ENTERPRISE RISK MANAGEMENT ASSESSMENT GUIDE
|
|
|
- Rhoda Norton
- 9 years ago
- Views:
Transcription
1 ENTERPRISE RISK MANAGEMENT ASSESSMENT GUIDE WHITEPAPER
2 CONTENTS CONTENTS INTRODUCTION 1 IS YOUR RISK MANAGEMENT PROCESS REALLY ASSESSING RISK? 1 IS YOUR RISK ASSESSMENT CONTEXT DRIVEN? 2 DOES YOUR RISK MANAGEMENT PROCESS ADDRESS ROOT CAUSE OF FAILURE? 2 WHAT DOES YOUR BUSINESS PERFORMANCE TELL YOU ABOUT RISK? 3 WHAT DO RISKS TELL YOU ABOUT YOUR CONTROLS? 4 WHAT DO CONTROLS TELL YOU ABOUT YOUR RISKS? 5 ARE YOU UP FOR THE TASK OF RISK MANAGEMENT? 6 KNOWLEDGE AND EXPERIENCE REQUIREMENTS FOR RISK MANAGEMENT LEADERS 6 ABOUT THOMSON REUTERS 7 II
3 INTRODUCTION Government bail outs, pro-cyclical financial markets, and an overall economic meltdown have placed a significant focus on the discipline and practice of risk management. In light of these events, risk professionals and organizational leaders are taking an introspective view of their risk management practices. By considering these seven questions, organizations and risk professionals will sharpen their daily risk management tools and be better equipped to make tactical improvements to risk management practices. 1. Is Your Risk Management Process Really Assessing Risk? 2. Is Your Risk Assessment Context-Driven? 3. Does Your Risk Management Process Address Root Cause of Failure? 4. What Does Your Business Performance Tell You About Risk? 5. What Do Risks Tell You About Your Controls? 6. What Do Controls Tell You About Your Risks? 7. Are You Up For the Task of Risk Management? IS YOUR RISK MANAGEMENT PROCESS REALLY ASSESSING RISK? In far too many cases the answer to this question is NO. Many so-called risk management processes are not necessarily identifying and assessing risks. Many risk management practices, as implemented, are simply identifying and assessing the risk of control failure, not the specific risk the control is to mitigate. Risk-based thinking approaches the assessment with the premise that risks are predictable and avoidable. The risk-based discipline tracks loss events, analyzes root causes, and eliminates or mitigates the cause of the risk failure. Control-based thinking takes the approach that events are unpredictable and unavoidable, and controls are needed to mitigate the risks. Negative impacts are the result of broken controls, not of unidentified or mitigated risks. Risk-based thinking approaches the assessment with the premise that risks are predictable and avoidable. A simple indicator on the general emphasis on controls versus risks in common practice is outlined in the table below which reflects the word count comparison of two risk management frameworks (Basel II and ISO 31000) and several well-known control frameworks including the risk-based PCAOB AS5, ISO 27001, and the COSO Guidance on Monitoring Internal Control Systems. The word count is a simple tally of where the words risk and control appear in the referenced documents. The relevant emphasis on risk and control is evidenced in the word counts. WORD COUNT COMPARISON Risk Control Basel II 1, ISO/DIS COSO Monitoring (Volumes 1 and 2) ISO 27001: PCAOB AS
4 If a risk is defined as a broken or failed control, a control-based approach is in use and controls are primarily being assessed, not risks. If inherent or residual risks are not measured and assessed, a control-based approach is being used and controls, not risks, are being assessed. It is imperative to know what risks the controls are addressing and to identify those risks first. If an organization reports on control effectiveness over risks, controls and not risks are being assessed. Risks are just there to hang controls from, not to be understood and managed. There is nothing wrong with identifying and assessing controls. It is a perfectly valid approach. But by itself it is insufficient and has proven to be inherently unreliable. It is imperative to know what risks the controls are addressing and to identify those risks first. For example, little faith would be put in a doctor who prescribed medication without identifying symptoms, e.g., performing a risk assessment. Don t trust control assessments where no risk assessment is conducted (or vice versa). IS YOUR RISK ASSESSMENT CONTEXT DRIVEN? Black swans hide where no one thinks to look. The history of risk assessment suggests that at least half of the problem is not looking in the right place for risks. The other half is looking in the right places and failing to find the risk. Context-driven risk assessment refers to the process of identifying all the topics or areas that need to be risk assessed. Contexts can be accounts, strategies, laws and regulations, organization entities, lines of business or any other relevant topic areas. It is wrong to believe that the right contexts will be identified and addressed from within the organization by business operational managers and professionals. These leaders have typically been proven to be blinded by narrow vision, short range thinking, or do not have perspective across the entire entity to have a good handle on the enterprise-wide risks. Therefore, context must be identified at the organization level and the related risk assessments must be coordinated by senior management and the board. DOES YOUR RISK MANAGEMENT PROCESS ADDRESS ROOT CAUSE OF FAILURE? With control-based approaches, there is typically no requirement for root cause analysis. In the control-based approach, control breakdowns simply need to be identified and reported, regardless if the root cause remains obscure. For example with PCAOB AS5 there is no requirement for the identification, reporting or remediation of any related root cause. Publicly-reported significant deficiencies and material weaknesses do not require and seldom receive any root cause analysis. The COSO Guidance on Monitoring Internal Control Systems does not require root cause analysis nor does ISO It would be unthinkable today for an airplane to crash or a bridge to collapse without a detailed public report on the root cause and measures taken to ensure the problem does not reoccur. This degree of scrutiny does not generally exist in the risk management professions. Notable exceptions are the quality, safety and environmental movements. Generally speaking, if incidents, near misses and loss events are not tracked, the root cause of failure will not be analyzed. If the root cause of failure is not addressed the problem will be repeated. The following table, created by the U.S. General Accounting Office lists the causes of bank failures in the U.S. Although created in 1987, it could have been written last week. 2
5 ROOT CAUSES OF BANK FAILURES (1987) % OF BANKS Management Philosophy and Operating Style Inadequate board supervision 49% Over reliance on volatile funding sources 32% Presence of dominant figure 37% Excessively growth oriented philosophies 26% Management Operational Practices Lack of general lending policies 79% Poor loan administration 42% Poor loan documentation/inadequate credit analysis 41% Inadequate loan loss allowance 29% WHAT DOES YOUR BUSINESS PERFORMANCE TELL YOU ABOUT RISK? Many risk and control practitioners fail to consider business performance when assessing either risk or control. In other words, it is not only possible, but common, to get a passing mark on risk management or control effectiveness when business performance is screaming the contrary. Here are some common symptoms of business performance issues that suggest risks are not being managed: 1. Process performance/error rates are off target 2. Key performance indicators are consistently outside target 3. Key performance indicators are never outside target 4. Budget/actual variances are material (positive or negative) 5. Capital projects are delayed or over/under spent 6. Earnings volatility is out of line with peers 7. Variances cannot be explained by known risks 8. Clean 404 opinions are followed by material weakness disclosures 9. Internal audit recommendations always increase vs. decrease controls Most risk and control frameworks fail to consider business or process performance. Neither SOX nor the PCAOB AS5 pay much attention to business performance. COSO monitoring prefers testing to monitoring performance. Basel II does support key risk indicators and key performance indicators. The premise here is that over time, on target, consistent business or process performance is de facto evidence of effective risk and control management. Many risk and control practitioners fail to consider business performance when assessing either risk or control. Performance variances should be explained as unidentified or unmanaged risks. Unusual business performance should be explained by unusual risks. But risk and control assessment not tied to business or process performance is not helpful and may be dangerous. 3
6 WHAT DO RISKS TELL YOU ABOUT YOUR CONTROLS? In late 2007, Standard & Poor s issued a discussion paper outlining their proposal to assess corporate risk management practices as part of their credit rating process. The Sample Risk Types they proposed in the discussion paper are very useful. In the normal course of events, most companies would be expected to encounter most of these risk types, quite often in multiple locations or processes. Not only that, but the nature and level of these risks will change constantly over time and by location or process. In short, most risks cannot be controlled, they must be managed. STANDARD & POOR S SAMPLE RISK TYPES In short, most risks cannot be controlled, they must be managed. Environmental risks Financial risks Supply risks Management risks Business continuity Business market environment Environmental Liability lawsuits Natural disasters/weather Pandemic Physical damage Political risk Regulatory/legislative Terrorism Capital availability Credit counterparty Financial market risk Inflation Interest rates Liquidity Commodity prices Supply chain Corporate governance Data security Employee health and safety Intellectual property Labor disputes Labor skills shortage M&A/restructuring Managing complexity Outsourcing problems Project management Reputation Risk management involves an ongoing process similar to the diagram below. It involves clarifying accountability and decision rules and continuously updating information and reporting. Risks need managing, not controlling. Controls designed to manage risks must be appropriate to the risk. COSO risk assessment, monitoring and control environment controls should be designed, documented and tested. 4
7 You are beginning to manage risks if: You can identify in which contexts these risks exist You can track frequency distributions of instances of risks by type You recognize risk identification and assessment in your compensation/reward system You track incidents/loss events/issues and actions associated with key risks You have identified risk tolerances and appetite WHAT DO CONTROLS TELL YOU ABOUT YOUR RISKS? More controls do not mean less risk; the opposite is often true. Too many controls may be evidence of lack of effective risk management practices. Good risk management considers a variety of risk responses, of which controls are only one. The proliferation of control-based approaches to risk has led to extensive identification, documentation, testing and reporting of controls. That can be a mistake if carried to an extreme. If you have gathered more knowledge about controls than about risks, and focus on the control side of the equation, it is a clear indication of bad risk management practices. More controls do not mean less risk; the opposite is often true. Generally speaking, good risk management practices will produce a 3:1 or greater ratio of risks to controls. Risk-based approaches gather more knowledge about risk than control. Today that ratio is often reversed. Risk control ratios of 1:3 are common. Some balance is required, but generally a risk control ratio of >1 is desirable. Risks can be documented and tested too, and should be continually assessed. If you get the risk side wrong, you can t get the control side right. Low risk:control ratios indicate business management has not been involved in risk identification, is unwilling to be candid or is not completely honest. In a healthy and safe environment, business managers, if asked, will provide a wealth of detailed information. Rich, detailed knowledge of 5
8 risks provides a basis for far more efficient-and-effective control portfolios. The more and better the knowledge of risk, the more effective and efficient the control portfolio. Expect fewer, not more controls, but expect them to be better, more powerful controls. Standard & Poor s, in assessing ERM, looks for compliance-based approaches to risk management and scores them poorly. Low risk:control ratios are indicative of compliance-based approaches to risk management. Many control portfolios are designed from a react and respond perspective. They are not designed with specific risks in mind. The philosophy is that risks are unknown and unavoidable but enough controls will save the day. That has proven to be inefficient and ineffective. ARE YOU UP FOR THE TASK OF RISK MANAGEMENT? Risk management requires the mastery of a body of knowledge, specific skill sets and the appropriate use of technology. A sample of the knowledge and skill requirements is set out below. KNOWLEDGE AND EXPERIENCE REQUIREMENTS FOR RISK MANAGEMENT LEADERS Risk management is a young profession with huge potential to help address and resolve some of the worst problems we are experiencing on a day-to-day basis. 1. Technology implementation for risk management which includes knowledge of best practices in a wide range of topics such as developing process structure, KPIs, KRIs and selecting or designing other critical contexts for risk management 2. Experience leading and completing ERM assessments for the organization as a whole or major business units or functions, completing SOX certifications and ORM and other process level risk assessments 3. Selection and application of risk models and use of the risk identification and rating desktop for identifying and classifying all relevant risks 4. Tools and techniques for root cause analysis and business process improvement 5. Development of reliable descriptions of loss events, incidents and issues or actions with respect to the context selected 6. Understanding the major approaches to self-assessment and business reasons for adopting self-assessment approaches to risk and control management 7. Understanding organizational risk and control self-assessment (RCSA) barriers and implementation of effective tactics and tools for RCSA 8. Understanding of generally accepted control criteria including all major control and quality models (COSO/CobiT/COCO/ISO/OTOL, etc.) 9. Understanding of generally accepted risk criteria including the leading risk standards and frameworks (COSOERM, AS/NZ4360, ISO31000, etc.) 10. Linkages between SOX legislation, relevant PCAOB audit standards, the Basel II and Solvency 2 ORM requirements and other major regulatory frameworks governing risk and control such as Turnbull, J-SOX and IIA Professional Practice Framework, etc. 11. Understanding and implementing major industry specific risk and control assessment frameworks Risk management is a young profession with huge potential to help address and resolve some of the worst problems we are experiencing on a day-to-day basis. But true professionals are rooted in public service and some degree of altruism. There is a long way to go to achieve that goal. But fundamental tools, practices, knowledge and skills exist today. Risk managers must proceed carefully but quickly. 6
9 ABOUT THOMSON REUTERS Thomson Reuters is the world s leading source of intelligent information for businesses and professionals. The company combines industry expertise with innovative technology to deliver critical information for leading decision-makers in the financial, legal, tax and accounting, scientific and healthcare markets. Our solutions dynamically connect business transactions, strategy, and operations to the everchanging regulatory environment, providing highly regulated firms with the knowledge to act. Our client groups include compliance, audit, legal and risk functions within the organization. We partner with firms to manage their risk exposure and accelerate their business at every step. The Thomson Reuters Accelus suite of products provides powerful tools and information that enable proactive insights, dynamic connections, and informed outcomes that drive overall business performance. Thomson Reuters Accelus is the combination of the market-leading solutions provided by the heritage businesses of Complinet, Oden, Paisley, West s Capitol Watch, Westlaw Business, and Westlaw Compliance Advisor. Learn More Call: [email protected] Visit: accelus.thomsonreuters.com Thomson Reuters. All rights reserved. Republication or redistribution of Thomson Reuters content, including by framing or similar means, is prohibited without the prior written consent of Thomson Reuters. 'Thomson Reuters' and the Thomson Reuters logo are registered trademarks and trademarks of Thomson Reuters and its affiliated companies.
USING SPREADSHEETS TO MANAGE GOVERNANCE, RISK AND COMPLIANCE:
USING SPREADSHEETS TO MANAGE GOVERNANCE, RISK AND COMPLIANCE: PROS, CONS AND HIDDEN DANGERS MIKE ROST CONTENTS INTRODUCTION... 3 GRC DISCIPLINES REQUIRE PURPOSE-BUILT TECHNOLOGY... 3 USING SPREADSHEETS
COMPLIANCE MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS COMPLIANCE MANAGEMENT SOLUTIONS
THOMSON REUTERS ACCELUS COMPLIANCE MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS Our solutions dynamically connect business transactions, strategy, and operations to the ever-changing regulatory environment,
building a business case for governance, risk and compliance
building a business case for governance, risk and compliance contents introduction...3 assurance: THe last major business function To be integrated...3 current state of grc: THe challenges... 4 building
PRACTICAL GUIDANCE: SEVEN STEPS FOR EFFECTIVE ENTERPRISE RISK MANAGEMENT
PRACTICAL GUIDANCE: SEVEN STEPS FOR EFFECTIVE ENTERPRISE RISK MANAGEMENT WHITEPAPER CONTENTS CONTENTS INTRODUCTION 1 DEFINING ENTERPRISE RISK MANAGEMENT 1 IF IT S SO GOOD WHY ISN T EVERYONE DOING IT? 2
ACCELUS RISK MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS ACCELUS RISK MANAGEMENT SOLUTIONS
ACCELUS RISK MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS ACCELUS RISK MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS Our solutions dynamically connect business transactions, strategy, and operations to
THOMSON REUTERS ACCELUS
THOMSON REUTERS ACCELUS ACCELUS Screening Resolution Service Executive Summary Thomson Reuters Accelus offers Screening Resolution Service (SRS): an outsourced screening service for Corporates and Financial
B o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing
B o a r d of Governors of the Federal Reserve System Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing January 23, 2013 P U R P O S E This policy statement is being issued
Getting to strong Leading Practices for value-enhancing internal audit By Richard Reynolds and Abhinav Aggarwal - PricewaterhouseCoopers LLP
Getting to strong Leading Practices for value-enhancing internal audit By Richard Reynolds and Abhinav Aggarwal - PricewaterhouseCoopers LLP Today's unpredictable business climate and challenging regulatory
An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management
Bridgework: An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management @Copyright Cura Software. All rights reserved. No part of this document may be transmitted or copied without
OWN RISK AND SOLVENCY ASSESSMENT AND ENTERPRISE RISK MANAGEMENT
OWN RISK AND SOLVENCY ASSESSMENT AND ENTERPRISE RISK MANAGEMENT ERM as the foundation for regulatory compliance and strategic business decision making CONTENTS Introduction... 3 Steps to developing an
Placing a Value on Enterprise Risk Management ADVISORY
Placing a Value on Enterprise Risk Management ADVISORY Placing a Value on Enterprise Risk Management 1 In turbulent economic times, the case for investing in an enterprise risk management (ERM) program
Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.
Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
Operational Risk Management - The Next Frontier The Risk Management Association (RMA)
Operational Risk Management - The Next Frontier The Risk Management Association (RMA) Operational risk is not new. In fact, it is the first risk that banks must manage, even before they make their first
Operational Risk Management Program Version 1.0 October 2013
Introduction This module applies to Fannie Mae and Freddie Mac (collectively, the Enterprises), the Federal Home Loan Banks (FHLBanks), and the Office of Finance, (which for purposes of this module are
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date
CFE 2. Enterprise Risk Management. Study Guide - Supplemental Background Material
P a g e 1 CFE 2 Enterprise Risk Management Study Guide - Supplemental Background Material The passing score for this test is 74% Reference Guides: Enterprise Risk Management Best Practices: From Assessment
Applying Risk Assessment to Your Audit Plan Break-out Session T3, Tuesday, October 26 2:00-2:50pm
Applying Risk Assessment to Your Audit Plan Break-out Session T3, Tuesday, October 26 2:00-2:50pm Mike Brown Senior Vice President, Corporate Audit State Street Corporation Rich Reynolds Partner PricewaterhouseCoopers
Analyzing Risks in Healthcare. February 12, 2014
Analyzing s in Healthcare February 12, 2014 1 Content What is Enterprise Management (ERM) ERM Benefits ERM Standards / ISO 31000:2009 ERM Process Register ERM Governance Model s Q&A 2 What is Enterprise
Foreign business partners under the FCPA
Foreign business partners under the FCPA by Tom Fox 1 TITLE about the writer Thomas Fox has practiced law in Houston for 25 years. He is now assisting companies with FCPA compliance, risk management and
ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES
THOMSON REUTERS ACCELUS ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES PROACTIVE. CONNECTED. INFORMED. THOMSON REUTERS ACCELUS Compliance management Solutions Introduction The advent of new and pending
Risk Management KPIs: Efficiency Tool or Formality?
Risk Management KPIs: Efficiency Tool or Formality? Marina Basova, CIRM, CIA Alexey Mitselsky, CIA 2011 Enterprise Risk Management Symposium Society of Actuaries March 14-16, 2011 Copyright 2011 by the
Exhibit 1: Structure of a heat map
Integrating risk and performance management processes Werner Bruggeman Geert Scheipers Valerie Decoene 1. Introduction Years ago, Kaplan & Norton interviewed managers about their time consumption and they
Developing an Effective Enterprise Risk Management Program
Developing an Effective Enterprise Risk Management Program Jay Brietz, CPA and CIA Senior Manager This material was used by Elliott Davis Decosimo during an oral presentation; it is not a complete record
The Essentials of Enterprise Risk Management. Steven C. Tourek, Senior Vice President, General Counsel & Secretary, The Marvin Companies
The Essentials of Enterprise Risk Management Steven C. Tourek, Senior Vice President, General Counsel & Secretary, The Marvin Companies Introduction How should an organization think about the management
Risk Assessment & Enterprise Risk Management
Risk Assessment & Enterprise Risk 1 Healthcare Corporate Governance Today s environment requires building a culture of risk awareness and management of risk across the organization, while formulating less
Preparing for the Convergence of Risk Management & Business Continuity
Preparing for the Convergence of Risk Management & Business Continuity Disaster Recovery Journal Webinar Series September 5, 2012 2012 Strategic BCP, Inc. All rights reserved. strategicbcp.com 1 Today
Operational Risk Management in a Debt Management Office
Operational Risk Management in a Debt Management Office Based on Client Presentation January 2008 Outline The importance of operational risk management (ORM) International best practice A high-level perspective,
Effective Internal Audit in the Financial Services Sector
Effective Internal Audit in the Financial Services Sector Recommendations from the Committee on Internal Audit Guidance for Financial Services: How They Relate to the Global Institute of Internal Auditors
Accelus Audit Manager THOMSON REUTERS ACCELUS
THOMSON REUTERS ACCELUS Accelus Audit Manager THOMSON REUTERS ACCELUS Our solutions dynamically connect business transactions, strategy, and operations to the ever-changing regulatory environment, providing
Get More Out of Your Risk Assessment. Austin Chapter of the IIA
Get More Out of Your Risk Assessment Austin Chapter of the IIA Speakers Alyssa G. Martin, CPA Dallas Executive Partner, Advisory Services 25 years of public accounting experience, with a practice emphasis
The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework
The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework Dorothy Gjerdrum, ARM-P, Chair of the ISO 31000 US TAG and Executive Director,
Risk management and the transition of projects to business as usual
Advisory Risk management and the transition of projects to business as usual Financial Services kpmg.com 2 Risk Management and the Transition of Projects to Business as Usual Introduction Today s banks,
Sample Financial institution Risk Management Policy 2011
Sample Financial institution Risk Management Policy 2011 1 Contents Risk Management Program...2 Internal Control and Risk Management Diagram... 2 General Control Environment... 2 Specific Internal Control
Understanding Today s Enterprise Risk Management Programs
Understanding Today s Enterprise Risk Management rograms Joel Tietz, TIAA-CREF Managing Director, Enterprise Risk Management March 23, 2015 TIAA-CREF - UBLIC USE Agenda 1) Enterprise Risk Management rograms
A Risk-Based Audit Strategy November 2006 Internal Audit Department
Mental Health Mental Retardation Authority of Harris County ENTERPRISE RISK MANAGEMENT A Framework For Assessing, Evaluating And Measuring Our Agency s Risk A Risk-Based Audit Strategy November 2006 Internal
How To Manage Risk At Atb Financial
Guidelines for Financial Institutions Legislative Compliance Management (LCM) Date: July 2004 Introduction Regulatory risk is the risk of non-compliance with applicable regulatory requirements. For the
Industry Sound Practices for Financial and Accounting Controls at Financial Institutions
Industry Sound Practices for Financial and Accounting Controls at Financial Institutions Federal Reserve Bank of New York January 2006 FINANCIAL AND ACCOUNTING CONTROLS: INDUSTRY SOUND PRACTICES FOR FINANCIAL
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)
INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Introduction to the International Standards Internal auditing is conducted in diverse legal and cultural environments;
CONSULTATION PAPER Proposed Prudential Risk-based Supervisory Framework for Insurers
INSURANCE CONSULTATION PAPER Proposed Prudential Risk-based Supervisory Framework for Insurers December 2010 CONSULTATION PAPER: Proposed Risk-based Supervisory Framework (Final December 2010) Page 1 of
RSA ARCHER OPERATIONAL RISK MANAGEMENT
RSA ARCHER OPERATIONAL RISK MANAGEMENT 87% of organizations surveyed have seen the volume and complexity of risks increase over the past five years. Another 20% of these organizations have seen the volume
Matthew E. Breecher Breecher & Company PC November 12, 2008
Applying COSO s Enterprise Risk Management Integrated Framework Matthew E. Breecher Breecher & Company PC November 12, 2008 The basic outline for this presentation was provided by: Objectives for the session:
fs viewpoint www.pwc.com/fsi
fs viewpoint www.pwc.com/fsi June 2013 02 11 16 21 24 Point of view Competitive intelligence A framework for response How PwC can help Appendix It takes two to tango: Managing technology risk is now a
ENTERPRISE RISK MANAGEMENT POLICY
ENTERPRISE RISK MANAGEMENT POLICY TITLE OF POLICY POLICY OWNER POLICY CHAMPION DOCUMENT HISTORY: Policy Title Status Enterprise Risk Management Policy (current, revised, no change, redundant) Approving
NEW YORK STATE-WIDE PAYROLL CONFERENCE. Presented to:
NEW YORK STATE-WIDE PAYROLL CONFERENCE Presented to: Felicia Cheek, Practice Leader Global Time to Pay Advisory 15 September 2014 Statement of Confidentiality and Usage Restrictions This document contains
AN INTEGRATED APPROACH TO COMPLIANCE AND RISK MANAGEMENT IS THE BEST WAY FORWARD BY MARTIN WOODS OCTOBER 2011
AN INTEGRATED APPROACH TO COMPLIANCE AND RISK MANAGEMENT IS THE BEST WAY FORWARD BY MARTIN WOODS OCTOBER 2011 FOREWORD The global financial crisis has led banks, firms, governments and societies to the
Sound Practices for the Management of Operational Risk
1 Sound Practices for the Management of Operational Risk Authority 1.1 Section 316 (4) of the International Business Corporations Act (IBC Act) requires the Commission to take any necessary action required
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
Enterprise risk management: A pragmatic, four-phase implementation plan
Enterprise risk management: A pragmatic, four-phase implementation plan Prepared by: John Brackett, Managing Director, Risk Advisory Services, RSM McGladrey, Inc. 704.442.3820, [email protected]
Tying It All Together: Practical ERM Integration. Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation
Tying It All Together: Practical ERM Integration Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation November 16, 2007 1 Agenda Basis for ERM Integration ERM Objectives ERM Focus
Organizing a Financial Institution to Deliver Enterprise-Wide Risk Management By Kaan H. Aksel PricewaterhouseCoopers
Organizing a Financial Institution to Deliver Enterprise-Wide Risk Management By Kaan H. Aksel PricewaterhouseCoopers Everyone seems to be talking about enterprise-wide risk management (ERM): boards of
The Value of Vulnerability Management*
The Value of Vulnerability Management* *ISACA/IIA Dallas Presented by: Robert Buchheit, Director Advisory Practice, Dallas Ricky Allen, Manager Advisory Practice, Houston *connectedthinking PwC Agenda
6/8/2016 OVERVIEW. Page 1 of 9
OVERVIEW Attachment Supervisory Guidance for Assessing Risk Management at Supervised Institutions with Total Consolidated Assets Less than $50 Billion [Fotnote1 6/8/2016 Managing risks is fundamental to
OPERATIONAL RISK RISK ASSESSMENT
OPERATIONAL RISK RISK ASSESSMENT 1 OVERVIEW Inherent Risk Risk Management Composite or Net Residual Risk Trend 2 INHERENT RISK Definition Sources Identification Quantification 3 Definition OPERATIONAL
RISK MANAGEMENT REPORT (for the Financial Year Ended 31 March 2012)
RISK MANAGEMENT REPORT (for the Financial Year Ended 31 March 2012) Integrated Risk Management Framework The Group s Integrated Risk Management Framework (IRMF) sets the fundamental elements to manage
GE Capital. Driving change and continuous process improvement. how-to
Driving change and continuous process improvement Process improvement or PI involves applying tools and techniques to help a company achieve its goals Characteristics Aligned around what customers value
Transforming risk management into a competitive advantage kpmg.com
INSURANCE RISK MANAGEMENT ADVISORY SOLUTIONS Transforming risk management into a competitive advantage kpmg.com 2 Transforming risk management into a competitive advantage Assessing risk. Building value.
MISSION VALUES. The guide has been printed by:
www.cudgc.sk.ca MISSION We instill public confidence in Saskatchewan credit unions by guaranteeing deposits. As the primary prudential and solvency regulator, we promote responsible governance by credit
SUPERVISION GUIDELINE NO. 9 ISSUED UNDER THE AUTHORITY OF THE FINANCIAL INSTITUTIONS ACT 1995 (NO. 1 OF 1995) RISK MANAGEMENT
SUPERVISION GUIDELINE NO. 9 ISSUED UNDER THE AUTHORITY OF THE FINANCIAL INSTITUTIONS ACT 1995 (NO. 1 OF 1995) RISK MANAGEMENT Bank of Guyana July 1, 2009 TABLE OF CONTENTS 1.0 Introduction 2.0 Management
APPENDIX A NCUA S CAMEL RATING SYSTEM (CAMEL) 1
APPENDIX A NCUA S CAMEL RATING SYSTEM (CAMEL) 1 The CAMEL rating system is based upon an evaluation of five critical elements of a credit union's operations: Capital Adequacy, Asset Quality, Management,
Assessing Credit Risk
Assessing Credit Risk Objectives Discuss the following: Inherent Risk Quality of Risk Management Residual or Composite Risk Risk Trend 2 Inherent Risk Define the risk Identify sources of risk Quantify
Impact of New Internal Control Frameworks
Impact of New Internal Control Frameworks Webcast: Tuesday, February 25, 2014 CPE Credit: 1 0 With You Today Bob Jacobson Principal, Risk Advisory Services Consulting Leader West Region [email protected]
ERM Standards of Practice and Shared Risk Principles
ERM Standards of Practice and Shared Risk Principles ERM 2011 Symposium Chicago IL March 15, 2011 Carol Fox Director, Strategic and Enterprise Risk Practices Agenda Global risk governance drivers Evolving
Credit Union Liability with Third-Party Processors
World Council of Credit Unions Annual Conference Credit Union Liability with Third-Party Processors Andrew (Andy) Poprawa CEO, Deposit Insurance Corporation of Ontario Canada 1 Credit Union Liability with
Beyond risk identification Evolving provider ERM programs
Beyond risk identification Evolving provider ERM programs March 2016 At a glance PwC conducted research to assess the state of enterprise risk management (ERM) within healthcare providers and found many
GUIDANCE FOR MANAGING THIRD-PARTY RISK
GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,
Good Practice Checklist
Investment Governance Good Practice Checklist Governance Structure 1. Existence of critical decision-making bodies e.g. Board of Directors, Investment Committee, In-House Investment Team, External Investment
Governance, Risk, and Compliance (GRC) White Paper
Governance, Risk, and Compliance (GRC) White Paper Table of Contents: Purpose page 2 Introduction _ page 3 What is GRC _ page 3 GRC Concepts _ page 4 Integrated Approach and Methodology page 4 Diagram:
Understanding and articulating risk appetite
Understanding and articulating risk appetite advisory Understanding and articulating risk appetite Understanding and articulating risk appetite When risk appetite is properly understood and clearly defined,
Operational Risk Management Table of Contents
Operational Management Table of Contents SECTION 1 Operational The Definition of Operational Drivers of Operational Management Governance Culture and Awareness Policies and Procedures SECTION 2 Operational
PRACTICE GUIDE. Formulating and Expressing Internal Audit Opinions
PRACTICE GUIDE Formulating and Expressing Internal Audit Opinions 2 of 23 Table of Contents 1. Executive Summary... 1 2. Introduction... 2 3. Planning the Expression of an Opinion... 3 3.1 Expressing an
The Unintended Effects of
The Unintended Effects of Healthcare Reform TOM SUROVY, PRINCIPLE COMPLIANCE ATTORNEY CONTENTS CHILD-ONLY POLICIES... 3 PRESCRIPTIONS FOR NONPRESCRIPTION OVER-THE-COUNTER DRUGS... 4 COMMISSIONS FOR INSURANCE
Facilitating sound practices in risk management with IBM OpenPages Operational Risk Management
Facilitating sound practices in risk management with IBM OpenPages Operational Risk Management Contents: 1 Executive summary 2 The importance of risk management 2 The need for sound business practices
CHAPTER 7 PLANNING THE AUDIT: IDENTIFYING AND RESPONDING TO THE RISKS OF MATERIAL MISSTATEMENT
A U D I T I N G A RISK-BASED APPROACH TO CONDUCTING A QUALITY AUDIT 9 th Edition Karla M. Johnstone Audrey A. Gramling Larry E. Rittenberg CHAPTER 7 PLANNING THE AUDIT: IDENTIFYING AND RESPONDING TO THE
Saxo Capital Markets CY Limited
Saxo Capital Markets CY Limited DISCLOSURES IN ACCORDANCE WITH THE REGULATION FOR THE CAPITAL REQUIREMENTS OF INVESTMENT FIRMS FOR THE YEAR ENDED 31 DECEMBER 2014 MAY 2015 CONTENTS 1. GENERAL INFORMATION
Operational Risk Management Excellence Get to Strong Survey
Operational Risk Management Excellence Get to Strong Survey Executive Report kpmg.com b KPMG/RMA Operational Risk Management Excellence Get to Strong Survey Executive Report Operational Risk Management
Global Technology Audit Guide. Auditing IT Governance
Global Technology Audit Guide Auditing IT Governance Global Technology Audit Guide (GTAG ) 17 Auditing IT Governance July 2012 GTAG Table of Contents Executive Summary... 1 1. Introduction... 2 2. IT
Enterprise Risk Management in a Highly Uncertain World. A Presentation to the Government-University- Industry Research Roundtable June 20, 2012
Enterprise Risk Management in a Highly Uncertain World A Presentation to the Government-University- Industry Research Roundtable June 20, 2012 CRO Council Introduction Mission The North American CRO Council
Feature. Developing an Information Security and Risk Management Strategy
Feature Developing an Information Security and Risk Management Strategy John P. Pironti, CISA, CISM, CGEIT, CISSP, ISSAP, ISSMP, is the president of IP Architects LLC. He has designed and implemented enterprisewide
RISK FACTORS AND RISK MANAGEMENT
Bangkok Bank Public Company Limited 044 RISK FACTORS AND RISK MANAGEMENT Bangkok Bank recognizes that effective risk management is fundamental to good banking practice. Accordingly, the Bank has established
The Role of the Board in Enterprise Risk Management
Enterprise Risk The Role of the Board in Enterprise Risk Management The board of directors plays an essential role in ensuring that an effective ERM program is in place. Governance, policy, and assurance
Physician Enterprise The Importance of Charge Capture, Business Intelligence and Being a Data Driven Organization
Physician Enterprise The Importance of Charge Capture, Business Intelligence and Being a Data Driven Organization Executive Summary Physician-hospital alignment is a key strategy for most hospitals across
THE PRACTICE OF PROFILING BY DAVID THOMAS
PROFILING PART 3 THE PRACTICE OF PROFILING BY DAVID THOMAS Statement of intent This paper follows the two previous titles The Psychology of Money Launderers and the Psychology of Anti-Money Launderers
AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS:
1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF VIEWS AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN
Auditing Standard 5- Effective and Efficient SOX Compliance
Auditing Standard 5- Effective and Efficient SOX Compliance September 6, 2007 Presented to: The Dallas Chapter of the Institute of Internal Auditors These slides are incomplete without the benefit of the
A proven 5-step framework for managing supplier performance
IBM Software Industry Solutions Industry/Product Identifier A proven 5-step framework for managing supplier performance Achieving proven 5-step spend framework visibility: benefits, for managing barriers,
The Value of Optimization in Asset Management
Experience the commitment white PAPER The Value of Optimization in Asset Management Better decisions to help utilities balance costs, risks, opportunities and performance May 2015 cgi.com Improving the
THOMSON REUTERS ACCELUS. Know Your Customer (KYC), Kontrol Your Costs (KYC) and Keep Your Customers (KYC) happy
THOMSON REUTERS ACCELUS Know Your Customer (KYC), Kontrol Your Costs (KYC) and Keep Your Customers (KYC) happy Know Your Customer (KYC), Kontrol Your Costs (KYC) and Keep Your Customers (KYC) happy Background
How To Use Risk It
Risk IT A set of guiding principles and the first framework to help enterprises identify, govern and effectively manage IT risk. In business today, risk plays a critical role. Almost every business decision
Risk mitigation for business resilience White paper. A comprehensive, best-practices approach to business resilience and risk mitigation.
Risk mitigation for business resilience White paper A comprehensive, best-practices approach to business resilience and risk mitigation. September 2007 2 Contents 2 Overview: Why traditional risk mitigation
WHITEPAPER LOOKING INTO THE FUTURE WITH THE THOMSON REUTERS/ PAYNET SMALL BUSINESS LENDING INDEX (SBLI)
WHITEPAPER LOOKING INTO THE FUTURE WITH THE THOMSON REUTERS/ PAYNET SMALL BUSINESS LENDING INDEX (SBLI) ANDREW CLARK - CHIEF INDEX STRATEGIST THOMSON REUTERS INDICES THOMAS WARE - SENIOR VICE PRESIDENT,
Advanced Data Analytics, the Fraudsters Worst Enemy
Advanced Data Analytics, the Fraudsters Worst Enemy Introducing Powerful Tools and Techniques to Uncover Fraud Agenda Overview of data analytics in the anti-fraud and fraud investigation context Capability
