This is a short article illustrating how the Internet can be used to support risk assessment activities.

Managers need to understand the business process and identify, measure, and prioritize business risks as an important part of management decision-making. Risk Managers and Internal Auditors are usually adept at these tasks, but often risk assessment is new to other members of the management team. The Internet has a wealth of resources for the professional Risk Manager, the Internal Auditor and the manager who needs to better understand the concepts and practice of risk assessment.

The first steps in risk assessment are understanding the business risk context, or how the business process works within an environment of risk, and identifying the types of risk that may affect operations.

Understanding the business risk context means gaining an understanding of the key interrelationships among the organization's business processes, the business culture, and the relevant external forces for change. The Internet can be used to assist in understanding the business risk context:

Risk identification is the most critical step of risk assessment. If you cannot identify it, you cannot analyze or treat it. The Internet can be used to assist in risk identification.

Risk identification has three requirements:

  1. A framework and common language for thinking about and discussing risk.
  2. A thorough knowledge of the business process(es).
  3. A means of stimulating your imagination about risk.

Frameworks for thinking about and discussing risk are usually developed within each organization, although some governments and private companies may follow standard models. Two national models are the Australian/New Zealand standard AS/NZS 4360 (information site at and the Canadian standard CAN/CSA-Q850-97. The "Big 5" accountancy consulting firms have developed various models in support of their practices, such as the Generally Accepted Risk Principles for financial institutions (see for instance, written originally by Coopers & Lybrand (now PriceWaterhouseCoopers).

Some of the ways the Internet has already been used to assist the risk identification process:

Using the Internet to gather information on the business processes. A form is created and sent via email to process owners/managers. Return email is automatically read and a database is populated with up-to-date information and self-assessments about what risks are being faced and the effectiveness of current measures to mitigate these risks. New Zealand Inland Revenue once used a manual version of this process. The Internet version is much more efficient.

Using the Internet "chat room" function for a private brainstorming session with key managers all over the globe to better understand the risks and controls in their processes.

Using the Internet to search for business process information in similar industries (see context suggestions, above).

Requesting risk assessment information on similar processes from:

The Internet is also a source for shareware and information about creativity tools necessary to "think out of the box" to identify hidden risks. One such tool is Mind Mapping.

The Internet can also be used for risk measurement. Risk measurement, is usually straightforward for quantitative data. Qualitative judgments and subjective risk factors are more difficult to handle without introducing bias. Delphi groups or other normative group techniques are used to minimize biases.

Delphi techniques involve a group of experts independently rating and ranking business risk for a business process or organization and blending the results into a consensus. Each expert in the Delphi group measures and prioritizes the risk for each element or criteria. A facilitator gathers the independent judgments and summarizes them. The summary is fed back to the expert panel along with their independent judgements, giving the opportunity for each expert to compare their judgment against the panel. The process is looped until consensus is reached. Delphi groups can be established easily on the Internet in an anyplace-anytime mode using email or Microsoft NetMeeting tools.

Far afield from risk management, market research organizations are working on Internet-based interactive data gathering and focus group techniques such as used in Control and Risk Self Assessment sessions. One product on the market is (Knowledge Networks), a group decision support system using Intranet/Internet access to link and process group decision making. This system is offered by Milagro Systems, Inc.

The Internet is a rich source for risk assessment information and tools for risk management. The links to Internet resources above are provided as examples of the available information and are not exclusive endorsements of any product or service.

