Compliance risk assessments The third ingredient in a world-class ethics and compliance program
|
|
|
- Alan Johnson
- 10 years ago
- Views:
Transcription
1 Compliance risk assessments The third ingredient in a world-class ethics and compliance program
2 You can t mitigate a risk if you don t know it s there As global regulations proliferate, and as stakeholder expectations increase, organizations are exposed to a greater degree of compliance risk than ever before. Compliance risk is the threat posed to an organization s financial, organizational, or reputational standing resulting from violations of laws, regulations, codes of conduct, or organizational standards of practice. To understand their risk exposure, many organizations may need to improve their risk assessment process to fully incorporate compliance risk exposure. The case for conducting robust compliance risk assessments is deeply rooted in the U.S. Federal Sentencing Guidelines for Organizations, which establishes the potential for credit or reduced fines and penalties should an organization be found guilty of a compliance failure. In today s environment of global regulatory convergence, ever-increasing complexity, and the expansion of businesses into new or adjacent industries, the need for a broader view of compliance risk has never been greater. Nevertheless, according to a survey conducted jointly by Deloitte and Compliance Week, 1 40 percent of companies do not perform an annual compliance risk assessment. Many ethics and compliance officers will likely agree that new ethics, compliance, and reputational risks appear each day. At the same time, the recent global recession forced many organizational functions to closely examine their budgets and resources. Together, these factors have created a tension between growing regulatory obligations and the pressure to do more with less. To help resolve this situation and continue to add value to their organizations, ethics and compliance professionals need to be sure they understand the full spectrum of compliance risks lurking in each part of the organization. They then need to assess which risks have the greatest potential for legal, financial, operational, or reputational damage and allocate limited resources to mitigate those risks. How is a compliance risk assessment different from other risk assessments? Organizations conduct assessments to identify different types of organizational risk. For example, they may conduct enterprise risk assessments to identify the strategic, operational, financial, and compliance risks to which the organization is exposed. In most cases, the enterprise risk assessment process is focused on the identification of bet the company risks those that could impact the organization s ability to achieve its strategic objectives. Most organizations also conduct internal audit risk assessments to aid in the development of the internal audit plan. A traditional internal audit risk assessment is likely to consider financial statement risks and other operational and compliance risks. While both of these kinds of risk assessments are typically intended to identify significant compliance-related risks, neither is designed to specifically identify legal or regulatory compliance risks (see illustrative table). Therefore, while compliance risk assessments should certainly be linked with the enterprise or internal audit risk processes, they generally require a more focused approach. That is not to say that they cannot be completed concurrently, or that they ought to be siloed efforts most organizations may be able to combine the activities that support various risk assessments, perhaps following an initial compliance risk identification and assessment process. 1 In focus: 2014 Compliance Trends Survey. us/en/pages/risk/articles/compliance-trends-survey-2014.html 2 As used in this document, Deloitte means, a subsidiary of Deloitte LLP. Please see for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.
3 The interrelationship among enterprise risk management (ERM), internal audit, and compliance risk assessments Objective Scope Typical owner ERM Internal audit Compliance Identify, prioritize, and assign accountability for managing strategic, operational, financial, and reputational risks Any risk significantly impacting the organization s ability to achieve its strategic objectives Chief Risk Officer/ Chief Financial Officer Determine and prioritize risks to aid in developing the internal audit plan, helping to provide the board and the executive team with assurances related to risk management efforts and other compliance activities Financial statement and internal control risks, as well as some operational and compliance risks that are likely to materially impact the performance of the enterprise or financial statements Chief Audit Executive Identify, prioritize, and assign accountability for managing existing or potential threats related to legal or policy noncompliance or ethical misconduct that could lead to fines or penalties, reputational damage, or the inability to operate in key markets Laws and regulations with which the organization is required to comply in all jurisdictions where it conducts business, as well as critical organizational policies whether or not those policies are based on legal requirements Chief Compliance Officer Understanding your top compliance risks The compliance risk assessment will help the organization understand the full range of its risk exposure, including the likelihood that a risk event may occur, the reasons it may occur, and the potential severity of its impact. An effectively designed compliance risk assessment also helps organizations prioritize risks, map these risks to the applicable risk owners, and effectively allocate resources to risk mitigation. Building a framework and methodology Because the array of potential compliance risks facing an organization is typically very complex, any robust assessment should employ both a framework and methodology. The framework lays out the organization s compliance risk landscape and organizes it into risk domains, while the methodology contemplates both objective and subjective ways to assess those risks. The framework needs to be comprehensive, dynamic, and customizable, allowing the organization to identify and assess the categories of compliance risk to which it may be exposed (see Figure 1). Some compliance risks are specific to an industry or organization for example, worker safety regulations for manufacturers or rules governing the behavior of sales representatives in the pharmaceutical industry. Other compliance risks transcend industries or geographies, such as conflicts of interest, harassment, privacy, and document retention. An effective framework may also outline and organize the elements of an effective risk mitigation strategy that can be applied to each compliance risk domain. Figure 1: Enterprise ethics and compliance program and risk exposure framework An illustrative example ( Deloitte Development LLC) Supply Chain Operations License & Permits Labor & Employment Financial Compliance Anti-Money Laundering Fraud and Corruption Anti-trust & Consumer Protection External/ Regulatory Reporting Environment, Health, and Safety Direct and Indirect Tax Compliance risk assessments The third ingredient in a world-class ethics and compliance program 3 Legal Trade/ Import/Export Third Party Compliance Testing and Monitoring Vendor Relationship Management Continuous Improvement Case Management and Investigations Culture of Ethics and Compliance Employee Reporting Governance and Leadership Risk Assessments and Due Diligence Standards, Policies, and Procedures Training and Communications Customer Relationship Management Cybersecurity & Privacy
4 Applying the methodology and conducting the risk assessment Using an objective methodology to evaluate the likelihood and potential impact of each risk will help the organization understand its inherent risk exposure. Inherent risk is the risk that exists in the absence of any controls or mitigation strategies. At the outset, gaining a preliminary understanding of inherent risk helps the organization develop an early view on its strategy for risk mitigation. And when organizations identify inherent risk they should consider key risk drivers that can be organized into the following four broad categories: Legal impact: Regulatory or legal action brought against the organization or its employees that could result in fines, penalties, imprisonment, product seizures, or debarment. Financial impact: Negative impacts with regard to the organization s bottom line, share price, potential future earnings, or loss of investor confidence. Business impact: Adverse events, such as embargos or plant shutdowns, that could significantly disrupt the organization s ability to operate. Reputational impact: Damage to the organization s reputation or brand for example, bad press or social media discussion, loss of customer trust, or decreased employee morale. It is important to provide both quantitative and qualitative measures for each category. However, as with all risk assessments, precise measurement may prove to be elusive. In the case of risks with direct financial impact, an actual monetary value may be measurable with respect to the risk. Another way to evaluate risk is using a criticality scale that indicates the extent of impact should noncompliance occur. Extent of impact can be described in qualitative terms. For example, for reputational impact, low impact might be minimal to no press coverage, while high impact might be extensive negative press in the national media (see Figure 2). Figure 2: An illustrative criticality scale ( Deloitte Development LLC) Rating Low High Reputational fallout/brand damage Sustained U.S. national (and international) negative media coverage (front page of business section) Negative U.S. national or international media coverage (not front page) Negative media coverage in a specific U.S. region or a foreign country Localized negative impact on reputation (such as a single large customer) but recoverable Civil or criminal fines or penalties Major federal or state action/ Fraud or bribery investigation Federal or state investigations Routine costly litigation Smaller actions, penalties/fines Loss of sales/customer confidence Significant loss or harm of customer relationship(s), including customer shut downs Failure of ability to meet customer needs, e.g., significant quality issues, customer delays, or inability to deliver products to customer Ineffective products delivered to customers or delay in customer delivery Less than optimal acceptance by customers No press exposure No regulatory or legal action Limited, if any, impact on customers 4
5 Determining residual risk Some key questions about your exposure While it is impossible to eliminate all of an organization s risk exposure, the risk framework and methodology help the organization prioritize which risks it wants to more actively manage. Developing a framework and methodology helps organizations determine the extent to which the organization s existing risk-mitigation activities (for example, testing and monitoring or employee training programs) are able to reduce risk. Effective risk mitigation activities may reduce the likelihood of the risk event occurring, as well as the potential severity of impact to the organization. When an organization evaluates inherent risk in light of its existing control environment and activities, the degree of risk that results is known as the residual risk. If existing risk mitigation strategies are insufficient at reducing residual risk to an acceptable level, this is an indication that additional measures are in order. There are a number of critical questions organizations should ask related to compliance risks and the program(s) in place to mitigate those risks: What kinds of compliance failures would create significant brand risk or reputational damage? Could the failures arise internally, in the supply chain, or with regard to third parties operating on the organization s behalf? What is the likely impact of that damage on the organization s market value, sales, profit, customer loyalty, or ability to operate? What kinds of compliance missteps could cause the organization to lose the ability to sell or deliver products/services for a period of time? How should the compliance program design, technology, processes, and resource requirements change in light of growth plans, acquisitions, or product/category/ service expansions? Is the organization doing enough to inform customers, investors, third parties, and other stakeholders about its vision and values? Is it making the most of ethics, compliance, and risk management investments as potential competitive differentiators? What are the total compliance costs beyond salaries and benefits at the centralized level and how are costs aligned with the most significant compliance risks that could impact the brand or result in significant fines, penalties, and/ or litigation? How well-positioned is the compliance function? Does it have a seat at the table in assessing and influencing strategic decisions? What makes a compliance risk assessment world class? While every compliance risk assessment is different, the most effective ones have a number of things in common. To build a world-class assessment, consider the following leading practices: Gather input from a cross-functional team: A compliance risk assessment requires the participation of deep subject matter specialists from the compliance department and across the enterprise. It is the people living and breathing the business those in specific functions, business units, and geographies who truly understand the risks to which the organization is exposed, and will help ensure all key risks are identified and assessed. In addition, if the methodology is designed in a vacuum without consulting the risk owners, the output of the process will lack credibility when it comes to implementing mitigation programs. Build on what has already been done: Rather than starting from scratch, look for ways to leverage existing material, such as enterprise risk assessments, internal audit reports, and quality reviews, and integrate compliance risk content where appropriate. Be sure to communicate the differences between the compliance risk assessments and other assessments to groups you seek to engage. Clearly, the output of each risk assessment process should inform and connect with each of the others. Establish clear risk ownership of specific risks and drive toward better transparency: A comprehensive compliance risk assessment will help identify those individuals responsible for managing each type of risk, and make it easier for executives to get a handle on risk mitigation activities, remediation efforts, and emerging risk exposures. Make the assessment actionable: The assessment both prioritizes risks and indicates how they should be mitigated or remediated. Remediation actions should be universally understood and viable across borders. Be sure the output of the risk assessment can be used in operational planning to allocate resources and that it can also serve as the starting point for testing and monitoring programs. What are the personal and professional exposures of executive management and the board of directors with respect to compliance? Compliance risk assessments The third ingredient in a world-class ethics and compliance program 5
6 Solicit external input when appropriate: By definition, a risk assessment relies on knowledge of emerging risks and regulatory behavior, which are not always well known within the organization. Tapping outside expertise can inform the assessment and ensure that it incorporates a detailed understanding of emerging compliance issues. Treat the assessment as a living, breathing document: Once you allocate resources to mitigate or remediate compliance risks, the potential severity of those risks will change. The same goes for events in the business environment. All of this should drive changes to the assessment itself. Use plain language that speaks to a general business audience: The assessment needs to be clear, easy to understand, and actionable. Avoid absolutes and complex legal analysis. Periodically repeat the risk assessment: Effective compliance risk assessments strive to ensure a consistent approach that continues to be implemented over time, e.g., every one or two years. At the same time, risk intelligence requires ongoing analysis and environment scanning to identify emerging risks or early warning signs. Many organizations are considering investments in technology, such as analytical and brand monitoring tools, to help leverage and analyze data to strengthen their risk-sensing capabilities. Additionally, organizations are considering investments in data, including traditional media/negative mention monitoring, social media data, surveying, and other data sources. Conclusion The constantly changing regulatory environment increases the vulnerability of most organizations to compliance risk. This is particularly true for those organizations that operate on a global scale. The complexity of the risk landscape and the penalties for non-compliance make it essential for organizations to conduct thorough assessments of their compliance risk exposure. A good ethics and compliance risk assessment includes both a comprehensive framework and a methodology for evaluating and prioritizing risk. With this information in hand, organizations will be able to develop effective mitigation strategies and reduce the likelihood of a major noncompliance event or ethics failure, setting themselves apart in the marketplace from their competitors. Leverage data: By incorporating and analyzing key data (e.g., hotline statistics, transactional records, audit findings, compliance exception reports, etc.), organizations can gain a deeper understanding of where existing or emerging risks may reside within the business. 6
7 Contacts Please contact one of our Enterprise Compliance Services leaders for more information. Nicole Sandford Partner Deloitte Advisory National Practice Leader, Enterprise Compliance Services Stamford, CT Brian Clark Partner Deloitte Advisory Kansas City, MO Kevin Lane Principal Deloitte Advisory Dallas, TX Keith Darcy Independent Senior Advisor to Stamford, CT Laurie Eissler Detroit, MI Thomas Nicolosi Principal Deloitte Advisory Philadelphia, PA Maureen Mohlenkamp Principal Deloitte Advisory Stamford, CT Nolan Haskovec Senior Manager Deloitte Advisory New York, NY Holly Tucker Partner Deloitte Advisory Deloitte Financial Advisory Services LLP Dallas, TX Additionally, feel free to reach out to our team of former compliance officers who are located across the country and experienced in a wide variety of industries. Martin Biegelman Deloitte Financial Advisory Services LLP [email protected] Phoenix, AZ Industry: Technology Rob Biskup Deloitte Financial Advisory Services LLP [email protected] Detroit, MI Timothy Cercelle [email protected] Cleveland, OH Industry: Consumer & Industrial ProductsIndustry: Insurance Michael Fay Principal Deloitte Advisory [email protected] Boston, MA Industry: Investment Management Peter Reynolds [email protected] Parsippany, NJ Industry: Investment Management Howard Friedman [email protected] Houston, TX Industry: Energy & Resources Thomas Rollauer Executive Director, Deloitte Center for Regulatory Strategies [email protected] New York, NY Industry: Financial Services/Banking & Securities George Hanley [email protected] Parsippany, NJ Industry: Insurance
8 This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this document. Copyright 2015 Deloitte Development LLC. All rights reserved. Member of Deloitte Touche Tohmatsu Limited
Corporate culture: The second ingredient in a world-class ethics and compliance program
Corporate culture: The second ingredient in a world-class ethics and compliance program A culture of ethics and compliance is at the core of a strong risk management program In a business environment where
Risk Considerations for Internal Audit
Risk Considerations for Internal Audit Cecile Galvez, Deloitte & Touche LLP Enterprise Risk Services Director Traci Mizoguchi, Deloitte & Touche LLP Enterprise Risk Services Senior Manager February 2013
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
Cybersecurity The role of Internal Audit
Cybersecurity The role of Internal Audit Cyber risk High on the agenda Audit committees and board members are seeing cybersecurity as a top risk, underscored by recent headlines and increased government
Fifth annual survey. Look before you leap Navigating risks in emerging markets
Fifth annual survey Look before you leap Navigating risks in emerging markets Table of contents 1 Executive summary 3 Significant concerns over compliance and integrity-related risks 4 Bribery leads the
Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks.
Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks. For anyone familiar with the banking industry, it comes as no surprise that banks are
Deloitte Forensic. Deloitte Forensic. Capability Statement
Deloitte Forensic Deloitte Forensic Capability Statement Deloitte named a Kennedy Vanguard Leader in Forensic Investigation Consulting, based on capabilities. Source: Kennedy Consulting Research & Advisory;
Framework for Enterprise Risk Management
Framework for Enterprise Risk Management 2013 Johnson & Johnson Contents Introduction.... 4 J&J Strategic Framework... 5 What is Risk?.......................................................... 7 J&J Approach
KNOW YOUR THIRD PARTY
Thomson Reuters KNOW YOUR THIRD PARTY EXECUTIVE SUMMARY The drive to improve profitability and streamline operations motivates many organizations to collaborate with other businesses, increase outsourcing
The Changing IT Risk Landscape Understanding and managing existing and emerging risks
The Changing IT Risk Landscape Understanding and managing existing and emerging risks IIA @ Noon Kareem Sadek Senior Manager, Deloitte Canada Chris Close Senior Manager, Deloitte Canada December 2, 2015
Building world-class ethics and compliance programs: Making a good program great Five ingredients for your program
Building world-class ethics and compliance programs: Making a good program great Five ingredients for your program Contents Introduction 1 How did we get here? 2 What are the ingredients? 3 Tone at the
Any business relationship between a bank and another entity, by contract or otherwise
An Overview for Bank Directors Managing the Third Party Relationship Patrick Neuman Boardman & Clark LLP Madison, Wisconsin Any business relationship between a bank and another entity, by contract or otherwise
Simplify the Complexity of Managing 3rd Party Anti-Bribery / FCPA Compliance
Simplify the Complexity of Managing 3rd Party Anti-Bribery / FCPA Compliance Arm Stakeholders with Critical Information to Assess 3rd Party Relationships and Comply with the Foreign Corrupt Practices Act
Fraud Risk Management
Fraud Risk Management Overview Discussion Questions 1) Does your organization follow a specific risk management model? If so, which one? Do you think this model adequately addresses the risks your organization
Aligning Compliance Program Priorities with Business Objectives
Aligning Compliance Program Priorities with Business Objectives By Jay G. Martin Vice President, Chief Compliance Officer and Senior Deputy General Counsel Baker Hughes Incorporated CAIL Institute for
Designing an Operational Risk Program for a Community Bank Stephan Salvador Managing Director, Risk Management Consulting
Consulting and Professional Services Designing an Operational Risk Program for a Community Bank Stephan Salvador Managing Director, Risk Management Consulting Designing an Operational Risk Program for
For Private circulation only www.deloitte.com/in. Creative. Clear. Focused. Forensic Services
For Private circulation only www.deloitte.com/in Creative. Clear. Focused. Forensic Services Do you conduct background checks on employees and vendors? Do you educate employees about the importance of
Anti-Money Laundering controls in Mergers & Acquisitions
White Paper Anti-Money Laundering controls in Mergers & Acquisitions June 2014 Anti-Money Laundering controls in Mergers & Acquisitions Authors: Ana L. Pereira and Ana Maria H. de Alba Caveat emptor let
Framing the future of corporate governance Deloitte Governance Framework
Framing the future of corporate governance Deloitte Governance Framework For those interested in the topic of corporate governance, these are dynamic times. The events of the past decade have led to the
Moving Forward with IT Governance and COBIT
Moving Forward with IT Governance and COBIT Los Angeles ISACA COBIT User Group Tuesday 27, March 2007 IT GRC Questions from the CIO Today s discussion focuses on the typical challenges facing the CIO around
FRANCHISORS AND FRANCHISEES: UNDERSTANDING COMPLIANCE RISKS
FRANCHISORS AND FRANCHISEES: UNDERSTANDING COMPLIANCE RISKS Franchisors and Franchisees: Understanding Compliance Risks What do KFC, Liberty Tax Service, Fatburger, and Orkin have in common? In addition
White Paper Achieving GLBA Compliance through Security Information Management. White Paper / GLBA
White Paper Achieving GLBA Compliance through Security Information Management White Paper / GLBA Contents Executive Summary... 1 Introduction: Brief Overview of GLBA... 1 The GLBA Challenge: Securing Financial
www.pwc.com Third Party Risk Management 12 April 2012
www.pwc.com Third Party Risk Management 12 April 2012 Agenda 1. Introductions 2. Drivers of Increased Focus on Third Parties 3. Governance 4. Third Party Risks and Scope 5. Third Party Risk Profiling 6.
Performing Effective Risk Assessments Dos and Don ts
Performing Effective Risk Assessments Dos and Don ts % Gary Braglia Security Specialist GreyCastle Security TCTC March 18, 2013 Introduction Who am I? Why Risk Management? Because you have to Because
The Role of the Board in Enterprise Risk Management
Enterprise Risk The Role of the Board in Enterprise Risk Management The board of directors plays an essential role in ensuring that an effective ERM program is in place. Governance, policy, and assurance
Cyber ROI. A practical approach to quantifying the financial benefits of cybersecurity
Cyber ROI A practical approach to quantifying the financial benefits of cybersecurity Cyber Investment Challenges In 2015, global cybersecurity spending is expected to reach an all-time high of $76.9
Compliance in motion A closer look at the Corporate Sector. Deloitte Risk Services March 2015
Compliance in motion A closer look at the Corporate Sector Deloitte Risk Services March 2015 2 Contents Preface 5 Management summary 6 The compliance culture 7 Compliance priorities for the next five years
Financial Services Regulatory Commission Antigua and Barbuda Division of Gaming Customer Due Diligence Guidelines for
Division of Gaming Customer Due Diligence Guidelines for Interactive Gaming & Interactive Wagering Companies November 2005 Customer Due Diligence for Interactive Gaming & Interactive Wagering Companies
IT Insights. Managing Third Party Technology Risk
IT Insights Managing Third Party Technology Risk According to a recent study by the Institute of Internal Auditors, more than 65 percent of organizations rely heavily on third parties, yet most allocate
Tying It All Together: Practical ERM Integration. Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation
Tying It All Together: Practical ERM Integration Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation November 16, 2007 1 Agenda Basis for ERM Integration ERM Objectives ERM Focus
Deloitte Analytics. Trusting big data: Perspective on data governance as a customer analytics investment
Deloitte Analytics Trusting big data: Perspective on data governance as a customer analytics investment Many companies are investing significant amounts in customer analytics to drive their business and
NCOE whitepaper Master Data Deployment and Management in a Global ERP Implementation
NCOE whitepaper Master Data Deployment and Management in a Global ERP Implementation Market Offering: Package(s): Oracle Authors: Rick Olson, Luke Tay Date: January 13, 2012 Contents Executive summary
Get More Out of Your Risk Assessment. Austin Chapter of the IIA
Get More Out of Your Risk Assessment Austin Chapter of the IIA Speakers Alyssa G. Martin, CPA Dallas Executive Partner, Advisory Services 25 years of public accounting experience, with a practice emphasis
February 2015. Audit committee performance evaluation
February 2015 Audit committee performance evaluation Audit committee performance evaluation The following questionnaire is based on emerging and leading practices to assist in the self-assessment of an
OFAC Compliance Overview and Recent Trends
OFAC Compliance Overview and Recent Trends Frederick E. Curry III Deloitte Transactions and Business Analytics LLP December 2015 Institute of International Bankers & Conference of State Bank Supervisors
Cyber Security Evolved
Cyber Security Evolved Aware Cyber threats are many, varied and always evolving Being aware is knowing what is going on so you can figure out what to do. The challenge is to know which cyber threats are
ASTRAZENECA GLOBAL POLICY SAFEGUARDING COMPANY ASSETS AND RESOURCES
ASTRAZENECA GLOBAL POLICY SAFEGUARDING COMPANY ASSETS AND RESOURCES THIS POLICY SETS OUT THE REQUIREMENTS FOR SAFEGUARDING COMPANY ASSETS AND RESOURCES TO PROTECT PATIENTS, STAFF, PRODUCTS, PROPERTY AND
Agile Master Data Management A Better Approach than Trial and Error
Agile Master Data Management A Better Approach than Trial and Error A whitepaper by First San Francisco Partners First San Francisco Partners Whitepaper Executive Summary Market leading corporations are
Key Cyber Risks at the ERP Level
Key Cyber Risks at the ERP Level Process & Industrial Products (P&IP) Sector December, 2014 Today s presenters Bhavin Barot, Sr. Manager Deloitte & Touche LLP Goran Ristovski, Manager Deloitte & Touche
Applying Risk Assessment to Your Audit Plan Break-out Session T3, Tuesday, October 26 2:00-2:50pm
Applying Risk Assessment to Your Audit Plan Break-out Session T3, Tuesday, October 26 2:00-2:50pm Mike Brown Senior Vice President, Corporate Audit State Street Corporation Rich Reynolds Partner PricewaterhouseCoopers
Take the right steps 9 principles for building the Risk Intelligent Enterprise
Take the right steps 9 principles for building the Risk Intelligent Enterprise Contents 9 principles for building a Risk Intelligent Enterprise 2 The Risk Intelligent Framework 4 1. Is risk a threat or
THIRD PARTY. T i m L i e t z R e g i o n a l P r a c t i c e L e a d e r R i s k A d v i s o r y S e r v i c e s
MANAGING THIRD PARTY RISK T i m L i e t z R e g i o n a l P r a c t i c e L e a d e r R i s k A d v i s o r y S e r v i c e s Experis -- a different kind of talent company. Experis Tuesday, January 08,
Conducting due diligence and managing cybersecurity in medical technology investments
Conducting due diligence and managing cybersecurity in medical technology investments 2015 McDermott Will & Emery LLP. McDermott operates its practice through separate legal entities in each of the countries
Deloitte Forensic Fraud Risk Management
Deloitte Forensic Fraud Risk Management Introduction Organizations cannot afford to be unconcerned about the risk of fraud. Directors and management have a fiduciary obligation and a corporate responsibility
THOMSON REUTERS ACCELUS
THOMSON REUTERS ACCELUS ACCELUS Screening Resolution Service Executive Summary Thomson Reuters Accelus offers Screening Resolution Service (SRS): an outsourced screening service for Corporates and Financial
Tapping the benefits of business analytics and optimization
IBM Sales and Distribution Chemicals and Petroleum White Paper Tapping the benefits of business analytics and optimization A rich source of intelligence for the chemicals and petroleum industries 2 Tapping
A Framework for Managing Crime and Fraud
A Framework for Managing Crime and Fraud ASIS European Security Conference & Exhibition Gothenburg, April 15, 2013 Torsten Wolf Group Head of Crime and Fraud Prevention Agenda Introduction Economic Crime
3 rd Party Vendor Risk Management
3 rd Party Vendor Risk Management Session 402 Tuesday, June 9, 2015 (11 to 12pm) Session Objectives The need for enhanced reporting on vendor risk management Current outsourcing environment Key risks faced
State of Compliance 2014 Healthcare provider industry brief
Delve into the full analysis of the 2014 State of Compliance Survey at: pwc.com/us/ stateofcompliance State of Compliance 2014 Healthcare provider industry brief Introduction The healthcare provider industry
SEC WHISTLEBLOWER RULES UNDER DODD- FRANK. Presented by: Michael A. Saslaw September 12, 2013 Matthew J. Jacobs David R. Woodcock Barefoot Bankhead
SEC WHISTLEBLOWER RULES UNDER DODD- FRANK Presented by: Michael A. Saslaw September 12, 2013 Matthew J. Jacobs David R. Woodcock Barefoot Bankhead DODD-FRANK OVERVIEW Response to financial crisis of late-2000s.
APEC General Elements of Effective Voluntary Corporate Compliance Programs
2014/CSOM/041 Agenda Item: 3 APEC General Elements of Effective Voluntary Corporate Compliance Programs Purpose: Consideration Submitted by: United States Concluding Senior Officials Meeting Beijing, China
University of Windsor Board of Governors. That the Board of Governors approve of the Enterprise Risk Management Framework.
University of Windsor Board of Governors BG130430-4.2.3 4.2.3 Enterprise Risk Management Framework Item for: Approval Forwarded by: Audit Committee MOTION: That the Board of Governors approve of the Enterprise
GUIDANCE FOR MANAGING THIRD-PARTY RISK
GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT Let me begin by thanking Baruch College for giving me the opportunity to present this year s prestigious Emanuel Saxe Lecture in Accounting.
THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS
THE NEW REALITY OF RISK CYBER RISK: TRENDS AND SOLUTIONS Read the Marsh Risk Management Research Briefing: Cyber Risks Extend Beyond Data and Privacy Exposures To access the report, visit www.marsh.com.
The Rising Tide of Pharmacy Benefit Cost and Complexity: A health plans roadmap to optimizing pharmacy services relationships
The Rising Tide of Pharmacy Benefit Cost and Complexity: A health plans roadmap to optimizing pharmacy services relationships New pharmacy benefit challenges After several years of manageable pharmacy
Platform Specialty Products Corporation Foreign Corrupt Practices Act/Anti-Corruption Policy
1. Introduction. Platform Specialty Products Corporation Foreign Corrupt Practices Act/Anti-Corruption Policy 1.1 Combating Corruption. Platform Specialty Products Corporation, including its subsidiaries,
BUSINESS PRINCIPLES FOR COUNTERING BRIBERY A MULTI-STAKEHOLDER INITIATIVE LED BY TRANSPARENCY INTERNATIONAL
BUSINESS PRINCIPLES FOR COUNTERING BRIBERY A MULTI-STAKEHOLDER INITIATIVE LED BY TRANSPARENCY INTERNATIONAL Transparency International is the global civil society organisation leading the fight against
Managing Risk Beyond a Plan's Direct Control: Improving Oversight of a Health Plan's First Tier, Downstream, and Related (FDR) Entities
Health Care March 2015 Managing Risk Beyond a Plan's Direct Control: Improving Oversight of a Health Plan's First Tier, Downstream, and Related (FDR) Entities Our Perspective Oversight of First Tier, Downstream,
CFO Insights: Gaining fi nancial visibility into your project portfolio
CFO Insights: Gaining fi nancial visibility into your project portfolio From simple research analyzing competitor data to complex ERP implementations, most work in modern corporations is done in projects.
RSA ARCHER OPERATIONAL RISK MANAGEMENT
RSA ARCHER OPERATIONAL RISK MANAGEMENT 87% of organizations surveyed have seen the volume and complexity of risks increase over the past five years. Another 20% of these organizations have seen the volume
Unlock your digital marketing potential
Unlock your digital marketing potential 1 Our digital marketing alliance. 2 Deloitte & Adobe: better together Our roots run deep. We have a proven history of collaborating for client advantage. Our decade-long
Culture of Purpose Building business confidence; driving growth 2014 core beliefs & culture survey
Culture of Purpose Building business confidence; driving growth 2014 core beliefs & culture survey Executive summary Our research indicates that focusing on purpose rather than profits builds business
Retail. White Paper. Driving Strategic Sourcing Effectively with Supply Market Intelligence
Retail White Paper Driving Strategic Sourcing Effectively with Supply Market Intelligence About the Author Devaraj Chithur Devaraj is part of the Supply Chain group within Tata Consultancy Services (TCS)
RSA Archer Risk Intelligence
RSA Archer Risk Intelligence Harnessing Risk to Exploit Opportunity June 4, 2014 Steve Schlarman GRC Strategist 1 Risk and Compliance Where is it today? 2 Governance, Risk, & Compliance Today 3 4 A New
Best Practices in Incident Response. SF ISACA April 1 st 2009. Kieran Norton, Senior Manager Deloitte & Touch LLP
Best Practices in Incident Response SF ISACA April 1 st 2009 Kieran Norton, Senior Manager Deloitte & Touch LLP Current Landscape What Large scale breaches and losses involving credit card data and PII
Pulling it all together: Integrated Solutions for Governance, Risk and Compliance
Customer Practice Profile Pulling it all together: Integrated Solutions for Governance, Risk and Compliance The business case for a new enterprise approach to GRC Integrated solutions for Governance, Risk
Consumer Goods and Services
Accenture Risk Management Industry Report Consumer Goods and Services 2011 Global Risk Management Point of View Consumer Goods and Services 2011 Global Risk Management Point of View Consumer Goods and
Customer effectiveness
www.pwc.com/sap Customer effectiveness PwC SAP Consulting Services Advance your ability to win, keep and deepen relationships with your customers. Are your customers satisfied? How do you know? Five leading
AML Topics Using analytics to get the most from your transaction monitoring system
www.pwc.com AML Topics Using analytics to get the most from your transaction monitoring system March 2011 Contents Components of the AML Compliance Program... 1 Transaction Monitoring... 1 Transaction
Mitigating and managing cyber risk: ten issues to consider
Mitigating and managing cyber risk: ten issues to consider The board of directors is responsible for managing and mitigating risk exposure. A recent study conducted by the Ponemon Institute 1 revealed
U.S. CORPORATE ETHICS AND COMPLIANCE POLICY
U.S. CORPORATE ETHICS AND COMPLIANCE POLICY Table of Contents Page 1. Letter from the President & CEO 3 2. Introduction 4 3. How to Handle and Report Ethical and/or Compliance Issues 5 3.1 Violations of
Minerals Technologies Inc. Summary of Policies on Business Conduct
Minerals Technologies Inc. Summary of Policies on Business Conduct Lawful and Ethical Behavior is Required at All Times This Summary of Policies on Business Conduct (this "Summary") provides an overview
PRIORITIZING CYBERSECURITY
April 2016 PRIORITIZING CYBERSECURITY Five Investor Questions for Portfolio Company Boards Foreword As the frequency and severity of cyber attacks against global businesses continue to escalate, both companies
Human Rights and Responsible Business Practices. Frequently Asked Questions
Human Rights and Responsible Business Practices Frequently Asked Questions Introduction The need for companies to understand and address human rights as a responsible business practice is growing. For
Broker-Dealer and Investment Adviser Compliance Programs
Lori A. Richards Principal, PricewaterhouseCoopers Financial Services Regulatory Practice Broker-Dealer and Investment Adviser Compliance Programs Regulatory Requirements, Common Minimum Elements, Other
Accenture Risk Management. Industry Report. Life Sciences
Accenture Risk Management Industry Report Life Sciences Risk management as a source of competitive advantage and high performance in the life sciences industry Risk management that enables long-term competitive
Administrative Policy and Procedure Manual. Code of Conduct Effective Date: 1/2005 Scope: Organizationwide Page 1 of 9
Scope: Organizationwide Page 1 of 9 I. Purpose The purpose of this policy is to provide direction to staff members to assist in carrying out daily activities within appropriate ethical and legal standards.
Internal audit FROM COMPLIANCE TO RISK MANAGEMENT: THE CHANGING ROLE OF INTERNAL AUDIT
Internal audit FROM COMPLIANCE TO RISK MANAGEMENT: THE CHANGING ROLE OF INTERNAL AUDIT 20 February 2015 A PLUS Rapid regulatory change and technology-fuelled trends have shifted internal auditors focus
OMNI TECHNICAL SOLUTIONS. Business Ethics, Compliance, Anti-Corruption and Anti-Money Laundering Policy
OMNI TECHNICAL SOLUTIONS Business Ethics, Compliance, Anti-Corruption and Anti-Money Laundering Policy Updated: September 2015 Table of Contents 1. Introduction... 2 2. Business Ethics... 3 2.1 Compliance...
IDENTIFYING VENDOR RISK THE CRITICAL FIRST STEP IN CREATING AN EFFECTIVE VENDOR RISK MANAGEMENT PROGRAM
IDENTIFYING VENDOR RISK THE CRITICAL FIRST STEP IN CREATING AN EFFECTIVE VENDOR RISK MANAGEMENT PROGRAM HEADQUARTERS 33 Bradford Street Concord, MA 01742 PHONE: 978-451-7655 THE CRITICAL FIRST STEP IN
COMPETITION TRIGGERS BATTLE FOR TALENT AND ACQUISITIONS
2015 www.bdo.com For more information on BDO USA s service offerings to this industry vertical, please contact one of the regional service leaders below: TIM CLACKETT Los Angeles 310-557-8201 / [email protected]
Pharmaceutical Sales Certificate
Pharmaceutical Sales Certificate Target Audience Medical representatives Objective The objective of this program is to provide the necessary skills and knowledge needed to succeed as medical representatives.
FinCEN Issues Notice of Proposed Rulemaking that Would Extend AML Requirements to Registered Investment Advisers
FinCEN Issues Notice of Proposed Rulemaking that Would Extend AML Requirements to Registered Investment Advisers On August 25, 2015, the Financial Crimes Enforcement Network (FinCEN), a bureau of the US
Leveraging data analytics and continuous auditing processes for improved audit planning, effectiveness, and efficiency. kpmg.com
Leveraging data analytics and continuous auditing processes for improved audit planning, effectiveness, and efficiency kpmg.com Leveraging data analytics and continuous auditing processes 1 Executive
White Paper Achieving HIPAA Compliance through Security Information Management. White Paper / HIPAA
White Paper Achieving HIPAA Compliance through Security Information Management White Paper / HIPAA Contents Executive Summary... 1 Introduction: Brief Overview of HIPAA... 1 The HIPAA Challenge: Protecting
It s a Regulatory Requirement But does it help and what does this really mean?
AML Compliance: Risk Based Approach It s a Regulatory Requirement But does it help and what does this really mean? Presented by: Jennifer Fiddian-Green Patrick Ho Grant Thornton LLP April 30, 2012 AML
WE GET SMALL-CAP COMPANIES IT S WHAT WE VE BEEN DOING FOR 15 YEARS
INVESTOR RELATIONS WE GET SMALL-CAP COMPANIES IT S WHAT WE VE BEEN DOING FOR 15 YEARS Lytham Partners provides expertise and guidance to small cap companies in the healthcare, technology, service, industrial,
Threat and Vulnerability Management (TVM) Protecting IT assets through a comprehensive program. Chicago IIA/ISACA
www.pwc.com Vulnerability Management (TVM) Protecting IT assets through a comprehensive program Chicago IIA/ISACA 2 nd Annual Hacking Conference Introductions Paul Hinds Managing Director Cybersecurity
The SEC's New Whistleblower Program: What It Means for Companies and How to Respond. July 22, 2011
The SEC's New Whistleblower Program: What It Means for Companies and How to Respond July 22, 2011 Agenda Introduction Presentation Questions and Answers (anonymous) Slides now available on front page of
