Why Strategic Risk Management?
|
|
|
- Horatio Hodge
- 9 years ago
- Views:
Transcription
1 Excerpt from the Economist Intelligent Unit 2010 research report Fall guys risk management in the front line : Strategic risks those that pose a threat to a company s ability to set and execute its overall strategy dominate the list of concerns for many companies. Asked about the key risks that they will face over the next 12 months, survey respondents point to weak demand as the most worrying threat. Other important issues that keep them awake at night include instability in one of their major markets and financial market volatility. These strategic risks can make the difference between survival and extinction but, in many cases, companies do not have a structured framework for identifying or mitigating them. This is not to say that strategic risks are being ignored indeed, most board members and executive directors would see this as a fundamental part of their role. But often, these discussions are being held without a formal, structured process for gathering, aggregating and analysing risk information. And without this input, boards may not be making decisions from a position of full knowledge and understanding. Respondents to our survey recognise the importance of strategic risk management, but the complexity of the task appears to prevent them from addressing it in a formal way. When asked about the main objectives of the risk management function, respondents point to the identification of new and emerging risks as the most important goal. And yet, when asked to rate their company s effectiveness at different aspects of risk management, respondents see the identification of new and emerging risks as one of their biggest weaknesses. Equally, just 46% think that their company is effective at linking risk management with overall corporate strategy EIU Reprinted by permission Why Strategic Risk Management? A few years ago, the RIMS Board of Directors identified strategic risk management as an emerging practice, viewing it as the next step in the evolution of enterprise risk management. It commissioned an external study in 2009 that came to similar conclusions: Concepts are immature, but developing Less consideration for the potential upside risks in actual practice Organizations are seeking direction from a global leading authority that can provide services in these evolving practices While a number of organizations already have embraced strategic risk management as an integral part of their respective enterprise risk management practices, others are developing or practicing strategic risk management as a focused discipline outside of a formal enterprise-wide risk management effort. RIMS intends to be the leading global authority on strategic risk management, whether an organization chooses to make it part of its enterprise risk management practices or focus its risk practices on strategy separately. Recognizing that strategic risk management is an evolving practice, RIMS formed a Strategic Risk Management Development Council to complement the strong work of its ERM Committee in this focused area. This advisory council is comprised of strategic and enterprise risk management practitioners as well as a published academic on the topic. By using common board and staff liaisons, as well as including a member liaison from the ERM Committee, the board sought to secure a solid directional link for RIMS. In creating the council, RIMS emphasized that SRM is not meant to supplant ERM, nor is this focus on SRM intended to create a new risk management silo. Indeed, we envision the convergence of ERM and SRM as more organizations formally adopt enterprise risk management. That said, RIMS recognizes that each organization determines what it needs from risk management and that strategy is driven by executive management, primarily through strategic planners. As such, RIMS in meeting its mission for advancing the risk management discipline is ready to serve those respective needs. The following paper is intended to provide the necessary context for two important definitions: enterprise risk management and strategic risk management Risk and Insurance Management Society, Inc. All rights reserved. 1
2 What is ERM? Enterprise risk management (ERM) is a strategic business discipline that supports the achievement of an organization s objectives by addressing the full spectrum of its risks and managing the combined impact of those risks as an interrelated risk portfolio. Along with other principles, ERM encompasses all areas of organizational exposure to risk (including strategic) and seeks to embed risk management as a component in all critical decisions throughout the organization. 1 As described in RIMS Executive Report, The 2008 Financial Crisis, A Wake-up Call for Enterprise Risk Management, all organizations practice risk management in multiple forms, depending on the exposure being addressed. As such, along with financial risk management, we have witnessed the emergence of terms such as IT risk management, operational risk management and supply chain risk management, to name a few. Regardless of focus, risk management is practiced in some form in most organizations. While some or all of these practices arguably may and ideally should be part of a larger enterprise risk management umbrella, not all organizations have embraced the scope of enterprise risk management. Certain organizations do not have an enterprise risk management program nor do they intend to look into one. In such cases, specifically focused risk management practices are important to the organizations in which they are practiced. Other organizations may choose to initiate an enterprise risk management approach from one of the focused areas where risk management practices have matured, or by integrating the more mature focused areas to achieve an interrelated portfolio view. Strategic risk management may make sense as a starting point for an enterprise approach given the visibility risk management has gained at the board level. 1 The other principles included in the RIMS ERM definition are: Prioritizes and manages those exposures as an interrelated risk portfolio rather than as individual silos Evaluates the risk portfolio in the context of all significant internal and external environments, systems, circumstances, and stakeholders Recognizes that individual risks across the organization are interrelated and can create a combined exposure that differs from the sum of the individual risks Provides a structured process for the management of all risks, whether those risks are primarily quantitative or qualitative in nature Views the effective management of risk as a competitive advantage 2011 Risk and Insurance Management Society, Inc. All rights reserved. 2
3 What is SRM? Specifically focused, strategic risk management (SRM) is a business discipline that drives deliberation and action regarding uncertainties and untapped opportunities that affect an organization s strategy and strategic execution. Strategic risk management, whether alone or integrated in an ERM program context, can potentially identify situations in which risk can be a competitive advantage instead of only a threat to the strategic plan. SRM encompasses the interdisciplinary intersection of strategic planning, risk management and strategy execution in managing risks and seizing opportunities, not only for protection against losses, but for reducing uncertainties and seizing opportunities, thus enabling better performance in achieving the organization s objectives and greater resilience in an uncertain environment. Through the work of the council, RIMS identified ten specific guiding principles important to strategic risk management for strategic decision-making which are more fully described in other RIMS documents: Value-driven Reflective Structured Informed Dynamic Process-based Condition-based Consequential Interdisciplinary Scenario-driven 2011 Risk and Insurance Management Society, Inc. All rights reserved. 3
4 Frequently Asked Questions Q1. Isn t SRM part of ERM already? It depends on whether the management of strategic risks is included in the scope and design of ERM. While many organizations do include strategic risks in their respective ERM risk registers, these risks may not be integrated fully into the strategic planning process where decisions on value creation as well as value protection are being made. Senior management teams may not have embraced strategic risk management as a vital component of enterprise risk management. This limits awareness of ERM s structured discipline and enabling capabilities to help the organization manage the risks most directly related to achievement of the organization s objectives. Furthermore, without a disciplined strategic risk assessment, risks arising from the plans to meet the objectives may be overlooked. Q2. We already have a process for developing strategy and risk considerations are part of that process. Isn t that enough? SRM provides a systematic framework and process to address the uncertainties defined at the outset of strategy-setting. For example, the identification of threats and opportunities in a SWOT analysis may be quite similar to the initial identification approach used in SRM. However the SWOT process does not involve systematic prioritization or the explicit handling of the identified threats and opportunities in relation to the organizational strengths and weaknesses. A SWOT analysis generally assumes that this activity is being done in the subsequent operational strategy execution planning process. There remains a development need for practical risk management applications in reducing uncertainty in strategy-setting as well as strategy execution. Formal risk assessments may be made at different points along the value chain. However, the methods and processes for aggregating and analyzing these strategic risks within an organization s appetite and tolerance for risk against the expected reward outcome are in limited use. The value-driven risk management techniques most useful in a strategic setting are different from those that may be used currently in strategic planning, in ERM or, for that matter, in strategic decision-making outside of the formal strategic planning process. While many strategy defining processes do embed risk and opportunity identification, few have included systematic or even explicit handling of the identified uncertainties, such as cut-off limits based on early warning measures. Furthermore, by applying a consistent SRM framework and process, organizations can gain an advantage by monitoring the consolidated uncertainty exposure of the strategic portfolio which is not the case if each strategy is defined separately. Finally, for an organization that has defined its strategic risk appetite, the consolidated measure of exposure can be compared to the risk appetite. This supports deliberations as to whether the proposed strategy portfolio is in fact more ambitious than allowed within the appetite, or not ambitious enough enabling the organization to pursue even higher targets Risk and Insurance Management Society, Inc. All rights reserved. 4
5 Q3. How are SRM methods and techniques different from those used in ERM? Overall, they are closely related, particularly in the process used. However, the emphasis is different as the level of insight and certainty differ considerably between current operational and future strategic uncertainties. ERM risk assessment methodologies used in many organizations focus on certain elements of risk: primarily relative impact (however defined internally) and probability (or frequency/likelihood) of occurrence, frequently focused on the present day or over a relatively short time horizon. Other elements that may be taken into consideration are speed to onset (also referenced as velocity or immediacy), impact to reputation, and impact to various stakeholders outside of the organization. ERM identification and analysis methodologies tend to focus on events, rather than trends, and may rely heavily on historical data, which may or may not be predictive of future conditions. Organizations apply varying levels of qualitative and quantitative techniques in risk evaluation. Monitoring and measuring methods focus on risk and performance indicators related to management of key risks. These risk-based and event-driven techniques may be limiting in strategic planning where the focus tends to be more trend-driven while considering potential future events. SRM methods and techniques focus primarily on uncertainty from a relevance and importance perspective in achieving strategic objectives. The assessment elements may also include timing, impact to reputation and impact to various stakeholders, but usually with less emphasis on relative impact and/or likelihood. The methods and techniques are forward looking over the strategic planning time horizon, use scenario planning and stress testing not as predictors but for alternate strategy planning purposes, incorporate emerging and dynamic risks as considerations, integrate change management for effective response to changing conditions, and are strongly linked to planning, allocation and management of capital and funding needs. Metrics and monitoring methods generally are linked to 1) risk/reward outcomes within a defined risk appetite framework and 2) performance, focusing on deviations from expected performance outcomes. While many of the risk assessment techniques used in an ERM context can be useful in strategic planning and decision-making, different or modified methods and techniques specific to strategysetting and execution can be applied. Q4. Why should an organization that has implemented ERM consider an SRM focus? Aren t the same people involved? There are multiple reasons why an organization that has an ERM program may want to include a specifically focused SRM approach within its ERM framework and practice. First, successful achievement of the organization s objectives is not considered fully if the ERM program s primary focus and contribution are on value protection (that is, mitigation, compliance and/or control). Value may be untapped and lost if the organization views risk only as an impediment rather than a potential opportunity. Second, different people within the organization may be accountable for corporate strategy and execution than those who are responsible for functional day-to-day operations. Decision-makers and influencers at the strategic level may include a board of directors, trustees, executive management and others in strategy setting who have a strong focus on emerging and dynamic risks, 2011 Risk and Insurance Management Society, Inc. All rights reserved. 5
6 while operational, financial, legal and compliance risks which may or may not be strategic in nature generally are managed at various levels throughout the organization with a primary focus on known or foreseen risks. Third, strategic and emerging risks may not find natural owners for identification, assessment, planning, threshold alerts and monitoring in current ERM governance structures, although such risks may affect multiple parts of the organization. By incorporating a disciplined strategic risk management focus, a more direct connection between the risks related to the strategy itself and its execution is achieved. Furthermore, a strategic risk management focus is more likely to reframe risks as potential opportunities. Risk practitioners, who support and drive a strong risk management process throughout an organization, provide the common discipline for SRM as well as ERM. Q5. What are the similarities between ERM and SRM? ERM and SRM are similar in that both evaluate risk in the context of significant internal and external environments and stakeholders. Both provide a structured framework and process, although methods and techniques may differ. Both seek to embed risk management as a critical component in decision-making. In fact, these similarities highlight the benefits of merging SRM into the ERM program and broadening the scope of ERM to include the strategy development process even when response measures may differ from those applied in traditional ERM. Q6. Can SRM be implemented if ERM has not been implemented or has not met expectations? Yes, strategic risk management can be implemented as a focused discipline in strategic planning, without having an enterprise risk management program in place. On the other hand, a number of organizations are initially testing or re-evaluating ERM by taking a strategic risk management focus to demonstrate the value of risk management in decision-making for achieving organizational objectives. Q7. What is the purpose of the SRM principles? The SRM principles are fundamental characteristics offered for guidance and direction. They are by no means prescriptive nor are they sequential, but they all are important for a strategic risk management focus. The degree of relative importance for each of the principles within particular industries, sectors or organizations is left to individual organizations to decide. Q8. Are the SRM principles only useful to organizations that define strategy well? No. Effective use of the SRM principles actually may help an organization to define its strategy with more clarity, as the discipline drives deeper consideration of the unintended consequences and potential exposures arising from and created by operational plans designed to execute the chosen strategy. Evaluation of significant internal and external conditions, such as organizational capabilities, environments, forces, events, trends and stakeholders if not already included in the strategy itself in fact may lead to different and potentially more value-producing strategies Risk and Insurance Management Society, Inc. All rights reserved. 6
7 Q9. How would an organization use the SRM principles? For organizations that formally have integrated risk management into strategic planning and execution already, the principles may serve to validate what is already being practiced, or to identify characteristics that currently are not being embraced by the organization. For organizations planning to integrate risk management into strategic planning and execution, the principles may serve as guidance as to the characteristics needed for effective implementation and practice. For organizations that have not considered integrating risk management into strategic planning and execution, the principles may serve as conversation-starters for enhancing the organization s current approach in order to link risk management with its corporate strategy more effectively. Q10. How is SRM related to operational risk management? Operational risk management generally focuses internally on the risks inherent in or arising from the organization s operations, such as people, processes and technology. It may also consider external events, external resources and regulatory compliance but only to the extent such events might affect operations, and not necessarily the overall strategy. As noted earlier, SRM specifically focuses on trends, future events and circumstances not only as threats but as untapped opportunities in strategic design, while considering the allocated resources needed to execute the adaptive strategy. While corporate strategies usually are set at an executive level, strategy execution occurs at the operational level. The relationship between strategic and operational risk management is the link between design and implementation. The stronger the link, the more successful the strategy can be. In addition, the link addresses the stakeholder, board and executive management desire for more effective risk management in strategic and operational decision-making. Q11. Who should be involved in SRM and how can it be implemented? Since this is an emerging practice, the who and how of SRM are still being defined. As with ERM, collaboration among the various internal stakeholders is required to advance the organizational objectives Risk and Insurance Management Society, Inc. All rights reserved. 7
8 RIMS would like to thank the following individuals for their contributions to this document: RIMS Strategic Risk Management Development Council Members Carol Fox, Council Chair, RIMS Michael Liebowitz, Council Vice Chair, New York University and Former RIMS President Judy Aakeberg, Greater Orlando Aviation Authority Eric Benson Mark L. Frigo, PhD, DePaul University Hans Læssøe, LEGO System A/S Monica Merrifield, YMCA of Greater Toronto Joe Restoule, Restoule Risk Management and Former RIMS President Nowell Seaman, University of Saskatchewan Drew Zavatsky, State of Washington RIMS ERM Committee Members Pete Fahrenthold, Committee Chair, United Ryan Egerdahl, Committee Vice Chair, Bonneville Power Authority Grace Crickette, University of California Radu Demian, University Hospitals Health System Inc. Carol Fox, RIMS John Hach, Lincoln Electric Co. Jayashree Ishwar, Erie Insurance Group Rupak Mazumdar, ehealth Ontario Russell McGuire, Milliman Risk Advisory Services Soubhagya Parija, Sterling Jewelers, Inc. Nowell Seaman, University of Saskatchewan Cristina Tate, Hewlett-Packard Company Walt Williams, Lowe s Companies, Inc. Drew Zavatsky, State of Washington RIMS would like to acknowledge the following individuals for their support of this work: RIMS Board of Directors Scott B. Clark, President, Miami-Dade County Public Schools Deborah M. Luthi, Vice President San Francisco Public Utilities Commission Janet Barnes, Public Utility District No. 1 of Snohomish County Robert Cartwright, Jr., Bridgestone Retail Operations, LLC Kim Hunton, City of Ottawa Daniel H. Kugler, Snap-on Inc. William J. Montanez, Ace Hardware Corporation Julie C. Pemberton, Chiquita Brands International Carolyn M. Snow, Treasurer, Humana Inc. John R. Phelps, Secretary Blue Cross and Blue Shield of Florida, Inc. Michael D. Phillipus, ATP Oil & Gas Corporation Richard J. Roberts, Jr. Ensign-Bickford Industries, Inc. Frederick J. Savage, Chevron Corporation Nowell R. Seaman, University of Saskatchewan Lori Seidenberg, Centerline Capital Group Terry Fleming, Montgomery County, Maryland Executive Director Mary Roth, RIMS Executive Director 2011 Risk and Insurance Management Society, Inc. All rights reserved. 8
GAINING CONTROL: Building Your Existing Framework into an ERM Model
GAINING CONTROL: Building Your Existing Framework into an ERM Model RIMS Northeast Ohio Chapter Education Day Carol Fox, ARM RIMS Director of Strategic and Enterprise Risk Practice November 19, 2013 Copyright
Enterprise Risk Management: From Theory to Practice
INSURANCE Enterprise Risk Management: From Theory to Practice KPMG LLP Executive Summary Enterprise Risk Management (ERM) is a structured and disciplined business tool aligning strategy, processes, people,
RIMS Executive Report The Risk Perspective. Emerging Risks. and. Enterprise Risk Management
RIMS Executive Report The Risk Perspective Emerging Risks and Enterprise Risk Management Emerging Risks and Enterprise Risk Management Editors Soubhagya Parija Walt Williams Drew Zavatsky Russell McGuire
Board oversight of risk: Defining risk appetite in plain English
www.pwc.com/us/centerforboardgovernance Board oversight of risk: Defining risk appetite in plain English May 2014 Defining risk appetite in plain English Risk oversight continues to be top-of-mind for
FlyntGroup.com. Enterprise Risk Management and Business Impact Analysis: Understanding, Treating and Monitoring Risk
Enterprise Risk Management and Business Impact Analysis: Understanding, Treating and Monitoring Risk 2012 The Flynt Group, Inc., All Rights Reserved FlyntGroup.com Enterprise Risk Management and Business
STANDARD. Risk Assessment. Supply Chain Risk Management: A Compilation of Best Practices
A S I S I N T E R N A T I O N A L Supply Chain Risk Management: Risk Assessment A Compilation of Best Practices ANSI/ASIS/RIMS SCRM.1-2014 RA.1-2015 STANDARD The worldwide leader in security standards
How to stay competitive in a converging healthcare system kpmg.com
Managing risk in a transforming healthcare organization How to stay competitive in a converging healthcare system kpmg.com 2 Healthcare Risk Management Managing the risk of healthcare transformation Healthcare
Strategic Risk Assessment. A first step for improving risk management and governance. COVER STORY. By Mark L. Frigo and Richard J.
Strategic Risk Assessment ILLUSTRATION: TIM LEE/WWW.LEEILLO.COM A first step for improving risk management and governance. By Mark L. Frigo and Richard J. Anderson December 2009 I STRATEGIC FINANCE 25
The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework
The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework Dorothy Gjerdrum, ARM-P, Chair of the ISO 31000 US TAG and Executive Director,
July 2015. New Entrants: Charting the Health Industry s Risk and Regulatory Landscape Where Risk Meets Opportunity
July 2015 New Entrants: Charting the Health Industry s Risk and Regulatory Landscape Where Risk Meets Opportunity The new health economy is bringing change and new entrants from diverse industries are
RSA ARCHER OPERATIONAL RISK MANAGEMENT
RSA ARCHER OPERATIONAL RISK MANAGEMENT 87% of organizations surveyed have seen the volume and complexity of risks increase over the past five years. Another 20% of these organizations have seen the volume
Supporting information technology risk management
IBM Global Technology Services Thought Leadership White Paper October 2011 Supporting information technology risk management It takes an entire organization 2 Supporting information technology risk management
ENTERPRISE RISK MANAGEMENT FRAMEWORK
ENTERPRISE RISK MANAGEMENT FRAMEWORK COVENANT HEALTH LEGAL & RISK MANAGEMENT CONTENTS 1.0 PURPOSE OF THE DOCUMENT... 3 2.0 INTRODUCTION AND OVERVIEW... 4 3.0 GOVERNANCE STRUCTURE AND ACCOUNTABILITY...
How to achieve excellent enterprise risk management Why risk assessments fail
How to achieve excellent enterprise risk management Why risk assessments fail Overview Risk assessments are a common tool for understanding business issues and potential consequences from uncertainties.
Enhanced Portfolio Management in uncertain times
Enhanced Portfolio Management in uncertain times How businesses can generate and protect value through enhanced, risk return techniques improving portfolio and capital allocation decisions Contents Executive
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012. Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012 Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund There are different risk assessments prepared: Annual risk assessment
Linking Risk Management to Business Strategy, Processes, Operations and Reporting
Linking Risk Management to Business Strategy, Processes, Operations and Reporting Financial Management Institute of Canada February 17 th, 2010 KPMG LLP Agenda 1. Leading Practice Risk Management Principles
IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS
IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS 1 Module 1: Principles of Risk and Risk Management Module aims The aim of this module is to provide an introduction to the principles and concepts of risk and
Introduction to Enterprise Risk Management at UVM DRAFT
Introduction to Enterprise Management at UVM 1 Enterprise What is Enterprise Management? Enterprise risk management is a structured, consistent, and continuous process across the whole organization for
Enterprise Risk Management: Taking the First Steps
Enterprise Risk Management: Taking the First Steps TN PRIMA, 2012 DOROTHY GJERDRUM, ARM, CIRM NOVEMBER 15, 2012 Agenda Goal: To understand how to begin to implement a broader approach to risk management
International Diploma in Risk Management Syllabus
International Diploma in Risk Management Syllabus Module 1: Principles of Risk and Risk Management The aim of this module is to provide an introduction to the principles and concepts of risk and risk management.
Enterprise Risk Management: Concepts & Issues
Enterprise Risk Management: Concepts & Issues Jacques Lapointe Internal Audit, Management Board Secretariat November 2003 1 The Basic Concept of Risk Management The active process of identifying risks,
Policy 10.105: Enterprise Risk Management Policy
Name: Responsibility: Complements: Enterprise Risk Management Framework Coordinator, Enterprise Risk Management Policy 10.105: Enterprise Risk Management Policy Date: November 2006 Revision Date(s): January
ENTERPRISE RISK MANAGEMENT POLICY
ENTERPRISE RISK MANAGEMENT Approved by the Audit Committee on 14 February 2003 and adopted by resolution of the Board on 28 March 2003 Revisions approved by the Audit and Risk Committee on 14 February
Cyber security: Are consumer companies up to the challenge?
Cyber security: Are consumer companies up to the challenge? 1 Cyber security: Are consumer companies up to the challenge? A survey of webcast participants kpmg.com 1 Cyber security: Are consumer companies
ENTERPRISE RISK MANAGEMENT SURVEY. 2013 RIMS Enterprise Risk Management (ERM) Survey SPONSORED BY:
t RIMS2013 ENTERPRISE RISK MANAGEMENT SURVEY 2013 RIMS Enterprise Risk Management (ERM) Survey SPONSORED BY: Administered by: Advisen Ltd. Zurich Authored by: RIMS and Advisen Ltd. Publishers: Mary Roth,
Remarks by. Carolyn G. DuChene Deputy Comptroller Operational Risk. at the
Remarks by Carolyn G. DuChene Deputy Comptroller Operational Risk at the Bank Safety and Soundness Advisor Community Bank Enterprise Risk Management Seminar Washington, D.C. October 22, 2012 Good afternoon,
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
Guiding Principles for Implementing Enterprise Risk Management (ERM)
1 Guiding Principles for Implementing Enterprise Risk Management (ERM) SEAC Conference New Orleans November 15-17, 2006 Hubert Mueller (860) 843-7079 Towers Towers Perrin Perrin 0 ERM raises many implementation
Tying It All Together: Practical ERM Integration. Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation
Tying It All Together: Practical ERM Integration Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation November 16, 2007 1 Agenda Basis for ERM Integration ERM Objectives ERM Focus
ERM Technology Tools: A Contemporary Look
RIMS Executive Report The Risk Perspective ERM Technology Tools: A Contemporary Look A Report of the RIMS Technology Advisory Council and RIMS ERM Committee CONTRIBUTORS Grace Crickette, Chief Risk Officer,
Hand IN Hand: Balanced Scorecards
ANNUAL CONFERENCE T O P I C Risk Management WORKING Hand IN Hand: Balanced Scorecards AND Enterprise Risk Management B Y M ARK B EASLEY, CPA; A L C HEN; K AREN N UNEZ, CMA; AND L ORRAINE W RIGHT Recent
How To Transform It Risk Management
The transformation of IT Risk Management kpmg.com The transformation of IT Risk Management The role of IT Risk Management Scope of IT risk management Examples of IT risk areas of focus How KPMG can help
Placing a Value on Enterprise Risk Management ADVISORY
Placing a Value on Enterprise Risk Management ADVISORY Placing a Value on Enterprise Risk Management 1 In turbulent economic times, the case for investing in an enterprise risk management (ERM) program
Presentation Objectives Why is Internal Audit here? Concepts (Enterprise Risk Management, Strategic Risk, Strategic Risk Management, etc.
Internal Audit 1 January 13, 2012 Presentation Objectives Why is Internal Audit here? Concepts (Enterprise Risk Management, Strategic Risk, Strategic Risk Management, etc.) Summary Internal Audit 2 January
IFAD Policy on Enterprise Risk Management
Document: EB 2008/94/R.4 Agenda: 5 Date: 6 August 2008 Distribution: Public Original: English E IFAD Policy on Enterprise Risk Management Executive Board Ninety-fourth Session Rome, 10-11 September 2008
UNITED NATIONS OFFICE FOR PROJECT SERVICES. ORGANIZATIONAL DIRECTIVE No. 33. UNOPS Strategic Risk Management Planning Framework
UNOPS UNITED NATIONS OFFICE FOR PROJECT SERVICES Headquarters, Copenhagen O.D. No. 33 16 April 2010 ORGANIZATIONAL DIRECTIVE No. 33 UNOPS Strategic Risk Management Planning Framework 1. Introduction 1.1.
Empower loss prevention with strategic data analytics
www.pwc.com/us/lossprevention January 2015 Empower loss prevention with strategic data analytics Empower loss prevention with strategic data analytics Amid heightened levels of business competition and
Chief Risk Officers in the Mutual Fund Industry: Who Are They and What Is Their Role Within the Organization?
Chief Risk Officers in the Mutual Fund Industry: Who Are They and What Is Their Role Within the Organization? Background Everyone within an organization has some responsibility for managing risk. In the
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN ABOUT THE AUTHOR Leveraging his background in internal audit and internal controls, Noah Gottesman provides industry thought leadership
Business Continuity Management Systems. Protecting for tomorrow by building resilience today
Business Continuity Management Systems Protecting for tomorrow by building resilience today Vital statistics 31% 40% of UK businesses have been affected by bad weather related transport problems, power
Periodic risk assessment by internal audit
Periodic risk assessment by internal audit I Introduction The Good Practice Internal Audit Manual Template, developed by the Internal Audit CoP of Pempal, defines the importance and the impact that an
Vision Statement for Innovative Software Development in a Large. Corporation
Vision Statement for Innovative Software Development in a Large Corporation Joseph C. Thomas Regent University Center for Leadership Studies LEAD606 Strategic Vision and Organizational Effectiveness 4-Nov-2002
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
Subject ST9 Enterprise Risk Management Syllabus
Subject ST9 Enterprise Risk Management Syllabus for the 2015 exams 1 June 2014 Aim The aim of the Enterprise Risk Management (ERM) Specialist Technical subject is to instil in successful candidates the
RIMS Executive Report The Risk Perspective. Exploring Risk Appetite and Risk Tolerance
RIMS Executive Report The Risk Perspective Exploring Risk Appetite and Risk Tolerance Contributors Grace Crickette Chief Risk Officer, University of California Radu Demian Manager, Corporate Risk Management,
Operational Risk Management Program Version 1.0 October 2013
Introduction This module applies to Fannie Mae and Freddie Mac (collectively, the Enterprises), the Federal Home Loan Banks (FHLBanks), and the Office of Finance, (which for purposes of this module are
Enterprise Risk Management
2013 Government Accounting and Auditing Update Enterprise Risk Management Understanding and Implementing an ERM Framework Mike Sargent, Director- CliftonLarsonAllen May 2013 cliftonlarsonallen.com Discussion
How to Develop Successful Enterprise Risk and Vendor Management Programs
Project Management Institute New York City Chapter January 2014 Chapter Meeting How to Develop Successful Enterprise Risk and Vendor Management Programs Christina S. Kite Senior Vice President Corporate
University of St. Gallen Law School Law and Economics Research Paper Series. Working Paper No. 2008-19 June 2007
University of St. Gallen Law School Law and Economics Research Paper Series Working Paper No. 2008-19 June 2007 Enterprise Risk Management A View from the Insurance Industry Wolfgang Errath and Andreas
FFIEC Cybersecurity Assessment Tool
Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,
Enterprise Risk Management
Enterprise Management ERM provides a framework for risk management, which typically involves identifying particular events or circumstances relevant to the organization's objectives (risks and opportunities),
Much attention has been focused recently on enterprise risk management (ERM),
By S. Michael McLaughlin and Karen DeToro Much attention has been focused recently on enterprise risk management (ERM), not just in the insurance industry but in other industries as well. Across all industries,
Framing the future of corporate governance Deloitte Governance Framework
Framing the future of corporate governance Deloitte Governance Framework For those interested in the topic of corporate governance, these are dynamic times. The events of the past decade have led to the
Beyond risk identification Evolving provider ERM programs
Beyond risk identification Evolving provider ERM programs March 2016 At a glance PwC conducted research to assess the state of enterprise risk management (ERM) within healthcare providers and found many
The Essentials of Enterprise Risk Management. Steven C. Tourek, Senior Vice President, General Counsel & Secretary, The Marvin Companies
The Essentials of Enterprise Risk Management Steven C. Tourek, Senior Vice President, General Counsel & Secretary, The Marvin Companies Introduction How should an organization think about the management
The Role of Internal Audit in Risk Governance
The Role of Internal Audit in Risk Governance How Organizations Are Positioning the Internal Audit Function to Support Their Approach to Risk Management Executive summary Risk is inherent in running any
Developing an Effective Enterprise Risk Management Program
Developing an Effective Enterprise Risk Management Program Jay Brietz, CPA and CIA Senior Manager This material was used by Elliott Davis Decosimo during an oral presentation; it is not a complete record
A Risk Management Standard
A Risk Management Standard Introduction This Risk Management Standard is the result of work by a team drawn from the major risk management organisations in the UK, including the Institute of Risk management
Deriving Value from ORSA. Board Perspective
Deriving Value from ORSA Board Perspective April 2015 1 This paper has been produced by the Joint Own Risk Solvency Assessment (ORSA) Subcommittee of the Insurance Regulation Committee and the Enterprise
Integrated Risk Management:
Integrated Risk Management: A Framework for Fraser Health For further information contact: Integrated Risk Management Fraser Health Corporate Office 300, 10334 152A Street Surrey, BC V3R 8T4 Phone: (604)
How ERM programs evolve
How to achieve excellent Enterprise Risk Management series www.pwc.com/us/ermexcellenceseries Article 3: June 2015 How ERM programs evolve Overview An organization s enterprise risk management (ERM) program
Guideline. Operational Risk Management. Category: Sound Business and Financial Practices. No: E-21 Date: June 2016
Guideline Subject: Category: Sound Business and Financial Practices No: E-21 Date: June 2016 1. Purpose and Scope of the Guideline This Guideline sets out OSFI s expectations for the management of operational
Enterprise-Wide Risk Assessment
Enterprise-Wide Risk Assessment Agenda 1. Definition of risk. 2. Risk drivers in higher education today. 3. Implementing an enterprise-wide risk management (ERM) program to effectively assess, manage,
RIMS Executive Report The Risk Perspective
RIMS Executive Report The Risk Perspective An Overview of Widely Used Risk management Standards and Guidelines A Joint Report of RIMS Standards and Practices Committee and RIMS ERM Committee An Overview
Saldanha Bay Municipality. Risk Management Strategy. Inclusive of, framework, procedures and methodology
Inclusive of, framework, procedures and methodology Contents 1 Introduction 1 1.1 Legislative Framework and best practice 1 1.2 Purpose of Enterprise Risk Management 2 1.3 Scope and Applicability 3 1.4
Internal Control Integrated Framework. May 2013
Internal Control Integrated Framework May 2013 0 Table of Contents COSO & Project Overview Internal Control-Integrated Framework Illustrative Documents Illustrative Tools for Assessing Effectiveness of
Commodity Price Risk Management (CPRM) - Trends and Challenges for Corporates
Advisory Commodity Price Risk Management (CPRM) - Trends and Challenges for Corporates May 2014 Agenda Industry Challenges CPRM A Business Case CPRM Maturity Model CPRM Trends What Should Companies Do?
Accenture Risk Management. Industry Report. Life Sciences
Accenture Risk Management Industry Report Life Sciences Risk management as a source of competitive advantage and high performance in the life sciences industry Risk management that enables long-term competitive
Accreditation Application Forms
The Institute of Risk Management The Institute of Risk Management Accreditation Application Forms Universities and Professional Associations The Institute of Risk Management Accreditation Application Forms
ISO 31000:2009 - ISO/IEC 31010 & ISO Guide 73:2009 - New Standards for the Management of Risk
Kevin W Knight AM CPRM; Hon FRMIA; FIRM (UK); LMRMIA: ANZIIF (Mem) ISO 31000:2009 - ISO/IEC 31010 & ISO Guide 73:2009 - New Standards for the Management of Risk History of the ISO and Risk Management Over
Department of Veterans Affairs VA Directive 0054. VA Enterprise Risk Management (ERM)
Department of Veterans Affairs VA Directive 0054 Washington, DC 20420 Transmittal Sheet April 8, 2014 VA Enterprise Risk Management (ERM) 1. REASON FOR ISSUE: This directive provides guidelines to help
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
Enterprise Risk Management in a Highly Uncertain World. A Presentation to the Government-University- Industry Research Roundtable June 20, 2012
Enterprise Risk Management in a Highly Uncertain World A Presentation to the Government-University- Industry Research Roundtable June 20, 2012 CRO Council Introduction Mission The North American CRO Council
Risk appetite as a dynamic management tool
Risk appetite as a dynamic management tool Background The topic of risk appetite is at the centre of attention currently. There are various reasons for this: the financial crisis, which has made it clear
Five steps to Enterprise Risk Management
risk decisions 2011 Five steps to Enterprise Risk Management by Val Jonas CEO Risk Decisions Group www.riskdecisions.com management solutions Val Jonas: Five steps to Enterprise Risk Management Five steps
Operational Risk Management - The Next Frontier The Risk Management Association (RMA)
Operational Risk Management - The Next Frontier The Risk Management Association (RMA) Operational risk is not new. In fact, it is the first risk that banks must manage, even before they make their first
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date
EVOLVING THE PROJECT MANAGEMENT OFFICE: A COMPETENCY CONTINUUM
EVOLVING THE PROJECT MANAGEMENT OFFICE: A COMPETENCY CONTINUUM Gerard M. Hill Many organizations today have recognized the need for a project management office (PMO) to achieve project management oversight,
Successfully identifying, assessing and managing risks for stakeholders
Introduction Names like Enron, Worldcom, Barings Bank and Menu Foods are household names but unfortunately as examples of what can go wrong. With these recent high profile business failures, people have
CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data
CRISC Glossary Term Access control Access rights Application controls Asset Authentication The processes, rules and deployment mechanisms that control access to information systems, resources and physical
An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management
Bridgework: An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management @Copyright Cura Software. All rights reserved. No part of this document may be transmitted or copied without
Table of Contents PERFORMANCE REVIEWS STRATEGIC REVIEWS
SECTION 270 PERFORMANCE AND STRATEGIC REVIEWS Table of Contents 270.1 To which agencies does this section apply? 270.2 What is the purpose of this section? PERFORMANCE REVIEWS 270.3 What is the purpose
INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS
Standard No. 13 INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS STANDARD ON ASSET-LIABILITY MANAGEMENT OCTOBER 2006 This document was prepared by the Solvency and Actuarial Issues Subcommittee in consultation
FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors
Overview for Chief Executive Officers and Boards of Directors In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed
fmswhitepaper Why community-based financial institutions should practice enterprise risk management.
fmswhitepaper Why community-based financial institutions should practice enterprise risk management. By Michael D. Cohn, CPA, CISA, CGEIT Director, WolfPAC Solutions Group Unique Insights Implementation
Scenario Analysis Principles and Practices in the Insurance Industry
North American CRO Council Scenario Analysis Principles and Practices in the Insurance Industry 2013 North American CRO Council Incorporated [email protected] December 2013 Acknowledgement The
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT Let me begin by thanking Baruch College for giving me the opportunity to present this year s prestigious Emanuel Saxe Lecture in Accounting.
Strategic Risk Management for School Board Trustees
Strategic Management for School Board Trustees A Management Process Framework May, 2012 Table of Contents Introduction Page I. Purpose....................................... 3 II. Applicability and Scope............................
Preparing for the Convergence of Risk Management & Business Continuity
Preparing for the Convergence of Risk Management & Business Continuity Disaster Recovery Journal Webinar Series September 5, 2012 2012 Strategic BCP, Inc. All rights reserved. strategicbcp.com 1 Today
Risk management systems of responsible entities
Attachment to CP 263: Draft regulatory guide REGULATORY GUIDE 000 Risk management systems of responsible entities July 2016 About this guide This guide is for Australian financial services (AFS) licensees
Social Intranets and the Supply Chain
THOUGHT LEADERSHIP Social Intranets and the Supply Chain EXECUTIVE OVERVIEW SEP 2015 Alan Pelz-Sharpe, Research Director, Business Applications Matt Mullen, Senior Analyst, Business Applications In one
ENTERPRISE RISK MANAGEMENT FRAMEWORK WHAT IS ERM? JOIN. ENGAGE. LEAD.
ENTERPRISE RISK MANAGEMENT FRAMEWORK WHAT IS ERM? JOIN. ENGAGE. LEAD. Enterprise Risk Credit Risk Market Risk Operational Risk Regulatory Compliance Securities Lending INCREASED FOCUS ON ERM Although the
Financial Evolution and Stability The Case of Hedge Funds
Financial Evolution and Stability The Case of Hedge Funds KENT JANÉR MD of Nektar Asset Management, a market-neutral hedge fund that works with a large element of macroeconomic assessment. Hedge funds
