A supermarket chain recently established more outlets in the city. Due to increased risk exposure occasioned by heightened insecurity in the country, the company saw the need to implement an effective management strategy aimed at minimizing attendant risks. The need is made even more apparent due to the introduction of more stringent regulatory requirements on handling perishable food items by the National Agency for Food and Drugs Administration and Control (NAFDAC). To this end, you have been engaged to provide advice to the company on risk management.

Required:

a.

  • i. Using the ALARP principle, advise the management on how to effectively manage the company’s risks. (2 Marks)
  • ii. Advise the company on the need to engage a risk manager. (2 Marks)
  • iii. Enumerate the roles of a risk manager. (5 Marks)

b.

  • i. What is a risk audit? Should the firm engage internal or external auditors (or consultants) to conduct a risk audit? Justify your position. (7 Marks)
  • ii. Illustrate to the management of the company the stages involved in conducting a risk audit. (4 Marks)

a.

  • i. ALARP (As Low as Reasonably Practicable) principle suggests that while it may be impossible or prohibitively expensive to eliminate all risk, any remaining risk should be as low as reasonably practicable. The company should identify high-priority risks, especially those related to security and compliance with NAFDAC regulations, and take steps to minimize them without incurring excessive costs.
  • ii. Engaging a risk manager would help the company manage its exposure to these risks more effectively by providing expert advice, risk assessment, and ensuring compliance with regulatory requirements.
  • iii. The roles of a risk manager include:
    1. Identifying and assessing risks.
    2. Developing and implementing risk mitigation strategies.
    3. Ensuring compliance with regulatory requirements.
    4. Training employees on risk management procedures.
    5. Monitoring the effectiveness of risk management strategies and making necessary adjustments.

b.

  • i. A risk audit is an examination of an organization’s risk management processes to ensure they are functioning effectively. Internal auditors are familiar with the company’s operations and may be more cost-effective, but external auditors provide an independent perspective and may offer greater objectivity. It is recommended to engage external auditors to avoid potential biases.
  • ii. The stages of conducting a risk audit include:
    1. Planning the audit by identifying the scope and objectives.
    2. Gathering data through interviews, document reviews, and risk assessments.
    3. Analyzing the data to identify areas of weakness or non-compliance.
    4. Reporting the findings to management, including recommendations for improvements.