07 · Risk, Compliance, Audit and Crisis Management
The through-line: how not to die.
Companies in different industries and of different natures have completely different risk maps.
The framework is the same: identify → assess → respond → monitor.
1. Risk maps by industry
| Industry / type |
Major risks |
| State-owned enterprises |
“Three Major & One Large” decision rules (major decisions, key personnel changes, major projects, large fund outlays), state-asset supervision, integrity & compliance |
| Finance |
Capital adequacy, anti-money-laundering, regulatory reporting |
| Technology |
Data security, IP, loss of core talent |
| Manufacturing |
Quality incidents & recalls, environmental & safety, supply chain disruption, FX |
| Services |
Customer complaints & public opinion, labor & employment |
| Cross-border / trading |
FX, tariffs / trade policy, platform account bans, destination-country regulation |
| E-cigarettes (special) |
Policy & regulation (licenses / flavor bans / destination-market PMTA & TPD) |
2. The four-step risk management loop
Identify → Assess (probability × impact) → Respond (avoid / reduce / transfer / accept) → Monitor
Risk matrix:
| Probability \ Impact |
Low |
Medium |
High |
| High |
Monitor |
Respond |
Priority response |
| Medium |
Monitor |
Respond |
Priority response |
| Low |
Accept |
Monitor |
Contingency plan |
3. Internal control & audit
3.1 Core internal controls (achievable even for SMBs)
- Segregation of incompatible duties: whoever handles money doesn’t keep the books; whoever procures doesn’t accept delivery; whoever approves doesn’t execute
- Approval authority matrix: who is authorized to spend how much (autonomy within budget, approval beyond)
- Seals / contracts / treasury management: two-person review
- Anti-fraud whistleblowing mechanism: channel + protection
3.2 Audit
- Annual internal audit (finance + processes)
- Annual external audit (by accountants)
- Special audits (procurement / expenses / inventory counts)
4. Crisis management (emergency planning)
4.1 Three types of crises
| Type |
Case |
Consequence |
| Quality incident |
Samsung Galaxy Note 7 |
CNY 10 billion+ in losses + brand damage |
| Sudden policy change |
2021 e-cigarette regulation |
Industry reshuffle |
| Public opinion / PR |
Food safety |
Collapse of brand trust |
4.2 Five steps to a crisis plan
- Identify possible crises (risk list)
- Define trigger conditions (what activates the plan)
- Appoint owners (who commands / who speaks)
- Rehearse (annual tabletop exercise)
- Review (mandatory post-crisis retrospective)
4.3 Crisis-handling principles
- The golden 24 hours: respond fast > respond perfectly
- Communicate candidly: covering up only magnifies the problem
- Customer interests first: compensate first, argue later
- One voice externally: designate a spokesperson
5. Case studies
| Company |
Event |
Lesson |
| Enron |
Accounting fraud |
Missing internal controls = destruction |
| Luckin Coffee |
2020 fraud |
Internal controls + the integrity red line |
| Samsung |
Note 7 |
Mishandled quality crisis |
| Toyota |
2010 recalls |
Crisis PR: the right and wrong way |
| E-cigarette industry |
2021 policy |
Policy is the biggest risk variable |
📌 One-line summary: The goal of risk management is not to eliminate risk — it’s “don’t let any single risk kill you”: set red lines, prepare plans, keep redundancy.