RIMS Executive Report The Risk Perspective. Emerging Risks. and. Enterprise Risk Management
|
|
|
- Junior Elliott
- 9 years ago
- Views:
Transcription
1 RIMS Executive Report The Risk Perspective Emerging Risks and Enterprise Risk Management
2 Emerging Risks and Enterprise Risk Management Editors Soubhagya Parija Walt Williams Drew Zavatsky Russell McGuire Contributors RIMS ERM Committee: Pete Fahrenthold Ryan Egerdahl Grace Crickette Jeffrey Vernor John Hach Rupak Mazumdar Joseph Milan Laurie Champion Michael Phillipus Carol Fox, Chair, RIMS Standards and Practices Committee Mary Roth, RIMS Executive Director Art Director Joseph Zwielich 2010 Risk and Insurance Management Society, Inc. (RIMS) All rights reserved.
3 Risk Management is a practice as old as mankind itself in its most fundamental objective of optimizing the outcome of risk-taking. Venturing out of the cave took courage and presumably a reasonable assessment of the risks and risk management options (I ll leave the cave, you watch my back and be ready to run!). As in primitive times, the concepts of danger, safety, adventure, reward, predictability and stability are common in daily life and in risk management theory. Like people, organizations vary in their ability and willingness to take risks and in their expectations regarding appropriate rewards associated with risk-taking behavior. As the complexity and pace of modern civilization has increased, the perceived value and sophistication of risk management has also evolved - not just in its use of formal tools of risk analysis, but also in terms of its importance to effective management of today s organizations. Background Enterprise Risk Management (ERM) has become a standard practice in most advanced organizations. ERM distinguishes itself from traditional risk management in several aspects, the most significant of which is that it considers risks from the enterprise perspective as opposed to focusing on risks that originate and are managed within functional silos or specific business units of an organization. Conceptually, ERM requires a mind shift to incorporate an entity-level view of risk, an understanding of risk management options and the use of consistently developed risk information to support decision making and management practices. The implicit idea is that ERM will help organizations focus on the most relevant risks to achieving an organization s goals, both from an operational as well as a strategic perspective. While ERM has yet to be universally accepted as an essential business discipline, ERM knowledge and experience have evolved to the point where there is a growing consensus regarding best practices and standards for excellence in the discipline. Generally accepted tools and resources, as well as internationally established standards, are available that can assist an organization to design and implement an ERM framework that fits well within each organization s culture and management practices. Unfortunately, many organizations tend to focus mainly on near-term risks without paying adequate attention to emerging risks, i.e., those issues that have not manifested themselves sufficiently to be managed using the tools commonly applied to more developed exposures. Emerging risks are those risks an organization has not yet recognized or those which are known to exist, but are not well understood. To quote Donald Rumsfeld, former US Secretary of Defense, There are known knowns. These are things we know that we know. There are known unknowns. That is to say, there are things that we know we don t know. But there are also unknown unknowns. There are things we don t know we don t know. An ERM program that does not address the potential challenges created by the existence and development of emerging risks will not meet its goal of protecting, and generating opportunity for, the organization. It is in this context that a discussion on emerging risks is necessary to continue the evolution of this discipline, and to help practitioners and organizations achieve full value from their investment in ERM. The recent global financial crisis which was identified early by some risk managers as an emerging risk raised many serious questions, some of which focused on the effectiveness of risk management practices and, more specifically, ERM. Analysis of the root causes of the resulting recession is ongoing Risk and Insurance Management Society, Inc. (RIMS) All rights reserved.
4 Do existing ERM frameworks and tools de-emphasize or overlook emerging risks? it is often challenging to establish credible links between the big picture global issues and the practical impact of these issues on the risk profile of any particular organization. Might emerging risks be de-emphasized when organizations place their focus on internal and better-known issues? Might emerging risks be overlooked when organizations think of external risk primarily in the context of macro-level global issues? Might these emerging risks be overlooked because an organization s existing ERM frameworks and tools do not identify the interconnectedness of various risk factors? The answers to these questions can provide insight into common deficiencies in existing ERM frameworks and tools. There have been several papers written on emerging risks by thought-leaders such as the Society of Actuaries, PricewaterhouseCoopers, Ernst & Young and Lloyd s that tend to focus on macro-level global issues such as global warming, energy supply disruption and nano-technology risks, etc. These issues are important and should be assessed for potential impact on an organization s risk profile both today and in the future. However, other emerging risk issues that are closer to home (those resulting from industry/sector prospects and trends; customer and supplier issues; strategic plans; etc.) are also important to consider. And, from a practicing risk professional s perspective, it is often challenging to establish credible links between the big picture global issues and the practical impact of these issues on the risk profile of any particular organization. Without credibility built on appropriate analysis of close-to-home risks, discussion of the macro issues and the emerging risks may have little actionable value. This paper will outline how ERM can address emerging risks and will: describe the characteristics of emerging risks; and describe certain best practices for identifying and assessing emerging risks. Characteristics of Emerging Risks Most existing ERM frameworks prioritize risks in terms of their potential impact and the likelihood of occurrence. While this is an effective technique for assessing known risks, it is not always effective in addressing emerging risks. Emerging risks differ in several key characteristics which suggest the need for additional and complementary risk analysis tools and risk management techniques. Characteristics of emerging risks commonly include: High level of uncertainty Both frequency and potential impact of risks are difficult to assess. Typically, emerging risks are expected to be characterized by very low frequency ( not likely to happen soon ) and relatively high impact. However, emerging risks are sometimes present at low impact levels with the potential to grow sometimes rapidly to a more significant level of impact. Example: Rapidly shifting demographic patterns While it is known that worldwide demographic patterns (e.g. age, ethnicity, etc.) are evolving, the impact of these changes on any enterprise can be highly uncertain as very few statistical benchmarks may exist. Lack of consensus There is a general lack of consensus both internally (within an organization) and externally (within the public at large) regarding the drivers, impacts and likelihood of an emerging risk event occurring. This seems logical, since by definition the risk is relatively new, unknown and/or changing in some new way. As quoted in the Survey of Emerging Risks published by the Society of Actuaries, assessment of emerging risks requires managers and modelers to think outside their comfort zone. Often there is 2010 Risk and Insurance Management Society, Inc. (RIMS) All rights reserved. 3
5 There is a real possibility of an emerging risk being perceived as so unlikely to occur that it does not warrant attention ( it can t happen here syndrome), or is relegated to a watch list as a type of phantom risk that has little bearing on existing circumstances. no incentive for firms to contemplate risks that others are ignoring. In fact, even when the management recognizes something is amiss, the market penalizes prudency at least in the short run and in these days of quarterly earnings announcements management continues to behave somewhat like lemmings. Example: Global financial meltdown Even after seeing signs of recession, there was a lack of consensus regarding the inter-relations of various causal factors, or the speed of the expected decline. This lack of consensus made understanding and managing the emerging risk very challenging. Confusion over root causes of an emerging risk can also make management of the risk more difficult and may facilitate further similar losses once again proving the adage that those who do not learn from the past are destined to repeat it. Uncertain relevance Uncertainty over evolution of the risk is a hallmark of emerging risks. Little guidance is available for determining how emerging risks can be obstacles to (or accelerate) the achievement of objectives. Without being able to analyze the relevance and importance of emerging risks to a particular set of objectives, emerging risks may be perceived as too futuristic to matter for strategic planning purposes. Example: Social media growth Adoption of digital technologies is a trend that has been gaining traction among broad demographic groups for dissemination of information, where the speed of dissemination is almost more important than the accuracy or meaning of that data. An emerging risk inherent in this trend is that companies may become unable to properly communicate with current and future customers. Without understanding or factoring in the degree of relevance and importance of this emerging risk on an organization s decision making and the achievement of its objectives, ignoring the trend of adopting new communication modes could prove detrimental to the company. On the other hand, if this emerging uncertainty is included in the organization s strategic planning, the emerging risk could become an opportunity for growth. Difficult to communicate It can be difficult to develop understanding about an emerging risk. There is a real possibility of an emerging risk being perceived as so unlikely to occur that it does not warrant attention ( it can t happen here syndrome), or is relegated to a watch list as a type of phantom risk that has little bearing on existing circumstances. This makes communication to senior management difficult, particularly using traditional risk management tools with their focus on silos. Example: 9/11 Prior to the attack on 9/11, few resources were allocated to terrorism preparedness. However, after 9/11, terrorism became a top boardroom agenda item, and massive funding has been assigned to identify and respond to terrorist threats within the U.S.A. and elsewhere. While the concept of terrorism was widely known prior to September 11, 2001, the perceived possibility of a significant terrorist event within the U.S.A. was not enough to allocate adequate time, attention and other resources to prepare for it. This was an emerging risk that was largely ignored until a significant event actually occurred. The prior attack on the World Trade Center in 1993, and the increasing negativity towards the policies of that time were, in hindsight, evidence of the emerging risk. This example underscores the difficulties in communicating the importance of risks that have not been experienced yet. The majority of risk management resources tend to be focused on current operational, financial and compliance risks. Less tangible (or already accepted) strategic risks and Taleb s black swan types of low-probability risks are often under-resourced. Difficult to assign ownership Emerging risks often defy easy categorization with known and accepted risks, and as a result it can be difficult to assign and/or encourage ownership of an emerging risk. Understanding and managing emerging risks often requires an interdisciplinary approach. Example: Global warming No one person or workgroup can sufficiently own this risk, as the increasing volatility of climate conditions can significantly impact personnel, shareholders, business resources, insurance markets and legal and regulatory demands. In addition, the timeline for the progression of climate change is widely unpredictable. Systemic or business practice issues Some emerging risks can be embedded in long accepted practices, but may not be fully understood or appreciated until triggered by some external or internal change. Example: Bundling subprime mortgages into securities The complexity of these instruments made accurate assessment of their inherent risk very difficult. The risks became widely understood only after many of the underlying mortgages began to fail Risk and Insurance Management Society, Inc. (RIMS) All rights reserved.
6 Why emphasize emerging risk management? Enterprise risk managers can add value to organizations by helping them communicate risk issues and allocate resources appropriately, and by turning emerging risks into opportunities. Organizations do not intend to fail. As Alan Lakein put it, failing to plan is planning to fail. This rather obvious statement provides the motivation for addressing emerging risks: as organizations gain a greater understanding of risk management, and attain more advanced competencies to manage risk, they have also developed processes, models and controls to give assurances that dramatic volatility in expected results can be avoided. While these risk management practices have proven to be useful, it is often the unexpected risk or a little understood interaction of some key risk factors that cause even the most risk-intelligent organizations to fail. For example, the increased complexity and pace within the macro business environment creates additional risks which may not always be well understood by an individual organization, sector or market. As finances, supply chains and business processes have become increasingly intertwined and time-sensitive, it has become more critical to understand these interdependencies and the risks associated with them. These relationships bring operational benefits, but may also expose the organization to risks which manifest themselves in ways that were not previously considered. This was evident in the recent financial crisis as many companies failed even though they had devoted substantial resources to quantifying and modeling the risks that were judged to present the most imminent threat. In some cases, the over-reliance on these models or their embedded assumptions actually provided a false sense of security that made companies like Lehman Brothers more vulnerable to emerging risks. Most importantly, as noted in the RIMS Executive Report entitled The 2008 Financial Crisis: A Wake-up Call for Enterprise Risk Management, the failure to use ERM to keep senior management informed on both risk-taking and risk-avoiding decisions ultimately created an even more uncertain environment. The challenge for risk managers lies in uncovering these emerging risks, bringing resources to bear to address these risks, and building resiliency and sustainability for events that cannot be predicted through the usual historical analysis and risk models. Given that competitive advantage lies in addressing issues in a nimble and efficient manner, enterprise risk managers can add value to organizations by helping them communicate risk issues and allocate resources appropriately, and by turning emerging risks into opportunities. By having a constant and robust discipline of scanning the internal and external environment for emerging trends, companies can formulate more effective strategies and build plans to execute those strategies while managing the underlying risks. Organizations that effectively manage these emerging risks can successfully outlast and outgrow their competition. Emerging Risk - Organized Crime and Data Incursions Data incursions have always existed since the deployment of computer systems. Initially, much of these incursions were accidental, or by inquisitive but not always malevolent computer geeks. However, with the increasing recognition of the value of personal data and the potential to use this data to obtain money, goods or even for money-laundering, organized crime has rapidly evolved as a primary driver of data incursions. Stolen personal data can be bought through multiple sources including some on-line auction sites (although not the usual freely-accessible public auction sites), and nearly one-third of the data on these underground sites is personal credit card details. The organized crime approach has led to an explosion in the theft of personal data records with over 280,000,000 records stolen in 2008 compared to 230,000,000 records stolen between 2004 and In other words 25% more records were stolen in 2008 than the total stolen for the prior 4 years! The causes of the attacks to gain access to this data have shifted dramatically, with 90% of breaches in 2008 involving organized crime. For a chronological view of reported data breaches visit Risk and Insurance Management Society, Inc. (RIMS) All rights reserved. 5
7 Best Practices in Identifying and Assessing Emerging Risks Enterprise Risk Management best practices, with regard to identifying and quantifying emerging risks, continue to evolve, and will do so for quite some time. While no clear best practice standard has been identified to recognize and mitigate emerging risks, various tools and processes provide greater insight for evaluating such risks. Conduct emerging risk reviews Organizations should establish a formal, documented process for identifying, assessing and periodically reviewing emerging risks. This process should involve the members of the management team responsible for the achievement of strategic goals, and should occur with sufficient frequency to ensure that the review of the risk environment is reasonably current. In addition, the review process should incorporate features that allow for immediate communication of new information about risk as it is discovered. Integrate emerging risk review into the strategic planning process Emerging risks may be more distant and more strategic in nature, and therefore aligned with the organization s strategic planning process. Conducting risk reviews in concert with the strategic planning process will help enforce a disciplined approach regarding the relevance, importance and effect of uncertainties on organizational objectives and improve management s decision-making process. Identify all assumptions and carry out disciplined assumption testing Establishing a disciplined approach to testing assumptions and beliefs in existing business models will help organizations avoid natural tendencies to prioritize known risks (those for which there is historical precedent and information) over emerging risks which may not be perceived as serious in the short term. The disciplined approach should include establishment of early warning signals to track the development of the emerging risks over time. For example, banks may not have taken on so much risk if they had tested their assumptions about the continuous rise in housing prices, particularly when there were signs of rising unemployment and an extraordinarily high level of leverage in the financial industry. Challenge conventional thought processes and expectations Testing the potential impact of an emerging risk against the organization s business model requires an assumption as to how the risk will manifest itself in terms of visibility and impact. As emerging risks are often the result of the continual evolution of the business environment, an emerging risk may manifest itself in a manner that differs from the conventional expectation. The analysis of an emerging risk should extend beyond what seems to be the most logical development path for that exposure and also consider other development paths that are possible given the characteristics of the risk, even if they seem extremely remote. Apply new and developing methodologies to better understand and predict risk One example is how the Bayesian Belief Networks are helping to drive the estimation of risk where previous tools failed to provide a defensible approach to developing realistic risk assessment values (e.g. probability and impact). The Bayesian Belief Networks can help capture and calculate the interconnectedness of different risk factors, along with the composite impact of these risk factors which may differ significantly from their individual impact. Also, use of simulations and scenario analysis to further develop emerging risk scenarios and what if analyses can help organizations understand the implications of potential emerging risk events. Approaching Emerging Risks Practitioners should balance focus on relevant macro-level trends with important micro-level organizational or industry issues that may be developing. This requires additional tools and techniques that are part of their existing risk management toolkit, though possibly in new applications where traditional approaches to risk identification and assessment may not work. Organizations are complex adaptive systems and many risks that may be measured in a traditional sense are often symptoms of more deeply rooted and less understood emerging risks. Misplaced confidence regarding the understanding of risks through historical/ statistical analysis can lead to a false understanding of the complex interplay of risk factors within the system. The key is to understand, articulate and manage risk within the risk appetite of the organization over a longer time horizon. This longer horizon not only considers known risks but the impact of emerging risks on the strategic objectives of the organization Risk and Insurance Management Society, Inc. (RIMS) All rights reserved.
8 About the Risk and Insurance Management Society, Inc. The Risk and Insurance Management Society, Inc. (RIMS) is a not-for-profit organization dedicated to advancing the practice of risk management. Founded in 1950, RIMS represents some 4,000 industrial, service, nonprofit, charitable and government entities. The Society serves more than 10,000 risk management professionals around the world. About the ERM Center of Excellence RIMS ERM Center of Excellence is the risk professional s source for news, tools and peer-to-peer networking on everything related to Enterprise Risk Management. Whether you are initiating an ERM program within your organization, in the implementation phase or streamlining processes, in RIMS ERM Center of Excellence you will gain access to the key information and connect with the risk practitioners that will put you on the road to ERM success. To find more information on RIMS programs and services, to enroll in membership or access RIMS ERM Center of Excellence, visit and RIMS 1065 Avenue of the Americas 13th Floor New York, NY Tel: [email protected] The information contained in this paper is based on sources believed to be reliable, but we make no representations or warranties, expressed or implied, regarding its accuracy. This publication provides a general overview of subjects covered and is not intended to be taken as advice regarding any individual situation. Individuals should consult their advisors regarding specific risk management issues.
How to achieve excellent enterprise risk management Why risk assessments fail
How to achieve excellent enterprise risk management Why risk assessments fail Overview Risk assessments are a common tool for understanding business issues and potential consequences from uncertainties.
Enterprise Risk Management: From Theory to Practice
INSURANCE Enterprise Risk Management: From Theory to Practice KPMG LLP Executive Summary Enterprise Risk Management (ERM) is a structured and disciplined business tool aligning strategy, processes, people,
Why Strategic Risk Management?
Excerpt from the Economist Intelligent Unit 2010 research report Fall guys risk management in the front line : Strategic risks those that pose a threat to a company s ability to set and execute its overall
EFFECTIVE STRATEGIC PLANNING IN MODERN INFORMATION AGE ORGANIZATIONS
EFFECTIVE STRATEGIC PLANNING IN MODERN INFORMATION AGE ORGANIZATIONS Cezar Vasilescu and Aura Codreanu Abstract: The field of strategic management has offered a variety of frameworks and concepts during
Much attention has been focused recently on enterprise risk management (ERM),
By S. Michael McLaughlin and Karen DeToro Much attention has been focused recently on enterprise risk management (ERM), not just in the insurance industry but in other industries as well. Across all industries,
Deriving Value from ORSA. Board Perspective
Deriving Value from ORSA Board Perspective April 2015 1 This paper has been produced by the Joint Own Risk Solvency Assessment (ORSA) Subcommittee of the Insurance Regulation Committee and the Enterprise
Cyber Security Evolved
Cyber Security Evolved Aware Cyber threats are many, varied and always evolving Being aware is knowing what is going on so you can figure out what to do. The challenge is to know which cyber threats are
The Role of Internal Audit in Risk Governance
The Role of Internal Audit in Risk Governance How Organizations Are Positioning the Internal Audit Function to Support Their Approach to Risk Management Executive summary Risk is inherent in running any
The Essential Guide to: Risk Post IPO
S TRATEGIC M ARKETS G ROWTH The Essential Guide to: Risk Post IPO Embracing risk for reward Introduction So you ve made it you have taken your business public. It s been a rollercoaster ride and you have
GAINING CONTROL: Building Your Existing Framework into an ERM Model
GAINING CONTROL: Building Your Existing Framework into an ERM Model RIMS Northeast Ohio Chapter Education Day Carol Fox, ARM RIMS Director of Strategic and Enterprise Risk Practice November 19, 2013 Copyright
Appendix B Data Quality Dimensions
Appendix B Data Quality Dimensions Purpose Dimensions of data quality are fundamental to understanding how to improve data. This appendix summarizes, in chronological order of publication, three foundational
Risk Management & Business Continuity Manual 2011-2014
ANNEX C Risk Management & Business Continuity Manual 2011-2014 Produced by the Risk Produced and by the Business Risk and Business Continuity Continuity Team Team February 2011 April 2011 Draft V.10 Page
Table of Contents. Application Vulnerability Trends Report 2013. Introduction. 99% of Tested Applications Have Vulnerabilities
Application Vulnerability Trends Report : 2013 Table of Contents 3 4 5 6 7 8 8 9 10 10 Introduction 99% of Tested Applications Have Vulnerabilities Cross Site Scripting Tops a Long List of Vulnerabilities
Guideline. Operational Risk Management. Category: Sound Business and Financial Practices. No: E-21 Date: June 2016
Guideline Subject: Category: Sound Business and Financial Practices No: E-21 Date: June 2016 1. Purpose and Scope of the Guideline This Guideline sets out OSFI s expectations for the management of operational
V1.0 - Eurojuris ISO 9001:2008 Certified
Risk Management Manual V1.0 - Eurojuris ISO 9001:2008 Certified Section Page No 1 An Introduction to Risk Management 1-2 2 The Framework of Risk Management 3-6 3 Identification of Risks 7-8 4 Evaluation
PRIORITIZING CYBERSECURITY
April 2016 PRIORITIZING CYBERSECURITY Five Investor Questions for Portfolio Company Boards Foreword As the frequency and severity of cyber attacks against global businesses continue to escalate, both companies
Supporting information technology risk management
IBM Global Technology Services Thought Leadership White Paper October 2011 Supporting information technology risk management It takes an entire organization 2 Supporting information technology risk management
ENTERPRISE RISK MANAGEMENT SURVEY. 2013 RIMS Enterprise Risk Management (ERM) Survey SPONSORED BY:
t RIMS2013 ENTERPRISE RISK MANAGEMENT SURVEY 2013 RIMS Enterprise Risk Management (ERM) Survey SPONSORED BY: Administered by: Advisen Ltd. Zurich Authored by: RIMS and Advisen Ltd. Publishers: Mary Roth,
STANDARD. Risk Assessment. Supply Chain Risk Management: A Compilation of Best Practices
A S I S I N T E R N A T I O N A L Supply Chain Risk Management: Risk Assessment A Compilation of Best Practices ANSI/ASIS/RIMS SCRM.1-2014 RA.1-2015 STANDARD The worldwide leader in security standards
Scenario Analysis Principles and Practices in the Insurance Industry
North American CRO Council Scenario Analysis Principles and Practices in the Insurance Industry 2013 North American CRO Council Incorporated [email protected] December 2013 Acknowledgement The
Raytheon and Vista Equity Partners form new cybersecurity company
Raytheon and Vista Equity Partners form new cybersecurity company Investor Presentation April 20, 2015 Dial In Number 866.825.3209 Domestic 617.213.8061 International Reservation Number: 48245306 Replay
Guidance Note: Stress Testing Class 2 Credit Unions. November, 2013. Ce document est également disponible en français
Guidance Note: Stress Testing Class 2 Credit Unions November, 2013 Ce document est également disponible en français This Guidance Note is for use by all Class 2 credit unions with assets in excess of $1
Assessing Your Information Technology Organization
Assessing Your Information Technology Organization Are you running it like a business? By: James Murray, Partner Trey Robinson, Director Copyright 2009 by ScottMadden, Inc. All rights reserved. Assessing
Organization transformation in times of change
Organization transformation in times of change Insurance is sold, not bought is a phrase of unknown attribution, but common wisdom for decades. Thus, insurers and most financial services organizations
Principles and Practices in Credit Portfolio Management Findings of the 2011 IACPM Survey. www.iacpm.org
Principles and Practices in Credit Portfolio Management Findings of the 2011 IACPM Survey www.iacpm.org TABLE OF CONTENTS I. INTRODUCTION...3 Survey Results Overview...3 Credit Portfolio Management Business
FlyntGroup.com. Enterprise Risk Management and Business Impact Analysis: Understanding, Treating and Monitoring Risk
Enterprise Risk Management and Business Impact Analysis: Understanding, Treating and Monitoring Risk 2012 The Flynt Group, Inc., All Rights Reserved FlyntGroup.com Enterprise Risk Management and Business
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
FFIEC Cybersecurity Assessment Tool
Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN
GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN ABOUT THE AUTHOR Leveraging his background in internal audit and internal controls, Noah Gottesman provides industry thought leadership
APICS INSIGHTS AND INNOVATIONS SUPPLY CHAIN RISK CHALLENGES AND PRACTICES
APICS INSIGHTS AND INNOVATIONS SUPPLY CHAIN RISK CHALLENGES AND PRACTICES APICS INSIGHTS AND INNOVATIONS ABOUT THIS REPORT This report examines the role that supply chain risk management plays in organizations
Corporate Risk Management Policy
Corporate Risk Management Policy Managing the Risk and Realising the Opportunity www.reading.gov.uk Risk Management is Good Management Page 1 of 19 Contents 1. Our Risk Management Vision 3 2. Introduction
The Future is Now: HR Competencies for High Performance
The RBL White Paper Series The Future is Now: HR Competencies for High Performance WAYNE BROCKBANK, DAVE ULRICH, JON YOUNGER, AND MIKE ULRICH The Future is Now: HR Competencies for High Performance * Wayne
Creating Line of Sight
Creating Line of Sight How to Get to the Bottom Line Through Your Employees Presented by: Ed Krow, SPHR, CCP, CHCM Objectives Identify key behaviors of all levels of employees and the link between those
Placing a Value on Enterprise Risk Management ADVISORY
Placing a Value on Enterprise Risk Management ADVISORY Placing a Value on Enterprise Risk Management 1 In turbulent economic times, the case for investing in an enterprise risk management (ERM) program
BASICS OF CREDIT VALUE ADJUSTMENTS AND IMPLICATIONS FOR THE ASSESSMENT OF HEDGE EFFECTIVENESS
BASICS OF CREDIT VALUE ADJUSTMENTS AND IMPLICATIONS FOR THE ASSESSMENT OF HEDGE EFFECTIVENESS This is the third paper in an ongoing series that outlines the principles of hedge accounting under current
A Risk Management Standard
A Risk Management Standard Introduction This Risk Management Standard is the result of work by a team drawn from the major risk management organisations in the UK, including the Institute of Risk management
Operational Risk Management - The Next Frontier The Risk Management Association (RMA)
Operational Risk Management - The Next Frontier The Risk Management Association (RMA) Operational risk is not new. In fact, it is the first risk that banks must manage, even before they make their first
How to audit your business strategy
How to audit your business strategy Andrew Carey Why conduct a business strategy audit? Nearly all the major initiatives undertaken by corporate executives today are called strategic. With everything having
Board oversight of risk: Defining risk appetite in plain English
www.pwc.com/us/centerforboardgovernance Board oversight of risk: Defining risk appetite in plain English May 2014 Defining risk appetite in plain English Risk oversight continues to be top-of-mind for
Are you sure that s beef in your burger?
pwc.com.au PwC s supplier risk management services Are you sure that s beef in your burger? Giving you confidence in the performance of your supply chain The recent horse meat substitution scandal is just
Tapping the benefits of business analytics and optimization
IBM Sales and Distribution Chemicals and Petroleum White Paper Tapping the benefits of business analytics and optimization A rich source of intelligence for the chemicals and petroleum industries 2 Tapping
Building the business case for continuity and resiliency
Global Technology Services Research Analysis Risk Management Building the business case for continuity and resiliency The economics of IT risk and reputation and their importance to business continuity
IMPLEMENTING A SECURITY ANALYTICS ARCHITECTURE
IMPLEMENTING A SECURITY ANALYTICS ARCHITECTURE Solution Brief SUMMARY New security threats demand a new approach to security management. Security teams need a security analytics architecture that can handle
Leveraging Network and Vulnerability metrics Using RedSeal
SOLUTION BRIEF Transforming IT Security Management Via Outcome-Oriented Metrics Leveraging Network and Vulnerability metrics Using RedSeal november 2011 WHITE PAPER RedSeal Networks, Inc. 3965 Freedom
Risk Management Primer
Risk Management Primer Purpose: To obtain strong project outcomes by implementing an appropriate risk management process Audience: Project managers, project sponsors, team members and other key stakeholders
Accenture Risk Management. Industry Report. Life Sciences
Accenture Risk Management Industry Report Life Sciences Risk management as a source of competitive advantage and high performance in the life sciences industry Risk management that enables long-term competitive
Developing National Frameworks & Engaging the Private Sector
www.pwc.com Developing National Frameworks & Engaging the Private Sector Focus on Information/Cyber Security Risk Management American Red Cross Disaster Preparedness Summit Chicago, IL September 19, 2012
6. Chief human resources officer
6. Chief human resources officer A Chief Human Resources Officer (CHRO) is a corporate officer who oversees all human resource management and industrial relations operations for an organization. Similar
INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS
Standard No. 13 INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS STANDARD ON ASSET-LIABILITY MANAGEMENT OCTOBER 2006 This document was prepared by the Solvency and Actuarial Issues Subcommittee in consultation
Cyber threat intelligence and the lessons from law enforcement. kpmg.com/cybersecurity
Cyber threat intelligence and the lessons from law enforcement kpmg.com/cybersecurity Introduction Cyber security breaches are rarely out of the media s eye. As adversary sophistication increases, many
Advanced Risk Analysis for High-Performing Organizations
Pittsburgh, PA 15213-3890 Advanced Risk Analysis for High-Performing Organizations Christopher Alberts Audrey Dorofee Sponsored by the U.S. Department of Defense 2006 by Carnegie Mellon University page
Organizational Change: Managing the Human Side
Organizational Change: Managing the Human Side Based on findings from the American Productivity & Quality Center s 1997 Organizational Change consortium benchmarking study Changing Regulatory or Legal
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
Davy Defensive High Yield Fund from New Ireland
Davy Asset Management For Financial Advisors Only Davy Defensive High Yield Fund from New Ireland Davy Asset Management is regulated by the Central Bank of Ireland. Exposure to: equity-market type returns
Leading Self. Leading Others. Leading Performance and Change. Leading the Coast Guard
Coast Guard Leadership Competencies Leadership competencies are the knowledge, skills, and expertise the Coast Guard expects of its leaders. The 28 leadership competencies are keys to career success. Developing
Building Public Trust: Ethics Measures in OECD Countries
Building Public Trust: Ethics Measures in OECD Countries Annex 1998 Recommendation of the OECD Council on Improving Ethical Conduct in the Public Service, 36 Including Principles for Managing Ethics in
CORPORATE INFORMATION AND TECHNOLOGY STRATEGY
Version 1.1 CORPORATE INFORMATION AND TECHNOLOGY STRATEGY The City of Edmonton s Information and Technology Plan, 2013-2016 Bringing the Ways to Life through Information and Technology June 2013 2 Copyright
Structured Products. Designing a modern portfolio
ab Structured Products Designing a modern portfolio Achieving your personal goals is the driving motivation for how and why you invest. Whether your goal is to grow and preserve wealth, save for your children
September 4, 2003. appearing before you today. I am here to testify about issues and challenges in providing for
Testimony of John A. McCarthy, Director of the Critical Infrastructure Protection Project, George Mason School of Law Before a joint hearing of the House Subcommittee on Infrastructure Security and The
Benefits make up an important component of the employment. Employee Benefits in a Total Rewards Framework. article Business Case for Benefits
article Business Case for Benefits Employee Benefits in a Total Rewards Framework Benefits represent one of the largest investments a company makes in its talent. However, our tendency can be to design,
Davis New York Venture Fund
Davis New York Venture Fund Price Is What You Pay, Value Is What You Get Over 40 Years of Reliable Investing Price Is What You Pay, Value Is What You Get Over 60 years investing in the equity markets has
Risk Management Strategy and Policy. The policy provides the framework for the management and control of risk within the GOC
Annex 1 TITLE VERSION Version 2 Risk Management Strategy and Policy SUMMARY The policy provides the framework for the management and control of risk within the GOC DATE CREATED January 2013 REVIEW DATE
Setting Up the Enterprise Risk Management Office
Setting Up the Enterprise Risk Management Office Rick Gorvett, FCAS, MAAA, FRM, ARM, Ph.D. 1 Vijendra Nambiar 2 Call Paper Program 2006 Enterprise Risk Management Symposium Chicago, IL Abstract In this
Article from: Risk Management. June 2009 Issue 16
Article from: Risk Management June 2009 Issue 16 CHAIRSPERSON S Risk quantification CORNER Structural Credit Risk Modeling: Merton and Beyond By Yu Wang The past two years have seen global financial markets
THE NEW INTERNATIONALS. Updating perceptions of SMEs in an increasingly globalised world
THE NEW INTERNATIONALS Updating perceptions of SMEs in an increasingly globalised world Contents Introduction 5 Born Global 6 International Futures 7 Supporting UK SMEs 8 UK Regions 9 Conclusion 10 About
Sample Strategic Plan The ABC Service Agency
Sample Strategic Plan The ABC Service Agency Table of Contents Introduction...2 Executive Summary...2 Background and History...2 Direction and Results...3 Goals...3 Organization of the Strategic Plan...4
Information Paper The Roles and Domain of the Professional Accountant in Business
Information Paper The Roles and Domain of the Professional Accountant in Business Published by the Professional Accountants in Business Committee Professional Accountants in Business Committee International
Investment manager research
Page 1 of 10 Investment manager research Due diligence and selection process Table of contents 2 Introduction 2 Disciplined search criteria 3 Comprehensive evaluation process 4 Firm and product 5 Investment
The changing role of the IT department in a cloud-based world. Vodafone Power to you
The changing role of the IT department in a cloud-based world Vodafone Power to you 02 Introduction With competitive pressures intensifying and the pace of innovation accelerating, recognising key trends,
Internal Control Integrated Framework. May 2013
Internal Control Integrated Framework May 2013 0 Table of Contents COSO & Project Overview Internal Control-Integrated Framework Illustrative Documents Illustrative Tools for Assessing Effectiveness of
Changing culture the experience of TU Delft Library
Abstract: Changing culture the experience of TU Delft Library Ellen van der Sar / Maria Heijne Delft University of Technology Library When seeking to introduce change into an organisation, it is usually
Solving Supply Chain Problems Proactively
Solving Supply Chain Problems Proactively By Chris Eckert President, Sologic, & Brian Hughes Vice President, Sologic A version of this article appeared in the February 2010 issue of Industrial Engineer
IMPLEMENTATION NOTE. Validating Risk Rating Systems at IRB Institutions
IMPLEMENTATION NOTE Subject: Category: Capital No: A-1 Date: January 2006 I. Introduction The term rating system comprises all of the methods, processes, controls, data collection and IT systems that support
Important Information about Real Estate Investment Trusts (REITs)
Robert W. Baird & Co. Incorporated Important Information about Real Estate Investment Trusts (REITs) Baird has prepared this document to help you understand the characteristics and risks associated with
Process-Centric Back Office Transformation
Industry Insights Banking Process-Centric Back Office Transformation Executive Summary By driving back-office efficiency, banks and other financial institutions seek to lower expenses and reduce business
Implementing Portfolio Management: Integrating Process, People and Tools
AAPG Annual Meeting March 10-13, 2002 Houston, Texas Implementing Portfolio Management: Integrating Process, People and Howell, John III, Portfolio Decisions, Inc., Houston, TX: Warren, Lillian H., Portfolio
Fraud Prevention and Detection for Credit and Debit Card Transactions
August 2009 Fraud Prevention and Detection for Credit and Debit Card Transactions Richard Collard Senior Business Lead and SME - Market Development ILOG, Software Sales, IBM Sales and Distribution Page
[project.headway] Integrating Project HEADWAY And CMMI
[project.headway] I N T E G R A T I O N S E R I E S Integrating Project HEADWAY And CMMI P R O J E C T H E A D W A Y W H I T E P A P E R Integrating Project HEADWAY And CMMI Introduction This white paper
ENTERPRISE RISK MANAGEMENT FRAMEWORK WHAT IS ERM? JOIN. ENGAGE. LEAD.
ENTERPRISE RISK MANAGEMENT FRAMEWORK WHAT IS ERM? JOIN. ENGAGE. LEAD. Enterprise Risk Credit Risk Market Risk Operational Risk Regulatory Compliance Securities Lending INCREASED FOCUS ON ERM Although the
2016 Charter School Application Evaluation Rubric. For applications submitted to The Louisiana Board of Elementary and Secondary Education
2016 Charter School Application Evaluation Rubric For applications submitted to The Louisiana Board of Elementary and Secondary Education 2016 Charter School Application Evaluation Rubric The purpose of
Real estate: The impact of rising interest rates
Fall 015 TIAA-CREF Asset Management Real estate: The impact of rising interest rates Overview TIAA-CREF Global Real Estate Strategy & Research Martha Peyton, Ph.D. Managing Director Edward F. Pierzak,
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis
DSIP List (Diversified Stock Income Plan)
Kent A. Newcomb, CFA, Equity Sector Analyst Joseph E. Buffa, Equity Sector Analyst DSIP List (Diversified Stock Income Plan) Commentary from ASG's Equity Sector Analysts January 2014 Concept Review The
Advancing Disaster Risk Reduction to Enhance Sustainable Development in a Changing World 20 June -1 July 2016, UN Campus, Bonn
CALL FOR APPLICATIONS Announcement UNITED NATIONS UNIVERSITY Institute for Environment and Human Security Intensive Summer Course 2016 Advancing Disaster Risk Reduction to Enhance Sustainable Development
Optimizing Rewards and Employee Engagement
Optimizing Rewards and Employee Engagement Improving employee motivation and engagement, and identifying the right total rewards strategy to influence workforce effectiveness. Kevin Aselstine, Towers Perrin
FINANCIAL ANALYSIS GUIDE
MAN 4720 POLICY ANALYSIS AND FORMULATION FINANCIAL ANALYSIS GUIDE Revised -August 22, 2010 FINANCIAL ANALYSIS USING STRATEGIC PROFIT MODEL RATIOS Introduction Your policy course integrates information
Business Continuity Management Systems. Protecting for tomorrow by building resilience today
Business Continuity Management Systems Protecting for tomorrow by building resilience today Vital statistics 31% 40% of UK businesses have been affected by bad weather related transport problems, power
Enterprise Risk Management: COSO, New COSO, ISO 31000. Review of ERM
Enterprise Risk Management: COSO, New COSO, Dr. Hugh Van Seaton, Ed. D., CSSGB, CGMA, CPA Review of ERM COSO a process, effected by an entity's board of directors, management and other personnel, applied
AD Management Survey: Reveals Security as Key Challenge
Contents How This Paper Is Organized... 1 Survey Respondent Demographics... 2 AD Management Survey: Reveals Security as Key Challenge White Paper August 2009 Survey Results and Observations... 3 Active
fmswhitepaper Why community-based financial institutions should practice enterprise risk management.
fmswhitepaper Why community-based financial institutions should practice enterprise risk management. By Michael D. Cohn, CPA, CISA, CGEIT Director, WolfPAC Solutions Group Unique Insights Implementation
