Learning Outcomes

By the end of this lesson, learners should be able to:

  • Explain the principles, framework, and process of ISO 31000:2018.

  • Describe the risk management process including identification, analysis, evaluation, and treatment.

  • Define risk appetite and tolerance in the context of sustainability.


Introduction

Effective sustainability risk management requires a structured and systematic approach. While the risks themselves may be novel and complex, the principles and processes for managing them are well-established. The international standard ISO 31000:2018 provides a comprehensive framework that organizations can adapt to their specific contexts, including the management of sustainability risks. This lesson introduces the ISO 31000 framework, the risk management process, and the concepts of risk appetite and tolerance, which are fundamental to integrating sustainability into enterprise risk management.

1. Overview of ISO 31000:2018 – Principles, Framework, and Process

ISO 31000:2018 is the international standard for risk management, providing principles, a framework, and a process for managing any type of risk. It is designed to be applicable to all organizations, regardless of size, sector, or activity. The standard is not prescriptive but rather provides guidance on how to create and embed a risk management culture within an organization.

The standard is structured around three core components: Principles, Framework, and Process. The principles are the foundation, describing the essential characteristics of effective risk management. These include being integrated, structured, comprehensive, inclusive, dynamic, and continually improving. The framework provides the organizational structure and governance needed to support effective risk management, including leadership commitment, integration into organizational structures, and resource allocation. The process is the iterative cycle of activities involved in managing risks, from identification to communication and consultation.

For sustainability risk management, ISO 31000 offers a particularly valuable framework because it emphasizes the importance of understanding the external and internal context in which risks arise. Sustainability risks are deeply interconnected with an organization’s external environment, including regulatory frameworks, societal expectations, and ecological systems. The standard encourages organizations to consider these broad contexts when identifying and assessing risks, ensuring that sustainability considerations are not overlooked.

2. Risk Identification, Analysis, Evaluation, and Treatment

The risk management process described in ISO 31000 consists of several iterative activities. Risk identification is the first step, and it involves finding, recognizing, and describing risks that could affect the achievement of organizational objectives. In the context of sustainability, this involves scanning the external environment for emerging issues such as climate change, social unrest, and regulatory changes, as well as internal processes such as supply chain operations and human resources practices. Effective risk identification requires input from diverse stakeholders, including employees, customers, suppliers, and community representatives, to capture a broad range of perspectives.

Risk analysis follows identification and involves developing an understanding of the nature and characteristics of the risks. This includes determining the likelihood of the risk occurring and the potential impact it could have on the organization. Risk analysis can be qualitative (using descriptive scales such as low, medium, high) or quantitative (using numerical values for probability and impact). For sustainability risks, quantitative analysis may involve modeling physical climate impacts, estimating the financial costs of regulatory changes, or assessing the potential revenue loss from reputational damage. The level of sophistication of the analysis depends on the complexity of the risk and the availability of data.

Risk evaluation is the process of comparing the results of risk analysis against risk criteria, including risk appetite and tolerance. This helps organizations prioritize risks and determine which risks require treatment and which are acceptable to retain. For instance, a risk with a very high probability and impact would be considered unacceptable and require urgent action, while a risk with low probability and impact might be accepted. Sustainability risks are often evaluated not just on their financial impact but also on their potential to affect stakeholders, reputation, and social license to operate.

Risk treatment is the process of selecting and implementing measures to modify risk. The options for treating risk include avoiding the risk (ceasing the activity causing the risk), reducing the risk (implementing controls), transferring the risk (purchasing insurance), or accepting the risk (deciding not to act). For sustainability risks, treatment may involve diversifying supply chains to reduce exposure to climate-related disruptions, implementing robust human rights due diligence policies, or investing in energy efficiency to reduce exposure to carbon pricing. The treatment plan must be proportionate to the significance of the risk and should be aligned with the organization’s strategic objectives.

3. Risk Appetite and Tolerance

Risk appetite is the amount and type of risk that an organization is willing to pursue or retain in order to achieve its strategic objectives. It represents a high-level statement of the organization’s willingness to accept risk in pursuit of its goals. Risk tolerance, on the other hand, is the specific amount of risk the organization is willing to take in relation to a particular objective or risk category. Tolerance levels provide the operational boundaries within which the organization operates, often expressed as thresholds or limits.

In the context of sustainability, risk appetite and tolerance are particularly important. An organization may have a low tolerance for human rights violations in its supply chain, meaning it is unwilling to accept even a small probability of such incidents occurring. Conversely, it may have a higher tolerance for the risks associated with entering a new market for renewable energy products, viewing the potential returns as commensurate with the risks involved.

Determining risk appetite and tolerance for sustainability risks requires careful consideration of the organization’s values, stakeholder expectations, and strategic priorities. It also requires a clear understanding of the potential consequences of accepting or not accepting sustainability risks. Organizations must articulate their sustainability risk appetite in their strategic documents and ensure that it is communicated throughout the organization. This helps to ensure consistency in decision-making and that sustainability considerations are integrated into all aspects of operations.

4. Integrating Sustainability into Enterprise Risk Management

Enterprise risk management (ERM) is a strategic business discipline that supports the achievement of an organization’s objectives by addressing the full spectrum of its risks and managing the combined impact of those risks as an interrelated risk portfolio. Integrating sustainability into ERM involves embedding sustainability considerations into the organization’s existing risk management structures and processes rather than creating separate, parallel processes for sustainability risks.

The integration begins with incorporating sustainability into the organization’s risk appetite statement and ensuring that the board and senior management provide strong leadership on sustainability issues. It then involves embedding sustainability considerations into the risk identification, analysis, evaluation, and treatment processes. This means that when the organization conducts its periodic risk assessments, it explicitly considers environmental, social, and governance factors, just as it considers financial and operational factors.

Integration also requires building the capacity of risk managers and other professionals to identify and assess sustainability risks. This may involve training on climate scenario analysis, human rights due diligence, and sustainability reporting standards. Additionally, it requires establishing systems to monitor sustainability risks and to report on them to senior management and the board. Sustainability risk management should be integrated into internal audit and assurance processes to ensure that the controls in place are effective.

The benefits of integrating sustainability into ERM are significant. It ensures that sustainability is not treated as a separate or peripheral issue but is recognized as fundamental to the organization’s success. It helps to break down silos and encourages collaboration across departments, such as finance, operations, and sustainability. Ultimately, it creates a more resilient organization that is better able to anticipate and respond to sustainability challenges and opportunities.


Key Takeaways

  • ISO 31000:2018 provides a comprehensive, adaptable framework for managing any type of risk, including sustainability risks, based on principles, a framework, and a process.

  • The risk management process involves identifying risks, analyzing their likelihood and impact, evaluating them against risk criteria, and selecting appropriate treatment options.

  • Risk appetite is the amount and type of risk an organization is willing to pursue to achieve its objectives, while risk tolerance defines specific operational limits.

  • Integrating sustainability into enterprise risk management ensures sustainability considerations are not separate but embedded in core risk management processes, creating a more resilient and forward-looking organization.