company-operating-system

07 · Risk, Compliance, Audit and Crisis Management

The through-line: how not to die. Companies in different industries and of different natures have completely different risk maps. The framework is the same: identify → assess → respond → monitor.


1. Risk maps by industry

Industry / type Major risks
State-owned enterprises “Three Major & One Large” decision rules (major decisions, key personnel changes, major projects, large fund outlays), state-asset supervision, integrity & compliance
Finance Capital adequacy, anti-money-laundering, regulatory reporting
Technology Data security, IP, loss of core talent
Manufacturing Quality incidents & recalls, environmental & safety, supply chain disruption, FX
Services Customer complaints & public opinion, labor & employment
Cross-border / trading FX, tariffs / trade policy, platform account bans, destination-country regulation
E-cigarettes (special) Policy & regulation (licenses / flavor bans / destination-market PMTA & TPD)

2. The four-step risk management loop

Identify → Assess (probability × impact) → Respond (avoid / reduce / transfer / accept) → Monitor

Risk matrix:

Probability \ Impact Low Medium High
High Monitor Respond Priority response
Medium Monitor Respond Priority response
Low Accept Monitor Contingency plan

3. Internal control & audit

3.1 Core internal controls (achievable even for SMBs)

3.2 Audit


4. Crisis management (emergency planning)

4.1 Three types of crises

Type Case Consequence
Quality incident Samsung Galaxy Note 7 CNY 10 billion+ in losses + brand damage
Sudden policy change 2021 e-cigarette regulation Industry reshuffle
Public opinion / PR Food safety Collapse of brand trust

4.2 Five steps to a crisis plan

  1. Identify possible crises (risk list)
  2. Define trigger conditions (what activates the plan)
  3. Appoint owners (who commands / who speaks)
  4. Rehearse (annual tabletop exercise)
  5. Review (mandatory post-crisis retrospective)

4.3 Crisis-handling principles


5. Case studies

Company Event Lesson
Enron Accounting fraud Missing internal controls = destruction
Luckin Coffee 2020 fraud Internal controls + the integrity red line
Samsung Note 7 Mishandled quality crisis
Toyota 2010 recalls Crisis PR: the right and wrong way
E-cigarette industry 2021 policy Policy is the biggest risk variable

📌 One-line summary: The goal of risk management is not to eliminate risk — it’s “don’t let any single risk kill you”: set red lines, prepare plans, keep redundancy.