Director Notes. Strategic Risk Management: A Primer for Directors
|
|
|
- Barbara Woods
- 9 years ago
- Views:
Transcription
1 Director Notes Strategic Risk Management: A Primer for Directors by Mark L. Frigo and Richard J. Anderson Recent significant risk events, including catastrophic weather events, cybercrime, macroeconomic issues, and supply chain interruptions, have resulted in an increased focus on risk and risk management by boards of directors. One of the board s key oversight roles is to understand the organization s s and the relationship between risk and strategy. This Director Notes describes the factors that are driving the need for management, outlines a assessment process, and offers recommendations for integrating risk management in strategy execution and measurement.* As noted by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), In the aftermath of the financial crisis, executives and their boards realize that ad hoc risk management is no longer tolerable and that current processes may be inadequate in today s rapidly evolving business world. 1 However, especially for nonfinancial companies that may be relatively new to these topics, enhancing risk management can be a somewhat daunting task. This article focuses on two key aspects of the relationship between risk and strategy: (1) understanding the organization s s and the related risk management processes, and (2) understanding how risk is considered and embedded in the organization s strategy setting and performance measurement processes. These two areas not only deserve the attention of boards, but also fit closely with one of the primary responsibilities of the board risk oversight. * This Director Notes is adapted from Mark L. Frigo and Richard J. Anderson, Strategic Risk Management: A Primer for Directors and Management Teams (2012). No. DN-V4N15 JULY 2012
2 The Advent of Strategic Risk Management Enterprise risk management ( ERM ) and risk management in general can encompass a wide range of risks that face any organization. Some risks may reflect exposures that, although harmful, will not threaten the overall health of an organization or its ability to ultimately meet its business objectives. For example, a temporary data center outage can result in a short-term problem or customer dissatisfaction, but once recovered, the organization can quickly be back on track. Other more significant risk events can be catastrophic, resulting in losses that can not only impair an organization s ability to meet its objectives, but may also threaten the organization s survival. The recent credit crisis is an example of this type of risk. These more significant risk exposures have given rise to a focus on s and strategic risk management. Strategic risks are those risks that are most consequential to the organization s ability to execute its strategies and achieve its business objectives. These are the risk exposures that can ultimately affect shareholder value or the viability of the organization. Strategic risk management then can be defined as the process of identifying, assessing and managing the risk in the organization s business strategy including taking swift action when risk is actually realized. Strategic risk management is focused on those most consequential and significant risks to shareholder value, an area that merits the time and attention of executive management and the board of directors. Standard & Poor s included the following attributes for management in its 2008 announcement that it would apply enterprise risk analysis to corporate ratings: Management s view of the most consequential risks the firm faces, their likelihood, and potential effect; The frequency and nature of updating the identification of these top risks; The influence of risk sensitivity on liability management and financial decisions, and The role of risk management in strategic decision making. 2 Clearly the potential impact of s is significant enough to deserve the attention of the board and its directors. Strategic Risk Management and the Role of the Board At the board level, management is a necessary core competency. 3 In Ram Charan s book, Owning Up: The 14 Questions Every Board Member Needs to Ask, one of the questions posed is Are we addressing the risks that could send our company over the cliff? 4 According to Charan, boards need to focus on the risk that is inherent in the strategy and strategy execution: Risk is an integral part of every company s strategy; when boards review strategy, they have to be forceful in asking the CEO what risks are inherent in the strategy. They need to explore what ifs with management in order to stress-test against external conditions such as recession or currency exchange movements. 5 Regarding risk culture, Charan provides the following insight: Boards must also watch for a toxic culture that enables ethical lapses throughout the organization. Companies set rules but the culture determines how employees follow them. 6 We believe that corporate culture plays a significant role in how well is managed and must be considered as part of a assessment. Understanding an Organization s Strategic Risks and Related Risk Management Processes A necessary first step for boards to understand their s and how management is managing and monitoring those risks is a assessment. A assessment is a systematic and continual process for assessing the most significant risks facing an enterprise. 7 It is anchored and driven directly by the organization s core strategies. As noted in a 2011 COSO report, Linkage of top risks to core strategies helps pinpoint the most relevant information that might serve as an effective leading indicator of an emerging risk. 8 Conducting an initial assessment can be a valuable activity and should involve both senior management and the board of directors. Management should take the lead in conducting the assessment, but the assessment process should include input from the board members and, as it is completed, a thorough review and discussion between management and the board. These dialogues and discussions may be the most beneficial activities of the assessment and afford an opportunity for management and the directors to come to a consensus view of the risks facing the company, as well any related risk management activities. The assessment process is designed to be tailored to an organization s specific needs and culture. To be most useful, a risk management process and the resultant reporting must reflect and support an enterprise s culture so the process can be embedded and owned by management. Ultimately, if the assessment process is not embedded and owned by management as an integral part of the business processes, the risk management process will rapidly lose its impact and will not add to or deliver on its expected role. 2 Director Notes management: a primer for directors
3 The Strategic Risk Assessment Process There are seven basic steps for conducting a assessment: 1 Achieve a deep understanding of the strategy of the organization The initial step in the assessment process is to gain a deep understanding of the key business strategies and objectives of the organization. Some organizations have welldeveloped strategic plans and objectives, while others may be much more informal in their articulation and documentation of strategy. In either case, the assessment must develop an overview of the organization s key strategies and business objectives. This step is critical, because without these key data to focus around, an assessment could result in a long laundry list of potential risks with no way to really prioritize them. This step also establishes a foundation for integrating risk management with the business strategy. In conducting this step, a strategy framework could be useful to provide structure to the activity. a 2 Gather views and data on s The next step is to gather information and views on the organization s s. This can be accomplished through interviews of key executives and directors, surveys, and the analysis of information (e.g., financial reports and investor presentations). This data gathering should also include both internal and external auditors and other personnel who would have views on risks, such as compliance or safety personnel. Information gathered in Step 1 may be helpful to frame discussions or surveys and relate them back to core strategies. This is also an opportunity to ask what these key individuals view as potential emerging risks that should also be considered. Strategy risk management framework Figure 1 Strategic Risk Assessment Process 2. Gather data and and views of 3. Prepare preliminary strategic risk profile 1. Understand the strategy of the organization Return-driven strategy framework 4. Validate and finalize the strategic risk profile 5. Develop management action plan 7. Implement management action plan 6. Communicate profile and action plan Strategic risk maturity diagnostic Strategic risk alignment guide { Mitigation activities Risk monitoring Updating process Risk reporting { Directors Senior management Line management GRC functions 3 Prepare a preliminary profile Combine and analyze the data gathered in the first two steps to develop an initial profile of the organization s s. The level of detail and type of presentation should be tailored to the culture of the organization. For some organizations, simple lists are adequate, while others may want more detail as part of the profile. At a minimum, the profile should clearly communicate a concise list of the top risks and their potential severity or ranking. Colorcoded reports or heat-maps may be useful to ensure clarity of communication of this critical information. 4 Validate and finalize the profile The initial profile must be validated, refined, and finalized. Depending on how the data gathering was accomplished, this step could involve validation with all or a portion of the key executives and directors. It is critical, however, to gain sufficient validation to prevent major disagreements on the final risk profile. 5 Develop a management action plan This step should be undertaken in tandem with Step 4. While significant effort can go into an initial risk assessment and profile, the real product of this effort should be an action plan to enhance risk monitoring or management actions related to the s identified. The ultimate value of this process is helping and enhancing the organization s ability to manage and monitor its top risks. 6 Communicate the profile and strategic risk management action plan Building or enhancing the organization s risk culture is a communications effort with two primary focuses. The first focus is the communication of the organization s top risks and the management action plan to help build an understanding of the risks and how they are being managed. This helps focus personnel on what those key risks are and potentially how significant they might be. A second focus is the communication of management s expectations regarding risk to help reinforce the message that the understanding and management of risk is a core competency and expected role of people across the organization. The risk culture is an integral part of the overall corporate culture. The assessment of the corporate culture and risk culture is an initial step in building and nurturing a high performance, high integrity corporate culture. 7 Implement the management action plan As noted above, the real value resulting from the risk assessment process comes from the implementation of an action plan for managing and monitoring risk. These steps define a basic, high-level process and allow for a significant amount of tailoring and customization to reflect the maturity and capabilities of the organization. As shown by Figure 1, assessment is an ongoing process, not just a one-time event. Reflecting the dynamic nature of risk, these seven steps constitute a circular or closed-loop process that should be ongoing and continual within the organization. a For a sample framework, see Mark L. Frigo and Joel Litman, DRIVEN: Business Strategy, Human Actions and the Creation of Wealth (Strategy & Execution, LLC 2008). Director Notes management: a primer for directors 3
4 Integrating Strategic Risk Management in Strategy Setting and Performance Measurement Processes The second step for an organization is to integrate strategic risk management into its existing strategy setting and performance measurement processes. As discussed above, there is a clear link between the organization s strategies and its related s. Just as management is an ongoing process, so is the need to establish an ongoing linkage with the organization s core processes to set and measure its strategies and performance. This would include integrating risk management into strategic planning and performance measurement systems. Again, the maturity and culture of the organization should dictate how this performed. For some organizations, this may be accomplished through relatively simple processes, such as adding a page or section to their annual business planning process for the business to discuss the risks it sees in achieving its business plan and how it will monitor those risks. For organizations with more developed performance measurement processes, the Kaplan- Norton Strategy Execution Model described in The Execution Premium may be useful. 9 This model describes six stages for strategy execution and provides a useful framework for visualizing where management can be embedded into these processes. Stage 1: Develop the strategy This stage includes developing the mission, values, and vision; strategic analysis; and strategy formulation. At this stage, a strategic risk assessment could be included using the Return Driven Strategy framework to articulate and clarify the strategy and the Strategic Risk Management framework to identify the organization s s. Stage 2: Translate the strategy This stage includes developing strategy maps, strategic themes, objectives, measures, targets, initiatives, and the strategic plan in the form of strategy maps, balanced scorecards, and strategic expenditures. Here, the management framework would be used to develop risk-based objectives and performance measures for balanced scorecards and strategy maps, and for analyzing risks related to strategic expenditures. 10 At this stage, boards may also want to consider developing a risk scorecard that includes key metrics. Stage 3: Align the organization This stage includes aligning business units, support units, employees, and boards of directors. The Strategic Risk Management Alignment Guide and Strategic Framework for GRC (Governance, Risk and Compliance) would be useful for aligning risk and control units toward more effective and efficient risk management and governance, and for linking this alignment with the strategy of the organization. 11 Stage 4: Plan operations This stage includes developing the operating plan, key process improvements, sales planning, resource capacity planning, and budgeting. In this stage, the management action plan can be reflected in the operating plan and dashboards, including risk dashboards. One organization we worked with developed a resources follow risk philosophy to make certain that resources were appropriately and efficiently allocated. This philosophy focused on ensuring that resources used in risk management are justified economically based on the relative amount of risk and cost-benefit analysis. Stage 5: Monitor and learn This stage includes strategy and operational reviews. Strategic risk reviews would be part of the ongoing assessment, which reinforces the necessary continual, closed-loop approach for effective strategy risk assessment and strategy execution. Stage 6: Test and adapt This stage includes profitability analysis and emerging strategies. Emerging risks can be considered part of the ongoing assessment in this stage. The assessment can complement and leverage the strategy execution processes in an organization toward improving risk management and governance. For more information about integrating risk management in the strategy execution model and a discussion of risk scorecards, see Risk Management and Strategy Execution Systems Director Notes management: a primer for directors
5 Final Thoughts: Moving Forward with Strategic Risk Management Management teams and boards must challenge themselves and their organizations to move up the management learning curve. Developing management processes and capabilities can provide a strong foundation for improving risk management and governance. Boards may want to consider engaging independent advisors to advise and educate themselves on these matters. For organizations that are early in this process, the seven keys to success for improving ERM as described in a 2011 COSO Thought Leadership Paper may be useful, and are applicable in management: 1 Support from the top is a necessity 2 Build ERM using incremental steps 3 Focus initially on a small number of top risks About the Authors Mark L. Frigo, Ph.D., CMA, CPA, is director of the Center for Strategy, Execution and Valuation and the Strategic Risk Management Lab in the Kellstadt Graduate School of Business and Ledger & Quill Alumni Foundation Distinguished Professor at DePaul University in Chicago. He also is an advisor to management teams and boards in the area of Strategic Risk Management and strategy development and execution. He can be reached at [email protected] or at Richard J. (Dick) Anderson, MBA, CPA, is a Clinical Professor in the Center for Strategy, Execution and Valuation and the Strategic Risk Management Lab at DePaul University and a retired partner of PricewaterhouseCoopers LLP. With PwC, he was a regional leader in the Financial Services Advisory practice, consulting with major financial services organizations on internal auditing practices, risk management, and audit committee activities. He can be reached at [email protected]. 4 Leverage existing resources 5 Build on existing risk management activities 6 Embed ERM into the business fabric of the organization 7 Provide ongoing ERM updates and continuing education for directors and senior management 13 However the board decides to proceed, their leadership, direction, and overall oversight will be critical to the success of a management process. Endnotes 1 Effective Enterprise Risk Oversight: The Role of the Board of Directors, COSO 2009, p Enterprise Risk Management, Standard & Poor s to Apply Enterprise Risk Analysis to Corporate Ratings Standard & Poor s press release, May 7, 2008 ( 3 Mark L. Frigo, Strategic Risk Management: The New Core Competency, Balanced Scorecard Report, 11, no. 1, January February Ram Charan, Owning Up: The 14 Questions Every Board Member Needs to Ask (San Francisco: John Wiley & Sons 2009). 5 Charan, Owning Up: The 14 Questions Every Board Member Needs to Ask, p Charan, Owning Up: The 14 Questions Every Board Member Needs to Ask, p Mark L. Frigo and Richard J. Anderson, Strategic Risk Assessment: A First Step for Improving Risk Management and Governance, Strategic Finance, December Mark S. Breasley, Bruce C. Branson and Bonnie V. Hancock, Developing Key Risk Indicators to Strengthen Enterprise Risk Management, COSO, 2011 p.2. 9 Robert S. Kaplan and David P. Norton, The Execution Premium (Cambridge, MA: Harvard Business Press, 2008). 10 Mark L. Frigo and Richard J. Anderson, Strategic Risk Management: A Primer for Directors and Management Teams, Mark L. Frigo and Richard J. Anderson, A Strategic Framework for Governance, Risk and Compliance, Strategic Finance, February Robert S. Kaplan, Risk Management and Strategy Execution Systems, Balanced Scorecard Report, Vol. 11, No. 6, November-December Mark L Frigo and Richard J. Anderson, Embracing Enterprise Risk Management: Practical Approaches for Getting Started, COSO, Director Notes management: a primer for directors 5
6 About Director Notes Director Notes is a series of online publications in which The Conference Board engages experts from several disciplines of business leadership, including corporate governance, risk oversight, and sustainability, in an open dialogue about topical issues of concern to member companies. The opinions expressed in this report are those of the author(s) only and do not necessarily reflect the views of The Conference Board. The Conference Board makes no representation as to the accuracy and completeness of the content. This report is not intended to provide legal advice with respect to any particular situation, and no legal or business decision should be based solely on its content. About the Executive Editor Melissa Aguilar is a researcher in the corporate leadership department at The Conference Board in New York focusing on issues of corporate governance, regulatory compliance, and risk management. Prior to joining The Conference Board, she was a contributor for more than five years at Compliance Week, where she reported on a variety of corporate governance topics, including proxy voting developments, executive compensation, risk management and shareholder activism. Her work has also appeared in Bloomberg s Bloomberg Brief Financial Regulation newsletter. Previously she held a number of editorial positions at SourceMedia Inc. Aguilar is a graduate of Binghamton University. About the Series Director Matteo Tonello is managing director of corporate leadership at The Conference Board in New York. In his role, Tonello advises members of The Conference Board on issues of corporate governance, regulatory compliance, and risk management. He regularly participates as a speaker and moderator in educational programs on governance best practices and conducts analyses and research in collaboration with leading corporations, institutional investors and professional firms. He is the author of several publications, including Corporate Governance Handbook: Legal Standards and Board Practices, the annual U.S. Directors Compensation and Board Practices and Institutional Investment reports, Sustainability in the Boardrooom, and the forthcoming Risk Oversight Handbook. Recently, he served as the co-chair of The Conference Board Expert Committee on Shareholder Activism and on the Technical Advisory Board to The Conference Board Task Force on Executive Compensation. He is a member of the Network for Sustainable Financial Markets. Prior to joining The Conference Board, he practiced corporate law at Davis Polk & Wardwell. Tonello is a graduate of Harvard Law School and the University of Bologna. About The Conference Board The Conference Board is a global, independent business membership and research association working in the public interest. Our mission is unique: to provide the world s leading organizations with the practical knowledge they need to improve their performance and better serve society. The Conference Board is a nonadvocacy, not-for-profit entity, holding 501(c)(3) tax-exempt status in the United States. For more information on this report, please contact: Melissa Aguilar, researcher, corporate leadership at or [email protected] THE CONFERENCE BOARD, INC. AMERICAS / [email protected] ASIA-PACIFIC / [email protected] EUROPE/AFRICA/MIDDLE EAST / [email protected] SOUTH ASIA / [email protected] THE CONFERENCE BOARD OF CANADA / by The Conference Board, Inc. All rights reserved. Printed in the U.S.A. The Conference Board and the torch logo are registered trademarks of The Conference Board, Inc.
Strategic Risk Assessment. A first step for improving risk management and governance. COVER STORY. By Mark L. Frigo and Richard J.
Strategic Risk Assessment ILLUSTRATION: TIM LEE/WWW.LEEILLO.COM A first step for improving risk management and governance. By Mark L. Frigo and Richard J. Anderson December 2009 I STRATEGIC FINANCE 25
Enterprise Risk Management: From Theory to Practice
INSURANCE Enterprise Risk Management: From Theory to Practice KPMG LLP Executive Summary Enterprise Risk Management (ERM) is a structured and disciplined business tool aligning strategy, processes, people,
Director Notes. The Link Between Brand Value and Sustainability
Director Notes The Link Between Brand Value and Sustainability by Bahar Gidwani This report presents the findings of a multiyear study that compares brand value and sustainability performance. It reveals
C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n
C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n T h o u g h t L e a d e r s h i p i n E R M E m b r a c i n g E n t e r p r i s e R i s
Enterprise Risk Management & Information Technology
Enterprise Risk Management & Information Technology Presented by Scott Perry and Gary Ross Slalom Consulting, San Francisco Agenda Introductions Session Objectives Overview of Enterprise Risk Management
COSO Framework 2013 & SOX Compliance. Roxanne L. Halverson, CISM, CGEIT Atlanta ISACA Geek Week August 19, 2013
COSO Framework 2013 & SOX Compliance Roxanne L. Halverson, CISM, CGEIT Atlanta ISACA Geek Week August 19, 2013 What s Happened On May 14, 2013, after a little more than 20 years the Committee of Sponsoring
How to stay competitive in a converging healthcare system kpmg.com
Managing risk in a transforming healthcare organization How to stay competitive in a converging healthcare system kpmg.com 2 Healthcare Risk Management Managing the risk of healthcare transformation Healthcare
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date
How quality assurance reviews can strengthen the strategic value of internal auditing*
How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,
Transforming risk management into a competitive advantage kpmg.com
INSURANCE RISK MANAGEMENT ADVISORY SOLUTIONS Transforming risk management into a competitive advantage kpmg.com 2 Transforming risk management into a competitive advantage Assessing risk. Building value.
Hand IN Hand: Balanced Scorecards
ANNUAL CONFERENCE T O P I C Risk Management WORKING Hand IN Hand: Balanced Scorecards AND Enterprise Risk Management B Y M ARK B EASLEY, CPA; A L C HEN; K AREN N UNEZ, CMA; AND L ORRAINE W RIGHT Recent
Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology
Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology May 20, 2015 Internal FR 2 Risk and Risk Assessment Defined Risk Institute of Internal Auditors (IIA) The
Presentation Objectives Why is Internal Audit here? Concepts (Enterprise Risk Management, Strategic Risk, Strategic Risk Management, etc.
Internal Audit 1 January 13, 2012 Presentation Objectives Why is Internal Audit here? Concepts (Enterprise Risk Management, Strategic Risk, Strategic Risk Management, etc.) Summary Internal Audit 2 January
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
DEVELOPING AN EFFECTIVE INTERNAL AUDIT TECHNOLOGY STRATEGY
DEVELOPING AN EFFECTIVE INTERNAL AUDIT TECHNOLOGY STRATEGY SEPTEMBER 2012 DISCLAIMER Copyright 2012 by The Institute of Internal Auditors (IIA) located at 247 Maitland Ave., Altamonte Springs, Fla., 32701,
DEFINING OUR ROLE IN A CHANGING LANDSCAPE
DEFINING OUR ROLE IN A CHANGING LANDSCAPE North American report October 2013 Disclaimer Table of Contents Introduction...1 Outlook for Internal Audit Remains Strong...3 Strategic Business Risk: Opportunity
The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012
The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only Agenda Introduction Basic program components Recent trends in higher education risk management Why
The Standard for Portfolio Management. Paul E. Shaltry, PMP Deputy PM PPMS (2003-06) BNS02
The Standard for Portfolio Management Paul E. Shaltry, PMP Deputy PM PPMS (2003-06) BNS02 Purpose of this Presentation To provide information about The Standard for Portfolio Management Agenda Background
Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization
Internal Audit Quality Assessment Presented To: World Intellectual Property Organization April 2014 Table of Contents List of Acronyms 3 Page Executive Summary Opinion as to Conformance to the Standards,
How to achieve excellent enterprise risk management Why risk assessments fail
How to achieve excellent enterprise risk management Why risk assessments fail Overview Risk assessments are a common tool for understanding business issues and potential consequences from uncertainties.
STANDARD. Risk Assessment. Supply Chain Risk Management: A Compilation of Best Practices
A S I S I N T E R N A T I O N A L Supply Chain Risk Management: Risk Assessment A Compilation of Best Practices ANSI/ASIS/RIMS SCRM.1-2014 RA.1-2015 STANDARD The worldwide leader in security standards
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN ABOUT THE AUTHOR Leveraging his background in internal audit and internal controls, Noah Gottesman provides industry thought leadership
TransAlta Corporation Energy Trading Compliance Program Assessment
www.pwc.com/ca Energy Trading Compliance Program Assessment Disclaimer We prepared this report based on information available at the time of its preparation. Our observations and conclusions are based
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
Improving Corporate Governance with the Balanced Scorecard
#04-044 Improving Corporate Governance with the Balanced Scorecard Robert S. Kaplan Michael E. Nagel Copyright 2004 Robert S. Kaplan and Michael E. Nagel Working papers are in draft form. This working
Exhibit 1: Structure of a heat map
Integrating risk and performance management processes Werner Bruggeman Geert Scheipers Valerie Decoene 1. Introduction Years ago, Kaplan & Norton interviewed managers about their time consumption and they
COSO Internal Control Integrated Framework (2013)
COSO Internal Control Integrated Framework (2013) The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released its updated Internal Control Integrated Framework (2013 Framework)
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT Let me begin by thanking Baruch College for giving me the opportunity to present this year s prestigious Emanuel Saxe Lecture in Accounting.
Performance Measures for Internal Auditing
Performance Measures for Internal Auditing A simple question someone may ask is Why measure performance? An even simpler response would be that what gets measured gets done. McMaster University s discussion
Enterprise risk management: A pragmatic, four-phase implementation plan
Enterprise risk management: A pragmatic, four-phase implementation plan Prepared by: John Brackett, Managing Director, Risk Advisory Services, RSM McGladrey, Inc. 704.442.3820, [email protected]
IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP
IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP IT Audit Perspective on Continuous Auditing/Continuous Monitoring INTRODUCTION New demands from the board, senior organizational
A&CS Assurance Review. Accounting Policy Division Rule Making Participation in Standard Setting. Report
A&CS Assurance Review Accounting Policy Division Rule Making Participation in Standard Setting Report April 2010 Table of Contents Background... 1 Engagement Objectives, Scope and Approach... 1 Overall
Director Notes. The Role of the Board in Fraud Risk Management
Director Notes The Role of the Board in Fraud Risk Management by Andi McNeal Civil charges against outside directors alleging negligence in the face of fraud serve as a sharp reminder for boards that ignorance
How To Understand The Role Of An Internal Audit
Top Ten Issues facing Internal Auditing in the Future The IIA Dallas Chapter April 6, 2006 Presented by: David A. Richards, CIA, CPA President The Institute of Internal Auditors [email protected] 1
Internal Control Integrated Framework. May 2013
Internal Control Integrated Framework May 2013 0 Table of Contents COSO & Project Overview Internal Control-Integrated Framework Illustrative Documents Illustrative Tools for Assessing Effectiveness of
The Role of the Board in Enterprise Risk Management
Enterprise Risk The Role of the Board in Enterprise Risk Management The board of directors plays an essential role in ensuring that an effective ERM program is in place. Governance, policy, and assurance
Enterprise Risk Management Panel Discussion
Enterprise Risk Management Panel Discussion Facilitators Bill Cole, VCU and VCUHS CAE Michael Bordoni, former Emory University CAE, now DHG (Dixon Hughes Goodman LLP) Risk Advisory Services Partner Gary
Unlocking value from your ERP service organization*
Consulting Application Managed Services Technology Unlocking value from your ERP service organization* Application Support Effectiveness Assessment can help you identify and dismantle the roadblocks that
Developing an Effective Enterprise Risk Management Program
Developing an Effective Enterprise Risk Management Program Jay Brietz, CPA and CIA Senior Manager This material was used by Elliott Davis Decosimo during an oral presentation; it is not a complete record
Risk Assessment & Enterprise Risk Management
Risk Assessment & Enterprise Risk 1 Healthcare Corporate Governance Today s environment requires building a culture of risk awareness and management of risk across the organization, while formulating less
CREATING AND PROTECTING VALUE STRATEGIC RISK MANAGEMENT: Cover Story B Y M ARK S. BEASLEY, CPA, AND M ARK L. FRIGO, CMA, CPA
Cover Story B Y M ARK S. BEASLEY, CPA, AND M ARK L. FRIGO, CMA, CPA Expectations that boards of directors and senior executives are effectively managing risks facing an enterprise are at an all-time high.
A Guide to the. Incorporating the Essential Elements of Strategy Within Your Organization. Empower
A Guide to the Balanced Scorecard Incorporating the Essential Elements of Strategy Within Your Organization This guide covers Create Keeping strategy creation practical, focused and agile Empower Empowering
Internal Controls and Risk Management Report
42 Internal Controls and Risk Management Report Responsibility Our Board of Directors has the overall responsibility to ensure that sound and effective internal controls are maintained, while management
Integrated Risk Management:
Integrated Risk Management: A Framework for Fraser Health For further information contact: Integrated Risk Management Fraser Health Corporate Office 300, 10334 152A Street Surrey, BC V3R 8T4 Phone: (604)
Supporting information technology risk management
IBM Global Technology Services Thought Leadership White Paper October 2011 Supporting information technology risk management It takes an entire organization 2 Supporting information technology risk management
Operational Risk Management - The Next Frontier The Risk Management Association (RMA)
Operational Risk Management - The Next Frontier The Risk Management Association (RMA) Operational risk is not new. In fact, it is the first risk that banks must manage, even before they make their first
Private Wealth Management. trusted experienced insightful
Private Wealth Management trusted experienced insightful The majority of our relationships are the result of referrals from our clients or their other professional advisors. We consider these endorsements
Executing Strategy with the Balanced Scorecard
Executing Strategy with the Balanced Scorecard Michael L. Werner (Corresponding author) School of Business Administration, University of Miami 5250 University Drive, Coral Gables, Florida 33146, United
ADOBE CORPORATE GOVERNANCE GUIDELINES
Contents 2 Introduction 2 The Mission of the Board of Directors 2 Guidelines for Corporate Governance ADOBE CORPORATE GOVERNANCE GUIDELINES 2 Selection of the Board 3 Board Leadership 3 Board Composition,
Metrics by design A practical approach to measuring internal audit performance
Metrics by design A practical approach to measuring internal audit performance September 2014 At a glance Expectations of Internal Audit are rising. Regulatory pressure is increasing. Budgets are tightening.
Designing a Metrics Dashboard for the Sales Organization By Mike Rose, Management Consultant.
Designing a Metrics Dashboard for the Sales Organization By Mike Rose, Management Consultant. Metrics can serve as critical measures of success for any organization and, in particular, the sales force
Management White Paper What is a modern Balanced Scorecard?
Management White Paper What is a modern Balanced Scorecard? For more information please visit: www.ap-institute.com What is a modern Balanced Scorecard? By Bernard Marr Abstract: The Balanced Scorecard
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE March 2012 Table of Contents Executive Summary... 1 Introduction... 1 Risk Management and Assurance (Assurance Services)... 1 Assurance Framework...
HRQM AND COLLIDING GYROSCOPES AN ALTERNATIVE WAY OF LOOKING AT VALUE CREATION IN ORGANIZATIONS
HRQM AND COLLIDING GYROSCOPES AN ALTERNATIVE WAY OF LOOKING AT VALUE CREATION IN ORGANIZATIONS Study stream Human resource and Quality management JOOP VINKE Arnhem Business School Arnhem, HAN University
6 Essential Characteristics of a PLC (adapted from Learning by Doing)
6 Essential Characteristics of a PLC (adapted from Learning by Doing) 1. Shared mission, vision, values, goals Educators in a PLC benefit from clarity regarding their shared purpose, a common understanding
Office of the Police and Crime Commissioner for Avon and Somerset and Avon and Somerset Constabulary
Office of the Police and Crime Commissioner for Avon and Somerset and Avon and Somerset Constabulary Internal Audit Report () FINAL Risk Management: Follow Up of Previous Internal Audit Recommendations
Cyber security: Are consumer companies up to the challenge?
Cyber security: Are consumer companies up to the challenge? 1 Cyber security: Are consumer companies up to the challenge? A survey of webcast participants kpmg.com 1 Cyber security: Are consumer companies
Asset Management Portfolio Solutions Disciplined Process. Customized Approach. Risk-Based Strategies.
INSTITUTIONAL TRUST & CUSTODY Asset Management Portfolio Solutions Disciplined Process. Customized Approach. Risk-Based Strategies. As one of the fastest growing investment managers in the nation, U.S.
HOW CORPORATE CULTURE AFFECTS PERFORMANCE MANAGEMENT
HOW CORPORATE CULTURE AFFECTS PERFORMANCE MANAGEMENT By Raef Lawson, CMA, CPA, CFA; Toby Hatch; and Denis Desroches Every progressive organization needs a management system that enables it to formulate
SIGNS YOU NEED A WEALTH MANAGER
5 A FIDUCIARY OF YOUR OWN SIGNS YOU NEED A WEALTH MANAGER Fiduciary Duty / Wealth Management for Individual Investors and Families Over one s lifetime, the need for sophisticated and professional financial
Audit of the Test of Design of Entity-Level Controls
Audit of the Test of Design of Entity-Level Controls Canadian Grain Commission Audit & Evaluation Services Final Report March 2012 Canadian Grain Commission 0 Entity Level Controls 2011 Table of Contents
Matthew E. Breecher Breecher & Company PC November 12, 2008
Applying COSO s Enterprise Risk Management Integrated Framework Matthew E. Breecher Breecher & Company PC November 12, 2008 The basic outline for this presentation was provided by: Objectives for the session:
Enterprise Risk Management
Enterprise Risk Management Topic Gateway Series No. 49 1 Prepared by Jasmin Harvey and Technical Information Service July 2008 About Topic Gateways Topic Gateways are intended as a refresher or introduction
www.pwc.com ERM006 ERM and Business Continuity Management: Together at Last RIMS Annual Conference April 13, 2016
www.pwc.com ERM006 ERM and Business Continuity Management: Together at Last RIMS Annual Conference April 13, 2016 Your presenters Phil Samson Principal PricewaterhouseCoopers, Dallas Leads s Risk Management
Enterprise Risk Management in a Highly Uncertain World. A Presentation to the Government-University- Industry Research Roundtable June 20, 2012
Enterprise Risk Management in a Highly Uncertain World A Presentation to the Government-University- Industry Research Roundtable June 20, 2012 CRO Council Introduction Mission The North American CRO Council
Placing a Value on Enterprise Risk Management ADVISORY
Placing a Value on Enterprise Risk Management ADVISORY Placing a Value on Enterprise Risk Management 1 In turbulent economic times, the case for investing in an enterprise risk management (ERM) program
INTERNAL AUDIT REPORT ON THE FINANCIAL MANAGEMENT CONTROL FRAMEWORK FOR INITIATIVES RELATED TO CANADA S ECONOMIC ACTION PLAN (EAP) REPORT.
INTERNAL AUDIT REPORT ON THE FINANCIAL MANAGEMENT CONTROL FRAMEWORK FOR INITIATIVES RELATED TO CANADA S ECONOMIC ACTION PLAN (EAP) REPORT July 2010 PREPARED BY THE INTERNAL AUDIT BRANCH (IAB) Project No:
Quality Assurance Checklist
Internal Audit Foundations Standards 1000, 1010, 1100, 1110, 1111, 1120, 1130, 1300, 1310, 1320, 1321, 1322, 2000, 2040 There is an Internal Audit Charter in place Internal Audit Charter is in place The
WHITE PAPER. 7 Keys to. successful. Organizational Change Management. Why Your CRM Program Needs Change Management and Tips for Getting Started
7 Keys to successful Organizational Change Management Why Your CRM Program Needs Change Management and Tips for Getting Started CONTENTS 2 Executive Summary 3 7 Keys to a Comprehensive Change Management
Board oversight of risk: Defining risk appetite in plain English
www.pwc.com/us/centerforboardgovernance Board oversight of risk: Defining risk appetite in plain English May 2014 Defining risk appetite in plain English Risk oversight continues to be top-of-mind for
Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013
Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013 Chitra Gopalakrishnan Director KPMG LLP Agenda Introduction Business Continuity / Disaster
fmswhitepaper Why community-based financial institutions should practice enterprise risk management.
fmswhitepaper Why community-based financial institutions should practice enterprise risk management. By Michael D. Cohn, CPA, CISA, CGEIT Director, WolfPAC Solutions Group Unique Insights Implementation
Balanced Scorecard: & Challenges. 23rd July 2007. Organized by: SMR
Balanced Scorecard: Implementation & Challenges 23rd July 2007 Organized by: SMR 1 Program Schedule» 9.00 am 10.30am» 2.00pm 3.30pm > Introduction PMS > BSC Terminology & Principles > Understanding BSC
Creating Business Value with Mature QA Practices
perspective Creating Business Value with Mature QA Practices Abstract The IT industry across the globe has rapidly evolved in recent times. The evolution has been primarily driven by factors like changing
A CFO s Guide to Corporate Governance
A CFO s Guide to Corporate Governance By Linda D. Henman, Ph.D. Few people can define governance in concrete terms, yet it remains one of those allencompassing words that people use frequently. The dictionary
Office of the Chief Information Officer
Office of the Chief Information Officer Business Plan: 2012 2015 Department / Ministère: Executive Council Date: November 15, 2012 1 P a g e This Page Left Intentionally Blank 2 P a g e Contents The Business
Guidance for audit committees. The internal audit function
Guidance for audit committees The internal audit function March 2004 The Combined Code on Corporate Governance July 2003 C.3 Audit Committee and Auditors Main Principle: The board should establish formal
UNITED NATIONS OFFICE FOR PROJECT SERVICES. ORGANIZATIONAL DIRECTIVE No. 33. UNOPS Strategic Risk Management Planning Framework
UNOPS UNITED NATIONS OFFICE FOR PROJECT SERVICES Headquarters, Copenhagen O.D. No. 33 16 April 2010 ORGANIZATIONAL DIRECTIVE No. 33 UNOPS Strategic Risk Management Planning Framework 1. Introduction 1.1.
treasury risk management
Governance, Concise guide Risk to and Compliance treasury risk management KPMG is a leading provider of professional services including audit, tax and advisory. KPMG in Australia has over 5000 partners
COSO s 2013 Internal Control Framework in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting
in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting Table of Contents EXECUTIVE SUMMARY... 3 BACKGROUND... 3 SIGNIFICANT CHANGES AFFECTING INTERNAL CONTROL
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012. Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012 Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund There are different risk assessments prepared: Annual risk assessment
The Role of Internal Audit In Business Continuity Planning
The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. [email protected] Actively involved in the Information
CSR / Sustainability Governance and Management Assessment By Coro Strandberg Principal, Strandberg Consulting www.corostrandberg.
Introduction CSR / Sustainability Governance and Management Assessment By Coro Strandberg Principal, Strandberg Consulting www.corostrandberg.com June 2015 Companies which adopt CSR or sustainability 1
An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management
Bridgework: An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management @Copyright Cura Software. All rights reserved. No part of this document may be transmitted or copied without
A Brief History of Change Management
A Brief History of Change Management IT S AN AMAZING STORY... THE BIRTH OF A PROFESSION L AMARSH.COM 3 3 2 S. M I C H I G A N AV E., 9 T H F L O O R C H I C A G O, I L L I N O I S 6 0 6 0 4 U S A P. 3
CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT
CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT April 16, 2014 INTRODUCTION Purpose The purpose of the audit is to give assurance that the development of the Metropolitan Council s Continuity
Export Development Canada
Export Development Canada Special Examination Report 2009 Office of the Auditor General of Canada Bureau du vérificateur général du Canada Ce document est également publié en français. Office of the Auditor
LEADERSHIP DEVELOPMENT FRAMEWORK
LEADERSHIP DEVELOPMENT FRAMEWORK February 13, 2008 LEADERSHJP PERSPECTIVE I consider succession planning to be the most important duty I have as the Director of the NOAA Corps. As I look toward the future,
The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework
The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework Dorothy Gjerdrum, ARM-P, Chair of the ISO 31000 US TAG and Executive Director,
Enterprise Risk Management in Colleges and Universities
Enterprise Risk Management in Colleges and Universities Cherry Bekaert & Holland, L.L.P. Neal Beggan, CISA, CRISC Shane Hester, CPA, CISA Cherry, Bekaert & Holland, L.L.P. The Firm of Choice. 1 Cherry,
Developing and Implementing a Balanced Scorecard: A Practical Approach
RL Consulting Developing and Implementing a Balanced Scorecard: A Practical Approach White Paper Prepared by: Rick Leopoldi March 31, 2004 Copyright 2004. All rights reserved. Duplication of this document
www.pwc.com/us/ias A worldwide view Successful integration of global mobility programs
www.pwc.com/us/ias A worldwide view Successful integration of global mobility programs Table of Contents Introduction... 3 Approach... 3 Risk assessment... 4 Mobility strategy and success measures... 4
