Acceptance is a decision, not neglect. Accepting a risk knowing its size and monitoring it is one thing; leaving it because you never noticed it is something else entirely.
1 The four treatment options
Avoid
Stop the activity that creates the risk
Reduce
Controls that lower the likelihood or the impact
Transfer
Insurance, outsourcing or a contractual clause
Accept
Documented approval, with monitoring
Choosing between the four balances the cost of treatment against the size of the risk
| Option | When is it used? | Example |
|---|---|---|
| Avoid | The risk is severe and the return does not justify it | Declining to operate in a market that is high-risk from a regulatory standpoint |
| Reduce | The most common option, where the cause can be controlled | Dual authorisation on bank transfers |
| Transfer | The impact is large and the likelihood low | Fire insurance, or outsourcing operations to a specialist |
| Accept | The risk is within appetite and treatment costs more than its impact | Accepting slight price volatility in a non-material input |
The cost-benefit rule
A control should never cost more than the expected loss from the risk. A control costing a million riyals to protect against a risk with an impact of a hundred thousand is bad management, not prudence.
2 Types of control
| Type | Its function | Examples |
|---|---|---|
| Preventive | Stops the risk before it occurs | Segregation of duties · system access rights · training · dual authorisation |
| Detective | Catches it quickly after it occurs | Bank reconciliations · surprise stock counts · exception reports |
| Corrective | Remedies the effect and prevents recurrence | A continuity plan · backups · amending the procedure |
| Directive | Guides the required behaviour | Policies · regulations · written instructions |
A healthy mix combines them: preventive alone can be circumvented, and detective alone comes too late.
3 The three lines of defence
First line
Operating departments: own the risk and apply the controls
Second line
Risk and compliance: set the framework and monitor
Third line
Internal audit: independent assurance to the board
Three lines that do not overlap: whoever executes is not whoever monitors, and neither is whoever assures
A common confusion
Asking internal audit to write the risk register and implement the controls. Once it does, it loses its independence and ends up auditing its own work.
4 The treatment plan
Every treatment needs a written plan answering five questions: what will we do? Who is responsible? By when? With what resources? And how will we know it worked? Without a date and an owner, a plan is a wish.
The risk: because there is no second authorisation on transfers, a fraudulent transfer may be executed, causing a direct cash loss.
| Action | Type | Owner | Date |
|---|---|---|---|
| Enable dual authorisation for every transfer above 50,000 | Preventive | CFO | Within a month |
| A daily report of large transfers for review | Detective | Senior accountant | Immediately |
| Train the team on common fraud techniques | Directive | HR | Within a quarter |
| A recovery procedure and bank contact on suspicion | Corrective | CFO | Always ready |
Success indicator: zero transfers executed on a single authorisation, and any exception detected in under 24 hours.
5 Monitoring with indicators
A key risk indicator (KRI) is a number tracked periodically to reveal a risk drawing closer before it materialises, with an agreed alert threshold:
| Risk | Indicator | Alert threshold |
|---|---|---|
| Collection failures | Share of receivables over 90 days | 10% |
| Operational outage | Number of system failures per month | 3 failures |
| Loss of key people | Employee turnover rate | 15% a year |
| Regulatory breach | Number of requirements past their deadline | Zero tolerance |
Chapter 1 summary
- There are four treatment options: avoid, reduce, transfer, accept — and acceptance is a documented decision, not neglect.
- Controls come in types: preventive, detective, corrective and directive, and they are combined.
- The cost of a control must not exceed the expected loss from the risk.
- The three lines of defence separate execution, monitoring and independent assurance.
- A treatment plan with no owner, date and success indicator is not a plan.
6 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. Buying a fire insurance policy represents which option?
Insurance transfers the financial impact to another party, but it does not prevent the event and does not remove the need for preventive controls.
2. The monthly bank reconciliation is which type of control?
A reconciliation catches differences after they occur, so it is a detective control. A preventive control stops the event in the first place.
3. In the three lines of defence, who owns the risk and applies the controls day to day?
The first line owns the risk and applies the controls, the second sets the framework and monitors, and the third gives independent assurance to the board.