ENTERPRISE RISK MANAGEMENT. J. Joseph Hoey, Ed.D. Bridgepoint Education CAIR 2015



Similar documents
Enterprise Risk Management in Colleges and Universities

Understanding Enterprise Risk Management. Presented by Dorothy Gjerdrum Arthur J Gallagher

Enterprise-Wide Risk Assessment

Developing an Effective Enterprise Risk Management Program

Managing Risk at Bank of America Corporation. Overview

Sample Enterprise Risk Management Work Plan Fiscal Years 20XX and 20YY Revised June Internal Environment / Objectives Setting

The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012

Matthew E. Breecher Breecher & Company PC November 12, 2008

Enterprise Risk Management: Taking the First Steps

Transportation Security Administration Enterprise Risk Management. ERM Policy Manual. August 2014

University of Windsor Board of Governors. That the Board of Governors approve of the Enterprise Risk Management Framework.

Attorney Perspectives: Enterprise Risk Management in a Time of Innovation

Enterprise Risk Management

Get More Out of Your Risk Assessment. Austin Chapter of the IIA

IASA Speaker: Alvin Tan

In accordance with risk management best practices, below describes the standard process for enterprise risk management (ERM), including:

Meeting the Challenges of Enterprise Risk Management in Higher Education

Risk Management Policy Adopted by:

ENTERPRISE RISK MANAGEMENT P R O G R A M. August 31, 2012

Avondale College Limited Enterprise Risk Management Framework

APPENDIX 50. Enterprise risk management - Risk management overview

Risk Management Policy

and Risk Tolerance in an Effective ERM Program

Enterprise Risk Management

Enterprise Risk Management

Bridgend County Borough Council. Corporate Risk Management Policy

Risk Management Policy

ENTERPRISE RISK MANAGEMENT FRAMEWORK

RISK MANAGEMENT OVERVIEW 2011 RISK CONFERENCE SPONSORED BY THE FEDERAL RESERVE BANK OF CHICAGO AND DEPAUL UNIVERSITY

Moving Forward with IT Governance and COBIT

Enterprise Risk Management & Information Technology

Information Technology

Presentation at the NACUBO Budgeting Forum Budget Balancing Strategies for Multi Year Plans: Case Study of the University of Michigan Rowan Miranda,

Risk Management: Coordinated activities to direct and control an organisation with regard to risk.

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

Enterprise Risk Management

IT GOVERNANCE PANEL BRING VALUE BY AUDITING IT GOVERNANCE GET THE

ENTERPRISE RISK MANAGEMENT POLICY

Policy and Procedure Statement

Enterprise Risk Management. Breaking Down the Barriers at Emory

Dr. Michael Reilly Executive Dean, Business Ashford University

Risk Management Policy and Framework

Enterprise Risk Management

East Carolina University Office of Internal Audit Risk Assessment Preliminary Work

A Risk-Based Audit Strategy November 2006 Internal Audit Department

How To Manage Risk At Atb Financial

IFAD Policy on Enterprise Risk Management

Performing Effective Risk Assessments Dos and Don ts

Risk Management Strategy and Guidelines

1.20 Appendix A Generic Risk Management Process and Tasks

Linking Risk Management to Business Strategy, Processes, Operations and Reporting

Council Meeting Agenda 27/07/15

Presentation Objectives Why is Internal Audit here? Concepts (Enterprise Risk Management, Strategic Risk, Strategic Risk Management, etc.

Enterprise Risk Management Handbook. June, 2010

How To Write A Risk Management Policy For The University Of Kerry

IT Governance. What is it and how to audit it. 21 April 2009

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

APPLICATION OF THE KING III REPORT ON CORPORATE GOVERNANCE PRINCIPLES

THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT

Enterprise Risk Management

Organizational Change Management: A Best Practice to Effective ERM Implementation

Enterprise Risk Management Panel Discussion

IT UNIFICATION Vision, Impact & Strategy. May 2015

RISK MANAGEMENT FRAMEWORK. 2 RESPONSIBLE PERSON: Sarah Price, Chief Officer

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework

Organizing a Financial Institution to Deliver Enterprise-Wide Risk Management By Kaan H. Aksel PricewaterhouseCoopers

Policy : Enterprise Risk Management Policy

International Diploma in Risk Management Syllabus

Copyright 2015 The Ins4tutes

Enterprise risk management: A pragmatic, four-phase implementation plan

Regulatory Compliance Framework An Electric Utility Model. Abstract. Grier Consulting Group LLC

SECURITY MANAGEMENT Produce security risk assessments

Professional. Compliance & Ethics. 19 The cost of unethical behavior. 33 Graduate degrees in Compliance: Training the next generation

FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund

Tailoring enterprise risk management strategies to the Main-Street insurer

ENTERPRISE RISK MANAGEMENT POLICY

Risk Assessment & Enterprise Risk Management

Strategic Planning Procedure Manual

ERM Symposium April Moderator Nancy Bennett

Model Risk, A company perspective Peter K. Reilly, FSA Valuation Actuary & Head of Actuarial Strategic Initiatives Aetna, Inc

Infrastructure Ontario Enterprise Risk Management Program. National Executive Forum Yellowknife, NWT May 2013

La Trobe Melbourne. Course Development Policy

The role and function of insurance company board of directors risk committees

COMPLIANCE GUIDELINE April 2009

RISK MANAGEMENT POLICY (Revised October 2015)

Enterprise Risk and Compliance Management

The Value of Vulnerability Management*

ENTERPRISE RISK MANAGEMENT NARACOORTE LUCINDALE COUNCIL GUIDELINES

Eclipx Group Limited Risk Management Policy

Enterprise Risk Management Process Improvement. Secure Banking Solutions, LLC

STANDARDS OF SOUND BUSINESS AND FINANCIAL PRACTICES. ENTERPRISE RISK MANAGEMENT Framework

Confident in our Future, Risk Management Policy Statement and Strategy

What others are saying about Risks!

How To Save Money At The University Of California

Enterprise Risk Management at Pennsylvania State University (A) Strategy Implementation in a Decentralized Organization

Enterprise Risk Management

Strategic Risk Management for School Board Trustees

Competency Requirements for Executive Director Candidates

Operational Risk Management Program Version 1.0 October 2013

COMPARATIVE STUDY BETWEEN TRADITIONAL AND ENTERPRISE RISK MANAGEMENT A THEORETICAL APPROACH

Transcription:

ENTERPRISE RISK MANAGEMENT J. Joseph Hoey, Ed.D. Bridgepoint Education CAIR 2015

Enterprise Risk Management (ERM) Defined ERM is a principles-based approach to manage, not eliminate risk. ERM is a process that is: Built into routine business practices Designed to: Identify emerging events with the potential to affect the entity, Assess the potential impact consistently, and Manage risk within a predetermined risk appetite Applied across the enterprise Tied to the organization s strategic goals

Why Is ERM Important? Consider these examples: Penn State athletics scandal Emory University USN & WR admissions data falsification Virginia Tech and other more recent campus shootings Others? They come up all the time!

Focus of ERM ERM focuses on an institution s achievement of its objectives or mission in the following areas: Strategic high-level goals aligned with the institution s mission Operational ongoing management processes Financial protection of institution s assets Legal and Regulatory adherence to applicable laws and regulations Political and Reputational risk includes loss or threat to accreditation, confrontation with legislators, and major institutional scandals

The Risk Management Process 1.Defining the risk universe 2.Identifying the risks 3.Assessing the risks Ranking the risks likelihood, impact, residual risk, and velocity Ascertaining the University s risk appetite Charting risk maps, creating influence maps to ID risk drivers Using event trees 4.Evaluating the risks What opportunities exist to mitigate? What is the cost-benefit analysis of mitigation? 5.Mitigating the risks mitigation plan development 6.Monitoring the plan keeping up with new risks

Responses to Risk High Medium Risk High Risk I M P A C Share Low Risk Mitigate and Control Medium Risk T Accept Control Low PROBABILITY High Source: AGB and NACUBO (2007). Meeting the Challenges of Enterprise Risk Management in Higher Education.

Campus Roles in ERM Board oversees ERM, but leaves the details to management; President sets high-level ERM agenda, and engages the faculty and board members in ERM; CFO establishes and manages ERM; CRO leads ERM and fosters a collaborative, campuswide approach; and Internal audit collaborates with CRO. Institutional Research provides supporting data, dashboards, and ongoing environmental scanning Source: NACUBO/AGB (2007)

AGB: The Board s Role in ERM The Board must enable the University to anticipate and respond rationally to the most serious exposures that could compromise the ability of the enterprise to function. To ensure that senior management develops and maintains a comprehensive ERM plan that maps out risk scenarios and potential responses. To ensure that plans, policies and practices adequately address critical risk exposures in every area of activity not just financial.

AGB Recommendations: The Board s Role in Monitoring ERM The Board can best monitor and oversee risk management through its committee structure Strategic risks are best evaluated in a finance committee or long-range planning committee Operational exposures and the measures to manage them are often best addressed by the audit committee The Board should conduct regular, rotating reviews of high-risk areas

Where to Start? Tips From The ERM Pros Start small Keep it simple - don t boil the ocean Focus on a limited set of risks Go for the quick wins Adopt change management framework and skill set Ensure accountability for risk areas Develop process capability through multiple iterations

Further ERM Resources Meeting the Challenges of Enterprise Risk Management in Higher Education. National Association of College and University Business Officers, Association of Governing Boards (2007). The State of Enterprise Risk Management at Colleges and Universities Today. Association of Governing Boards/United Educators (2009). Lots of great tools developed by the UC Office of the President: http://www.ucop.edu/enterprise-riskmanagement/tools-templates/risk-assessment-toolboxcontent/higher-education-risk-assessment-tool.html