Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures
|
|
|
- Corey White
- 10 years ago
- Views:
Transcription
1 ISSN (online) ISSN X (print) Research Executive Summaries Series Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures Vol. 2, No. 11 By Paul M Collier Anthony J Berry Gary T Burke Aston Business School
2 Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures 2 A book based on this report will be available to purchase from Introduction This executive summary presents the findings from two research projects on risk management which were funded by grants provided by CIMA. The first grant was for a pilot study comprising four mini-case studies. Our major focus in that study was on how risk impacted upon budgeting. The second grant was for a comprehensive survey and analysis of risk management in organisations and in particular how risk management impacted on both internal controls and on the role of the management accountant. Following the statistical analysis of the survey, interviews were conducted with survey respondents and risk management professionals in order to help us explain our findings. This summary therefore provides the results of these three phases of our research. A review of the practitioner and academic literature as it affects governance, risk management and management accounting. The four exploratory case studies. A comprehensive description of the survey design and results. Excerpts from the interview data in relation to the survey results. A summary of the research findings Implications for best practice. Risk and risk management Risk has traditionally been defined in terms of the possibility of danger, loss, injury or other adverse consequences. In accounting and finance risk is considered in terms of decision trees, probability distributions, cost-volume-profit analysis, discounted cash flow, capital assets pricing models and hedging techniques, etc. Risk management is the process by which organisations methodically address the risks attaching to their activities in pursuit of organisational objectives and across the portfolio of all their activities. Effective risk management involves: risk assessment; risk evaluation; risk treatment; and risk reporting. The focus of good risk management is the identification and treatment of those risks in accordance with the organisation s risk appetite. The enterprise risk management approach is intended to align risk management with business strategy and embed a risk management culture into business operations. A well known and respected risk management approach has been developed by COSO. The COSO (2004) model of internal control comprises eight components: 1. The internal environment sets the basis for how risk is viewed and the organisational appetite for risk. 2. Organisational objectives must be consistent with risk appetite. 3. Events affecting achievement of objectives must be identified, distinguishing between risks and opportunities. 4. Risk assessment involves the analysis of risks into their likelihood and impact in order to determine how they should be managed. 5. Management then selects risk responses in terms of how risks may be mitigated, transferred or held. 6. Control activities in the form of policies and procedures ensure that risk responses are carried out effectively.
3 3 Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures 7. Information needs to be captured and communicated as the basis for risk management. 8. The enterprise risk management system should be regularly monitored and evaluated. (Source: Committee of Sponsoring Organizations of the Treadway Commission (COSO: 2004) Enterprise Risk Management Integrated Framework.) Case study findings: process and content of budgeting The purpose of the exploratory case studies was to understand the relationship between risk and budgeting.this involved consideration of how risk was enacted in budgeting and how managerial perceptions of risk influenced the process and content of budgets.the findings from the four case studies (Collier & Berry, 2002) reveal differences based on the contexts of unique circumstances, histories and technologies of the organizations.the four cases illustrated how the different social constructions of participants in the budgeting process influenced the domains or alternative lenses through which the process of budgeting took place and how the content of the budget was determined.the purpose and use of budgets was constructed in social settings such that different functional groups (accountants, sales, operations, etc.) saw budgets in different ways (e.g. as a rational planning device, as a political tool to dominate others, or as a method of enforced cost reduction, etc.). Four domains of risk were observed, reflecting the different social constructions of participants, financial, operational, political and personal.the process of budgeting in all four cases was characterised as risk considered, in which a topdown budgeting process reflected negotiated targets. By contrast, the content of budget documents was risk excluded, being based on a set of single point estimates, in which all of the significant risks were excluded from the budget itself.the separation of budgeting and risk management has significant consequences for the management of risk as the process of budgeting needs to be considered separately from the content of budget documents. Objective and subjective risk Despite the traditional accounting and finance emphasis, many risks are not objectively identifiable and measurable but are subjective and qualitative. For example, the risks of litigation, economic downturns, loss of key employees, natural disasters, and loss of reputation are all subjective judgments. Risk is therefore to a considerable extent socially constructed and responses to risk reflect that social construction. There is an important distinction between objective, measurable risk and subjective, perceived risk. Risk can be thought about by reference to: the existence of internal or external events; information about those events (i.e. their visibility); managerial perception about events and information (i.e. how they are perceived); and how organisations establish tacit/informal or explicit/formal ways of dealing with risk. Adams (1995) has shown that everyone has a propensity to take risks (from being risk averse to risk seeking), but the propensity to take risks varies from person to person, being influenced by the potential rewards of risk taking and perceptions of risk which are influenced by experience of accidents. Hence individual risk taking represents a balance between perceptions of risk and the propensity to take risks. Prior research shows that we know little about how managers consider risks but managers do take risks, based on risk preferences at individual and organisational levels. Some of these risk preferences vary with national cultures while others are individual traits. Individual traits may emphasise risk averse or risk seeking behaviour while some national cultures may also emphasise one or other of these traits. Risk perception is a cultural process, with each culture, each set of shared values and supporting social institutions being biased toward highlighting certain risks and downplaying others.we found that this socially constructed view of risk was a better reflection of organisational risk management than rational modelling approaches typified by text books and professional training as it reflected the subjectivity of risk perceptions and preferences, cultural constraints and individual traits.the four ideal types developed by Adams (1995) and adapted in the full report as risk stance: risk sceptical (or fatalists), hierarchists, individualists, and risk aware (or egalitarians), was helpful in our research in understanding individual and organisational risk management practices.the risk sceptical are resigned to their fate and see no point in trying to change it, so managing risks is irrelevant. Hierarchists are always evident in large organisations with strong structures, procedures and systems and are most comfortable with a bureaucratic risk management style using various risk management techniques. Individualists are enterprising, selfmade people, relatively free from control by others, to whom risk management is typically intuitive rather than systematic. Risk aware are most comfortable in situations of risk sharing through insurance, hedging or transfer to other organisations. Our survey found that the propensity of managers to take risk and the risk stance (the attitude to risk management in terms of the four ideal types) did influence the risk management practices in use.
4 Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures 4 Risk management survey Following the case studies, it was decided to undertake a survey of organisations in the UK to examine risk management practices and the role of management accountants in risk management.the relationships we conjectured during our research design were: Perceived environmental uncertainty Risk stance Subsequently, we conducted a survey of CIMA members, finance directors of FTSE listed companies and chief executives of SMEs and analysed 333 usable responses, a response rate of 11%.We subsequently interviewed a number of respondents to aid our interpretation of the survey analysis. Risk management practices External regulation Risk management practices Risks factored into planning Supporting procedures Improved performance We found that risk management systems appeared to improve the organisational capacity to process information, both through vertical information systems but also through the role of risk managers.their role was a cross-functional one, supporting the distinction made between event-uncertainty, commonly viewed as risk, and information-uncertainty (Galbraith,1977: p.4). The survey found that the methods for risk management that were in highest use were the more subjective ones (particularly experience), with quantitative methods used least of all.these results suggested a heuristic method of risk management is at work in contrast to the systems-based approach that is associated with risk management in much professional training and in the professional literature.the survey responses implied that traditional methods of managing risk through transfer (insurance, hedging, etc.) were still seen as more effective than more proactive risk management processes. Risk was seen on an individual level as much about achieving positive consequences as avoiding negative ones. However, organisational risk management was reported to be more about avoiding negative consequences. In terms of methods of risk management, our interviewees advised us that keeping things simple was best, although more sophisticated techniques were more likely to be used at lower organisational levels.this was largely because business was so complex and supposedly objective methods may not be as reliable as they are sometimes perceived to be. The trends in risk management were reported to have shifted from being considered tacitly to being considered more formally and the survey results reflected the respondents expectation that this trend will shift markedly to a more holistic approach with risk management being used to aid decision making. Interviewees provided examples of the beginning of a shift to a more proactive stance towards risk management where this was seen to deliver business benefits. There was a strong emphasis from our interviewees that this shift was likely to increase with a move away from the tick box approach. It was accepted by our interviewees that there was a need to culturally embed risk into organisations as a taken-for-granted practice. Costs and benefits of risk management Risk management may be seen largely as a compliance exercise. However, half of the respondents reported that the benefits exceeded the costs, with forty percent reporting that benefits and costs were neutral. Although this was a subjective judgement, the Vice President of a European federation of risk management associations summed up the benefits as: An organisation that doesn t issue profit warnings, doesn t have major unjustified exceptional costs on its annual accounts because they thought about things in advance.they have managed acquisitions and mergers proactively to ensure that they have met their targets and objectives and haven t impaired the goodwill or asset values.these are some of the things you might see. A profitable and successful company, excellent reputation, corporate social responsibility you wouldn t see them being fingered as people who are exploiting the third world, child labour, etc. all those things sort of come out of it.they have got their supply chain issues sorted out. I guess out in the City analysts are comfortable with what they are hearing and probably their estimates are pretty close to what the organisation achieves. Good credit rating, because they can see that they are good value and their ratios are all good.
5 5 Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures Governance and the drivers of risk management The Combined Code on Corporate Governance (Financial Reporting Council, 2003) is an important motivator for risk management and internal control practices, requiring Boards to maintain a sound system of internal control to safeguard shareholders investment and the company s assets. Internal control is the whole system of internal controls, financial and otherwise, established in order to provide reasonable assurance of effective and efficient operation; internal financial control and compliance with laws and regulations. However as profits are, in part, the reward for successful risktaking in business then the purpose of internal control is to help manage and control risk appropriately rather than to eliminate it. Given the significant public visibility of corporate governance requirements, our survey findings suggested that risk management may be seen largely as a compliance exercise. Management action to decrease the likelihood of risk was given the highest ranking by respondents, rather than action to achieve organisational objectives. Risk still appears to be dominated by downside concerns and risk transfer through hedging and insurance remains dominant over proactive risk management practices. Contrary to expectations that risk management practices vary between organisations as a result of their size or industry sector, there was little evidence of any contingent explanations for risk management based on either size or business sector. Similarly, if somewhat surprisingly, respondents perceptions of the environmental uncertainty and risk facing their organisations did not appear to influence basic risk management practices in those organizations. The survey results suggested that risk management was driven by an institutional response to calls for improved corporate governance which may reflect both protection and economic opportunity.the external drivers of risk management practices were observed to be external stakeholders and the demands of regulators and legislation, enacted through boards of directors which were likely to exert influence over the policies and methods adopted for risk management. Financial market risk In relation to financial market risk, the implication of our regression analysis is that the risk aware stance, in attending to both protection and to opportunity, does create organisations to which the capital markets award a lower beta, and hence a higher value. This led us to infer that the requirements of corporate governance do not necessarily have to work in opposition to economic rationales of risk as opportunity and adventure. However, given the small samples this observation is indicative only and would need to be replicated on a larger scale. Risk and management accountants Management accountants, whose professional training included the analysis of information and systems, performance and strategic management, can have a significant role to play in developing and implementing risk management and internal control systems within their organisations (Chartered Institute of Management Accountants, 2002). The research results have some significant implications for the role of accountants.the responses reveal that line managers were mostly concerned with identifying risk, analysing and reporting on risk. Finance directors had a major role in analysing and assessing, and reporting and monitoring risk. Deciding on risk management action was predominantly the concern of the chief executive and the board.the finance director was identified with more aspects of risk management than any other role, suggesting that they probably have a pivotal role in risk management. The changing role of management accountants is an important factor in establishing the context for their role in risk management and wider views of management control. Perhaps reinforcing traditional stereotypes, CIMA respondents were more risk-concerned than the other respondent groups in relation to their organisations, despite having a lower perception of the competitive intensity and uncertainty in their industry/sector. The reliance on formal accounting-based controls was also called into question. Importantly, CIMA respondents were less confident in the formal control systems that existed in their organisations, suggesting that the professional knowledge of accountants accommodates an understanding of the limits of accounting information, a knowledge not shared by nonaccountants. Further, management accountants in the overwhelming majority of organisations were being marginalised in relation to risk management.while CIMA respondents consider that management accountants should have more involvement in risk management, this was not a view shared by other respondents.
6 Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures 6 Interviewees saw the skill set of management accountants as not being appropriate to a wider involvement in risk management, although their analytic and modelling skills were essential in a supporting role.the distinction between taskoriented management accountants and strategic finance directors was reinforced in our interviews. Framework for risk management Our survey results, amplified by our interview data, enabled us to put forward a framework for risk management.this Framework reflects the primary research findings, in particular that: There are many external drivers to risk management, not only regulatory but that these are enacted by or through the board of directors. Other than organisation size, there appears to be no correlation between environmental uncertainty or competitive factors and risk management practices. Risk propensity was not as important as risk stance. Risk management practices exist along a continuum of heuristic to systematic but at corporate level the heuristic methods dominate. Risk management practices are believed by respondents to move along a life cycle from heuristic to systems dependent to culturally embedded. The involvement of accountants in risk management was marginal. Risk management was perceived to improve organisational performance and there is indication that a risk aware stance could be related to a lower capital market risk profile. Emphasising the importance of culturally-embedding risk awareness in organisations. Training users of financial information in the limitations of that information. There are further best practice implications for CIMA and its members: The role of management accountants needs to shift towards a more strategic and value adding role, which by definition includes a consideration of risk, if management accountants are not to be marginalised in risk management processes. CIMA members may have to reach Finance Director positions before they can contribute more significantly to risk management, but clearly they should be educated to be able to fulfil that function. The framework, in conjunction with that developed by Solomon et al (2000) presents a useful model for understanding how risk management practices are introduced and develop over time. Best practice implications Based on our research, our report highlights some fundamental best practice implications for risk management: Taking a broader opportunistic approach to risk management, based on a risk/return trade-off, rather than a purely defensive or protective stance. Using appropriate and effective tools, but these tools should be supplemented by experience, intuition and judgement. A deliberately proactive stance towards risk management, rather than an excessive reliance on traditional techniques, except to the extent that these techniques remain useful.
7 7 Risk and management accounting: best practice guidelines for enterprise-wide internal control procedures References Adams J. (1995). Risk. London: UCL Press Chartered Institute of Management Accountants. (2002). Risk Management:A Guide to Good Practice, London: CIMA Publishing Collier PM, Berry AJ. (2002). Risk in the process of budgeting. Management Accounting Research 13: Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2004). Enterprise Risk Management - Integrated Framework Financial Reporting Council. (2003). The Combined Code on Corporate Governance Galbraith J. (1977). Designing Complex Organizations. Reading, Mass.: Addison-Wesley Publishing Company Solomon, J.F, A. Solomon, et al. (2000). A Conceptual Framework for Corporate Risk Disclosure Emerging from the Agenda for Corporate Governance Reform, British Accounting Review Copyright CIMA 2006 First published in 2006 by: The Chartered Institute of Management Accountants 26 Chapter Street London SW1P 4NP Printed in Great Britain The publishers of this document consider that it is a worthwhile contribution to discussion, without necessarily sharing the views expressed which are those of the authors. No responsibility for loss occasioned to any person acting or refraining from action as a result of any material in this publication can be accepted by the author or publishers. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any means, method or device, electronic (whether now or hereafter known or developed), mechanical, photocopying, recorded or otherwise, without the prior permission of the publishers. Translation requests should be submitted to CIMA.
8 CIMA (The Chartered Institute of Management Accountants) represents members and supports the wider financial management and business community. Its key activities relate to business strategy, information strategy and financial strategy. Its focus is to qualify students, to support both members and employers and to protect the public interest. May 2006 The Chartered Institute of Management Accountants 26 Chapter Street London SW1P 4NP T +44 (0) F +44 (0) E [email protected] REF: TE036V0506
Management accounting practices in the UK food and drinks industry
ISSN 1744-7038 (online) ISSN 1744-702X (print) Research Executive Summaries Series Management accounting practices in the UK food and drinks industry Vol. 2, No. 8 By Magdy Abdel-Kader University of Essex
Enterprise Risk Management
Enterprise Risk Management Topic Gateway Series No. 49 1 Prepared by Jasmin Harvey and Technical Information Service July 2008 About Topic Gateways Topic Gateways are intended as a refresher or introduction
Accounting for ethical, social, environmental and economic issues: towards an integrated approach
Accounting for ethical, social, environmental and economic issues: towards an integrated approach Research Executive Summaries Series Vol. 2, No. 12 By Professor Carol A Adams La Trobe University and Dr
Barriers and Catalysts to Sound Financial Management Systems in Small Sized Enterprises
ISSN 1744-7038 (online) ISSN 1744-702X (print) Research Executive Summaries Series Barriers and Catalysts to Sound Financial Management Systems in Small Sized Enterprises Vol. 1, No. 3 By Stuart McChlery,
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date
Topic Gateway Series. Operational risk. Operational Risk. Topic Gateway series No. 51
Operational Risk Topic Gateway series No. 51 1 Prepared by Helen Matthews and Technical Information Service September 2008 About Topic Gateways Topic Gateways are intended as a refresher or introduction
How to gather and evaluate information
09 May 2016 How to gather and evaluate information Chartered Institute of Internal Auditors Information is central to the role of an internal auditor. Gathering and evaluating information is the basic
ENTERPRISE RISK MANAGEMENT POLICY
ENTERPRISE RISK MANAGEMENT POLICY TITLE OF POLICY POLICY OWNER POLICY CHAMPION DOCUMENT HISTORY: Policy Title Status Enterprise Risk Management Policy (current, revised, no change, redundant) Approving
CIMA'S Official Learning System
cima CIMA'S Official Learning System Strategic Level Paul M. Collier Sam Agyei-Ampomah ELSEVIER AMSTERDAM BOSTON HEIDELBERG LONDON NEW YORK OXFORD PARIS SAN DIEGO SAN FRANCISCO SINGAPORE SYDNEY TOKYO Contents
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT
THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT Let me begin by thanking Baruch College for giving me the opportunity to present this year s prestigious Emanuel Saxe Lecture in Accounting.
Principles for An. Effective Risk Appetite Framework
Principles for An Effective Risk Appetite Framework 18 November 2013 Table of Contents Page I. Introduction... 1 II. Key definitions... 2 III. Principles... 3 1. Risk appetite framework... 3 1.1 An effective
Enterprise-Wide Risk Assessment
Enterprise-Wide Risk Assessment Agenda 1. Definition of risk. 2. Risk drivers in higher education today. 3. Implementing an enterprise-wide risk management (ERM) program to effectively assess, manage,
UNITED NATIONS OFFICE FOR PROJECT SERVICES. ORGANIZATIONAL DIRECTIVE No. 33. UNOPS Strategic Risk Management Planning Framework
UNOPS UNITED NATIONS OFFICE FOR PROJECT SERVICES Headquarters, Copenhagen O.D. No. 33 16 April 2010 ORGANIZATIONAL DIRECTIVE No. 33 UNOPS Strategic Risk Management Planning Framework 1. Introduction 1.1.
Integrated Risk Management:
Integrated Risk Management: A Framework for Fraser Health For further information contact: Integrated Risk Management Fraser Health Corporate Office 300, 10334 152A Street Surrey, BC V3R 8T4 Phone: (604)
Applying Integrated Risk Management Scenarios for Improving Enterprise Governance
Applying Integrated Risk Management Scenarios for Improving Enterprise Governance János Ivanyos Trusted Business Partners Ltd, Budapest, Hungary, [email protected] Abstract: The term of scenario is used
INTERNATIONAL COUNCIL OF NURSES
INTERNATIONAL COUNCIL OF NURSES 3, place Jean-Marteau CH-1201 Geneva (Switzerland) Tel. (+41 22) 908 01 00 Fax (+41 22) 908 01 01 E-mail: [email protected] Web site: www.icn.ch Guidelines on shaping effective
The use and consequences of performance management and control systems: a study of a professional services firm
Wendy Beekes Lancaster University David Otley Lancaster University Valentine Ururuka Lancaster University The use and consequences of performance management and control systems: a study of a professional
Risk Management & Business Continuity Manual 2011-2014
ANNEX C Risk Management & Business Continuity Manual 2011-2014 Produced by the Risk Produced and by the Business Risk and Business Continuity Continuity Team Team February 2011 April 2011 Draft V.10 Page
Board oversight of risk: Defining risk appetite in plain English
www.pwc.com/us/centerforboardgovernance Board oversight of risk: Defining risk appetite in plain English May 2014 Defining risk appetite in plain English Risk oversight continues to be top-of-mind for
Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS. www.fic.gov.bc.ca
Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS www.fic.gov.bc.ca INTRODUCTION The Financial Institutions Commission 1 (FICOM) holds the Board of Directors 2 (board) accountable for the stewardship
IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS
IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS 1 Module 1: Principles of Risk and Risk Management Module aims The aim of this module is to provide an introduction to the principles and concepts of risk and
Financial risk management
Financial risk management Topic Gateway Series No. 47 1 Prepared by Jasmin Harvey and Technical Information Service February 2008 About Topic Gateways Topic Gateways are intended as a refresher or introduction
research Budgeting practice and organisational structure executive summaries
Budgeting practice and organisational structure research executive summaries Volume 6 Issue 4 Professor David Dugdale and Dr Stephen Lyne Department of Accounting and Finance, University of Bristol ISSN
Corporate Portfolio Management
Corporate Risk Corporate Portfolio Management Capital allocation from a risk-return perspective Premise Aligning the right information with the right people to make effective corporate decisions is one
Enterprise Governance
Enterprise Governance Topic Gateway series no. 32 Prepared by Gillian Lees and Technical Information Service June 2007 1 About Topic Gateways Topic Gateways are intended as a refresher or introduction
ENGINEERING COUNCIL. Guidance on Risk for the Engineering Profession. www.engc.org.uk/risk
ENGINEERING COUNCIL Guidance on Risk for the Engineering Profession www.engc.org.uk/risk This guidance describes the role of professional engineers and technicians in dealing with risk, and their responsibilities
IIA POSITION PAPER: THE ROLE OF INTERNAL AUDITING IN ENTERPRISE-WIDE RISK MANAGEMENT
IIA POSITION PAPER: THE ROLE OF INTERNAL AUDITING IN ENTERPRISE-WIDE RISK MANAGEMENT Revised: Page 1 of 8 Introduction The importance to strong corporate governance of managing risk has been increasingly
Enterprise Risk Management
2013 Government Accounting and Auditing Update Enterprise Risk Management Understanding and Implementing an ERM Framework Mike Sargent, Director- CliftonLarsonAllen May 2013 cliftonlarsonallen.com Discussion
RISK MANAGEMENT FRAMEWORK. 2 RESPONSIBLE PERSON: Sarah Price, Chief Officer
RISK MANAGEMENT FRAMEWORK 1 SUMMARY The Risk Management Framework consists of the following: Risk Management policy Risk Management strategy Risk Management accountability Risk Management framework structure.
Risk Management. National Occupational Standards February 2014
Risk Management National Occupational Standards February 2014 Skills CFA 6 Graphite Square, Vauxhall Walk, London, SE11 5EE T: 0207 0919620 F: 0207 0917340 E: [email protected] www.skillscfa.org Skills
International Diploma in Risk Management Syllabus
International Diploma in Risk Management Syllabus Module 1: Principles of Risk and Risk Management The aim of this module is to provide an introduction to the principles and concepts of risk and risk management.
Clarius Group Risk Management Policy and Framework
1. Introduction Clarius Group Risk Management Policy and Framework 1.1 Definition Risk is the chance of something happening that will have an impact on objectives. Risk provides the opportunity (upside)
Brand metrics: Gauging and linking brands with business performance
Brand metrics: Gauging and linking brands with business performance Received (in revised form): rd February, 00 TIM MUNOZ is a managing partner of Prophet (www.prophet.com), a management consulting firm
Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement
Understanding the Entity and Its Environment 1667 AU Section 314 Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement (Supersedes SAS No. 55.) Source: SAS No. 109.
Integrating Risk Management with Performance Management * Margaret Woods Aston Business School
Integrating Risk Management with Performance Management * Margaret Woods Aston Business School Why Risk Management Matters Sometimes it is the things you don t see that really matter. Source: Enron Corporation
Fraud Prevention and Deterrence
Fraud Prevention and Deterrence Fraud Risk Assessment 2016 Association of Certified Fraud Examiners, Inc. What Is Fraud Risk? The vulnerability that an organization faces from individuals capable of combining
Much attention has been focused recently on enterprise risk management (ERM),
By S. Michael McLaughlin and Karen DeToro Much attention has been focused recently on enterprise risk management (ERM), not just in the insurance industry but in other industries as well. Across all industries,
Operational Risk Management - The Next Frontier The Risk Management Association (RMA)
Operational Risk Management - The Next Frontier The Risk Management Association (RMA) Operational risk is not new. In fact, it is the first risk that banks must manage, even before they make their first
COMPLIANCE CHARTER 1
COMPLIANCE CHARTER 1 Contents 1. Compliance Policy Statement... 2 2. Purpose... 2 3. Mission and objective of the Directorate: Compliance... 2 3.1 Mission... 2 3.2 Objective... 3 4. Compliance risk management...
The Proposed Quality Competency Framework for the Future Quality Professional
The Proposed Quality Competency Framework for the Future Quality Professional Ian R McKay FCQI CQP CQI Competency Project Lead 1 The CQI Definition of Quality 2 The CQI Competency Project 2012 The CQI
A structured approach to Enterprise Risk Management (ERM) and the requirements of ISO 31000
A structured approach to Enterprise Risk Management (ERM) and the requirements of ISO 31000 Contents Executive summary Introduction Acknowledgements Part 1: Risk, risk management and ISO 31000 1 Nature
A Risk Management Standard
A Risk Management Standard Introduction This Risk Management Standard is the result of work by a team drawn from the major risk management organisations in the UK, including the Institute of Risk management
Please contact me on 0207 213 4378 or [email protected] if you would like to discuss this further.
House of Commons Public Bill Committee, Scrutiny Unit, 7 Millbank, London, SW1P 3JA. 8 September 2014 Dear Sirs, Modern Slavery Bill call for written evidence We appreciate the opportunity to respond to
Embedding ethical values
Chartered Institute of Management Accountants Chartered Institute of Management Accountants Embedding ethical values A guide for CIMA partners Embedding ethical values Overview The CIMA Training and Development
Frontier International
International research insights from Frontier Advisors Real Assets Research Team Issue 15, June 2015 Frontier regularly conducts international research trips to observe and understand more about international
Understanding and articulating risk appetite
Understanding and articulating risk appetite advisory Understanding and articulating risk appetite Understanding and articulating risk appetite When risk appetite is properly understood and clearly defined,
Risk assessment. made simple
Risk assessment made simple July 2015 1 Sayer Vincent LLP Chartered accountants and statutory auditors Invicta House 108 114 Golden Lane London EC1Y 0TL Offices in London, Bristol and Birmingham 020 7841
Proposed Code of Ethical Principles for Professional Valuers
INTERNATIONAL VALUATION STANDARDS COUNCIL Second Exposure Draft Proposed Code of Ethical Principles for Professional Valuers Comments to be received by 31 August 2011 Copyright 2011 International Valuation
Zurich s approach to Enterprise Risk Management. John Scott Chief Risk Officer Zurich Global Corporate
Zurich s approach to Enterprise Risk Management John Scott Chief Risk Officer Zurich Global Corporate Agenda 1. The risks we face 2. Strategy risk and risk tolerance 3. Zurich s ERM framework 4. Capital
www.pwc.co.uk Cyber security Building confidence in your digital future
www.pwc.co.uk Cyber security Building confidence in your digital future November 2013 Contents 1 Confidence in your digital future 2 Our point of view 3 Building confidence 4 Our services Confidence in
Formal and informal feedback in management accounting
Hanna Pitkänen Turku School of Economics, Finland Kari Lukka Turku School of Economics, Finland Formal and informal feedback in management accounting Taking a look beyond the balanced scorecard Research
The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012
The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only Agenda Introduction Basic program components Recent trends in higher education risk management Why
Hand IN Hand: Balanced Scorecards
ANNUAL CONFERENCE T O P I C Risk Management WORKING Hand IN Hand: Balanced Scorecards AND Enterprise Risk Management B Y M ARK B EASLEY, CPA; A L C HEN; K AREN N UNEZ, CMA; AND L ORRAINE W RIGHT Recent
How To Manage Risk
Fund Board Oversight of Risk Management September 2011 Nothing contained in this report is intended to serve as legal advice. Each investment company board should seek the advice of counsel for issues
Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire. P3M3 Project Management Self-Assessment
Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire P3M3 Project Management Self-Assessment Contents Introduction 3 User Guidance 4 P3M3 Self-Assessment Questionnaire
SOL PLAATJE MUNICIPALITY ENTERPRISE RISK MANAGEMENT FRAMEWORK AND POLICY
SOL PLAATJE MUNICIPALITY ENTERPRISE RISK MANAGEMENT FRAMEWORK AND POLICY Prepared by: SOL PLAATJE MUNICIPALITY RISK MANAGEMENT UNIT AND Consolidated Advisory Services This document should be read in conjunction
Accreditation Application Forms
The Institute of Risk Management The Institute of Risk Management Accreditation Application Forms Universities and Professional Associations The Institute of Risk Management Accreditation Application Forms
Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology
Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology May 20, 2015 Internal FR 2 Risk and Risk Assessment Defined Risk Institute of Internal Auditors (IIA) The
Basel Committee on Banking Supervision. Working Paper No. 17
Basel Committee on Banking Supervision Working Paper No. 17 Vendor models for credit risk measurement and management Observations from a review of selected models February 2010 The Working Papers of the
RISK APPETITE STATEMENT
RISK APPETITE STATEMENT make or break? PREPARED BY NADINE BOGHDADI, RISK CONSULTANT WILLIS RISK SERVICES MARCH 2015 When an organisation embarks on defining its risk appetite, the process, debate and discussion
Module 4. Risk assessment for your AML/CTF program
Module 4 Risk assessment for your AML/CTF program AML/CTF Programs Risk assessment for your AML/CTF program Page 1 of 27 Module 4 Risk assessment for your AML/CTF program Risk assessment for your AML/CTF
Better Practice Guide
Better Practice Guide June 2008 Risk Management COMCOVER Commonwealth of Australia 2008 ISBN 1 921182 78 4 print ISBN 1 921182 79 2 online Department of Finance and Deregulation This work is copyright.
MARCH 2012. Strategic Risk Policy Update March 2012 v1.10.doc
MARCH 2012 Version 1.10 Strategic Risk Policy Update March 2012 v1.10.doc Document History Current Version Document Name Risk Management Policy Statement and Strategic Framework Last Updated By Alan Till
Risk assessment. made simple. sayer vincent consultants and auditors. Introduction 3. step1 Identifying the risks 4. step2 Assessing the risks 7
Risk assessment made simple Introduction 3 step1 Identifying the risks 4 step2 Assessing the risks 7 step3 Establishing action points 11 step4 Developing a risk register 13 Monitoring and assessment 14
How To Understand The Importance Of Internal Control
FINANCIAL REPORTING COUNCIL INTERNAL CONTROL REVISED GUIDANCE FOR DIRECTORS ON THE COMBINED CODE OCTOBER 2005 FINANCIAL REPORTING COUNCIL INTERNAL CONTROL REVISED GUIDANCE FOR DIRECTORS ON THE COMBINED
P3M3 Portfolio Management Self-Assessment
Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire P3M3 Portfolio Management Self-Assessment P3M3 is a registered trade mark of AXELOS Limited Contents Introduction
STATEMENT OF INVESTMENT BELIEFS AND PRINCIPLES
STATEMENT OF INVESTMENT BELIEFS AND PRINCIPLES Investment Advisory Board, Petroleum Fund of Timor-Leste August 2014 CONTENTS Page Summary... 1 Context... 3 Mission Statement... 4 Investment Objectives...
Enterprise Risk Management
Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's
Beyond risk identification Evolving provider ERM programs
Beyond risk identification Evolving provider ERM programs March 2016 At a glance PwC conducted research to assess the state of enterprise risk management (ERM) within healthcare providers and found many
Internal Auditing Guidelines
Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may
Maturity Model. March 2006. Version 1.0. P2MM Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce
Maturity Model March 2006 Version 1.0 P2MM Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce This is a Value Added product which is outside the scope of the HMSO
Risk Management Practices in the Public and Private Sector: Executive Summary
Office of Risk Management and Analysis Risk Management Practices in the Public and Private Sector: Executive Summary September 2010 Homeland Security This publication is presented on behalf of the Office
Risk Management Policy
1 Purpose Risk management relates to the culture, processes and structures directed towards the effective management of potential opportunities and adverse effects within the University s environment.
Project Risk Management Single Subject Certificate Syllabus Levels 1&2 4 th Edition
Project Risk Management Single Subject Certificate Syllabus Levels 1&2 4 th Edition The Single Subject Certificates in Project Risk Management (Risk SSC) are designed to build on the knowledge gained in
Key Account Management
Key Account Management Brent Warren What is KAM? the art of developing long-term relationships with selected customers The Financial Times. KAM is an art not a formula. It is a process of development,
Admission Criteria Minimum GPA of 3.0 in a Bachelor s degree (or equivalent from an overseas institution) in a quantitative discipline.
Overview Offered by the Mona School of Business in conjunction with the Department of Mathematics, Faculty of Science & Technology, The University of the West Indies. The MSc. ERM degree programme is designed
Quick Guide: Meeting ISO 55001 Requirements for Asset Management
Supplement to the IIMM 2011 Quick Guide: Meeting ISO 55001 Requirements for Asset Management Using the International Infrastructure Management Manual (IIMM) ISO 55001: What is required IIMM: How to get
Enterprise Risk Management: Taking the First Steps
Enterprise Risk Management: Taking the First Steps TN PRIMA, 2012 DOROTHY GJERDRUM, ARM, CIRM NOVEMBER 15, 2012 Agenda Goal: To understand how to begin to implement a broader approach to risk management
Risk Assessment & Enterprise Risk Management
Risk Assessment & Enterprise Risk 1 Healthcare Corporate Governance Today s environment requires building a culture of risk awareness and management of risk across the organization, while formulating less
Guidance on Risk Management, Internal Control and Related Financial and Business Reporting
Guidance Corporate Governance Financial Reporting Council September 2014 Guidance on Risk Management, Internal Control and Related Financial and Business Reporting The FRC is responsible for promoting
Deriving Value from ORSA. Board Perspective
Deriving Value from ORSA Board Perspective April 2015 1 This paper has been produced by the Joint Own Risk Solvency Assessment (ORSA) Subcommittee of the Insurance Regulation Committee and the Enterprise
HOW MANAGEMENT ACCOUNTING DRIVES SUSTAINABLE SUCCESS
HOW ACCOUNTING DRIVES SUSTAINABLE SUCCESS WHAT ACCOUNTANTS DO ACCOUNTING IS MORE THAN YOU THINK Chartered Global Management Accountants combine financial expertise and business acumen. ACCOUNTING Management
ENTERPRISE RISK MANAGEMENT FRAMEWORK
ROCKHAMPTON REGIONAL COUNCIL ENTERPRISE RISK MANAGEMENT FRAMEWORK 2013 Adopted 25 June 2013 Reviewed: October 2015 TABLE OF CONTENTS 1. Introduction... 3 1.1 Council s Mission... 3 1.2 Council s Values...
Benefits Realization from IS & IT, and Change Management of roles and the working practices of individuals and teams.
: Delivering Value from IS & IT Investments John Ward and Elizabeth Daniel John Wiley & Son Ltd ISBN: 9780470094631, 399 pages Theme of the Book This book explores a process and practical tools and frameworks
Morningstar Qualitative Rating & Morningstar Fund Research Report
Morningstar Qualitative Rating & Morningstar Fund Research Report February, 2009 2009 Morningstar, Inc. All rights reserved. The information in this document is the property of Morningstar, Inc. Reproduction
Good practice for annual reports
Guidance note Good practice for Contents: 1 Introduction 2 How the best reports set themselves apart 3 Examples of the best May 2015 1 Introduction An annual report can generate more value if viewed as
Topic Gateway Series. Business ethics. Business ethics. Topic Gateway Series No. 46
Topic Gateway Series No. 46 Prepared by Danielle Cohen and Technical Information Service April 2008 1 About Topic Gateways Topic Gateways are intended as a refresher or introduction to topics of interest
school transport: survey of good practice
school transport: survey of good practice IMPROVING SERVICES SAFE WORKING TOGETHER SUSTAINABLE SCHOOL TRANSPORT: SURVEY OF GOOD PRACTICE 1 MVA Consultancy was commissioned to undertake a survey of good
Standards for the Professional Practice of Internal Auditing
Standards for the Professional Practice of Internal Auditing THE INSTITUTE OF INTERNAL AUDITORS 247 Maitland Avenue Altamonte Springs, Florida 32701-4201 Copyright c 2001 by The Institute of Internal Auditors,
CORPORATE CODE OF ETHICS. Codes of corporate ethics normally have features including:
E. Professional values and ethics CORPORATE CODE OF ETHICS An ethical code typically contains a series of statements setting out the organization s values and explaining how it sees its responsibilities
ENTERPRISE RISK MANAGEMENT FRAMEWORK
ENTERPRISE RISK MANAGEMENT FRAMEWORK COVENANT HEALTH LEGAL & RISK MANAGEMENT CONTENTS 1.0 PURPOSE OF THE DOCUMENT... 3 2.0 INTRODUCTION AND OVERVIEW... 4 3.0 GOVERNANCE STRUCTURE AND ACCOUNTABILITY...
University of St. Gallen Law School Law and Economics Research Paper Series. Working Paper No. 2008-19 June 2007
University of St. Gallen Law School Law and Economics Research Paper Series Working Paper No. 2008-19 June 2007 Enterprise Risk Management A View from the Insurance Industry Wolfgang Errath and Andreas
Enterprise Risk Management in a Highly Uncertain World. A Presentation to the Government-University- Industry Research Roundtable June 20, 2012
Enterprise Risk Management in a Highly Uncertain World A Presentation to the Government-University- Industry Research Roundtable June 20, 2012 CRO Council Introduction Mission The North American CRO Council
