Implementation of SAP-GRC with the Pictet Group



Similar documents
In Brief February 2015

Office of the Auditor General / Bureau du vérificateur général FOLLOW-UP TO THE 2010 AUDIT OF COMPRESSED WORK WEEK AGREEMENTS 2012 SUIVI DE LA

Centre International de Hautes Etudes Agronomiques MÄditerranÄennes. International Centre for Advanced Mediterranean Agronomic Studies POINT 9

Enterprise Risk Management & Board members. GUBERNA Alumni Event June 19 th 2014 Prepared by Gaëtan LEFEVRE

Message from the Partners

Pourquoi une gestion de portefeuille efficace doit se fonder sur une approche intégrée?

A Cross Border One Stop Shop for Alternative Investments Managers

RISK MANAGEMENT POLICY

Langages Orientés Objet Java

ULYSSES L.T. FUNDS EUROPEAN GENERAL. L.T. Funds European General: Share Price Evolution INVESTMENT STRATEGY AUGUST 2015 COMMENT

Risk Management: Coordinated activities to direct and control an organisation with regard to risk.

Fondation Rennes 1. Atelier de l innovation. Fondation Rennes 1. Fondation Rennes 1 MANAGEMENT AGILE. Fondation Rennes 1 ET INNOVATION

Survey on Conference Services provided by the United Nations Office at Geneva

«Object-Oriented Multi-Methods in Cecil» Craig Chambers (Cours IFT6310, H08)

Archived Content. Contenu archivé

HELPING HEALTH CARE: A HOSPITAL ERGONOMICS (MUSCULOSKELETAL INJURY) RISK ASSESSMENT PROJECT

PICTET GROUP CONSOLIDATED FINANCIAL STATEMENTS AT 30/06/2014. Pictet Group. Consolidated financial statements at 30 June 2014

Introduction au BIM. ESEB Seyssinet-Pariset Economie de la construction contact@eseb.fr

Another way to look at the Project Une autre manière de regarder le projet. Montpellier 23 juin - 4 juillet 2008 Gourlot J.-P.

Private banking: the post-eldorado era

Managing Risk Control Environment and Responsibilities

Millier Dickinson Blais

Régression logistique : introduction

Audit de sécurité avec Backtrack 5

Strategic Workforce Planning and Competency Management at Schneider Electric

Risk Management Policy

Detection of water leakage using laser images from 3D laser scanning data

Paris Orléans. Full year 2013/2014 results presentation

Convention sur la lutte contre la Désertification

Expérience appui ANR Zimbabwe (Medicines Control Authority of Zimbabwe -MCAZ) Corinne Pouget -AEDES

Unrealized Gains in Stocks from the Viewpoint of Investment Risk Management

SWIFT and Payment Factory projects

Study on Exit Mechanism for Private Equity Investment

Tous les documents de la présente réunion se trouvent sur le site internet du FMC : rubrique services. Login : ourdata Password : areyours

Holinger AG / Holinger Group Facts and Figures Holinger SA / Groupe Holinger Faits et chiffres 2011

Core Infrastructure Risk Management Plan

MINING DATA BANK OF THE ACP STATES

Report to Rapport au: Council Conseil 9 December 2015 / 9 décembre Submitted on October 26, 2015 Soumis le 26 octobre 2015

Bibliothèque numérique de l enssib

Gabon Tourist visa Application for citizens of Canada living in Alberta

LABORATORY EQUIPMENT HARMONIZATION AS A TOOL FOR COST-EFFECTIVE MANAGEMENT OF LABORATORY COMMODITIES AND MAINTENANCE CONTRACTS:

J.P. Morgan Global Liquidity. Managed Reserves Fund Operation Services Guide. JPM Managed Reserves Fund

PMI Switzerland Chapter NewsFLASH

BUSINESS PROCESS OPTIMIZATION. OPTIMIZATION DES PROCESSUS D ENTERPRISE Comment d aborder la qualité en améliorant le processus

San Francisco International Airport Enterprise Risk Management

PhD Program in Pharmaceutical Sciences From drug discovery to the patient Training the next generations of pharmaceutical scientists

site et appel d'offres

RAPPORT FINANCIER ANNUEL PORTANT SUR LES COMPTES 2014

International Diversification and Exchange Rates Risk. Summary

Archived Content. Contenu archivé

Wealth & Tax Planning Escrow Service

GENERAL COURSE INFORMATION

Open call for tenders n SCIC C4 2014/01

Wealth & Tax Planning Private Insurance

Integration of Risk Management and Internal Audit. Chartered Institute of Management Accountants, New Zealand

Liste d'adresses URL

Accélérer le développement d'applications avec DevOps

Short Form Description / Sommaire: Carrying on a prescribed activity without or contrary to a licence

Investment Funds. Professional Qualification in. Professional Qualification

Version: 3.0. Effective From: 19/06/2014

THE CITY OF TORONTO S JOB DEMANDS ANALYSIS AND JOB MATCH SYSTEM

Capacity building and Strengthening of the implementation of IOTC Conservation and management Measures. Madagascar

AgroMarketDay. Research Application Summary pp: Abstract

Troncatures dans les modèles linéaires simples et à effets mixtes sous R

Analyzing Risks in Healthcare. February 12, 2014

POL ENTERPRISE RISK MANAGEMENT SC51. Executive Services Department BUSINESS UNIT: Executive Support Services SERVICE UNIT:

Tool & Asset Manager 2.0. User's guide 2015

Risk Mitigation Applied to Decision Making. Steve Wenke 2012 Northwest Hydro Operators Forum September 26,2012

CORP RISK MANAGEMENT POLICY & METHODOLOGY

Statistiques en grande dimension

The Lowitja Institute Risk Management Plan

We are pleased to present you with detailed instructions on processing your visa application with us. Within this information pack you will find:

In accordance with risk management best practices, below describes the standard process for enterprise risk management (ERM), including:

Guidance on Extended Producer Responsibility (EPR) Analysis of EPR schemes in the EU and development of guiding principles for their functioning

Audit Committee, 28 November. HCPC Project Risk Management. Executive summary and recommendations. Introduction

Measuring Policing Complexity: A Research Based Agenda

CFT ICT review Questions/Answers

Travaux publics et Services gouvernementaux Canada. Title - Sujet LEARNING SERVICES. Solicitation No. - N de l'invitation E60ZH

Business Analytics. one technology. product. right decisions. one vision. Performance Management

Travaux publics et Services gouvernementaux Canada. Title - Sujet HRSDC FUNCTIONAL SUPPORT. Solicitation No. - N de l'invitation G /A

Standardization of Lending Services: A Peek Inside

CAHIER DES CHARGES POUR LA MISE EN PLACE D UN SYSTÈME DE GESTION INTÉGRÉE DES OPÉRATIONS DANS LE CEPS

ISO/TC 46/SC 11 N 1401

CUSTOMER FUNDS PROTECTION AT NEWEDGE FINANCIAL SINGAPORE PTE LTD

Introduction to Enterprise Risk Management at UVM DRAFT

First-half 2012 Results. August 29 th, Jean-Paul AGON. Chairman and CEO

Transcription:

Implementation of SAP-GRC with the Pictet Group Olivier VERDAN, Risk Manager, Group Risk, Pictet & Cie 11 th December 2013 Zürich

Table of contents 1 Overview of the Pictet Group 2 Operational Risk Management at the Pictet Group 3 SAP-GRC Project 4 Main challenges of SAP-GRC implementation 5 Results of SAP-GRC implementation

1 Overview of the Pictet Group Founded in Geneva in 1805, the Pictet Group is today one of Europe's leading independent wealth and asset managers. 3

Facts & Figures 1805 3300 25 founded in Geneva employees offices around the world 650 investment professionals $433bn in assets under management and custody at 30 September 2013 8 partners responsible for all of the Group s activities Independently owned Group, no external shareholder pressure 4

A unique positioning around three areas of business Pictet Group Wealth management Asset management Asset services Wealth management solutions for private clients Solutions for institutional investors and distribution of investment funds Custody bank, fund administration and trading services for institutional clients and banks Pictet Wealth Management Services for independent asset managers Pictet Asset Management Pictet Alternative Investments Pictet Asset Services Trading 5

2 Operational Risk Management at the Pictet Group 6

Monitoring at business lines and Group legal entities level CFO COO Compliance Officer Risk Officer CFO COO Compliance Officer Risk Officer Monitoring at Group level Pictet Organisation of Operational Risk Management Philosophy = Decentralisation Pictet & Cie Partners Committee Group Internal Audit Group Risk Group Compliance Group Security Legal Department Board of Directors of the Group legal entities Senior Management of the business lines Senior Management of the Group legal entities 7

Date of closing Overall progress Deadline Overall responsible Level of Residual Risk Impact/Severity Likelihood/Frequency Level of Residual Risk Impact/Severity Likelihood/Frequency Level of Residual Risk Amount for Financial impact in CHF Impact/Severity Likelihood/Frequency Level of Residual Risk Impact/Severity Likelihood/Frequency Level of Residual Risk Impact/Severity Likelihood/Frequency Level of Residual Risk Amount for Financial impact in CHF Impact/Severity Likelihood/Frequency Effectiveness of Strategies Last update Date of Entry Legal entity / site 100'000 100'000 30.06.10 31.12.08 8051 GE 25% 31.03.11 B. Mnp 1'000'000 1'000'000 30.06.10 31.12.08 8052 GE 85% 31.12.10 A. Xyz 5'000'000 10'000'000 30.06.10 30.06.09 8053 GE / LUX GE Catégorie du risque 06/09 12/09 06/10 Tendance Avancement Echéance prévue Risk target Likelihood - Frequency 30.06.10 31.12.09 8054 Reputational damage Financial impact BL / Entity scale 200'000 Other impact or damage 200'000 Risk ranking 90% 31.12.10 G. Fgh Methodology for Operational Risk Mgmt (2007-2013) Risk Register by Group Unit Sent to Group- Risk by email Manual risks consolidation Discussion of risk map between G- R and Unit Group Risk Report released ID 1 = Rare : 5 years 2 = Unlikely : 1-5 years 3 = Possible : < 1 year 4 = Likely : monthly 5 = Almost certain : weekly Identified Risks Manual process using MS Office tools Unit Risk Description Risk Category PF xxx Organisation PF xxx Technique 1 = Insignificant : 2 = Minor : 3 = Moderate : 4 = Major : 5 = Extreme : Description by Unit Contrôles / réconciliation quotidienne des positions... Reporting des incidents Contrôle 4 yeux pour chaque opération No media attention. Minor complaint. No media attention. Multiple minor complaints. Local media reporting. Moderate complaints. National & international media reporting. Major complaints. Long term negative image. Substantial complaints with losses. Group Risk Register for Operational Risks Existing Controls / Mitigation Techniques H 2 1 L 3 2 PF xxx Humain xxx M 2 4 PF xxx Externe xxx H 4 1 1 = 2 = 3 = 4 = 5 = Financial Risk Min. 0 500'001 1'000'001 5'000'001 20'000'001 Reputational Risk Max. 500'000 1'000'000 5'000'000 20'000'000 Analysis & Evaluation of Residual Risk Other Risks Key Risk Indicators Description by Unit Description by Unit (short description of key elements) L 2 2 M Nombre d'incidents - 2 1 M 3 3 H 3 1 L Rapport d'erreurs H 2 2 M Nombre d'incidents 1 = Insignificant : No regulatory consequence. 2 = Minor : 3 = Moderate : 4 = Major : 5 = Extreme : - Automatisation des contrôles - Abaissement des niveaux d'alerte - Projet sécurisation des données - Projets d'évolution du MIS 3 2 2 3 M 4 3 H 4 3 H Nombre de pannes xxx 3 1 No regulatory consequence. Minor reversible injury. Limited regulatory consequence. Moderate reversible injury. Significant regulatory consequence. Major injury. Closure of major part of business. Irreversible injury. Unit / Date EXCEL Action plan to reduce risk Evaluation of Target Risk Financial Risk Reputational Risk L 2 2 M Other Risks M 3 2 M 3 1 L M 2 2 M 2 1 L L 3 3 H 3 1 L 1-3 Low Risk 4-6 Moderate Risk 8-12 High Risk 15-25 Extremely High Risk Sévérité 5 4 3 2 1 0 0 1 11 Zone des risques modérés et faibles non détaillés 2 1 12 17 3 2 4 Fréquence POWERPOINT 9 4 1 5 1 4 PCS Sévérité 5 4 3 2 1 0 0 1 Unité Descriptif PCS Xxxxx PCS Erreurs d'exécution xxxx PCS Survenance d'un problème xxxxx 1 1 1 1 1 2 3 4 Fréquence Lors de la réévaluation au 30 juin, un nouveau risque élevé a été identifié concernant xxxxxxx xxx Si le risque d erreurs dans l exécution d un ordre de xxxxx est toujours évalué globalement comme élevé, son évolution actuelle est considérée en amélioration par PCS. En effet, le nombre d erreurs et l impact financier 5 des incidents sont moins importants que durant les semestres précédents. Plan d actions & responsables / Commentaires WORD Xxxx xxx xx xxx xxxx Fin. 2011 Responsable : M. Xyv 1) xxxxx x xxx xxxx. 2) xxxx xxxx xxx x xxx 2011 Responsable : A. Ghj Xxxxx xx xx xx xx x xx xx Xxx xx xxx xxxx. 2011 Responsable : R. Hgk 8

3 SAP-GRC Project 9

Main objectives of the SAP-GRC Project Reduce the risk of operational risks non-detection by interlinking information Reduce the administrative workload to concentrate on tasks with high added value A unique tool in the Group for the management of all types of operational risks Provide a complete functional coverage in a structured and standardized framework Improve compliance to Finma-Circ. 08/24 Supervision and internal control banks and Finma Circ. 08/21 Operational risks at banks 10

Preliminary phases 2011 2012 Study of market risk management tools Contacts with various banks that have deployed integrated tools for operational risk management Choice of the tool ORC (Interexa), used by Workshops with Interexa : March - April Workshops with Unit Risk Managers : June Decision to stop ORC and start SAP : August Final estimated cost too high ORC doesn t provide an internal control module Presentation by SAP of GRC (including internal control module) Strong sponsorship by Pictet IT as SAP already used for Finances and HR 11

SAPPORO Project Risk Management module Selection of SAP-GRC : August 2012 Proof of Concept : November 2012 Start of SAPPORO Project : Preliminary phase with Riscomp : February-March 2013 Business Blueprint : April 2013 Implementation and UAT with Riscomp : May-July 2013 Training and UAT with Unit Risk Managers : May-June 2013 Go-Live : 29 th July 2013 12

The 3 phases of the SAPPORO Project Phase 3 Incidents Study - Implementation Phase 2 Internal Control Syst. Study - Implementation Phase 1 Risk Management Study - Implementation 08.2013 06.2014 13

4 Main challenges of SAP-GRC implementation 14

Main challenges Pictet Methodology 1. Decentralised operational risk management Pictet Group Policy for Operational Risks Challenges were: - Collecting Unit Risk Managers needs, with very different maturity on the operational risk management process - Various approaches (bottom up, top down, mixed) - Implement a solution that suits all, within a reasonable budget Integration of decentralised Unit Risk Managers throughout the project 15

Main challenges Pictet Methodology 1. Decentralised operational risk management Pictet Group Policy for Operational Risks 2. Matrix organisation 16

Matrix Organisation Multiple business lines, crossed with multiple legal entities, in 25 sites in the world. Reporting needs: By business line (for the Management) By legal entity (for Supervision Authority) By site (for local Management) Example of business lines Pictet Wealth Management Pictet Asset Management Distribution Pictet Asset Services Pictet Asset Management Investment Example of legal entities Pictet & Cie (Europe) SA Pictet Investment Co. Ltd, London Pictet Funds SA Paris Branch Italian Branch Hong Kong Branch Etc Négoce Bank Pictet (Asia) Ltd, Singapore Etc Pictet Asset Management Ltd Etc 17

Matrix Organisation Solution = 3 costumed defined fields within the Organisational Unit: Team name Company name Site name Risk Response Org. Unit Name Company Site 18

Main challenges Pictet Methodology 1. Decentralised operational risk management Pictet Group Policy for Operational Risks Because full organisation requires to download 1544 organisational units, others challenges were: 2. Matrix organisation - Response time was too long for users with limited access (Unit Risk Managers) - Temporary solution : partial organisation loaded into SAP-GRC only (567 org units) - SAP has improved response time - Automatic update of the organisation 19

5 Results of SAP-GRC implementation 20

Outcomes of the project Positive: Pictet Methodology fits in SAP-GRC (risk valuation, risk categories) Ops Risk Mgmt Framework more robust Time saving: less administrative tasks more added-value works Heatmap immediate reporting tool, with extended drill down / selection capabilities Unique Ops Risks Register Negative: SAP-GRC seemed not matured enough: we encountered a lot of bugs which tend to demonstrate the tool was not tested extensively. Examples: Impossible to remove a Response from a Risk Risk Aspect worked on Org. Name, not Org. ID Ergonomics not user friendly Graphical view incomplete Response can be saved without compulsory info (name) But good reactivity of SAP to correct bugs 21

Most desired improvements Response time Automatic update of Organisation / Risk Thresholds Underlying Risks: possibility to include or exclude them in the Heatmap Validity extension of a Risk 22

Implementation of SAP-GRC with the Pictet Group Questions? Thank you for your attention 23