coined by strategist Michelle Wucker to describe “highly probable, high-impact yet neglected threats.” Such risks include climate change, demographic shifts, technological change, evolving educational preferences, and geopolitical developments.

When everyone on campus is asked to share responsibility for risk management, it’s likely that no one will take responsibility.

Decision makers tend to ignore gray rhino events for too long for many reasons, from the prevalence of herd behavior to the slow speed of crisis onset. But when COVID-19 interacted with gray rhino risks, it sent their slow development into “hyper-speed.” For example, the pandemic accelerated innovations in online education in ways that could offer fundamental challenges to traditional face-to-face instruction.

COVID-19 has compelled many business schools to invest substantially in technology upgrades, program redesign, and faculty training. But schools that already had adapted to the slow-moving changes they saw in the market prior to 2020 were able to transition to online education during the pandemic far more easily.

Principle 3: Avoid the compliance trap.

Parent universities often oversee risk management for all academic units, an approach that appears logical at first. After all, total exposure is the aggregate of risk exposures across an institution’s subunits. But while a compliance model encourages business school leaders to record, report, and discuss potential risks, it often does not force them to manage or mitigate those risks. When everyone on campus is asked to share responsibility for risk management, it’s likely that no one will take responsibility (see Principle 4).

Consider the extent to which some business schools relied on only a few markets, such as India and China, for student recruitment. While many of these institutions expressed the importance of mitigating their risk by diversifying their student recruitment, few took concrete action. As a result, institutions with the most exposure to these markets saw the biggest enrollment drops due to COVID. This was true for Australia’s regional universities, where enrollments dropped by a staggering 40 percent in the first half of 2021.

Principle 4: Establish robust governance.

Responsibilities for risk management need to be clearly defined and assigned. Take, for instance, a school’s flagship program. Who should manage the risks for this program? The associate dean of teaching and learning, the academic director, the head of admissions, the chief marketing officer, or if all else fails, the dean? When the delegation of responsibility is fragmented, it only invites inaction. Consequently, everybody may merely “watch the ball” as it drops to the ground.

Corporate practice teaches us that school administrators should appoint a person holding the remit for a specific risk (the “risk owner”) and a person responsible for monitoring and mitigating that risk (the “risk manager”). In practice, both roles are often combined. In this way, organizations make clear who is responsible to act when a particular crisis occurs and ensure that someone is there to catch the ball before it drops.

Principle 5: Use tools—and data—smartly.

Today’s state-of-the-art “weapon of choice” for risk management is the risk register, where administrators record information such as potential risks, their likelihood, institutional vulnerability, potential impact, speed of onset, mitigation actions, risk owner, and risk manager. In its simplest and most used form, a risk register is set up as an Excel spreadsheet that senior management can use to facilitate risk-related discussions.

In many cases, these documents can be transformed into “heat maps” rating the likelihood and potential impact of certain risks. These ratings can be based on a Likert scale (for example, 1 = “very low” to 5 = “very high”) or a traffic light system to flag dangerous “red” zones.

There are three main problems with risk registers. First, academic leaders might rely too heavily on Likert-scale ratings, which can be influenced by subjective perception biases. Consider, for example, the term “almost certain.” When people describe a risk as “almost certain,” they might ascribe a subjective probability of anywhere from 80 percent to 100 percent.

If business schools had had the right systems in place, they possibly could have detected a trail of weak signals that foreshadowed the pandemic in late 2019, months before the entire sector was abruptly forced into crisis mode.

Second, risk registers can suffer from aggregation biases, in which leaders fail to link top-level thinking with intraschool operational realities. For that reason, it is valuable for the executive team to create not only a schoolwide risk map, but also risk maps for each subunit within the school, so that they can better identify potential sources of trouble.

Third, risk registers often are not supported by automatic data feeds. But data is crucial to effective risk assessment. With student recruitment, for instance, an executive committee can consider data such as the number of signed student contracts and web clicks on degree pages. In addition, when used in combination with artificial intelligence, such data-based assessment can help schools track ranking performance data and predict forthcoming positioning changes.

An Excel spreadsheet with ordinal scoring is not enough to support effective risk management. Schools also must employ data-driven approaches to create reliable reference points and manage their operational risk.

Principle 6: Learn to detect weak signals.

Business schools started to take COVID seriously in late February to early March 2020. But if they had had the right systems in place, they possibly could have detected a trail of weak signals that foreshadowed the coming crisis in late 2019, months before the entire sector was abruptly forced into crisis mode. These signals included the unusual way governmental bodies in China were handling the earliest stages of the crisis, as well as social media communication surrounding the emerging pandemic. Instead of reacting to these signals, most schools assumed that China would bring this outbreak under control as it had in previous instances.

Too often, schools measure risk using key performance indicators (KPIs) such as tuition income and student enrollments. Unfortunately, these lagging indicators measure past rewards and outcomes. Instead, schools should employ forward-looking measures such as the faculty’s engagement with pedagogical innovation or the perceptions key stakeholders (such as prospective students) have of the school’s quality. Such measures that act as leading indicators of future performance are far more useful at revealing signals of a coming crisis.

Principle 7: Appreciate the benefits of trial and error.

Here, we can be inspired by the well-known marshmallow challenge, in which small teams of people are asked to build free-standing towers using raw spaghetti, tape, and string, before placing a marshmallow on top. Kindergarteners, who let their creativity reign and are always ready to start over, tend to perform much better in this challenge than business school graduates, who are driven more by strategy and KPIs.

The marshmallow challenge has a key takeaway: Complex design problems are better tackled through trial and error than through the application of predetermined practices. When one approach doesn’t work, we must exhibit ambidexterity, agility, and resilience, and we must be willing to change and start afresh.

Principle 8: Become a wayfinding leader.

Wayfinding describes a leader’s ability to navigate the future with little information to go by. Think, for example, of the impact of AI on faculty’s work. Some faculty perceive AI as an opportunity, while others view it as a threat. The best academic leaders will provide narratives surrounding emerging trends such as the adoption of AI to support better sensemaking among faculty and staff. In this way, they can encourage them to embrace new technology and manage risks associated with it more effectively.

Principle 9: Make risk management a team sport.

In auto racing, the current Formula 1 record for changing a set of tires during a pit stop stands at an amazing 1.82 seconds. To perform at this level, teams must practice hundreds of times every season. The same logic applies to business school teams when dealing with risk.

Schools should not only have clear risk management processes in place, but also make sure people know their specific roles as thoroughly as Formula 1 pit crew members know theirs. Otherwise, when a crisis is imminent, faculty and staff will behave like sideline coaches. Everyone will observe, no one will act.

When organizations emerge from crisis stronger than they were before, that outcome does not reflect superior crisis management—it reflects effective risk management.

Principle 10: If not now, when?

Many leaders subscribe to the theory that “a crisis is not the appropriate time to improve ‘back office’ capabilities.” But this sentiment contains two errors in thinking. First, it fails to recognize that people throughout the organization are responsible for risk management, not just “back-office” staff. Second, it diverts attention away from managing risk during a crisis—exactly when risk management is required most. We need only look to the financial markets, where the greatest long-term outperformance occurs during market downturns, not market upswings.

It is always a good time for business schools to enhance their risk management capabilities. For example, those that have worked to improve their market positioning during the pandemic will emerge stronger than they were before. This outcome does not reflect superior crisis management—it reflects effective risk management.

Developing a School’s Risk Culture

For organizations, the biggest challenges of risk management are related not to adopting risk governance strategies or using analytics, but to developing an organization’s risk culture and appetite for risk. By putting these 10 principles into practice, business schools can create cultures where all employees understand the importance of managing exposure to risks and can establish their capacity for risk (benchmarked, for example, against their financial slack) across all cash flow streams, actors, and subunits.

When managing risks, senior management teams at business schools tend to hold their cards close to their vests, sharing little of their planning outside their circle. This is the exact opposite of what they should do. Instead, leaders should make sure everyone is informed of potential risks, invited to contribute his or her knowledge, and included in the risk mitigation process. Only then can leaders ensure that their institutions are truly prepared for future crises, no matter how unexpected.

The views expressed by contributors to AACSB Insights do not represent an official position of AACSB, unless clearly stated.

10 Principles of Effective Risk Management | AACSB (2024)

FAQs

What are the principles of effective risk management? ›

The 7 key principles of risk management—a proactive approach, systematic process, informed decisions, integrated framework, resource allocation, transparency and communication, and continuous monitoring and review—provide the blueprint for an effective risk management program.

What are the principles of risk management in the USMC? ›

PRINCIPLES OF RM

Accept no unnecessary risk. Accept risk when benefits outweigh cost. Make risk decisions at the right level. Anticipate and manage risk by planning.

What are the 8 principles under ISO 31000 risk management? ›

ISO 31000 Principles of Risk Management
  • Integrated. ...
  • Structured and Comprehensive. ...
  • Customized. ...
  • Inclusive. ...
  • Dynamic. ...
  • Best Available Information. ...
  • Human and Cultural Factors. ...
  • Continual Improvement.

What are the basic principles of risk management identified? ›

The 5 basic principles of risk management are to: Avoid risk - Identify appropriate strategies that can be used to avoid the risk whenever possible, if a risk cannot be eliminated then it must be managed Identify risk - Assess the risk, identify the nature of the risk and who is involved Analyse risk - By examining how ...

What is the principle of effective management? ›

At the most fundamental level, management is a discipline that consists of a set of five general functions: planning, organizing, staffing, leading and controlling. These five functions are part of a body of practices and theories on how to be a successful manager.

What are the 6 basic principles of risk management? ›

  • Step 1: Hazard identification. This is the process of examining each work area and work task for the purpose of identifying all the hazards which are “inherent in the job”. ...
  • Step 2: Risk identification.
  • Step 3: Risk assessment.
  • Step 4: Risk control. ...
  • Step 5: Documenting the process. ...
  • Step 6: Monitoring and reviewing.

What are the 5 principles of risk management army? ›

RM is a five-step process which consists of identifying the hazards, assessing those hazards, developing controls and making risk decisions, implementing controls, and supervising and evaluating throughout the execution of the event.

What are the 5 steps of risk management USCG? ›

The Coast Guard has adopted a 5-step RM process that consists of 1) Identifying Hazards, 2) Assessing Hazards, 3) Developing Controls and Making Decisions, 4) Implementing Controls, and 5) Supervising and Evaluating Controls.

What are the 11 risk management principles identified in ISO 31000? ›

The eleven risk management principles are:
  • Risk management establishes and sustains value.
  • Risk management is an integral part of all organizational processes.
  • Risk management is part of decision making.
  • Risk management explicitly addresses uncertainty.
  • Risk management is systematic, structured, and timely.

What is one of the 5 principles of risk management? ›

While risk professionals are well familiar with the core principles of risk management — risk identification, risk analysis, risk control, risk financing and claims management — they are certainly not the only ones to rely on them in their daily thinking and decision-making.

What is the 8th principle of management? ›

8. Centralization. Centralization refers to the concentration of power in the hands of the authority and following a top-bottom approach to management. In decentralization, this authority is distributed to all levels of management.

Which of the following are principles of risk management in the USMC? ›

Accept risks when benefits outweigh costs. Accept no unnecessary risk. Anticipate and manage risk by planning. Make risk decisions at the right level.

What are the four principles of effective risk management? ›

There are four basic principles of risk management principles identification, assessment, control, and financing. The identification principle focuses on evaluating risks and determining which ones will have an impact on an organization.

What are the 7 steps of the risk management process? ›

The 7 steps below provide a good framework for effectively managing project risk.
  • Step 1 | Outlining Objectives. ...
  • Step 2 | Risk Management Plan. ...
  • Step 3 | Identification. ...
  • Step 4 | Evaluation. ...
  • Step 5 | Planning. ...
  • Step 6 | Management. ...
  • Step 7 | Feedback.
Jul 10, 2017

What are the four principles of risk management? ›

Accept risks when benefits outweigh costs. Accept no unnecessary risk. Anticipate and manage risk by planning. Make risk decisions at the right level.

What is effective risk management? ›

Effective risk management means attempting to control, as much as possible, future outcomes by acting proactively rather than reactively. Therefore, effective risk management offers the potential to reduce both the possibility of a risk occurring and its potential impact.

What are the five principal risk measures? ›

Risk measures are also major components in modern portfolio theory (MPT), a standard financial methodology for assessing investment performance. The five principal risk measures include alpha, beta, R-squared, standard deviation, and the Sharpe ratio.

References

Top Articles
The joy of preserving (and a recipe for preserved green figs)…
Homemade Kahlua Recipe - Wilson Homestead
Star Wars Mongol Heleer
Joi Databas
Hannaford Weekly Flyer Manchester Nh
Blue Ridge Now Mugshots Hendersonville Nc
Slmd Skincare Appointment
Oc Craiglsit
6001 Canadian Ct Orlando Fl
9044906381
Nutrislice Menus
Urban Dictionary: hungolomghononoloughongous
Craigslist In Flagstaff
Spoilers: Impact 1000 Taping Results For 9/14/2023 - PWMania - Wrestling News
Red Devil 9664D Snowblower Manual
Concordia Apartment 34 Tarkov
Acts 16 Nkjv
Menards Eau Claire Weekly Ad
Reptile Expo Fayetteville Nc
Rqi.1Stop
Like Some Annoyed Drivers Wsj Crossword
yuba-sutter apartments / housing for rent - craigslist
LCS Saturday: Both Phillies and Astros one game from World Series
eugene bicycles - craigslist
Die 8 Rollen einer Führungskraft
Studentvue Calexico
Danielle Moodie-Mills Net Worth
27 Fantastic Things to do in Lynchburg, Virginia - Happy To Be Virginia
12657 Uline Way Kenosha Wi
Kacey King Ranch
Mkvcinemas Movies Free Download
Blue Beetle Movie Tickets and Showtimes Near Me | Regal
Imperialism Flocabulary Quiz Answers
Mvnt Merchant Services
2020 Can-Am DS 90 X Vs 2020 Honda TRX90X: By the Numbers
Hireright Applicant Center Login
Dcilottery Login
Torrid Rn Number Lookup
Vérificateur De Billet Loto-Québec
Love Words Starting with P (With Definition)
What Is The Optavia Diet—And How Does It Work?
Gli italiani buttano sempre più cibo, quasi 7 etti a settimana (a testa)
What is 'Breaking Bad' star Aaron Paul's Net Worth?
15 Best Places to Visit in the Northeast During Summer
The Sports Academy - 101 Glenwest Drive, Glen Carbon, Illinois 62034 - Guide
Vci Classified Paducah
Clock Batteries Perhaps Crossword Clue
Mytmoclaim Tracking
116 Cubic Inches To Cc
Jigidi Jigsaw Puzzles Free
Estes4Me Payroll
Latest Posts
Article information

Author: Roderick King

Last Updated:

Views: 6091

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Roderick King

Birthday: 1997-10-09

Address: 3782 Madge Knoll, East Dudley, MA 63913

Phone: +2521695290067

Job: Customer Sales Coordinator

Hobby: Gunsmithing, Embroidery, Parkour, Kitesurfing, Rock climbing, Sand art, Beekeeping

Introduction: My name is Roderick King, I am a cute, splendid, excited, perfect, gentle, funny, vivacious person who loves writing and wants to share my knowledge and understanding with you.