Internal Audit. Final Report: Enterprise Risk Management Report Number: Audit Period: 01 May - 31 July 2013
|
|
|
- Sharyl Lee
- 9 years ago
- Views:
Transcription
1 Final Report: Enterprise Risk Management Report Number: Audit Period: 01 May - 31 July 2013 Contents: I. Audit Objective and Scope... 2 II. III. IV. Management Summary... 2 Detailed Findings and Recommendations... 4 Remediation... 6 V. Action Plan... 8 VI. Appendix Distributed to: Seth Berkley Helen Evans cc. Executive Team Adrien de Chaisemartin Ciara Goldstein
2 I. Audit Objective and Scope Audit Objective The objective of the audit was to evaluate the process by which risks are identified, evaluated, reported and managed in the GAVI Secretariat ( GAVI ). The audit focus was primarily on the structures and processes used rather than being an assessment of the outcomes achieved in applying the risk management processes. Audit Scope Risk may be described as the uncertainty about events and/or their outcomes that could have a material effect on the achievement of an organisation s goals. Enterprise Risk Management (ERM) is the set of processes and associated structures, policies, and methods which enable an organisation to understand and manage its risks so as to achieve its goals with an acceptable level of variation. The scope of the audit encompassed all of GAVI s activities and the associated risk management processes. There are many elements which make up the ERM framework; a chart, prepared in the course of the audit, sets out the key components of GAVI s ERM Framework, and is shown in the Appendix, section VI. The audit was undertaken using as a reference point the industry standard, the International Organisation for Standardization (ISO) 31000, Risk Management Principles and Guidelines. This sets out a recognised best-practice framework which is used to help organisations develop and enhance their risk management processes. II. Management Summary The ERM framework established in GAVI is effective and operates well. At its core is a risk register and associated processes which management reviews and updates quarterly; items considered to be of high risk and newly emerging risks are reviewed by the Executive Team (ET) and routinely reported to the Board, and these are discussed at Board meetings. Internal Audit Report Page 2 / 11
3 The means by which GAVI sets and monitors its objectives (mission, strategic goals, and corporate goals) is highly structured and monitoring metrics have been established by which the achievement of goals and objectives can be assessed. These are essential components in an effective risk management process. The risk management process has a number of features which are consistent with best practice; key amongst them are that the risk register very formally links to the organisation s goals, and that there is a structured process of regular review, update, discussion, and reporting of risk which is well-integrated into management processes. Many of the practices around the establishment and monitoring of corporate objectives, and the identification and management of risks within the risk register and associated processes are consistent with best practice; key elements of the existing processes are: There is engagement of a broad set of functions right across GAVI. Risks are identified by managers on a bottom-up basis by those close to the relevant departments and functions. This maximises the likelihood that relevant risks will be identified and brought into the scope of the risk management process through their inclusion in the risk register. There is effective process around the operation of the risk register which ensures that identified risks are analysed appropriately, mitigating actions are prioritised, and responsible management is identified. There is participation of partners (WHO, UNICEF) in providing input to the risk identification and evaluation process. While GAVI does not have staff involved in overseeing execution in-country, the involvement of Alliance partners who act as GAVI s eyes and ears on the ground in the risk identification process increases the likelihood of bringing relevant risks into the scope of the risk management process. The risks identified in the risk register are mapped against GAVI s strategic goals. This ensures that risks are clearly associated with the possibility of failing to achieve key objectives of the organisation. Internal Audit Report Page 3 / 11
4 There is quarterly review and discussion of the risk register at ET meetings. This helps validate and socialise the identified risks, and helps achieve buy-in at senior levels of management both to the process of risk management, and the relevance of the risks identified. The risk register is updated quarterly. The risk environment and the emerging risks are highly dynamic and it is important that there is a process of regular review. A risk paper describing new risks emerging and setting out the highest risks is prepared and presented to the Board regularly. The Key Performance Indicators, KPIs, which are prepared and monitored quarterly, include metrics relating to risk specifically, and also more generally, in that they help maintain oversight on the achievement of corporate goals. ERM is a process which should be continually reviewed and enhanced as an organisation grows and matures and certain findings are made which would strengthen the framework of risk identification and management in the medium term. These are set out in summary, following. III. Detailed Findings and Recommendations (1) Development of a risk policy Although elements of risk management are encapsulated in many GAVI policies (covering a variety of programmatic policies, finance-related policies, and policies and guidelines of a cross-cutting nature) there is no overarching statement of management s approach to risk management. As with any organisation, there are aspects of risk management which are subjective in nature, and would benefit from articulation. In particular, it would strengthen risk management if there was a policy setting out, amongst other things: a description of what is meant by risk and risk management in GAVI, a definition of risk tolerance and a description of how the organisation applies this in a practical way, Internal Audit Report Page 4 / 11
5 a statement on the willingness to accept risk, and a determination of how that should be defined in terms of trade-offs against objectives. The finalisation of a risk policy would create a common understanding of what risk is and how it is represented at GAVI, and help establish a common language that can be used to facilitate discussion and agreement with the Board on matters of risk management and risk tolerance. (2) Establishing processes to identify and manage mission-critical risks and operational risks Risk management should be comprehensive in covering all aspects of risk which may challenge the ability of the organisation to achieve its goals: this includes missioncritical risks, strategic risks, and operational risks. While the classification of these different risk types is not always clear as there is some overlap amongst them, the risk register tends to focus on risks associated with the achievement of the strategic goals and corporate goals. Benefit would be obtained by more formally identifying and evaluating other risks: Mission-critical risks. These are the higher-level risks which potentially jeopardise an organisation fulfilling its core mission. This would require the development of a mechanism by which mission-critical issues are identified, and then the establishment of a process by which they are evaluated and options for managing them are agreed. Operational risks. These are the risks of loss resulting from inadequate or failed internal processes, people and systems, or from external events. Operational risks are managed as a matter of routine every day; however, if there are failures of an operational risk nature, they can have profound effect on an organisation especially if multiple failures occur and compound their impact, as can happen when a major failure occurs. Operational risks are routinely managed across the organisation but there is no mechanism by which they are identified and evaluated in a structured way so as to ensure that all relevant risks have been identified, evaluated, and managed as appropriate. Internal Audit Report Page 5 / 11
6 (3) Establishing a country-risk profile At the heart of GAVI s risk management are the challenges posed by supporting 73 of the world s poorest countries. The achievement of GAVI s mission will be crucially affected by successful execution in a relatively small number of large and critical countries; there will also be common factors across the portfolio of countries which may benefit from common assessment and management. This would require that GAVI evaluates risk across the country portfolio as a whole; although country-bycountry plans are being developed for the most significant countries, this does not offer a risk assessment across the whole range of countries in a way which would allow a country-sensitive risk management programme to be put in place. (4) Enhance certain processes used to capture, manage and track remediation of risks in the register to improve the rigour and consistency of approach In addition, certain areas of potential enhancement were identified which would improve the mechanics of the existing process. None are considered of primary importance and they are not summarised here. IV. Remediation Management has agreed to progress these recommendations and responsible Managing Directors have agreed to sponsor each of these main developments. A number of initiatives are already underway which will be leveraged to develop appropriate solutions: The development of the strategy will be used as an opportunity to identify and plan for the identification and management of critical risks (the consideration of mission-challenging risks is a natural component of the strategic process) (to be sponsored by Helen Evans, Deputy Chief Executive). A country risk assessment process will be established as part of the Grant Application and Monitoring and Review process (to be sponsored by Hind Khatib- Othman, Managing Director of Country Programmes). Internal Audit Report Page 6 / 11
7 Other initiatives will need to be newly established: The development of a process to map and create an inventory of operational risks will be piloted in Finance and Operations where many, but not all, of the operational risks reside (to be sponsored by Barry Greene, Managing Director, Finance and Operations). This will then serve as a model by which other parts of the organisation can map and inventory their operational risks. The development of a risk policy will be taken forward by the Policy and Performance Team (to be sponsored by Nina Schwalbe, Managing Director, Policy and Performance). Detailed action plans are set out in the following section. Internal Audit Report Page 7 / 11
8 V. Action Plan Issue Issue 01 Development of a risk policy 02 Establishment of processes to identify and manage missioncritical and operational risks 02 Establishment of processes to identify and manage mission- REC Recommendation 01 Prepare a risk policy covering key elements of management's risk management approach (including a description of what is meant by risk at GAVI, key responsibilities in managing risk, and a description of risk tolerances and how they are described and managed). 01 Review and identify a small number of risks which might be considered to be potentially mission-challenging if they were to crystallise. Evaluate their significance for GAVI, and determine if additional actions should be taken to remediate and manage the risk. 02 Review and document the key operational risks. Identify the actions in place to manage those risks, and assess whether any are Recommendation Action Date Responsible ET Responsible Responsible Priority member Manager Function High Nina Schwalbe Aurelia Nguyen Policy and (Board Performance presentation, ) High Helen Evans Adrien de Executive Office Chaisemartin Medium Barry Greene (establishment of approach in Finance and Tony Dutson and Andy Mends Finance and Operations Internal Audit Report Page 8 / 11
9 Issue Issue REC Recommendation Recommend- Action Date Responsible ET Responsible Responsible ation Priority member Manager Function critical and not appropriately managed within Operations for operational risks the risk tolerances that broader role- management are willing to accept. out) 03 Establishment of a 01 Establish a process of risk High Hind Khatib- Charlie Whetham Country country-risk profile assessment covering the risks that Othman Programmes, GAVI incurs in supporting GAMR countries, differentiated by country. This should facilitate a riskweighted, pro-active management by Country Support. 04 Enhancement of 01 Certain aspects of the risk register Medium Nina Schwalbe Adrien de Policy and certain processes process could be enhanced: Chaisemartin Performance used to capture, introduce definitions for 'impact' manage and track and 'likelihood' to improve the remediation of risks consistency of application across in the register to the contributing management improve the rigour team; consider the residual risk and consistency of both in the current state and post- approach. mitigation - evaluate whether the timescale to achieve the mitigated state is sufficiently long to suggest that additional mitigation actions Internal Audit Report Page 9 / 11
10 Issue Issue REC Recommendation Recommend- Action Date Responsible ET Responsible Responsible ation Priority member Manager Function should be considered in the interim; ensure that all relevant functions are feeding into the risk register (aspects of risk of certain functions were found not to be included in the risk register in the course of the audit). Internal Audit Report Page 10 / 11
11 VI. Appendix Internal Audit Report Page 11 / 11
The Gavi grant management change process
The Gavi grant management change process Overall change process Frequently asked questions June 2015 1. How was it decided that grant management changes were needed? Over recent years, through a series
Risk Management Report. Thirty-Third Board Meeting. GF/B33/05 Board Information
Thirty-Third Board Meeting Risk Management Report Board Information PURPOSE: 1. To provide information that enables the Board to fulfill its responsibilities with respect to risk management. 2. The report
Governance, Risk and Best Value Committee
Governance, Risk and Best Value Committee 2.00pm, Wednesday 23 September 2015 Internal Audit Report: Integrated Health & Social Care Item number Report number Executive/routine Wards Executive summary
GAVI FULL COUNTRY EVALUATION 2013 PROCESS EVALUATION OF PNEUMOCOCCAL VACCINE INTRODUCTION
GAVI FULL COUNTRY EVALUATION 2013 PROCESS EVALUATION OF PNEUMOCOCCAL VACCINE INTRODUCTION ALLIANCE RESPONSE JULY 2014 The GAVI Alliance is a learning organisation; we take the need for independent evaluation
APPENDIX 50. Enterprise risk management - Risk management overview
APPENDIX 50 Enterprise risk management - Risk management overview Energex regulatory proposal October 2014 ENTERPRISE RISK MANAGEMENT Risk Management Overview (RMO) 06 11 2013 Table of Contents 1. INTRODUCTION...
Risk Management Policy
1 Purpose Risk management relates to the culture, processes and structures directed towards the effective management of potential opportunities and adverse effects within the University s environment.
Quality Assurance. Policy P7
Quality Assurance Policy P7 Table of Content Quality assurance... 3 IIA Australia quality assurance and professional standards... 3 Quality assurance and professional qualifications... 4 Quality assurance
Risk Management Policy
Risk Management Policy June 2015 1 2 Contents 1. Policy Objectives and Background... 4 1.1. Policy Background... 4 1.2. Policy Objective... 4 1.3. Policy Sponsor and Maintenance... 4 2. Risk Types and
Risk Management Strategy EEA & Norway Grants 2009-2014. Adopted by the Financial Mechanism Committee on 27 February 2013.
Risk Management Strategy EEA & Norway Grants 2009-2014 Adopted by the Financial Mechanism Committee on 27 February 2013. Contents 1 Purpose of the strategy... 3 2 Risk management as part of managing for
The Department for Business, Innovation and Skills IMA Action Plan PRIORITY RECOMMENDATIONS
PRIORITY RECOMMENDATIONS R1 BIS to elevate the profile of information risk in support of KIM strategy aims for the protection, management and exploitation of information. This would be supported by: Establishing
Corporate Risk Management Policy
Corporate Risk Management Policy Managing the Risk and Realising the Opportunity www.reading.gov.uk Risk Management is Good Management Page 1 of 19 Contents 1. Our Risk Management Vision 3 2. Introduction
Policy 10.105: Enterprise Risk Management Policy
Name: Responsibility: Complements: Enterprise Risk Management Framework Coordinator, Enterprise Risk Management Policy 10.105: Enterprise Risk Management Policy Date: November 2006 Revision Date(s): January
BEST PRACTICES IN CYBER SUPPLY CHAIN RISK MANAGEMENT
BEST PRACTICES IN CYBER SUPPLY CHAIN RISK MANAGEMENT DuPont Crop Protection Operating Disciplines for Supply Chain Sustainability, Risk Management and Resilience INTERVIEWS George Poe Integrated Operations
COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY
COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY 1. INTRODUCTION The effective management of risk is central to the ongoing success and resilience of Coca-Cola Hellenic Bottling Company (CCHBC).
Information Commissioner's Office
Information Commissioner's Office IT Procurement Review Ian Falconer Partner T: 0161 953 6480 E: [email protected] Last updated 18 June 2012 Will Simpson Senior Manager T: 0161 953 6486 E: [email protected]
Confident in our Future, Risk Management Policy Statement and Strategy
Confident in our Future, Risk Management Policy Statement and Strategy Risk Management Policy Statement Introduction Risk management aims to maximise opportunities and minimise exposure to ensure the residents
Risk Management Strategy & Implementation Plan 2014 2016
St George s Healthcare NHS Trust: the next decade Risk Management Strategy & Implementation Plan 2014 2016 DRAFT VERSION 6.0 UPDATED 19.11.14 Executive summary We know, from external assurances received
ENTERPRISE RISK MANAGEMENT POLICY
ENTERPRISE RISK MANAGEMENT POLICY TITLE OF POLICY POLICY OWNER POLICY CHAMPION DOCUMENT HISTORY: Policy Title Status Enterprise Risk Management Policy (current, revised, no change, redundant) Approving
ENTERPRISE RISK MANAGEMENT FRAMEWORK
ENTERPRISE RISK MANAGEMENT FRAMEWORK COVENANT HEALTH LEGAL & RISK MANAGEMENT CONTENTS 1.0 PURPOSE OF THE DOCUMENT... 3 2.0 INTRODUCTION AND OVERVIEW... 4 3.0 GOVERNANCE STRUCTURE AND ACCOUNTABILITY...
Business Continuity Management
Business Continuity Management Policy Statement & Strategy July 2009 Basildon District Council Business Continuity Management Policy Statement The Council is committed to ensuring robust and effective
PM Governance. Executive Team ADCA ADCA
Item 6.5a Action Plan against the Recommendations Made in the Review of Risk Management Arrangements by PM Governance, November 2014 Key: PM Governance Paul Moore, Risk Consultant ADCA Associate Director
Good Practice Guide: the internal audit role in information assurance
Good Practice Guide: the internal audit role in information assurance Janaury 2010 Good Practice Guide: the internal audit role in information assurance January 2010 Official versions of this document
Qualification details
Qualification details Title New Zealand Diploma in Organisational Risk and Compliance (Level 6) Version 1 Qualification type Diploma Level 6 Credits 120 NZSCED 080317 Quality Management DAS classification
Audit and risk assurance committee handbook
Audit and risk assurance committee handbook March 2016 Audit and risk assurance committee handbook March 2016 Crown copyright 2016 This publication is licensed under the terms of the Open Government Licence
ENTERPRISE RISK MANAGEMENT FRAMEWORK
ROCKHAMPTON REGIONAL COUNCIL ENTERPRISE RISK MANAGEMENT FRAMEWORK 2013 Adopted 25 June 2013 Reviewed: October 2015 TABLE OF CONTENTS 1. Introduction... 3 1.1 Council s Mission... 3 1.2 Council s Values...
Terms of Reference - Board Risk Committee
Terms of Reference - Board Risk Committee The Board Risk Committee is authorised by the Board to oversee the Group s risk management arrangements. It ensures that the overarching risk appetite is appropriate
Board of Directors Meeting 12/04/2010. Operational Risk Management Charter
Board of Directors Meeting 12/04/2010 Document approved Operational Risk Management Charter Table of contents A. INTRODUCTION...3 I. Background...3 II. Purpose and Scope...3 III. Definitions...3 B. GOVERNANCE...4
COBIT 5 Introduction. 28 February 2012
COBIT 5 Introduction 28 February 2012 COBIT 5 Executive Summary 2012 ISACA. All rights reserved. 2 Information! Information is a key resource for all enterprises. Information is created, used, retained,
Project Management Policy and Procedure
Project Management Policy and Procedure Author(s): Laura Graham Peter Griggs Approved SMT: October 2006 Issue Date: October 2006 Policy Review Date Ref: Contents: 1. Purpose and Scope 2. Aims and Objectives
fmswhitepaper Why community-based financial institutions should practice enterprise risk management.
fmswhitepaper Why community-based financial institutions should practice enterprise risk management. By Michael D. Cohn, CPA, CISA, CGEIT Director, WolfPAC Solutions Group Unique Insights Implementation
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date
Solihull Clinical Commissioning Group
Solihull Clinical Commissioning Group Business Continuity Policy Version v1 Ratified by SMT Date ratified 24 February 2014 Name of originator / author CSU Corporate Services Review date Annual Target audience
CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY AND POLICY
Zurich Management Services Limited Registered in England: No 2741053 Registered Office The Zurich Centre, 3000 Parkway Whiteley, Fareham Hampshire, PO15 7JZ CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY
IFAD Policy on Enterprise Risk Management
Document: EB 2008/94/R.4 Agenda: 5 Date: 6 August 2008 Distribution: Public Original: English E IFAD Policy on Enterprise Risk Management Executive Board Ninety-fourth Session Rome, 10-11 September 2008
Safety Management Systems (SMS) guidance for organisations
Safety and Airspace Regulation Group Safety Management Systems (SMS) guidance for organisations CAP 795 Published by the Civil Aviation Authority, 2014 Civil Aviation Authority, CAA House, 45-59 Kingsway,
Xavier Catholic College Risk Management - Policy & Procedure
Xavier Catholic College Risk Management Policy 18 March 2013 Sourced from CSOHS Online. Source CSO Broken Bay 2012 Page 1 Risk Management Policy (Draft) PURPOSE Risk management is the culture, processes
PROGRESS THROUGH PARTNERSHIP MAKING A DIFFERENCE GUIDANCE PERFORMANCE MANAGEMENT FRAMEWORK AND CONTINUOUS IMPROVEMENT
PROGRESS THROUGH PARTNERSHIP MAKING A DIFFERENCE GUIDANCE PERFORMANCE MANAGEMENT FRAMEWORK AND CONTINUOUS IMPROVEMENT July 2014 Contents Page Introduction 3 What is continuous improvement? 4 Why do we
Consultation requirements under the Offshore Petroleum and Greenhouse Gas Storage (Environment) Regulations 2009
Information Paper N-04750-IP1411 Revision No 2 December 2014 Consultation requirements under the Offshore Petroleum and Core concepts The requirement that effective consultation be undertaken by titleholders
Personal Development Planning
Personal Development Planning Scope All programmes leading to a City University London award. This policy will apply for partnership programmes unless equivalent arrangements have been specifically agreed
7 Directorate Performance Managers. 7 Performance Reporting and Data Quality Officer. 8 Responsible Officers
Contents Page 1 Introduction 2 2 Objectives of the Strategy 2 3 Data Quality Standards 3 4 The National Indicator Set 3 5 Structure of this Strategy 3 5.1 Awareness 4 5.2 Definitions 4 5.3 Recording 4
Child Selection. Overview. Process steps. Objective: A tool for selection of children in World Vision child sponsorship
Sponsorship in Programming tool Child Selection Objective: A tool for selection of children in World Vision child sponsorship We ve learned some things about selecting children. It is not a separate sponsorship
Ealing, Hammersmith and West London College
FURTHER EDUCATION COMMISSIONER ASSESSMENT SUMMARY Ealing, Hammersmith and West London College JANUARY 2016 Contents Assessment... 3 Background... 3 Assessment Methodology... 3 The Role, Composition and
Position Description
Position Description Wesley Disability Services Quality Risk & Compliance Specialist Agreement Signed Quality Risk and Compliance Specialist Signed Executive Manager, Wesley Disability Services Date Date
KENYA NATIONAL BUREAU OF STATISTICS RISK MANAGEMENT POLICY
KENYA NATIONAL BUREAU OF STATISTICS RISK MANAGEMENT POLICY SEPTEMBER 2009 Table of Contents Pg No. FOREWARD... ii PREFACE...iii CHAPTER ONE... 1 INTRODUCTION... 1 1.0 Background... 1 1.1 KNBS policy statement...
Office of the Police and Crime Commissioner for Avon and Somerset and Avon and Somerset Constabulary
Office of the Police and Crime Commissioner for Avon and Somerset and Avon and Somerset Constabulary Internal Audit Report () FINAL Risk Management: Follow Up of Previous Internal Audit Recommendations
A Framework of Quality Assurance for Responsible Officers and Revalidation
A Framework of Quality Assurance for Responsible Officers and Revalidation Supporting responsible officers and designated bodies in providing assurance that they are discharging their statutory responsibilities.
High level principles for risk management
16 February 2010 High level principles for risk management Background and introduction 1. In their declaration of 15 November 2008, the G-20 leaders stated that regulators should develop enhanced guidance
Risk Management Policy Adopted by:
Risk Management Policy Adopted by: Infigen Energy Limited Infigen Energy (Bermuda) Limited Infigen Energy RE Limited in its capacity as Responsible Entity of Infigen Energy Trust Adopted: 17 December 2009
DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Performance, Risk and Business Continuity Management Policy
Not Protectively Marked Item 6 Appendix B DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Management Policy The Dorset & Wiltshire Fire and Rescue Authority () is the combined fire and rescue authority for
STANDARDS OF SOUND BUSINESS AND FINANCIAL PRACTICES. ENTERPRISE RISK MANAGEMENT Framework
STANDARDS OF SOUND BUSINESS AND FINANCIAL PRACTICES ENTERPRISE RISK MANAGEMENT Framework September 2011 Notice This document is intended as a reference tool to assist Ontario credit unions to develop an
Risk Management Policy and Process Guide
Risk Management Policy and Process Guide Status: pending Next review date: December 2015 Page 1 Information Reader Box Directorate Medical Nursing Patients & Information Commissioning Operations (including
POLICY : CORPORATE RISK MANAGEMENT
APPENDIX 5 POLICY : CORPORATE RISK MANAGEMENT 1 Scope This is a Service wide policy. 2 Aims and Objectives Lancashire Combined Fire Authority provides services to a diverse range of people and organisations,
Compliance Management Framework. Managing Compliance at the University
Compliance Management Framework Managing Compliance at the University Risk and Compliance Office Effective from 07-10-2014 Contents 1 Compliance Management Framework... 2 1.1 Purpose of the Compliance
RISK MANAGEMENT POLICY (Revised October 2015)
UNIVERSITY OF LEICESTER RISK MANAGEMENT POLICY (Revised October 2015) 1. This risk management policy ( the policy ) forms part of the University s internal control and corporate governance arrangements.
AfDB New Procurement Policy: Training Program for the Bank s Procurement Staff. Risk-based design of Procurement Arrangements - Introduction
11 AfDB New Procurement Policy: Training Program for the Bank s Procurement Staff Risk-based design of Procurement Arrangements - Introduction 2 Bank's new Approach to Procurement New Vision of the Procurement
NORTH EAST DERBYSHIRE DISTRICT COUNCIL AUDIT AND CORPORATE GOVERNANCE SCRUTINY COMMITTEE 4 APRIL 2013
6 NORTH EAST DERBYSHIRE DISTRICT COUNCIL AUDIT AND CORPORATE GOVERNANCE SCRUTINY COMMITTEE 4 APRIL 2013 REPORT NO: DCR/07/13/BM OF THE DIRECTOR OF CORPORATE RESOURCES 6(e) CORPORATE DEBT RECOVERY UPDATE
The Compliance Universe
The Compliance Universe Principle 6.1 The board should ensure that the company complies with applicable laws and considers adherence to non-binding rules, codes and standards This practice note is intended
The Role of Internal Audit in Risk Governance
The Role of Internal Audit in Risk Governance How Organizations Are Positioning the Internal Audit Function to Support Their Approach to Risk Management Executive summary Risk is inherent in running any
EVOLVING THE PROJECT MANAGEMENT OFFICE: A COMPETENCY CONTINUUM
EVOLVING THE PROJECT MANAGEMENT OFFICE: A COMPETENCY CONTINUUM Gerard M. Hill Many organizations today have recognized the need for a project management office (PMO) to achieve project management oversight,
ILM Level 3 Certificate in Using Active Operations Management in the Workplace (QCF)
PAGE 1 ILM Level 3 Certificate in Using Active Operations Management in the Workplace (QCF) CONTENTS Qualification Overview: ILM Level 5 Award, Certificate and Diploma in Management APPENDICES Appendix
How To Write A Risk Management Policy For The University Of Kerry
Risk Management Policy Originator name: Department: Implementation date: Ruth Anderson Finance 1 August 2013 Date of next review: 1 August 2016 Related policies: Health & Safety Policy, Equality & Diversity
Solvency II Own Risk and Solvency Assessment (ORSA)
Solvency II Own Risk and Solvency Assessment (ORSA) Guidance notes September 2011 Contents Introduction Purpose of this Document 3 Lloyd s ORSA framework 3 Guidance for Syndicate ORSAs Overview 7 December
RISK MANAGEMENT FRAMEWORK. 2 RESPONSIBLE PERSON: Sarah Price, Chief Officer
RISK MANAGEMENT FRAMEWORK 1 SUMMARY The Risk Management Framework consists of the following: Risk Management policy Risk Management strategy Risk Management accountability Risk Management framework structure.
How To Transform It Risk Management
The transformation of IT Risk Management kpmg.com The transformation of IT Risk Management The role of IT Risk Management Scope of IT risk management Examples of IT risk areas of focus How KPMG can help
APPENDIX C. Internal Audit Report South Holland District Council Project Management
APPENDIX C Internal Audit Report South Holland District Council Project Management Date: 20th December 2012 Contents Introduction and Scope 1 Executive Summary Assurance Opinion Key Messages 2 3 Management
INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS
Standard No. 13 INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS STANDARD ON ASSET-LIABILITY MANAGEMENT OCTOBER 2006 This document was prepared by the Solvency and Actuarial Issues Subcommittee in consultation
RISK MANAGEMENT OVERVIEW 2011 RISK CONFERENCE SPONSORED BY THE FEDERAL RESERVE BANK OF CHICAGO AND DEPAUL UNIVERSITY
RISK MANAGEMENT OVERVIEW 2011 RISK CONFERENCE SPONSORED BY THE FEDERAL RESERVE BANK OF CHICAGO AND DEPAUL UNIVERSITY PRESENTED BY: LEN WIATR, CHIEF RISK OFFICER Len s Risk Management Philosophy Build a
Swinburne University of Technology Gender Equality Strategic Action Plan 2015-2016
Swinburne University of Technology Gender Equality Strategic Action Plan 2015-2016 Page 1 of 8 1. Introduction 1.1. Context and Swinburne s HR Strategic Planning Framework Swinburne has established its
Shepway District Council Risk Management Policy
Shepway District Council Risk Management Policy Contents Section 1 Risk Management Policy... 3 1. Updates and amendments... 3 2. Definition... 3 3. Policy statement... 3 4. Objectives... 3 Section 2 Risk
COBIT 5 For Cyber Security Governance and Management. Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE)
COBIT 5 For Cyber Security Governance and Management Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE) Cybersecurity Governance using COBIT5 Cyber Defence Summit Riyadh, KSA
TGA key performance indicators and reporting measures
TGA key indicators and reporting measures Regulator Performance Framework Version 1.0, May 2015 About the Therapeutic Goods Administration (TGA) The Therapeutic Goods Administration (TGA) is part of the
NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY
NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY AUTHOR/ APPROVAL DETAILS Document Author Written By: Human Resources Authorised Signature Authorised By: Helen Shields Date: 20
INTERNAL AUDIT FINAL REPORT. Project Management. June 2013
Broxbourne Borough Council Contract Audit Project Management APPENDIX E INTERNAL AUDIT FINAL REPORT Project Management June 2013 Ref 18.12/13 June 2013 Page 1 Broxbourne Borough Council Contract Audit
Health and Safety Policy and Procedures
Health and Safety Policy and Procedures Health & Safety Policy & Procedures Contents s REVISION AND AMENDMENT RECORD : Summary of Change Whole Policy 4.0 05 Nov 08 Complete re-issue Whole Policy 4.1 10
Delivering Excellence in Insurance Claims Handling
Delivering Excellence in Insurance Claims Handling Guide to Best Practice Delivering Excellence in Insurance Claims Handling Contents Page 1. Introduction 1 2. Executive Summary 2 3. Components of Best
Avondale College Limited Enterprise Risk Management Framework 2014 2017
Avondale College Limited Enterprise Risk Management Framework 2014 2017 President s message Risk management is part of our daily life, something we do regularly; often without realising we are doing it.
Ethical Trading Initiative Management Benchmarks
Ethical Trading Initiative Management Benchmarks The Management Benchmarks are the means by which ETI (a) sets out its expectations of members and (b) measures members progress in applying the ETI Base
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012. Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012 Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund There are different risk assessments prepared: Annual risk assessment
COMPLIANCE CHARTER 1
COMPLIANCE CHARTER 1 Contents 1. Compliance Policy Statement... 2 2. Purpose... 2 3. Mission and objective of the Directorate: Compliance... 2 3.1 Mission... 2 3.2 Objective... 3 4. Compliance risk management...
The Audit of Best Value and Community Planning The City of Edinburgh Council. Best Value audit 2016
The Audit of Best Value and Community Planning The City of Edinburgh Council Best Value audit 2016 Report from the Controller of Audit February 2016 The Accounts Commission The Accounts Commission is the
Research and Innovation Strategy: delivering a flexible workforce receptive to research and innovation
Research and Innovation Strategy: delivering a flexible workforce receptive to research and innovation Contents List of Abbreviations 3 Executive Summary 4 Introduction 5 Aims of the Strategy 8 Objectives
Request for Proposal. Supporting Document 3 of 4. Contract and Relationship Management for the Education Service Payroll
Request for Proposal Supporting Document 3 of 4 Contract and Relationship December 2007 Table of Contents 1 Introduction 3 2 Governance 4 2.1 Education Governance Board 4 2.2 Education Capability Board
City of Canning. Asset Management Strategy 2015 2018
City of Canning Asset Management Strategy 2015 2018 Document Control Version No Version Date Description TRIM Reference 1.0 11 December 2012 Asset Management Strategy D12/68776 2.0 23 September 2015 Updated
RISK MANAGEMENT STRATEGY 2014-17
RISK MANAGEMENT STRATEGY 2014-17 DOCUMENT NO: Lead author/initiator(s): Contact email address: Developed by: Approved by: DN128 Head of Quality Performance [email protected] Quality Performance Team
University of Edinburgh Risk Policy and Risk Appetite
University of Edinburgh Risk Policy and Risk Appetite 1. Pushing the boundaries of knowledge, innovating, and implementing strategic developments will always have risks. Effective risk management increases
Audit of Business Continuity Planning
Cumbria Office of the Police & Crime Commissioner Audit of Business Continuity Planning 0 Cumbria Shared Internal Audit Service Images courtesy of Carlisle City Council except: Parks (Chinese Gardens),
Enterprise Risk Management: From Theory to Practice
INSURANCE Enterprise Risk Management: From Theory to Practice KPMG LLP Executive Summary Enterprise Risk Management (ERM) is a structured and disciplined business tool aligning strategy, processes, people,
Guideline. Operational Risk Management. Category: Sound Business and Financial Practices. No: E-21 Date: June 2016
Guideline Subject: Category: Sound Business and Financial Practices No: E-21 Date: June 2016 1. Purpose and Scope of the Guideline This Guideline sets out OSFI s expectations for the management of operational
Report to Parliament No. 4 for 2011 Information systems governance and security. Financial and Assurance audit. Enhancing public sector accountability
Financial and Assurance audit Report to Parliament No. 4 for 2011 Information systems governance and security ISSN 1834-1128 Enhancing public sector accountability RTP No. 4 cover.indd 1 15/06/2011 3:19:31
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT Let me begin by thanking Baruch College for giving me the opportunity to present this year s prestigious Emanuel Saxe Lecture in Accounting.
Update on NHSCB Key features of (proposed) NHSCB operating model for primary care
Aim to cover Update on NHSCB Key features of (proposed) NHSCB operating model for primary care NHSCB dental commissioning strategy all dental services Concept and context of local professional networks
