Corporate ERM: Risk Maps, Cash Flow at Risk, and Microsoft’s Approach

Book: Enterprise Risk Management: From Incentives to Controls
Author: James Lam
ISBN: 978-1-118-41361-6


Every Company Is a Risk-Taker Whether It Admits It or Not

Non-financial corporations face the same pressure as banks and utilities: globalization, tech disruption, consolidation, outsourcing, and investors who hate earnings surprises. Hedging FX or buying property insurance is table stakes. Leading firms use enterprise risk management to protect the brand, stabilize finance, and support strategy.

Lam’s framing is blunt. Screw up critical risks and you die fast. Take too few risks and you die slow as competitors eat your lunch.

Major Risk Categories

Credit risk shows up in receivables, trade finance, derivatives, and vendor dependence. A bankrupt IT outsourcer can stall your supply chain. Executives need totals on doubtful accounts, collection processes, contract protections, and backup plans.

Market risk hits through transaction, economic, and translation exposure. A U.S. automaker selling in Japan feels all three when the dollar strengthens.

Stock price risk is market risk people ignore until it hurts. Dot-com collapses killed firms with no revenue. Procter & Gamble lost 40% market cap in a week after an 11% earnings miss in March 2000.

Investment and pension risk sits in corporate portfolios and defined-benefit plans. Underfunding topped $453 billion across the largest 100 DB plans by late 2012 as low rates raised liabilities. Firms shift to lump sums, annuities, and liability-driven investing.

Hedging risk can backfire. Gibson Greetings lost $20 million in 1994 on complex Bankers Trust derivatives meant to hedge rates. FAS 133 later forced mark-to-market volatility many CFOs hated.

Secondary exposures like temperature for utilities or snowfall for airports increasingly have insurance and derivative solutions.

Operational risk spans product liability, failed deals, bad models, regulatory shifts, culture, and cyber. Bhopal and Exxon Valdez remain reference points for catastrophic ops failures.

Business and strategy risk is choosing the wrong future. Olivetti clung to typewriters while PCs won. Boeing vs Airbus on super-jumbo vs point-to-point jets is a bet-the-company fork. Mini-jumbo competition continues with different material choices (metal vs carbon fiber) reflecting different risk appetites.

Cultural risk turned IBM’s strength into near-death before its services pivot.

Outsourcing is standard (60%+ in Deloitte 2012 surveys) but adds vendor and offshore control issues. Boeing’s Dreamliner troubles vs Toyota’s supplier model illustrate the gap.

Reputational risk can dwarf direct losses. Coca-Cola’s 1999 European contamination scare triggered the largest recall in its history, hit earnings, and wiped billions from market cap.

Best Practices: Identify, Quantify, Control

Risk identification via risk maps ranks severity vs probability. Steps: enterprise taxonomy, bottom-up lists from units, score each risk, note controls, assign owners, roll up to enterprise view, refresh regularly. High severity + high probability (running out of cash) demands action. Low/low items still need monitoring if they repeat.

Quantification for corporates often means cash-flow-at-risk and earnings-at-risk, not trading VaR. Methods:

  • Pro forma sensitivity on budget line items
  • Regression betas vs rates, FX, labor costs
  • Simulation with path-dependent relationships and competitive response

Economic capital compares to book capital to test adequacy and allocate to units for risk-adjusted ROI. NPV and EVA without risk-adjusted capital charges favor reckless businesses over time.

Management and control means accepting strategic risk on purpose, monitoring tactical risk, using vendor SLAs with exit clauses, diversifying products, staging R&D, lowering fixed cost leverage, hedging concentrations, quality control for frequent medium losses, insurance and contingency plans for rare big losses, and killing single points of failure.

Case Study: Microsoft

Scott Lange cataloged risks across a dozen categories in the mid-1990s and found insurance covered only ~30%. Risk maps plotted frequency vs severity with color codes for insured vs uninsured gaps. A risk grid compared current vs goal processes across identification, assessment, mitigation, financing, and services.

They dropped micro-policies, priced keyboard repetitive-stress risk into products, built loss databases, and launched a risk intranet so units could self-serve. CFO Mike Brown backed tech as a cost cutter and quality booster. Future plans included holistic risk transfer packaging.

Case Study: Ford

Ford mortgaged assets early, stayed liquid, and brought in Boeing’s Alan Mulally as CEO. That let Ford skip TARP and bankruptcy while GM and Chrysler restructured. Mulally shed Jaguar and Volvo, focused on Focus and Taurus, and later pushed China growth. Engineer-driven culture (curve control idea born at a restaurant) shows risk thinking embedded in product design.

Case Study: Airbus and Boeing

Outsourcing run amok left Boeing with dozens of flawed Dreamliners parked. Both OEMs tightened supplier oversight, aligned designs and tools across plants, and track “risky” suppliers closely. Long development cycles mean pricing must include risk cost, as Airbus CFO Hans Peter Ring acknowledged publicly.

My Take

Chapter 18 is the “you do not need a trading floor to need ERM” chapter. Risk maps and CFaR translate Wall Street tooling into language CFOs and division heads understand.

Microsoft’s insurance gap analysis is a simple exercise any company can copy this quarter. Ford shows leadership and balance sheet choices as risk decisions, not just hero narratives.

The Boeing/Airbus epilogue proves Lam’s outsourcing warning: efficiency without visibility is borrowed time.

Non-financial ERM is not about copying bank capital models verbatim. It is about seeing the full risk inventory, pricing and resourcing accordingly, and not mistaking luck for a process.


Previous: Previous: ERM for Energy Firms (Chapter 17)
Next: Next: The Future of Risk Management (Chapter 19)