Welcome to P3 Risk Management: Who Does What?

Welcome, future CGMAs! We are diving into a crucial part of the Enterprise Risk section of your P3 syllabus. Many students think risk management is just something the "Risk Department" does, but in reality, it is a team sport. In this chapter, we will explore the roles and responsibilities of everyone from the CEO down to the shop floor.

Don't worry if this seems like a lot of titles and committees at first. We will break it down using simple analogies so you can remember exactly who is responsible for what when the exam day arrives!

1. The Top Tier: The Board of Directors

In any organization, the Board of Directors carries the ultimate responsibility for risk management. Think of them as the captains of a ship. They don't pull every rope, but they decide which direction the ship goes and how much stormy weather they are willing to brave.

The Board's primary duties include:

- Setting Risk Appetite: Deciding how much risk the company is willing to take to achieve its goals.
- Risk Strategy: Ensuring that the risk management framework aligns with the business strategy.
- Tone at the Top: Creating a culture where risk is taken seriously and discussed openly.

Analogy: If a company were a car, the Board decides the speed limit (Risk Appetite) and the destination (Strategy).

Quick Review: The Board

Key Takeaway: The Board is ultimately accountable for the risk management system. They don't do the daily work, but they set the rules and the culture.

2. Specialized Committees: Audit vs. Risk

Because Boards are busy, they delegate specific tasks to committees. In CIMA P3, you need to know the difference between the Audit Committee and the Risk Committee.

The Audit Committee

This committee is usually made up of Independent Non-Executive Directors (NEDs). Their job is to look at the "rear-view mirror" and the "engine check lights." They focus on:

- Financial reporting integrity.
- Monitoring the Internal Control systems.
- Overseeing the relationship with External Auditors.

The Risk Committee

While the Audit Committee focuses on controls and numbers, the Risk Committee looks at the "road ahead." They look at emerging risks like cyber-attacks, economic shifts, or new competitors. Their job is to ensure the Board's Risk Appetite is actually being followed in practice.

Did you know? In many smaller companies, these two committees are merged into one. However, for large, complex companies (especially in banking), the CIMA syllabus highlights the benefit of having a dedicated Risk Committee to ensure risk gets the attention it deserves.

Common Mistake to Avoid

Do not assume the Audit Committee manages the risks. They monitor and review how well the managers are doing it. They provide oversight, not daily execution.

3. The Chief Risk Officer (CRO)

The Chief Risk Officer (CRO) is a senior executive who acts as the "Risk Champion" for the organization. They are the bridge between the Board and the rest of the company.

The CRO's responsibilities include:

- Developing the risk management framework.
- Reporting risk updates to the Board and Risk Committee.
- Ensuring that risk management is "embedded" (meaning it's part of daily life, not just a box-ticking exercise).

Mnemonic: The "3 Cs" of the CRO
Champion: Promoting risk awareness.
Challenger: Questioning managers who take too much (or too little) risk.
Coordinator: Making sure all departments report risks in the same way.

4. The Three Lines of Defence Model

This is perhaps the most important concept in this chapter. CIMA loves to test your understanding of how an organization protects itself. Imagine a castle under attack—you need different layers of protection.

1st Line: Business Operations (The "Doers")

These are the Operational Managers. They own the risks because they are the ones performing the daily activities. If a factory manager sees a safety hazard, they are the first line of defence because they must manage that risk immediately.

2nd Line: Risk & Compliance (The "Overseers")

These are the specialists (like the CRO or the Compliance team). They don't do the daily business tasks, but they provide the tools, policies, and systems for the 1st line to use. They monitor whether the 1st line is following the rules.

3rd Line: Internal Audit (The "Assurers")

This is the Internal Audit function. They are independent of the first two lines. Their job is to provide independent assurance to the Board that the first and second lines are actually working correctly.

Analogy: In a football match...
1st Line = The Players (trying to win while not letting the other team score).
2nd Line = The Coach (setting the tactics and monitoring performance).
3rd Line = The Referee (an independent person making sure the rules are followed).

Key Takeaway: The Three Lines

1st Line: Owns and manages risk.
2nd Line: Monitors and sets the risk framework.
3rd Line: Provides independent assurance.

5. Internal Audit vs. External Audit

It is easy to get these confused, but their roles in risk management are very different.

Internal Audit:
- Who do they work for? The Board/Audit Committee.
- What is their focus? Improving the company's operations, risk management, and internal controls.
- Scope: Very broad (can look at anything from IT security to HR policies).

External Audit:
- Who do they work for? The Shareholders.
- What is their focus? Giving an opinion on whether the Financial Statements are "true and fair."
- Scope: Narrow (focused on financial numbers and the risks that might make those numbers wrong).

6. The Role of Every Employee

Finally, risk management isn't just for the bosses. Every single employee has a responsibility to:

- Understand the risks associated with their specific job.
- Follow internal controls (like not sharing passwords).
- Report new risks or "near misses" to their managers.

Quick Tip: If you see an exam question about "Who is responsible for identifying risks?", the answer is usually everyone, but the Board is the one accountable for making sure it happens.

Chapter Summary Checklist

Before moving on, make sure you can answer these questions:

1. Who sets the "Risk Appetite"? (The Board)
2. Which line of defence does Internal Audit belong to? (The 3rd Line)
3. What is the main difference between the Audit and Risk Committees? (Audit = controls/past; Risk = strategy/future)
4. Who "owns" the risk on a daily basis? (Operational Managers/1st Line)

Great job! You've just mastered the roles and responsibilities of managing risk. Keep this structure in mind, and you'll find those P3 scenario questions much easier to navigate.