Risk management has been recently gaining increasing attention in business due to its impact on the stability and continuity of business entities.
Such attention has devolved into establishing specialist professional organizations entrusted with issuing the risk management framework, which includes international standards intended to create common understanding, implementation, and reporting within a single country and worldwide.
Such organizations include the UK-based Institute of Risk Management (IRM) and the International Organization for Standardization (ISO), which issued ISO 31000: 2009.
The Institute of Risk Management set a definition of the risk management process as follows:
“Risk management involves understanding, analyzing and addressing risk to make sure organizations achieve their objectives. So it must be proportionate to the complexity and type of organization involved. Enterprise Risk Management (ERM) is an integrated and joined up approach to managing risk across an organization and its extended networks”.
From a theoretical perspective, business entities are required to set up an organizational unit charged with examining and managing risks and reporting the same to the Board of Directors in order to make informed decisions with respect to such risks.
In view of the attention paid to risk management activity, a professional framework has been established for those interested in developing their knowledge of risk management to set for exams and receive international specialist professional certificates in the risk management area.
In the State of Kuwait, Law No. 7 of 2010 regarding the Establishment of Capital Markets Authority and Regulation of Securities Activity and its Executive Regulations were promulgated, which include in Module 15 – Corporate Governance – the risk management requirements that are mandatory for listed and licensed companies in accordance with the following articles:
Article 6-4 | The Board of Directors shall constitute a committee named Risk Management Committee, which shall comprise a minimum of three members. The Chairman of the Committee shall be a non-executive director. The Chairman of the Board of Directors may not serve as a member of this Committee. The Board of Directors shall determine the membership term and its process of activities. |
Article 6-5 | The minimum authorities and roles of the Committee are as follows: |
|
|
Article 6-3 | The Company’s organizational structure (as approved by the Board of Directors) shall include an independent risk management department/ office/ unit, which will primarily measure, monitor, and mitigate all types of risks facing the Company as per the following: |
|
In light of the above, the following is a summary of the risk management reports that listed and licensed companies should prepare:
- Periodic reports by the Risk Committee about the nature of risks to which the Company is exposed, which reports will be presented to the Board of Directors.
- The Integrated Report shall include a section covering the risks facing the Company, for the use of the Board of Directors and the executive management.
It is worth mentioning that the above reports are for internal use and are not required to be submitted to the Capital Markets Authority. However, CMA has the right to request reviewing the same when conducting an inspection.
Furthermore, the companies licensed by shall comply with the provisions of Module 6 – Internal Policies and Procedures of Licensed Person – of the Executive Regulations of Law No. 7 of 2010, pertaining to the risk management report as per the following articles:
Article 4-2 | The risk management systems of a licensed person shall include the key aspects enabling it to identify and properly manage risks; in particular, these should include the following: |
|
|
Article 4-4 | The Risk Management Officer shall present a risk report to the Board of Directors every six months along with providing the CMA with a copy thereof. The Board of Directors shall notify CMA immediately upon the occurrence of deviation from the risk management systems and explain the actions to be taken to handle the same. |
Added value to business entities from the engagement of Risk Management Services in Kuwait
- Safeguard and maximize enterprise value.
- Ensure that the business entity complies with risk management requirements set forth in instructions and resolutions issued by the relevant regulators.
- Reduce the impact of various types of risks through an effective risk management framework that shall identify, measure, analyze, and use effective techniques to address or mitigate such risks.
- Enhance the entity’s performance efficiency and ensure the integrity of its financial statements and effective internal controls in place.
- Improve credit rating.
- Ensure that the business entity is able to continue to provide products and services at reasonable levels if they are exposed to incidents that may cause disruption thereof, and accordingly, achieve the competitive edge.
- Improve the business’ operations and increase awareness of critical operational aspects.
- Cost savings and avoidance of financial losses.
- Protect the interests of stakeholders, business reputation, and the brand.
Risk Management Services in Kuwait provided by Baker Tilly
Baker Tilly provides consulting services to companies licensed by Capital Markets Authority, listed and other companies in connection with risk management as follows:
- Biannual Risk Management Reports with respect to the risks encountered by the licensed person, which will be submitted to the Board of Directors and Capital Markets Authority.
(Reference: Executive Regulations – Module 6: Internal Policies and Procedures of Licensed Person – Chapter 4, Article 4.4)
- Periodic reports on the nature of risks to which a company is exposed will be submitted to the Risk Committee and the Board of Directors.
(Reference: Executive Regulations – Module 15: Corporate Governance, Chapter 6, 5th Rule, Article 6.3/2 and 6.5/8)
- Assist with setting up independent risk management functions, i.e. department, office, or unit within the company.
(Reference: Executive Regulations – Module 15: Corporate Governance, Chapter 6, 5th Rule, Article 6.3)
- Assist with developing risk management system including key aspects, which enable identifying and classifying all risks to which the company is exposed, methods of sound management of such risks, and ongoing control techniques. Such systems shall cover in particular credit risk, market risk, liquidity risk, operating risk, and any other risks that may face the Company.
(Reference: Executive Regulations – Module 6: Internal Policies and Procedures of Licensed Person – Chapter 4, Article 4.2)
(Reference: Executive Regulations – Module 15: Corporate Governance, Chapter 6, 5th Rule, Article 6.3/1)
- Develop Risk Committee Charter
(Reference: Executive Regulations – Module 15: Corporate Governance, Chapter 3, 2nd Rule, Article 3.7)
- Develop policies, procedures, and forms that define and classify all risks to which the company may be exposed, the methods adopted to measure such risks, sound risk management methodologies, and ongoing control techniques.
(Reference: Executive Regulations – Module 6: Internal Policies and Procedures of Licensed Person – Chapter 4, Article 4.3)
(Reference: Executive Regulations – Module 15: Corporate Governance, Chapter 6, 5th Rule, Article 6.3/1)