Aon s Comprehensive Approach to Food Safety and Defense

Size: px
Start display at page:

Download "Aon s Comprehensive Approach to Food Safety and Defense"

Transcription

1 Aon s Comprehensive Approach to Food Safety and Defense March 2011 Aon Global Risk Consulting 200 East Randolph Street Chicago, IL Aon Corporation Aon Risk Solutions Global Risk Consulting

2 Aon s Comprehensive Approach to Food Safety and Defense The Food Safety Modernization Act (FSMA) was signed on January 4, 2011, and represents the first major overhaul of the FDA s food safety provisions since The Act does not materially change the food safety and defense risks inherent to agribusiness and food companies, but it highlights the industry s importance and requires risk management activities in the industry. The new law most notably grants the Department of Health and Human Services (HHS) and the Food and Drug Administration (FDA) regulatory authority to increase the frequency of inspections, to establish mandatory recall authority, to strengthen food import tracing capabilities, and to create open access to records and documentation. Among many FSMA provisions, one of the most critical is Section 103 which requires the owner, operator or agent of each registered facility to conduct a hazard analysis and implement preventive controls plans. The hazard analysis and risk-based preventive controls plan must include the identification and evaluation of all known or reasonably foreseeable hazards to the facility biological, chemical, physical, radiological hazards, natural toxins, pesticides, drug residues, parasites, allergens, or unapproved food additives. In addition, the facility owner, operator or agent must identify and implement preventative controls to assure and prevent any hazardous outbreak, formally monitor such controls, take corrective action when necessary, and maintain records of each. Anchored by a strong industry presence and dedicated Food System, Agribusiness and Beverage group, Aon has an extended and proven track record in helping clients manage food safety and defense risks. We offer end-to-end capabilities from risk assessment and quantification to insurance placements that not only allow our clients to comply with FSMA regulations, but enable them to optimize their risk management program in the face of an increasingly challenging marketplace. An Innovative Approach to Food Safety and Defense Over the past 24 months, as food-related risks and events have received significant publicity and scrutiny, Aon has leveraged industry expertise, risk knowledge, and thought leadership to develop innovative food safety and defense assessment capabilities. The results of our development efforts include the following: A proprietary Food Safety and Defense Assessment (FSDA TM ) tool A unique risk quantification platform developed in partnership with Sandia National Laboratories The unique combination of Aon s innovative tools and expertise provides our clients with customized and unmatched capabilities to meet our clients growing food safety and defense assessment needs. Food Safety and Defense Assessment (FSDA TM ) To address growing needs for industry-specific risk assessments, Aon has developed proprietary Food Safety and Defense Assessment (FSDA TM ) protocols. FSDA is a powerful tool for understanding how a food system business manages its risks and exposures. Aon s approach is predicated on the analysis of a range of food safety and defense management characteristics: including industry risks, product development, quality management, supplier management, contract risk management and the associated interrelationships. Aon Risk Solutions Global Risk Consulting 1

3 The deployment of Aon s FSDA TM solution has been developed to assist clients in meeting specific FSMA s requirements as described through the following outcomes: Diagnosing the maturity of current Food Safety and Food Defense systems and controls, including key benchmarks for Safe Quality Food Initiative (SQFI) certification. Identification of gaps and vulnerabilities in food products hazard analysis and preventive controls at various stages of product development, procurement/sourcing, defense and distribution, as well as contract risk management, allergens management and recalls. Development of action plans to address identified deficiencies in hazard analysis and preventive controls systems. Prioritization of mitigation plans to assist in risk reduction at both local and corporate levels. Reducing potential food-borne illnesses, product contamination and recalls. Providing continuous improvement and sustainable product quality, food safety and food defense management programs. Assisting in the management of Foreign Vendors Verification plans. Food Safety and Defense Risk Quantification Risk quantification takes the risk assessment further by incorporating advanced analytics, allowing for a broad range of food risk scenarios to be quantified. Additionally, it creates a foundation for a capital deployment decision framework in order to measure the potential impact of investments, de-risking the supply system from food safety or defense events. To provide industry-leading capabilities, Aon combined its industry and corporate risk quantification capabilities with the broad-based food system approach taken by Sandia National Laboratories (Sandia) resulting in an unmatched decision framework and food system risk knowledge. The Aon / Sandia risk quantification approach follows a straightforward, four-step process: 1. Supply system topology mapping to understand key concentration points and the interdependencies of the supply system from farm/field to end consumer 2. Risk identification and prioritization that builds on our FSDA TM and ERM (enterprise risk management) capabilities to create an understanding of the most significant and current supply system vulnerabilities as well as current mitigation strategies 3. Stochastic model construction and simulation results to quantify the existing food safety and defense risks in the supply system through thousands of computer-simulated scenarios 4. Mitigation strategy stress testing to compare the benefits of competing mitigation strategies, based on the risk scenarios generated through simulation (step three) The result is a comprehensive tool that enables food industry risk leaders to make better-informed decisions regarding their food safety and defense risk investments. Preparing in the Event Are you prepared to respond when the unexpected happens? The time to prepare for a potential contingency is not during the actual event, but well in advance. Business continuity management plans help ensure a catastrophe-resilient organization, which provide human capital and brand protection, improves supplier and customer relationships, enhancing financial performance in the time of a crisis. Aon Risk Solutions Global Risk Consulting 2

4 The Aon Business Continuity Management team does not directly address food or personnel safety. We do ensure that the emergency management component includes evacuation and personnel accountability, medical management and a formally established reporting protocol and hierarchy to senior management. Crisis and Business Continuity Management Aon s approach focuses on three main preparation and response components: Emergency Management This is one of the traditional components most often addressed in business continuity planning. It involves immediate first-hour reaction to any interruption event including injury, fire, flood, chemical spill and similar events. Any current emergency management/response procedures that exist will be reviewed and incorporated into this process. We will work with your organization to formalize the decision-making framework and capture the management actions necessary to stabilize the situation (e.g., notification, activation, escalation, assessment and management). Note: We do not address the following activities which are normally part of a comprehensive emergency response program: training of the emergency response team and employees; incidentspecific emergency response protocols and procedures development; emergency operations center layout, staffing, equipment, and infrastructure requirement definitions. Crisis Management & Communications This provides the decision-making framework to ensure communication structure and strategy both internal and external are properly executed to protect the organization s brand and reputation during an event. We provide a workshop for key management that outlines their role in leadership, decision-making, communications, and control, focusing on identification of triggers and escalation points, team deployment and event recognition, escalation and plan activation. The workshop does not include training of the recovery communications team and employees in media handling; message substance, timing and development review, including sample messages; target audience information dissemination; spokesperson identification and training; layout, location, staffing and equipment of the crisis command center; detailed media strategy; and communication structure, policies and procedures. Business Restoration & Operational Recovery This component involves longer-term actions designed to bring business operations back to pre-disaster levels as quickly and effectively as possible. Our focus is to restore the functions, applications, systems, and processes rather than individual buildings or facilities, although the two may be intermingled. The actions captured in the plan are based upon a recovery time objective that is developed during collaborative sessions with the departments and steering committee after understanding the department requirements. Aon s Continuity Blueprint, which has been adopted by many clients, is a critical component of crisis communications and business continuity management that helps organizations implement and maintain an effective approach to continuity planning. The Continuity Blueprint methodology reduces deployment and activation time when compared to other planning approaches. This allows users of the plan to implement response and recovery procedures, by department or business unit, following pre-determined timelines. The goal of a crisis communication and business continuity management program is to create a catastropheresilient organization. Aon s planning approach leverages years of hands-on experience serving clients and it Aon Risk Solutions Global Risk Consulting 3

5 aligns with accepted standards, practices and guidelines 1. Aon s process is designed to deliver strong core competencies in the following areas: Program management Risk evaluation, control and remediation Business impact analysis Business continuity strategies Emergency management & response Crisis management & communications Business restoration & operational recovery Plan audits, awareness and training, maintenance and testing Risk Transfer Although risk transfer does not decrease the likelihood of a food safety or food defense event, it can significantly mitigate its financial impact on your organization. Risk transfer, as related to food events, can potentially cover product recall or accidental, or intentional / deliberate (i.e., economically motivated adulteration) or malicious product tampering/adulteration (product contamination) incidents. Aon has a dedicated practice devoted to production recall and contamination and has the market knowledge to construct the best policy for client needs, which may include several first- and third-party options for product contamination: First-Party Covers Recall Expense Repair, Replacement or Refund Business Interruption Brand Rehabilitation Consulting Costs Third-Party Covers Recall Expense Recall Liability - Broad Recall Liability - Named The coverage options that best suit your organization are dependent on many characteristics, such as company and product profile, packaging, QA/QC procedures, product shelf life and use life, geographic distribution, manufacturing locations, and other supply system factors. Risk assessment, risk quantification, and business continuity expertise can also be used to find the most appropriate coverage from a cost benefit perspective. 1 Includes National Fire Protection Association (NFPA) Standard on Disaster / Emergency Management and Business Continuity Programs ; Disaster Recovery Institute International (DRII) - Professional Practices for Business Continuity; National Institute of Standards and Technology (NIST) Special Publication ; ISO 17799; BCI Business Continuity Management Good Practice Guide; FEMA Emergency Management Guide for Business & Industry and the FFIEC Business Continuity Planning guide Aon Risk Solutions Global Risk Consulting 4

6 Combining all of the Ingredients A Comprehensive Risk Management Approach Aon s multi-disciplinary approach examines your food safety and food defense programs from multiple angles, pinpointing vulnerabilities and gaps, identifying potential continuity and risk transfer solutions, and building a framework for investment decisions to protect the firm against accidental and intentional events. This process can assist in establishing a foundation for the new requirements included in the Food Safety and Modernization Act. When all the ingredients are combined, Aon s industry-leading expertise, unparalleled partnerships (Sandia), innovative assessment tools, crisis management experience, and specialized product recall and contamination insurance expertise are unrivaled in the industry. No other risk advisory firm can match the level of service and commitment to clients. For more information, please contact: Food System, Agribusiness and Beverage Group Rick Shanks Practice Leader rick.shanks@aon.com Food Safety & Defense Assessment (FSDA TM ) George Nassif george.nassif@aon.com Food Safety and Defense Risk Quantification Mike Giacobbe mike.giacobbe@aon.com Crisis Management Planning & Preventive Controls Philip Huntley philip.huntley@nyainternational.com Business Continuity Planning Jim Pinzari james.pinzari@aon.com Head of Crisis Management Americas Bernie Steves bernie.steves@aon.com About Aon Aon Corporation (NYSE: AON) is the leading global provider of risk management services, insurance and reinsurance brokerage, and human capital consulting. Through its more than 59,000 colleagues worldwide, Aon delivers distinctive client value via innovative and effective risk management and workforce productivity solutions. Aon's industry-leading global resources and technical expertise are delivered locally through more than 500 offices in more than 120 countries. Named the world's best broker by Euromoney magazine's 2008, 2009 and 2010 Insurance Survey, Aon also ranked highest on Business Insurance's listing of the world's largest insurance brokers based on commercial retail, wholesale, reinsurance and personal lines brokerage revenues in 2008 and Visit for more information. Aon Risk Solutions Global Risk Consulting 5

Aon Risk Solutions. Life Sciences Practice. Providing End-to-End Solutions for Life Sciences Companies. Risk. Reinsurance. Human Resources.

Aon Risk Solutions. Life Sciences Practice. Providing End-to-End Solutions for Life Sciences Companies. Risk. Reinsurance. Human Resources. Aon Risk Solutions Life Sciences Practice Providing End-to-End Solutions for Life Sciences Companies Risk. Reinsurance. Human Resources. 1 The Life Cycle Risk Continuum An overview of industry-specific

More information

FOOD FOR THOUGHT Topical Insights from our Subject Matter Experts

FOOD FOR THOUGHT Topical Insights from our Subject Matter Experts FOOD FOR THOUGHT Topical Insights from our Subject Matter Experts A PHASED APPROACH TO PROVIDE A COMPLETE AND COMPLIANT CHEMICAL HAZARD ANALYSIS OF YOUR INCOMING INGREDIENTS The NFL White Paper Series

More information

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis

More information

Restaurants & Hospitality

Restaurants & Hospitality TRADE NAME RESTORATION (TNR ) Business Interruption Coverage For Food Borne Illness Restaurants & Hospitality These Industries May Need More Than Just Traditional Coverages Policy Property General Liability

More information

Safety Management Function Organization and Responsibilities

Safety Management Function Organization and Responsibilities Safety Management Function Organization and Responsibilities An Aon Survey September 2011 Aon Global Risk Consulting Casualty Risk Consulting Christopher Iovino, Managing Director 2011 Aon Corporation

More information

Aon Risk Solutions Global Risk Consulting Captive & Insurance Management. Cyber risk and the captive market - a match made in the cloud?

Aon Risk Solutions Global Risk Consulting Captive & Insurance Management. Cyber risk and the captive market - a match made in the cloud? Aon Risk Solutions Global Risk Consulting Captive & Insurance Management Cyber risk and the captive market - a match made in the cloud? With increasing news coverage of cyber-attacks and despite indications

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

Executive Liability Insurance

Executive Liability Insurance Aon Risk Solutions Financial Services Group Life Sciences Industry Practice Executive Liability Insurance Solutions from Experts in the Life Sciences Industry Challenges on the Rise for Life Sciences Companies

More information

FFIEC Cybersecurity Assessment Tool

FFIEC Cybersecurity Assessment Tool Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,

More information

Vendor Management. Outsourcing Technology Services

Vendor Management. Outsourcing Technology Services Vendor Management Outsourcing Technology Services Objectives Board and Senior Management Responsibilities Risk Management Program Risk Assessment Service Provider Selection Contracts Ongoing Monitoring

More information

MHA Consulting. Business Continuity Management 101

MHA Consulting. Business Continuity Management 101 0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Factsheet To prepare for change, change the way you prepare In an intensely competitive environment, a permanent market presence is essential in order to satisfy customers

More information

Effective Dates and FDA Requirements in the FDA Food Safety Modernization Act Prepared by Hogan Lovells US LLP, February 2011

Effective Dates and FDA Requirements in the FDA Food Safety Modernization Act Prepared by Hogan Lovells US LLP, February 2011 in the FDA Food Safety Modernization Act Prepared by Hogan Lovells US LLP, February 2011 Provision Facility Registration Food facilities are required to register with FDA every 2 years, starting in 2012,

More information

HSMS. Group Health AND Safety Management System

HSMS. Group Health AND Safety Management System 3 2 CONSULTATION AND EMPOWERMENT 4 RISK MANAGEMENT 1 AMBITION, POLICY AND RULES LEADERSHIP, ACCOUNTABILITY AND ORGANISATION PLAN AND COMMIT 5 EMERGENCY PREPAREDNESS 10 AUDIT AND MATURITY PATH 9 LEARN AND

More information

Principles for BCM requirements for the Dutch financial sector and its providers.

Principles for BCM requirements for the Dutch financial sector and its providers. Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011

More information

CYBER AND PRIVACY INSURANCE: LOSS MITIGATION SERVICES

CYBER AND PRIVACY INSURANCE: LOSS MITIGATION SERVICES CYBER AND PRIVACY INSURANCE: LOSS MITIGATION SERVICES How can you better prepare and respond to cyber risks? ACE developed Loss Mitigation Services to help policyholders understand and gauge various areas

More information

Response XL North America. XL Group Insurance. Product Recall

Response XL North America. XL Group Insurance. Product Recall Response XL North America XL Group Insurance Product Recall 01 Introduction 02 Our network and approach 03 Our crisis and risk management consulting service 04 The Response XL service We understand that

More information

Incident Management & Communications. Top 8 Focus Areas to Mitigate Risk

Incident Management & Communications. Top 8 Focus Areas to Mitigate Risk Incident Management & Communications Top 8 Focus Areas to Mitigate Risk Incident Management & Communications Top 8 Focus Areas to Mitigate Risk Delays and errors in operational communications happen every

More information

Enterprise Information Management for the Food and Beverage Industry

Enterprise Information Management for the Food and Beverage Industry Enterprise Information Management for the Food and Beverage Industry Integrate information across systems, functions, and the supply chain Today s global business and regulatory environments are too complex

More information

fs viewpoint www.pwc.com/fsi

fs viewpoint www.pwc.com/fsi fs viewpoint www.pwc.com/fsi June 2013 02 11 16 21 24 Point of view Competitive intelligence A framework for response How PwC can help Appendix It takes two to tango: Managing technology risk is now a

More information

The Role of Internal Audit In Business Continuity Planning

The Role of Internal Audit In Business Continuity Planning The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. dan.bailey@protiviti.com Actively involved in the Information

More information

Organization transformation in times of change

Organization transformation in times of change Organization transformation in times of change Insurance is sold, not bought is a phrase of unknown attribution, but common wisdom for decades. Thus, insurers and most financial services organizations

More information

Product Recall. Written by Michael Lincoln and Donna Niblock. The Liberty White Paper Series

Product Recall. Written by Michael Lincoln and Donna Niblock. The Liberty White Paper Series Product Recall Written by Michael Lincoln and Donna Niblock The Liberty White Paper Series Executive Summary The growth of the global supply chain in recent years has had a significant impact on managing

More information

MANAGING THE COMPLEXITIES OF GLOBAL PHARMACEUTICAL SOURCING

MANAGING THE COMPLEXITIES OF GLOBAL PHARMACEUTICAL SOURCING DPT Thought Leadership Issue 10 MANAGING THE COMPLEXITIES OF GLOBAL PHARMACEUTICAL SOURCING With the increased globalization and complexity of the pharmaceutical supply chain, managing the sourcing of

More information

Emergency Management & Business Continuity Program Self-Assessment Checklist

Emergency Management & Business Continuity Program Self-Assessment Checklist Emergency Management & Business Continuity Program Self-Assessment Checklist Self-assessment tool for evaluating preparedness based on NFPA 1600 Standard on Disaster/Emergency Management and Business Continuity

More information

Shell s Health, Safety and Environment (HSE) management system (see Figure 11-1) provides the framework for managing all aspects of the development.

Shell s Health, Safety and Environment (HSE) management system (see Figure 11-1) provides the framework for managing all aspects of the development. Section 11.1 APPLICATION FOR APPROVAL OF THE DEVELOPMENT PLAN FOR NIGLINTGAK FIELD PROJECT DESCRIPTION INTRODUCTION 11.1.1 HSE MANAGEMENT SYSTEM Shell s Health, Safety and Environment (HSE) management

More information

Mitigating and managing cyber risk: ten issues to consider

Mitigating and managing cyber risk: ten issues to consider Mitigating and managing cyber risk: ten issues to consider The board of directors is responsible for managing and mitigating risk exposure. A recent study conducted by the Ponemon Institute 1 revealed

More information

CYBER & PRIVACY LIABILITY INSURANCE GUIDE

CYBER & PRIVACY LIABILITY INSURANCE GUIDE CYBER & PRIVACY LIABILITY INSURANCE GUIDE 01110000 01110010 011010010111011001100001 01100 01110000 01110010 011010010111011001100001 0110 Author Gamelah Palagonia, Founder CIPM, CIPT, CIPP/US, CIPP/G,

More information

US Food Safety Modernization Act:

US Food Safety Modernization Act: US Food Safety Modernization Act: Overview and Impact for Importers and Exporters August 2012 This paper covers important updates related to the US Food Safety Modernization Act (FSMA) and recent changes

More information

2014 NABRICO Conference

2014 NABRICO Conference Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000

More information

CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS

CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS 1 As regulators around the world move to tighten compliance requirements for financial institutions, improvement in cyber security controls will become

More information

Overview. Emergency Response. Crisis Management

Overview. Emergency Response. Crisis Management Prudential Financial s Preparedness Strategy Overview Emergency Response, Crisis Management, Business Continuation, Technology Disaster Recovery & Health Crisis Preparedness Prudential is committed to

More information

SAFETY and HEALTH MANAGEMENT STANDARDS

SAFETY and HEALTH MANAGEMENT STANDARDS SAFETY and HEALTH STANDARDS The Verve Energy Occupational Safety and Health Management Standards have been designed to: Meet the Recognised Industry Practices & Standards and AS/NZS 4801 Table of Contents

More information

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact. Aon Business Continuity Planning The Aon Business Continuity Planning practice provides consulting services that allow Aon clients to measure and manage their strategic and tactical risks through Crisis

More information

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Business Continuity and Emergency Preparedness Planning Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Overview Define key terms and list essential elements of business continuity

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

Client Engagement and Compensation Guide

Client Engagement and Compensation Guide Aon Risk Solutions Client Engagement and Compensation Guide Risk. Reinsurance. Human Resources. Introduction The aim of this document is to provide a high-level summary of the work that Aon Risk Solutions

More information

Building and Maintaining a Business Continuity Program

Building and Maintaining a Business Continuity Program Building and Maintaining a Business Continuity Program Successful strategies for financial institutions for effective preparation and recovery Table of Contents Introduction...3 This white paper was written

More information

THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS

THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS Read the Marsh Risk Management Research Briefing: Cyber Risks Extend Beyond Data and Privacy Exposures To access the report, visit www.marsh.com.

More information

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk

More information

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION EXCERPT FROM THE FOREWORD TO THE 2ND EDITION The events of 9/11 have cast a long shadow over the world and led to a vital reappraisal of Enterprise Risk

More information

Cybersecurity: Considerations for Internal Audit. IIA Atlanta Chapter Meeting January 9, 2015

Cybersecurity: Considerations for Internal Audit. IIA Atlanta Chapter Meeting January 9, 2015 Cybersecurity: Considerations for Internal Audit IIA Atlanta Chapter Meeting January 9, 2015 Agenda Key Risks Incorporating Internal Audit Resources for Internal Auditors Questions 2 Key Risks 3 4 Key

More information

FDA 50-State Conference Call OIG Early Alert on FDA s Voluntary Food Recall Initiation Process. June 10, 2016 2:30 pm EDT

FDA 50-State Conference Call OIG Early Alert on FDA s Voluntary Food Recall Initiation Process. June 10, 2016 2:30 pm EDT Page 1 FDA 50-State Conference Call OIG Early Alert on FDA s Voluntary Food Recall Initiation Process June 10, 2016 2:30 pm EDT Operator: Welcome and thank you for standing by. At this time, all lines

More information

Captive & Insurance Management

Captive & Insurance Management Aon Risk Solutions Global Risk Consulting Captive & Insurance Management Location of captive parent company 500+ captives 250-500 captives 51-249 captives 10-50 captives

More information

Rethinking contingency planning for an integrated world

Rethinking contingency planning for an integrated world Business Continuity* January 2010 Rethinking contingency planning for an integrated world Highlights: Increased supply chain complexities require broadened scope of contingency planning. Increasing outsourcing

More information

Disaster Recovery Journal Spring World 2014

Disaster Recovery Journal Spring World 2014 Disaster Recovery Journal Spring World 2014 What works: Services and service supply chain business continuity risk management Don Hall, CBCP, Cisco Services Business Continuity Analyst Cisco Systems, Inc.

More information

TSM ASSESSMENT PROTOCOL

TSM ASSESSMENT PROTOCOL TSM ASSESSMENT PROTOCOL A Tool for Assessing Crisis Management and Communications Planning Performance Purpose The purpose of the assessment protocol is to provide guidance to the member companies in completing

More information

Cybersecurity and internal audit. August 15, 2014

Cybersecurity and internal audit. August 15, 2014 Cybersecurity and internal audit August 15, 2014 arket insights: what we are seeing so far? 60% of organizations see increased risk from using social networking, cloud computing and personal mobile devices

More information

Business Continuity Planning. Presentation and. Direction

Business Continuity Planning. Presentation and. Direction Business Continuity Planning Presentation and Direction Thomas Bronack, president Data Center Assistance Group, Inc. 15180 20 th Avenue Whitestone, NY 11357 Phone: (718) 591-5553 Email: bronackt@dcag.com

More information

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015 Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level June 9, 2015 By: Tracy Hall MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company,

More information

Moving Forward with IT Governance and COBIT

Moving Forward with IT Governance and COBIT Moving Forward with IT Governance and COBIT Los Angeles ISACA COBIT User Group Tuesday 27, March 2007 IT GRC Questions from the CIO Today s discussion focuses on the typical challenges facing the CIO around

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

Evaluating and Improving Your Business Continuity Plan

Evaluating and Improving Your Business Continuity Plan Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015 Contact Information Karen Weir, MAC, CISA, CBCP Manager kweir@accretivesolutions.com

More information

Click here to order the IFSQN FSSC 22000 Certification Package Now

Click here to order the IFSQN FSSC 22000 Certification Package Now This comprehensive Food Safety Management System Certification package contains all the tools you will need to achieve FSSC 22000 Certification. This workbook is provided to assist in the implementation

More information

CRR Supplemental Resource Guide. Volume 6. Service Continuity Management. Version 1.1

CRR Supplemental Resource Guide. Volume 6. Service Continuity Management. Version 1.1 CRR Supplemental Resource Guide Volume 6 Service Continuity Management Version 1.1 Copyright 2016 Carnegie Mellon University This material is based upon work funded and supported by Department of Homeland

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

How To Plan A Crisis Management Program

How To Plan A Crisis Management Program Building a Security Conscious Business Continuity Management (BCM) Program Sam Stahl, CBCP, MBCI EMC Global Professional Services Program Manager stahl_samuel@emc.com ASIS Singapore, 2014 Agenda Overview

More information

Real Estate Practice. Fact-Based Solutions for Real Estate Risk Management. Risk. Reinsurance. Human Resources.

Real Estate Practice. Fact-Based Solutions for Real Estate Risk Management. Risk. Reinsurance. Human Resources. Aon Risk Solutions Real Estate Practice Real Estate Practice Fact-Based Solutions for Real Estate Risk Management Risk. Reinsurance. Human Resources. Today s Real Estate Risk Trends and Priorities Our

More information

Business Management System Manual. Context, Scope and Responsibilities

Business Management System Manual. Context, Scope and Responsibilities Business Management System BMS Manual Page 1 of 11 Business Management System Manual Context, Scope and Responsibilities ISO 9001:2015 BMS.0100 R1 MAS Solutions LLC 29810 FM 1093 Suite C Fulshear, TX 77441

More information

MARSH REPORT October 2015. International Business Resilience Survey 2015

MARSH REPORT October 2015. International Business Resilience Survey 2015 MARSH REPORT October 2015 International Business Resilience Survey 2015 CONTENTS October 2015 CONTENTS 3 Introduction 4 Non-traditional risks top concerns, both in terms of likelihood and impact 7 Insurance

More information

CISM Certified Information Security Manager

CISM Certified Information Security Manager CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective

More information

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013 Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013 Chitra Gopalakrishnan Director KPMG LLP Agenda Introduction Business Continuity / Disaster

More information

INSURANCE. Moody s Analytics Solutions for the Insurance Company

INSURANCE. Moody s Analytics Solutions for the Insurance Company INSURANCE Moody s Analytics Solutions for the Insurance Company Moody s Analytics Solutions for the Insurance Company HELPING PROFESSIONALS OVERCOME TODAY S CHALLENGES Recent market events have emphasized

More information

Industrial Cyber Security Risk Manager. Proactively Monitor, Measure and Manage Industrial Cyber Security Risk

Industrial Cyber Security Risk Manager. Proactively Monitor, Measure and Manage Industrial Cyber Security Risk Industrial Cyber Security Risk Manager Proactively Monitor, Measure and Manage Industrial Cyber Security Risk Industrial Attacks Continue to Increase in Frequency & Sophistication Today, industrial organizations

More information

SQF Level 2 Proposed Preventive Controls Comparison Modules 2 & 11

SQF Level 2 Proposed Preventive Controls Comparison Modules 2 & 11 http://leavittpartners.com/global-food-solutions Contact: david.acheson@leavittpartners.com April 2013 SQF Level 2 Proposed Preventive Controls Comparison Modules 2 & 11 Introduction SQF Level 2, which

More information

Is Business Continuity Certification Right for Your Organization?

Is Business Continuity Certification Right for Your Organization? 2008-2013 AVALUTION CONSULTING, LLC ALL RIGHTS RESERVED i This white paper analyzes the business case for pursuing organizational business continuity certification, including what it takes to complete

More information

RISK MANAGEMENT REPORT (for the Financial Year Ended 31 March 2012)

RISK MANAGEMENT REPORT (for the Financial Year Ended 31 March 2012) RISK MANAGEMENT REPORT (for the Financial Year Ended 31 March 2012) Integrated Risk Management Framework The Group s Integrated Risk Management Framework (IRMF) sets the fundamental elements to manage

More information

Does Fraud Matter? ASIS Middle East Security Conference and Exhibition Dubai, February 16, 2015. Torsten Wolf, CPP Head of Group Security Operations

Does Fraud Matter? ASIS Middle East Security Conference and Exhibition Dubai, February 16, 2015. Torsten Wolf, CPP Head of Group Security Operations Does Fraud Matter? ASIS Middle East Security Conference and Exhibition Dubai, February 16, 2015 Torsten Wolf, CPP Head of Group Security Operations Agenda Introduction Economic Crime Landscape Economic

More information

MONTGOMERY COUNTY, KANSAS EMERGENCY OPERATIONS PLAN. ESF14-Long Term Community Recovery

MONTGOMERY COUNTY, KANSAS EMERGENCY OPERATIONS PLAN. ESF14-Long Term Community Recovery MONTGOMERY COUNTY, KANSAS EMERGENCY OPERATIONS PLAN ESF14-Long Term Community Recovery Planning Team Support Agency Coffeyville Public Works Independence Public Works Montgomery County Public Works 1/15/2009

More information

Managing Risk at Bank of America Corporation. Overview

Managing Risk at Bank of America Corporation. Overview Managing Risk at Bank of America Corporation Overview Risk is inherent in every material business activity that we undertake. Our business exposes us to strategic, credit, market, liquidity, compliance,

More information

Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization

Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization Internal Audit Quality Assessment Presented To: World Intellectual Property Organization April 2014 Table of Contents List of Acronyms 3 Page Executive Summary Opinion as to Conformance to the Standards,

More information

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,

More information

Risk Management Primer

Risk Management Primer Risk Management Primer Purpose: To obtain strong project outcomes by implementing an appropriate risk management process Audience: Project managers, project sponsors, team members and other key stakeholders

More information

Appendix 3 Disaster Recovery Plan

Appendix 3 Disaster Recovery Plan Appendix 3 Disaster Recovery Plan December 13, 2006 Revision XXQwest Government Services, Inc. 4250 North Fairfax DriveArlington, VA 22203(Delete this page)revision history Revision Number Revision Date

More information

PBSi Business Continuity Planning

PBSi Business Continuity Planning Business Continuity Planning Definition Business Continuity planning is a planning process designed to reduce the risk that disruptive failures or events could seriously harm your business. It is designed

More information

Desktop Scenario Self Assessment Exercise Page 1

Desktop Scenario Self Assessment Exercise Page 1 Page 1 Neil Jarvis Head of IT Security & IT Risk DHL Page 2 From reputation to data loss - how important is business continuity? Neil Jarvis Head of IT Security (EMEA) DHL Logistics IT Security Taking

More information

Title: Rio Tinto management system

Title: Rio Tinto management system Standard Rio Tinto management system December 2014 Group Title: Rio Tinto management system Document No: HSEC-B-01 Standard Function: Health, Safety, Environment and Communities (HSEC) No. of pages: 23

More information

BUSINESS CONTINUITY POLICY

BUSINESS CONTINUITY POLICY BUSINESS CONTINUITY POLICY Document Type Corporate Policy Unique Identifier CO-038 Document Purpose To provide a structure through which: i. A comprehensive business continuity management system (BCMS)

More information

GUIDELINES FOR FOOD IMPORT CONTROL SYSTEMS

GUIDELINES FOR FOOD IMPORT CONTROL SYSTEMS GUIDELINES FOR FOOD IMPORT CONTROL SYSTEMS SECTION 1 SCOPE CAC/GL 47-2003 1. This document provides a framework for the development and operation of an import control system to protect consumers and facilitate

More information

10-POINT FRAMEWORK. for Pandemic Influenza Business Preparedness

10-POINT FRAMEWORK. for Pandemic Influenza Business Preparedness 10-POINT FRAMEWORK for Pandemic Influenza Business Preparedness In using this business framework, keep in mind the following principles: The framework is intended to serve as a guideline to trigger business

More information

SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 BUSINESS CONTINUITY GUIDELINES

SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 BUSINESS CONTINUITY GUIDELINES SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 Business Continuity Issued: 1 st May, 2007 Revised: 14 th October 2008 BUSINESS CONTINUITY GUIDELINES I. INTRODUCTION The Central Bank of The Bahamas (

More information

An Introduction to ISO 22000: Food Safety Management Systems

An Introduction to ISO 22000: Food Safety Management Systems : Food Safety Management Systems Stefan Nygren What is ISO 22000? ISO 22000, Food safety management systems - Requirements for any organization in the food chain, was first published in 2005. The standard

More information

T31: Before, During and After Outsourcing David Fong, BlackRock

T31: Before, During and After Outsourcing David Fong, BlackRock T31: Before, During and After Outsourcing David Fong, BlackRock Before, During and After Outsourcing David Fong, CISA, CPA Objective o Explore reasons why some organizations choose to outsource o Understanding

More information

GLOBAL PROPERTY. Commercial Property START

GLOBAL PROPERTY. Commercial Property START Commercial Property START A LEADER About Global Property AIG s Global Property division brings sophisticated and extensive capabilities to our clients risk management programs. AIG s unrivalled worldwide

More information

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance

Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance Be Afraid, Be Very Afraid!!! Hacking Out the Pros and Cons of Captive Cyber Liability Insurance Today s agenda Introductions Cyber exposure overview Cyber insurance market and coverages Captive cyber insurance

More information

Cybersecurity The role of Internal Audit

Cybersecurity The role of Internal Audit Cybersecurity The role of Internal Audit Cyber risk High on the agenda Audit committees and board members are seeing cybersecurity as a top risk, underscored by recent headlines and increased government

More information

Improving Cyber Security Risk Management through Collaboration

Improving Cyber Security Risk Management through Collaboration CTO Corner April 2014 Improving Cyber Security Risk Management through Collaboration Dan Schutzer, Senior Technology Consultant, BITS Back in March 2013, I wrote a CTO Corner on Operational and Cyber Risk

More information

Symantec Security Compliance Solution Symantec s automated approach to IT security compliance helps organizations minimize threats, improve security,

Symantec Security Compliance Solution Symantec s automated approach to IT security compliance helps organizations minimize threats, improve security, Symantec Security Compliance Solution Symantec s automated approach to IT security compliance helps organizations minimize threats, improve security, streamline compliance reporting, and reduce the overall

More information

ORACLE CONSULTING GROUP

ORACLE CONSULTING GROUP ORACLE CONSULTING GROUP An Official United States Agent Firm for Foreign Establishments CONSULTING MEMORANDUM: DEALING WITH A MEDICAL DEVICE IN THE U.S. 5398 Golder Ranch Rd., Ste. 1 Tucson, Arizona 85739

More information

CGI Cyber Risk Advisory and Management Services for Insurers

CGI Cyber Risk Advisory and Management Services for Insurers CGI Cyber Risk Advisory and Management Services for Insurers Minimizing Cyber Risks cgi.com 3 As organizations seek to create value in today s highly interconnected world, they inherently increase their

More information

Welcome to Modulo Risk Manager Next Generation. Solutions for GRC

Welcome to Modulo Risk Manager Next Generation. Solutions for GRC Welcome to Modulo Risk Manager Next Generation Solutions for GRC THE COMPLETE SOLUTION FOR GRC MANAGEMENT GRC MANAGEMENT AUTOMATION EASILY IDENTIFY AND ADDRESS RISK AND COMPLIANCE GAPS INTEGRATED GRC SOLUTIONS

More information

Disaster Recovery/Business Continuity

Disaster Recovery/Business Continuity CITY AUDITOR'S OFFICE Disaster Recovery/Business Continuity March 6, 2015 AUDIT REPORT NO. 1511 CITY COUNCIL Mayor W.J. Jim Lane Suzanne Klapp Virginia Korte Kathy Littlefield Vice Mayor Linda Milhaven

More information

Security. Security consulting and Integration: Definition and Deliverables. Introduction

Security. Security consulting and Integration: Definition and Deliverables. Introduction Security Security Introduction Businesses today need to defend themselves against an evolving set of threats, from malicious software to other vulnerabilities introduced by newly converged voice and data

More information

The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant

The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant THE MARKET LEADER IN IT, SECURITY AND COMPLIANCE SERVICES FOR COMMUNITY FINANCIAL INSTITUTIONS The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant Agenda

More information

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities

More information

Enterprise Security Tactical Plan

Enterprise Security Tactical Plan Enterprise Security Tactical Plan Fiscal Years 2011 2012 (July 1, 2010 to June 30, 2012) Prepared By: State Chief Information Security Officer The Information Security Council State of Minnesota Enterprise

More information

Information Technology

Information Technology Information Technology Information Technology Session Structure Board of director actions Significant and emerging IT risks Practical questions Resources Compensating Controls at the Directorate Level

More information