Integrating risk and performance in management reporting. Research executive summary series Volume 7 Issue 5
|
|
|
- Felix Fletcher
- 9 years ago
- Views:
Transcription
1 Integrating risk and performance in management reporting Research executive summary series Volume 7 Issue 5 Tommaso Palermo London School of Economics and Political Science
2
3 Key findings: Risk and performance are related, but the combination of risk and performance information into a single instrument is not always the most feasible solution to reach alignment. The way in which risk is related to performance management is based around a variety of organisational elements that may inhibit or conversely facilitate the integration of risk and performance management processes. For instance: The presence of a different periodicity of risk and performance reporting may limit their integration. The presence of a clear cut strategy that serves as a reference point for both risk and performance targets may foster alignment. Risk is often implicitly related to performance management. Performance management tools can provide risk information without much additional efforts. For instance: Performance reports can contribute to develop an awareness of emergent issues by highlighting performances that are changing unexpectedly. In certain areas, for example Health and Safety (H&S), KPIs can become good measures around risk. Trends in the number of incidents (or near misses) can be analysed to understand whether the business is becoming more or less risky.
4 Acknowledgement The researcher would like to thank CIMA General Charitable Trust for funding this project. This study was carried out while the author was affiliated with the Department of Management, Economics and Industrial Engineering, Politecnico di Milano. The author kindly thanks Margaret Woods who provided guidance on the project and the reviewers for their helpful comments on earlier versions of the research summary. Introduction The recent economic crisis has focused attention on risk management, but managing risk is all about achieving objectives (Woods et al. 2008; Cotter, 2009; Van der Stede, 2009). Senior managers in particular, are expected to build sustainable performances: create value at acceptable risk levels over time (Calandro and Lane, 2006). To this end, they should be clearly aware of the multiple sources and types of risks (CIMA, 2007). A stronger focus on risk in performance reports addressed to senior managers can address such expectation. Incorporating risk into performance management processes can foster a better understanding of the overall organisational risk exposure and improve business results. The way in which senior managers are made aware of risks via top management reporting is however an open ground where different professions and processes may find a role. On the one hand, the reporting of high level risk information is considered a constituent element of enterprise-wide risk management (ERM) frameworks. This attempts to provide an overview of crucial business risks, integrating traditional, function-specific risk management efforts, for example labour safety and information system security. This reporting can include a range of different information (Lam, 2006): qualitative information such as objectives at risk, audit findings and escalation of particular events or quantitative data such as early warning indicators, key risk indicators (KRIs) and financial risk measures, for example value at risk (VaR). On the other hand, it is argued that innovative performance management frameworks may contribute to foster senior managers ability to oversee business risks (IMA, 2006). In fact, frameworks such as the Balanced Scorecard (BSC) try to overcome the shortcomings of traditional accounting indicators by means of a balanced set of non-financial performance measures. This allows an early detection of weak signals from the environment and provide a more timely and long-term oriented view of the business (Kaplan and Norton, 1992, 1996, 2001). The use of such frameworks can help signal that some risks related to an item exist and will eventually cause poor financial performances. This project aims at providing some insights on how it is possible to link risk to performance management via top management reporting. Specifically, the project examines how: 1. Risk-related information are reported to senior managers. 2. Risk-related information are linked to performance management. Research method The research is based on a case study on one large UK energy company (hereafter: Energy Company). Background information on the Energy Company is presented in Table 1. Table 1 Energy Company - background information Industry sector Ownership Energy Wholly-owned subsidiary Employees More than 10,000 Structure Governance Four Business Units (BUs) Corporate and steering functions (HR, strategy and regulation, finance), corporate shared services (IT, procurement, project management) The board of directors is composed by two executive directors and four non-executive directors and a company secretary An executive committee, composed by the chief executive, chief financial officer, the BUs managing directors and corporate and steering functions (HR, strategy and regulation) 1 Integrating risk and performance in management reporting
5 Table 2 Job title Corporate risk director Performance manager (corporate function) Responsibilities Responsible for the risk management process (company-wide level) Responsible for company performance reporting (company-wide level) Local risk co-ordinator (corporate functions and shared services) Internal audit manager (business unit) Risk and compliance manager Contribute to internal audit processes (business unit level) Compliance with regulatory conditions Contributing to the development of departmental audits and maintenance of local risk register (business unit level) The case study is based on documentary information (including internal reports and guidelines on risk management) and a set of face to face interviews. Key informants of the case study are managers responsible for the reporting of performance information and managers responsible for the risk management process at different organisational levels (see Table 2). Interviews were based on a framework that was made available to interviewees beforehand. The structure of all interviews is similar, although adjustments are made according to the specific role of each interviewee. An outline of the main points discussed through interviews is presented in the appendix. The case study The Energy Company has a central risk management policy that describes the minimum risk management standards that Business Units (BUs) have to comply with. Risks are scored using a standard template that is based on a one to five impact scale. Descriptions are provided to help people identify a consistent score, especially for non-financial risks such as customer, safety, staff and reputation and so on. Specific methodologies are not mandated to score risks. BUs are free to choose the most appropriate approach for the risks they are managing. Generally speaking, BUs can have their own risk management policy as long as they remain aligned with central requirements. The approaches adopted across the company range from stochastic modelling to subjective judgement and experience. Workshops are used to facilitate the risk management process. They typically start with the identification of organisational objectives and continue with a brainstorming exercise on the possible risks that may affect their achievement. A corporate risk director, supported by a central team (hereafter: central risk team), is responsible for the risk management process, while BUs senior managers are accountable for the actual management of risks in accordance to the central risk management policy. BUs collect key risks data and put together a report with the support of local risk teams. Local risk teams report quarterly to the corporate risk director, who then reports to the executive committee. At the BU level, the composition of local risk teams and the job description of their members can vary across different BUs and departments, which are BUs sub-organisational units. For instance, in one BU there is a senior person who is nominated to be responsible for risk reporting in each department. They are supported by a subordinate who is responsible for maintaining each area s risk function. Different arrangements are possible in different departments. For instance, in one department a role has been created with specific responsibilities including compliance with the regulatory conditions, support to departmental audits and maintenance of risk registers. In other departments the responsibility to maintain the risk management process may not be so apparent or it may be characterised by different elements, for example a greater emphasis on business continuity. A team of two people (local risk team) co-ordinates and steers all risk management efforts within this BU. From each department, the local risk team receives a quarterly risk management review, aggregates the information and reports to the BU executive committee, before reporting to the central risk team. In addition, a local risk champion who is usually part of local risk teams, supports and promotes the risk management process in the BUs, making sure that people are collecting risk information properly. The corporate risk director meets formally with the risk champions at least once every other month. Furthermore, when the quarterly reporting cycle of risk information is closed, the corporate risk director has a post report meeting with local risk champions. In this meeting, the 2 Integrating risk and performance in management reporting
6 corporate risk director explains what has been discussed at the board level and how the risk management process has been run for the quarter. Issues typically discussed are timeliness of the delivery of reports, implementation of action plans, and the escalation of specific trends. The work of risk champions in the company varies across different BUs. For instance, the risk champion of the corporate functions and shared services unit aims at making people use the risk register practically through engagement. He works with senior managers to make sure that risks reflect their personal objectives and that action plans reflect the work that they are doing against risks. In general, risk champions have an oversight of the risk register of all the senior managers of the BU. This facilitates the risk management process because it allows to point out connected elements; for example audit, governance and assurance, and to calibrate risk assessment and mitigation strategies. Each risk register can be linked, although in most cases not explicitly, to a list of KRIs, which are simply function-related KPIs. For instance, for the media team of the corporate functions and shared services the number of negative stories that appear on the media could be one of the indicators used. In general, KRIs can be used to assess how well risks have been managed and they can become a more assured way of scoring risks. Performance management in the company is based on an adapted version of the balanced scorecard methodology. Performance management is initiated by a company scorecard, which is then cascaded down by means of operational scorecards at the BUs level. The company scorecard constitutes the corporate-wide strategic reference framework for decision making. It illustrates a set of ambitions that cover strategic areas such as people, financial, H&S and so on. These ambitions are equally rated and are associated to a limited set of financial and non-financial KPIs. BUs scorecards aim at linking company s ambitions to each business area by means of a larger number of measures that are more closely associated with operational effectiveness at a daily management level. Bonus schemes are structured around the same performance metrics used in the reports so to reach alignment between individual and company s performance. The company has a monthly performance report which summarises information for the whole business, followed by a monthly report for each BU and the corporate functions and shared services unit. The company report has a section on how the risk management process is run, but risks and risk measures are not formally incorporated at this level. Risk information can occasionally be incorporated into performance reports at lower organisational levels. For instance, the report for the corporate functions and shared services unit has a section that include a dashboard of KRIs. The report of one department incorporates the departmental risk map, the trends of risk indicators and information on risk mitigation strategies. In general, it is acknowledged that the company is a big business and mapping a direct relationship between risk and performance measures can be tricky, since many risks are over a longerterm horizon. However, this does not mean that performance management does not consider risks. For instance, the team that reports to the executives company-wide performance information (performance team) focuses on developing an awareness of the key areas and developing trends by looking at where new risks are emerging or performances are changing unexpectedly. There are no pre-defined thresholds to determine when a further examination of performance is needed. The team investigates measures that are persistently below target, but also measures that are constantly above target. This latter case might suggest that targets are set too tightly or too loosely or risks are poorly understood. Performance management can also provide a source of quantitative information for risk management via performance indicators. In certain areas most of the KPIs can become good measures around risk. For instance, in the H&S area the company records the number and the types of operational incidents, or near misses (incidents that could have potentially happened), that have occurred in a given period. These evidences are reviewed monthly by all the heads of H&S units in the company. This can be considered as a form of quantified risk assessment based on real evidence. Trends in the number of incidents, or near misses, are analysed to understand whether the business is becoming more or less risky. Main findings A general finding of this research is that incorporating risk into performance management is not simply an issue of combining risk and performance information into the same report. This finding can be more relevant than its apparent simplicity might suggest. As a matter of fact, practitioner-oriented contributions (e.g. Scholey, 2006; Beasley et al. 2006) suggest that the combination of risk and performance information into a single management tool, such as a risk BSC, can be a solution to increase the risk awareness of senior managers. The evidence of the case study calls for caution to be taken when considering this claim. The company has an enterprise-wide approach to risk management and a BSC approach to performance management, but information from the former; for example impact/ probabilities matrices, risk registers and KRIs, is incorporated into performance reports only at lower organisational levels. The business is simply too complex to combine company-wide risk and performance information in the same document. 3 Integrating risk and performance in management reporting
7 However, risk and performance are related and the relationship between them is based around different organisational elements. These elements can be grouped in three clusters: barriers that hamper integrating risk and performance, facilitators that help overcome barriers, and levers which consist of performance management tools that if used in a particular way, can provide risk-related information. These organisational elements are described in the following paragraphs with examples on how they practically affect linking risk to performance management in the case study. Barriers The first barrier concerns the relationship between risk and performance. Informants in the case study suggest there is a tension in the relationship between risk and performance. The same element can be interpreted in different ways if a risk perspective or a performance perspective is embraced. An indicative example is provided by the different approaches that can be embraced in the analysis of results that exceed expectations. A performance based approach may suggest that results exceeding expectations is a positive signal as the organisation is over performing targets. A risk based approach might instead suggest being more cautious as results well beyond expectations might be a hint of a problematic situation. This possibly has problematic consequences in the future (see section on the levers for a more detailed explanation on the approach of the company related this issue). The second barrier relates to the different time frame of risk and performance management processes. The evidence of the case study suggests that risk and performance management are likely to focus on different time horizons. In general, it is argued that risk management, especially an enterprise-wide approach, draws attention to strategic, longer-term risks, while performance management focuses on shorter-term issues. In the Energy Company this is reflected in the different periodicity of risk and performance reporting. The first is quarterly, whilst the second is monthly. There might be different rationales behind the choice to adopt a different periodicity in the two lines of reporting; for example historical reasons, time and resources constraints, regulatory and governance requirements. Yet, the main argument that emerged from interviews is the difficulty to capture risk information, or changes in risk information, over a short-term period. It is argued that risks can be captured only over a longer time frame (e.g. how a change in the production capacity for instance, the construction of a new power plant, might affect the company s competitive position); events that increase/decrease the risk exposure of a company often occur on a discontinued basis (e.g. major incidents or changes in regulatory conditions). Facilitators The case study suggests there are some elements that can facilitate reaching alignment between risk and performance management. The first relates to the development and communication of a clear-cut strategy, the second concerns the role embraced by actors that locally support and promote the risk management process (risk champions). Strategy If risk and performance metrics relate to the same set of common strategic objectives, they are more likely to be aligned. For instance, in the company the strategic ambition zero harm serves as a reference point for both risk and performance target, which fosters alignment. Even if individual measures for a year may not be explicitly related to the risk register, the strategic ambition makes clear the company s risk appetite when setting and evaluating performance targets. For example, actions that might lead to greater profitability, but increase the likelihood of harmful consequences should not be taken. Risk champions In the company each senior manager has to keep a risk register that contains key risks and controls put in place. As risk is embedded in any type of activity, the risk register can be a useful starting point for managing activities. Yet, this can be facilitated by having someone that challenges managers to practically use risk register. Within each BU in the company this responsibility is assigned to risk champions, who help people to manage their risks. Furthermore, risk champions keep track of the key risks of a wide range of senior managers (ideally all senior managers that belong to the same BU). This helps them to articulate and calibrate individual risks for different activities. Levers The case reveals there are certain performance management tools that, if used in a particular way, can provide risk-related information. Their use can be leveraged to reach alignment between risk and performance management. Key performance indicators Non-financial metrics can become useful risk indicators. This emerged looking at the company both from a risk perspective and a performance perspective. On the one hand, local risk champions use KRIs to calibrate risk assessment and mitigation strategies. On the other hand, the team in charge of company-wide performance reporting analyses anomalies in the trends of KPIs to find evidence of potential risks that might impinge on the company s activities. In both cases, it emerged how 4 Integrating risk and performance in management reporting
8 thinking in terms of processes might help identify good risk indicators, as risks are intrinsically part of what people do. KRIs are simply defined as function-related KPIs. As safety is a primary issue, an indicative example for the company is the use of records on the number and the types of incidents. These records provide a basis for a quantitative risk assessment on business processes. Another example that relates to a different setting is the number of negative stories for the media team that can be used to assess reputational risks. Variance analysis. The analysis of variances between results and expected targets can become an excellent source of risk information, as it helps shed light on performances that are changing unexpectedly. Variance analysis is certainly not a novelty for managerial control. However, it emerges from the case study the distinctive role that variance analysis can play for risk management. In fact, in a traditional management by exception approach variance analysis is made between actual results and expected targets and negative variances are primarily investigated. Embracing this approach, companies tend to direct attention primarily to areas of underperformance relative to target and assume that all is well where and when performance meets or beats expectations. In the Energy Company, the performance team instead examines variances when actual results are too distant from targets (both below or above) to verify if targets are set too tightly or too loosely or risks are poorly understood. It is interesting to note that performances both above and below target are investigated, so to reach a healthy scrutiny of actual performances in expansion periods. This suggests that variance analysis can be used not only to identify performance problems, but also the emergence of possible risky situations, for example targets are missspecified or positive performances are occurring at the expense of something else, that might result detrimentally to the long-term profitability of a company. Conclusion The findings of this project are based on data from a single company that operates in the energy sector. The focus on a single company certainly does not allow any generalisation of the results. Bearing in mind such limitation, it is acknowledged that the findings are not directly extendable elsewhere. Nevertheless, this research has some implications for practical application. Specifically, it suggests that the combination of risk and performance information into a single report is not always the most feasible solution to reach alignment between risk and performance management, especially for complex businesses. However, the project allows extrapolating a number of key elements for enhancing risk and performance alignment. An examination of these elements might help understand how close an organisation is, or can be, to link risk and performance management. This can be achieved by considering different issues: the presence of a clearly identifiable company-wide strategy that can be used as a reference frame for both risk and performance management activities, the use of risk registers to organise management activities, the presence of someone that helps senior managers to articulate and understand key risks, the use of KPIs and variance analysis to investigate unexpected trends both above and below expectations. These issues consider different organisational elements and activities and may play a different role in the overall management of an organisation, certainly having a strategy is more critical than the type of use of variance analysis. Indeed, they are not presented as a structured set of elements that have to be met in order to obtain an optimal way of managing risk and performance management. On the contrary, they may simply be considered of interest to anyone who is willing to reflect on how close (or distant) an organisation is to align risk and performance management, considering they already emerged as important to reach alignment in a particular organisation. The apparent simplicity of some (e.g. the investigation of results exceeding expectations) can be considered as strength rather than a weakness, as it implies that it might be easier to implement changes in the current way of acting and thinking of an organisation. In conclusion, integrating risk and performance management is not a matter of implementing a single management tool. It can be more important to focus attention to a set of organisational elements: some can constitute obstacles (barriers), some can facilitate incorporating risk into management processes (facilitators, levers). In the end, risk is often implicitly related performance management: performance management tools, if used in particular ways, can provide risk information with minor efforts. The author is interested to hear from practitioners who would like to discuss any of the issues raised in this report and perhaps also share their experiences of risk and performance management practice. To contact the author, please [email protected] 5 Integrating risk and performance in management reporting
9 Appendix Interviews protocol Performance management Performance management team: role and activities Performance management frameworks and information reported Use of performance information Frequency and direction of the reporting of performance information Risk management Governance structure and key risks Risk team: role and activities Risk management process (actors, techniques and measures) Use of risk information Frequency and direction of the reporting of risk information Internal audit Governance structure and key risks Audit team: role and activities Use of audit reports Frequency and direction of the reporting of internal audits 6 Integrating risk and performance in management reporting
10 References Beasley, M., Chen, A., Nunez, K., and Wright, L. (2006), Working Hand in Hand: Balanced Scorecard and Enterprise Risk Management, Strategic Finance, March, pp Calandro J. and Lane S. (2006), Insights from the balanced scorecard An introduction to the enterprise risk scorecard, Measuring Business Excellence, Vol. 10 No. 3, pp CIMA (2007), CIMA Strategic Scorecard Boards engaging in strategy, April, available at ImportedDocuments/ tech_execrep_strategic_scorecard_boards_engaging_in_strategy_mar_2007.pdf Cotter, C. (2009), Risk management, Financial Management, January, pp Kaplan, R.S. and Norton, D.P. (1992), The balanced scorecard measures that drive performance, Harvard Business Review, Vol. 70 No. 1, pp Kaplan, R.S. and Norton, D.P. (1996), The Balanced Scorecard, Harvard Business School Press, Boston, MA. Kaplan, R.S. and Norton, D.P. (2001), The Strategy-Focused Organisation, Harvard Business School Press, Boston, MA. Lam, J. (2006), Emerging Best Practices in Developing Key Risk Indicators and ERM Reporting, James Lam & Associates, Inc. Scholey, C. (2006), Risk and the Balanced Scorecard, CMA Management, Vol. 32, pp Van der Stede, W. (2009), Enterprise Governance, Financial Management, February, pp Woods, M. Kajüter, P. and Linsley, P. (2008), International risk management, CIMA publishing, London. Tommaso Palermo London School of Economics and Political Science Department of Accounting Houghton Street London, WC2A 2AE E. 7 Integrating risk and performance in management reporting
11
12 ISSN X (print) Chartered Institute of Management Accountants 26 Chapter Street London SW1P 4NP United Kingdom T. +44 (0) E. April 2011, Chartered Institute of Management Accountants
Enterprise Risk Management: From Theory to Practice
INSURANCE Enterprise Risk Management: From Theory to Practice KPMG LLP Executive Summary Enterprise Risk Management (ERM) is a structured and disciplined business tool aligning strategy, processes, people,
Risk appetite How hungry are you?
Risk appetite How hungry are you? 8 by Richard Barfield Richard Barfield Director, Valuation & Strategy, UK Tel: 44 20 7804 6658 Email: [email protected] 9 Regulatory pressures, such as Basel
Enterprise Risk Management
Enterprise Risk Management Topic Gateway Series No. 49 1 Prepared by Jasmin Harvey and Technical Information Service July 2008 About Topic Gateways Topic Gateways are intended as a refresher or introduction
research Budgeting practice and organisational structure executive summaries
Budgeting practice and organisational structure research executive summaries Volume 6 Issue 4 Professor David Dugdale and Dr Stephen Lyne Department of Accounting and Finance, University of Bristol ISSN
Reporting Service Performance Information
AASB Exposure Draft ED 270 August 2015 Reporting Service Performance Information Comments to the AASB by 12 February 2016 PLEASE NOTE THIS DATE HAS BEEN EXTENDED TO 29 APRIL 2016 How to comment on this
The role of modern board. Chartered Institute of Management Accountants
The role of the CFO on the modern board Chartered Institute of Management Accountants The role of the CFO on the modern board 1 INTRODUCTION This briefing is based on the discussion at a recent CIMA event,
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date
The use and consequences of performance management and control systems: a study of a professional services firm
Wendy Beekes Lancaster University David Otley Lancaster University Valentine Ururuka Lancaster University The use and consequences of performance management and control systems: a study of a professional
Understanding and articulating risk appetite
Understanding and articulating risk appetite advisory Understanding and articulating risk appetite Understanding and articulating risk appetite When risk appetite is properly understood and clearly defined,
V1.0 - Eurojuris ISO 9001:2008 Certified
Risk Management Manual V1.0 - Eurojuris ISO 9001:2008 Certified Section Page No 1 An Introduction to Risk Management 1-2 2 The Framework of Risk Management 3-6 3 Identification of Risks 7-8 4 Evaluation
Sample risk committee charter
Sample risk committee charter 1 Next This sample risk committee charter is based on leading practices observed by Deloitte in the analysis of a variety of materials. It is important to note that the Risk
Terms of Reference - Board Risk Committee
Terms of Reference - Board Risk Committee The Board Risk Committee is authorised by the Board to oversee the Group s risk management arrangements. It ensures that the overarching risk appetite is appropriate
RISK MANAGEMENT POLICY (Revised October 2015)
UNIVERSITY OF LEICESTER RISK MANAGEMENT POLICY (Revised October 2015) 1. This risk management policy ( the policy ) forms part of the University s internal control and corporate governance arrangements.
Operational Risk Management - The Next Frontier The Risk Management Association (RMA)
Operational Risk Management - The Next Frontier The Risk Management Association (RMA) Operational risk is not new. In fact, it is the first risk that banks must manage, even before they make their first
Information Governance Management Framework
Information Governance Management Framework Responsible Officer Author Business Planning & Resources Director Governance Manager Date effective from October 2015 Date last amended October 2015 Review date
Creating a Strategy-Focused Organization
Creating a Strategy-Focused Organization Werner Bruggeman Valerie Decoene Geert Scheipers In recent years, organizations have sought to develop more comprehensive performance measurement systems to provide
The Role of Internal Audit in Risk Governance
The Role of Internal Audit in Risk Governance How Organizations Are Positioning the Internal Audit Function to Support Their Approach to Risk Management Executive summary Risk is inherent in running any
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT Let me begin by thanking Baruch College for giving me the opportunity to present this year s prestigious Emanuel Saxe Lecture in Accounting.
Enterprise Governance
Enterprise Governance Topic Gateway series no. 32 Prepared by Gillian Lees and Technical Information Service June 2007 1 About Topic Gateways Topic Gateways are intended as a refresher or introduction
Final Draft Guidance on Audit Committees
Guidance Corporate Governance April 2016 Final Draft Guidance on Audit Committees The FRC is responsible for promoting high quality corporate governance and reporting to foster investment. We set the UK
THE COMBINED CODE PRINCIPLES OF GOOD GOVERNANCE AND CODE OF BEST PRACTICE
THE COMBINED CODE PRINCIPLES OF GOOD GOVERNANCE AND CODE OF BEST PRACTICE Derived by the Committee on Corporate Governance from the Committee s Final Report and from the Cadbury and Greenbury Reports.
Key functions in the system of governance Responsibilities, interfaces and outsourcing under Solvency II
Responsibilities, interfaces and outsourcing under Solvency II Author Lars Moormann Contact solvency [email protected] January 2013 2013 Münchener Rückversicherungs Gesellschaft Königinstrasse 107,
2.2 Reviewing the company s internal financial controls and the company s internal control and risk management systems;
Beazley plc Audit and Terms of reference Approved by board resolution dated 23 July 2015 1. Objectives To assist the board of directors in fulfilling its oversight responsibilities for the financial reporting
RISK MANAGEMENT STRATEGY 2014-17
RISK MANAGEMENT STRATEGY 2014-17 DOCUMENT NO: Lead author/initiator(s): Contact email address: Developed by: Approved by: DN128 Head of Quality Performance [email protected] Quality Performance Team
Enterprise-Wide Risk Assessment
Enterprise-Wide Risk Assessment Agenda 1. Definition of risk. 2. Risk drivers in higher education today. 3. Implementing an enterprise-wide risk management (ERM) program to effectively assess, manage,
Quality Impact Assessment. Executive summary
Report to Public Trust Board 28 th February 2013 Title Sponsoring Executive Director Author(s) Purpose Previously considered by Quality Impact Assessment Director of Quality and Safety/ Chief Nurse Director
Management White Paper What is a modern Balanced Scorecard?
Management White Paper What is a modern Balanced Scorecard? For more information please visit: www.ap-institute.com What is a modern Balanced Scorecard? By Bernard Marr Abstract: The Balanced Scorecard
Hand IN Hand: Balanced Scorecards
ANNUAL CONFERENCE T O P I C Risk Management WORKING Hand IN Hand: Balanced Scorecards AND Enterprise Risk Management B Y M ARK B EASLEY, CPA; A L C HEN; K AREN N UNEZ, CMA; AND L ORRAINE W RIGHT Recent
Central bank corporate governance, financial management, and transparency
Central bank corporate governance, financial management, and transparency By Richard Perry, 1 Financial Services Group This article discusses the Reserve Bank of New Zealand s corporate governance, financial
The Role of the Board in Enterprise Risk Management
Enterprise Risk The Role of the Board in Enterprise Risk Management The board of directors plays an essential role in ensuring that an effective ERM program is in place. Governance, policy, and assurance
Risk Management Plan template <TEMPLATE> RISK MANAGEMENT PLAN FOR THE <PROJECT-NAME> PROJECT
RISK MANAGEMENT PLAN FOR THE PROJECT Prepared by: Approved by: Reference: Version: Date: INTRODUCTION This document is the Risk Management
Exhibit 1: Structure of a heat map
Integrating risk and performance management processes Werner Bruggeman Geert Scheipers Valerie Decoene 1. Introduction Years ago, Kaplan & Norton interviewed managers about their time consumption and they
A Risk Management Standard
A Risk Management Standard Introduction This Risk Management Standard is the result of work by a team drawn from the major risk management organisations in the UK, including the Institute of Risk management
the role of the head of internal audit in public service organisations 2010
the role of the head of internal audit in public service organisations 2010 CIPFA Statement on the role of the Head of Internal Audit in public service organisations The Head of Internal Audit in a public
Relationship Manager (Banking) Assessment Plan
Relationship Manager (Banking) Assessment Plan ST0184/AP03 1. Introduction and Overview The Relationship Manager (Banking) is an apprenticeship that takes 3-4 years to complete and is at a Level 6. It
GUIDELINES FOR PILOT INTERVENTIONS. www.ewaproject.eu [email protected]
GUIDELINES FOR PILOT INTERVENTIONS www.ewaproject.eu [email protected] Project Lead: GENCAT CONTENTS A Introduction 2 1 Purpose of the Document 2 2 Background and Context 2 3 Overview of the Pilot Interventions
The Business Balanced Scorecard and Key Performance Indicators. The principles and approach to build
The Business Balanced Scorecard and Key Performance Indicators The principles and approach to build Some relevant quotes Business performance measurement is as necessary as the scorecard of sports What
APPENDIX 50. Enterprise risk management - Risk management overview
APPENDIX 50 Enterprise risk management - Risk management overview Energex regulatory proposal October 2014 ENTERPRISE RISK MANAGEMENT Risk Management Overview (RMO) 06 11 2013 Table of Contents 1. INTRODUCTION...
How quality assurance reviews can strengthen the strategic value of internal auditing*
How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,
5/30/2012 PERFORMANCE MANAGEMENT GOING AGILE. Nicolle Strauss Director, People Services
PERFORMANCE MANAGEMENT GOING AGILE Nicolle Strauss Director, People Services 1 OVERVIEW In the increasing shift to a mobile and global workforce the need for performance management and more broadly talent
PRUDENTIAL FINANCIAL, INC. CORPORATE GOVERNANCE PRINCIPLES AND PRACTICES
PRUDENTIAL FINANCIAL, INC. CORPORATE GOVERNANCE PRINCIPLES AND PRACTICES A. THE ROLE OF THE BOARD OF DIRECTORS 1. Direct the Affairs of the Corporation for the Benefit of Shareholders The Prudential board
Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.
Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance
IIA POSITION PAPER: THE ROLE OF INTERNAL AUDITING IN ENTERPRISE-WIDE RISK MANAGEMENT
IIA POSITION PAPER: THE ROLE OF INTERNAL AUDITING IN ENTERPRISE-WIDE RISK MANAGEMENT Revised: Page 1 of 8 Introduction The importance to strong corporate governance of managing risk has been increasingly
Accounting for ethical, social, environmental and economic issues: towards an integrated approach
Accounting for ethical, social, environmental and economic issues: towards an integrated approach Research Executive Summaries Series Vol. 2, No. 12 By Professor Carol A Adams La Trobe University and Dr
Risk Management Committee (Committee) Terms of Reference
Risk Management Committee (Committee) Terms of Reference 1. Objective of Committee 1.1 The Risk Management Committee ( the Committee ) is a formal sub-committee of the Board of the JSE ( the Board ). 1.2
Guideline. Operational Risk Management. Category: Sound Business and Financial Practices. No: E-21 Date: June 2016
Guideline Subject: Category: Sound Business and Financial Practices No: E-21 Date: June 2016 1. Purpose and Scope of the Guideline This Guideline sets out OSFI s expectations for the management of operational
Solvency II Own Risk and Solvency Assessment (ORSA)
Solvency II Own Risk and Solvency Assessment (ORSA) Guidance notes September 2011 Contents Introduction Purpose of this Document 3 Lloyd s ORSA framework 3 Guidance for Syndicate ORSAs Overview 7 December
Office of the Police and Crime Commissioner for Avon and Somerset and Avon and Somerset Constabulary
Office of the Police and Crime Commissioner for Avon and Somerset and Avon and Somerset Constabulary Internal Audit Report () FINAL Risk Management: Follow Up of Previous Internal Audit Recommendations
How To Manage Risk At Atb Financial
Guidelines for Financial Institutions Legislative Compliance Management (LCM) Date: July 2004 Introduction Regulatory risk is the risk of non-compliance with applicable regulatory requirements. For the
Measuring and. Communicating. Security's Value. A Compendium of Metrics. for Enterprise Protection
Measuring and Communicating Security's Value A Compendium of Metrics for Enterprise Protection George Campbell AMSTERDAM BOSTON HEIDELBERG LONDON NEW YORK OXFORD PARIS SAN DIEGO SAN FRANCISCO SINGAPORE
Linking risk management to strategic controls: a case study of Tesco plc
Linking risk management to strategic controls: a case study of Tesco plc Margaret Woods Nottingham University Business School, Wollaton Road, Nottingham, UK E mail: [email protected] Abstract:
High level principles for risk management
16 February 2010 High level principles for risk management Background and introduction 1. In their declaration of 15 November 2008, the G-20 leaders stated that regulators should develop enhanced guidance
Solvency II Own risk and solvency assessment (ORSA)
Solvency II Own risk and solvency assessment (ORSA) Guidance notes MAY 2012 Contents Introduction Page Background 3 Purpose and Scope 3 Structure of guidance document 4 Key Principles and Lloyd s Minimum
Board Governance Principles Amended September 29, 2012 Tyco International Ltd.
BOD Approved 9/13/12 Board Governance Principles Amended September 29, 2012 Tyco International Ltd. 2012 Tyco International, Ltd. - Board Governance Principles 1 TABLE OF CONTENTS TYCO VISION AND VALUES...
Solvency II Data audit report guidance. March 2012
Solvency II Data audit report guidance March 2012 Contents Page Introduction Purpose of the Data Audit Report 3 Report Format and Submission 3 Ownership and Independence 4 Scope and Content Scope of the
Risk management systems of responsible entities
Attachment to CP 263: Draft regulatory guide REGULATORY GUIDE 000 Risk management systems of responsible entities July 2016 About this guide This guide is for Australian financial services (AFS) licensees
Risk Management Policy
Risk Management Policy Responsible Officer Author Ben Bennett, Business Planning & Resources Director Julian Lewis, Governance Manager Date effective from December 2008 Date last amended December 2012
Barriers and Catalysts to Sound Financial Management Systems in Small Sized Enterprises
ISSN 1744-7038 (online) ISSN 1744-702X (print) Research Executive Summaries Series Barriers and Catalysts to Sound Financial Management Systems in Small Sized Enterprises Vol. 1, No. 3 By Stuart McChlery,
Capital Adequacy: Advanced Measurement Approaches to Operational Risk
Prudential Standard APS 115 Capital Adequacy: Advanced Measurement Approaches to Operational Risk Objective and key requirements of this Prudential Standard This Prudential Standard sets out the requirements
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
1. Introduction. 1 http://www.centralbank.ie/regulation/poldocs/consultationpapers/documents/cp75/consultation%20paper%20cp75%20final.
National Consumer Agency submission to the Central Bank of Ireland s consultation paper: Additional Consumer Protection Requirements for Debt Management Firms 1. Introduction 1.1. The National Consumer
INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS
Standard No. 13 INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS STANDARD ON ASSET-LIABILITY MANAGEMENT OCTOBER 2006 This document was prepared by the Solvency and Actuarial Issues Subcommittee in consultation
Effective objective setting provides structure and direction to the University/Faculties/Schools/Departments and teams as well as people development.
Effective objective setting provides structure and direction to the University/Faculties/Schools/Departments and teams as well as people development. The main purpose of setting objectives is to reflect
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis
Risk Management Policy and Process Guide
Risk Management Policy and Process Guide Status: pending Next review date: December 2015 Page 1 Information Reader Box Directorate Medical Nursing Patients & Information Commissioning Operations (including
Supervisory Statement SS18/13. Recovery planning. December 2013. (Last updated 16 January 2015)
Supervisory Statement SS18/13 Recovery planning December 2013 (Last updated 16 January 2015) Prudential Regulation Authority 20 Moorgate London EC2R 6DA Prudential Regulation Authority, registered office:
Formal and informal feedback in management accounting
Hanna Pitkänen Turku School of Economics, Finland Kari Lukka Turku School of Economics, Finland Formal and informal feedback in management accounting Taking a look beyond the balanced scorecard Research
PRINCIPLES FOR THE MANAGEMENT OF CONCENTRATION RISK
ANNEX 2G PRINCIPLES FOR THE MANAGEMENT OF CONCENTRATION RISK Concentration risk can be defined as any single (direct and/or indirect) exposure or group of exposures with the potential to produce losses
A CFO s Guide to Corporate Governance
A CFO s Guide to Corporate Governance By Linda D. Henman, Ph.D. Few people can define governance in concrete terms, yet it remains one of those allencompassing words that people use frequently. The dictionary
FINANCIAL ASSESSMENT CRITERIA (The Assessment Criteria should be read in conjunction with OSFI s Supervisory Framework)
ROLE OF Financial is an independent function responsible for ensuring the timely and accurate reporting and in-depth analysis of the operational results of the operating units (including business lines)
Saldanha Bay Municipality. Risk Management Strategy. Inclusive of, framework, procedures and methodology
Inclusive of, framework, procedures and methodology Contents 1 Introduction 1 1.1 Legislative Framework and best practice 1 1.2 Purpose of Enterprise Risk Management 2 1.3 Scope and Applicability 3 1.4
EBA RECOVERY PLANNING
EBA RECOVERY PLANNING COMPARATIVE REPORT ON GOVERNANCE ARRANGEMENTS AND RECOVERY INDICATORS 05 July 2016 Contents Executive summary 2 Introduction 4 1. Approach 5 2. Governance Recovery plan development,
Risk Management & Business Continuity Manual 2011-2014
ANNEX C Risk Management & Business Continuity Manual 2011-2014 Produced by the Risk Produced and by the Business Risk and Business Continuity Continuity Team Team February 2011 April 2011 Draft V.10 Page
Inquilab Housing Association. Job Profile
Inquilab Housing Association Job Profile Post: Salary Scale: Reporting to: Governance and Research Officer c 32,640, pa plus up to 10% PRP Head of Governance JOB PURPOSE: To oversee and support the governance
Assessment Policy. 1 Introduction. 2 Background
Assessment Policy 1 Introduction This document has been written by the National Foundation for Educational Research (NFER) to provide policy makers, researchers, teacher educators and practitioners with
Chief Risk Officers in the Mutual Fund Industry: Who Are They and What Is Their Role Within the Organization?
Chief Risk Officers in the Mutual Fund Industry: Who Are They and What Is Their Role Within the Organization? Background Everyone within an organization has some responsibility for managing risk. In the
Title. Learning from Incidents, Complaints and Claims. Description of Document
Title Description of Document Scope Author and designation Equality Impact Assessment (EIA) Associated Documents Supporting References Learning from Incidents, Complaints and Claims This policy identifies
Scenario Analysis Principles and Practices in the Insurance Industry
North American CRO Council Scenario Analysis Principles and Practices in the Insurance Industry 2013 North American CRO Council Incorporated [email protected] December 2013 Acknowledgement The
Audit Quality Thematic Review
Thematic Review Professional discipline Financial Reporting Council January 2014 Audit Quality Thematic Review Fraud risks and laws and regulations The FRC is responsible for promoting high quality corporate
Basel Committee on Banking Supervision
Basel Committee on Banking Supervision Guidelines Corporate governance principles for banks July 2015 This publication is available on the BIS website (www.bis.org). Bank for International Settlements
GROWTH/REPLICATION STRATEGIES
Stage 7: Long Term Growth/Replication Theme 4: Business Model GROWTH/REPLICATION STRATEGIES Long-term growth is the objective of most organisations. For commercial businesses, the goal is incremental economic
Much attention has been focused recently on enterprise risk management (ERM),
By S. Michael McLaughlin and Karen DeToro Much attention has been focused recently on enterprise risk management (ERM), not just in the insurance industry but in other industries as well. Across all industries,
SEDP MBA By Laws. ACGS Manual. ACGS Manual
E. Responsibilities of the Board E.1 Board Duties and Responsibilities / E.1.1 Clearly defined board responsibilities and corporate governance policy Does the company disclose its corporate governance
Review of Financial Planning and Monitoring. City of York Council Audit 2008/09 Date
Review of Financial Planning and Monitoring City of York Council Audit 2008/09 Date Contents Introduction and Background 3 Audit approach 4 Main conclusions 5 Financial Planning Findings 6 Financial Monitoring
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
STRATEGIC CONTROL AND THE PERFORMANCE MEASUREMENT SYSTEMS
Cr ciun Liviu STRATEGIC CONTROL AND THE PERFORMANCE MEASUREMENT SYSTEMS University of Craiova,Faculty of Economics and Business Administration, A.I. Cuza,no. 13, [email protected], 0744197459 Gîrboveanu
Perspectives. Employee voice. Releasing voice for sustainable business success
Perspectives Employee voice Releasing voice for sustainable business success Empower, listen to, and act on employee voice through meaningful surveys to help kick start the UK economy. 2 Releasing voice
Appendix 15 CORPORATE GOVERNANCE CODE AND CORPORATE GOVERNANCE REPORT
Appendix 15 CORPORATE GOVERNANCE CODE AND CORPORATE GOVERNANCE REPORT The Code This Code sets out the principles of good corporate governance, and two levels of recommendations: code provisions; and recommended
Balanced Scorecard: & Challenges. 23rd July 2007. Organized by: SMR
Balanced Scorecard: Implementation & Challenges 23rd July 2007 Organized by: SMR 1 Program Schedule» 9.00 am 10.30am» 2.00pm 3.30pm > Introduction PMS > BSC Terminology & Principles > Understanding BSC
Audit, Risk Management and Compliance Committee Charter
Audit, Risk Management and Compliance Committee Charter Woolworths Limited Adopted by the Board on 27 August 2013 page 1 1 Introduction This Charter sets out the responsibilities, structure and composition
Risk Management Primer
Risk Management Primer Purpose: To obtain strong project outcomes by implementing an appropriate risk management process Audience: Project managers, project sponsors, team members and other key stakeholders
7 Directorate Performance Managers. 7 Performance Reporting and Data Quality Officer. 8 Responsible Officers
Contents Page 1 Introduction 2 2 Objectives of the Strategy 2 3 Data Quality Standards 3 4 The National Indicator Set 3 5 Structure of this Strategy 3 5.1 Awareness 4 5.2 Definitions 4 5.3 Recording 4
Agency Board Meeting 28 July 2015
SEPA 22/15 Agency Board Meeting 28 July 2015 Report Number: SEPA 22/15 Audit Committee Annual Performance Report 2014-2015 Summary: Risks: Resource and Staffing Implications Equalities: Environmental and
Operational Risk Management in a Debt Management Office
Operational Risk Management in a Debt Management Office Based on Client Presentation January 2008 Outline The importance of operational risk management (ORM) International best practice A high-level perspective,
Risk Management Policy
Risk Management Policy June 2015 1 2 Contents 1. Policy Objectives and Background... 4 1.1. Policy Background... 4 1.2. Policy Objective... 4 1.3. Policy Sponsor and Maintenance... 4 2. Risk Types and
Risk Management Strategy and Policy. The policy provides the framework for the management and control of risk within the GOC
Annex 1 TITLE VERSION Version 2 Risk Management Strategy and Policy SUMMARY The policy provides the framework for the management and control of risk within the GOC DATE CREATED January 2013 REVIEW DATE
Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization
Internal Audit Quality Assessment Presented To: World Intellectual Property Organization April 2014 Table of Contents List of Acronyms 3 Page Executive Summary Opinion as to Conformance to the Standards,
