Business Risk and Internal Controls

Stepping out on a rainy day, it is sensible to carry an umbrella. You cannot stop the rain, but with preparation you can avoid getting soaked. Business risk management is the same proposition: not eliminating uncertainty, which is impossible, but knowing which uncertainties would actually hurt and deciding in advance what to do about them.

Know Where the Business Sits

Before you can assess risk you have to understand the environment the organization operates in, and it is worth separating the layers.

  • The wider environment — the economy, interest rates, politics and regulation, technology, demographics, and social change. You cannot influence these; you can only anticipate them.
  • The industry environment — customers, competitors, suppliers, substitutes, and how easily a new entrant could arrive. You have some influence here.
  • The internal environment — your people, processes, systems, finances, and culture. This is where you have real control, and where most failures actually originate.

The point of the exercise is direction of attention. Organizations tend to worry about dramatic external events while being undone by something internal and entirely foreseeable.

Assessing Risk

The mechanics are straightforward and their value comes from doing them explicitly rather than in your head.

  • List what could go wrong — and get the list from the people doing the work, who know things the leadership does not.
  • Score each on likelihood and impact, even roughly. High-impact and low-likelihood is a different problem from constant small losses.
  • Rank them, because everything cannot be a priority.
  • Decide the response for each of the significant ones.
  • Assign an owner and a review date. A risk register nobody owns is decoration.

There are only four possible responses to any risk: avoid it by not doing the thing; reduce it with controls; transfer it, usually through insurance or a contract term; or accept it consciously. Accepting a risk deliberately is a legitimate answer. Accepting it by never having looked is not.

The Risks Businesses Actually Face

  • Cash flow — the most common cause of failure, and frequently in profitable businesses. See cash flow management.
  • Customer concentration. If one client is 40% of revenue, that is not a customer, it is a dependency.
  • Key person. Whatever only one person can do is a risk with a name attached.
  • Supply — a single supplier, a single component, a single route.
  • Technology and data — systems failing, data lost, or a security breach.
  • Regulatory and legal, including employment law.
  • Reputational, which now moves considerably faster than it used to.
  • Fraud, internal and external, which small businesses persistently assume happens elsewhere.

Internal Controls

Internal controls are the procedures and policies designed to prevent error, fraud, and manipulation of a company’s processes for personal benefit. The large accounting scandals of the early 2000s happened partly because such controls were weak or overridden, and the regulatory response since has made them a board-level obligation for public companies.

Small businesses need them just as much, and the fundamentals do not require a department:

  • Separation of duties. The person who authorizes a payment should not also be the person who records it and reconciles the bank. This single control prevents most small-business fraud, and its absence is how long-trusted bookkeepers end up in court.
  • Authorization limits — who can commit the business to what, in writing.
  • Reconciliation. Bank, inventory, and receivables checked against records on a schedule by someone who did not create them.
  • Physical and system access restricted to those who need it, and removed the day someone leaves.
  • Documentation — if a transaction cannot be traced to a document, it cannot be audited.
  • Someone independent looking, even occasionally. The knowledge that anything might be checked is a large part of the deterrent.

Controls have a cost, in money and in friction, and there is a real judgment about how much is proportionate. Too few invites loss; too many slow the business down and get quietly bypassed, which is worse than not having them.

Regulatory Compliance

Regulation has always been part of business life, but the emphasis on demonstrable compliance has grown sharply, along with penalties that can reach directors and board members personally rather than stopping at the organization.

  • Know which rules apply to you — industry-specific licensing, employment law, tax, health and safety, data protection, and anything attached to handling money or personal information.
  • Assign ownership. Compliance that is everyone’s job is nobody’s.
  • Keep records that show compliance, not merely compliance itself. In a review, undocumented is treated as undone.
  • Train the people who have to comply, and repeat it.
  • Watch for changes. Rules move, and “we have always done it this way” is not a defense.
  • Treat it as a floor. Compliance is the minimum standard, not evidence that the business is being run well — see business ethics.

See also small business insurance basics and small business legal basics.