Situation
Entities tend to distinguish itself as either for profit or nonprofit organizations. However,
when it comes to facing risk, the differences between the entities does not matter as entities
all face the same three different categories of risk. The three different risk categories are
Category I: Risk Arising from Employees’ Undesirable or Unauthorized Actions, Category
II: Risks Associated with Strategy Execution, and Category III: Risks from Uncertain,
Uncontrollable External Events. For companies to mitigate these risks, organizations
should devise their risk management processes to the inherent nature of the three different
categories of risk they face.
Problem
Under Category I Risks, companies face risks that arise from employees’ failure to
perform routine, standardized, or predictable processes. Failure to perform the processes as
specified can expose the firm to substantial losses. In addition, breakdowns can occur and
also expose the firm to losses and highly adverse consequences. When breakdowns occur
companies become less diligent in enforcement or induce laxity through forgetfulness and
inattention. Furthermore, companies cannot predict all the risks that an employee might
encounter and therefore do not have a solution to every situation.
As for Category II Risks, these are risks associated with strategy execution. Strategy
describes how it intends to offer products and services to its customers with high value
while consequently differentiating itself from its competitors. While implementing the
strategy, the strategy also requires the company to voluntarily assume some risk. For
example, a bank assumes default risk when it extends credit to customers or when a high
tech company risks financial loss when it funds the R&D of a new product platform.