Introduction to TTC s Enterprise Risk Management (ERM) Program. TTC Audit and Risk Management Committee



Similar documents
IIA POSITION PAPER: THE ROLE OF INTERNAL AUDITING IN ENTERPRISE-WIDE RISK MANAGEMENT

Enterprise Risk Management: Concepts & Issues

The Role of the Board in Enterprise Risk Management

Enterprise-Wide Risk Assessment

TRANSPORT FOR LONDON AUDIT COMMITTEE STRATEGIC RISK MANAGEMENT PROGRESS REPORT

RSA ARCHER OPERATIONAL RISK MANAGEMENT

Tying It All Together: Practical ERM Integration. Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation

Office of the Chief Information Officer

Enterprise Risk Management Program

Applying Risk Assessment to Your Audit Plan Break-out Session T3, Tuesday, October 26 2:00-2:50pm

Linking Risk Management to Business Strategy, Processes, Operations and Reporting

Using Technology to Automate Fraud Detection Within Key Business Process Areas

Matthew E. Breecher Breecher & Company PC November 12, 2008

The rise of third party relationships means rise in risk and regulation. Non-compliance is risky business for financial institutions

Enterprise Risk Management & Information Technology

Using data analytics and continuous auditing for effective risk management

Transforming risk management into a competitive advantage kpmg.com

IFAD Policy on Enterprise Risk Management

THE ROLE OF FINANCE AND ACCOUNTING IN ENTERPRISE RISK MANAGEMENT

Following up recommendations/management actions

Operational Risk Management - The Next Frontier The Risk Management Association (RMA)

RISK MANAGEMENT OVERVIEW 2011 RISK CONFERENCE SPONSORED BY THE FEDERAL RESERVE BANK OF CHICAGO AND DEPAUL UNIVERSITY

An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management

APPENDIX 50. Enterprise risk management - Risk management overview

RIMS Risk Management Models. Traditional Risk Management Progressive Risk Management Strategic Risk Management

THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS

Planning the audit scope The fundamentals

ERM and GRC Fundamentals. Risk Management Definitions & Guiding Principles. Module 1

Enterprise risk management: A pragmatic, four-phase implementation plan

Balance Sheet Integrity The Utopian Close: Creating a low risk, highly effective financial close

DISCIPLINE DATA GOVERNANCE GOVERN PLAN IMPLEMENT

Moving Forward with IT Governance and COBIT

Beyond risk identification Evolving provider ERM programs

ACCELUS RISK MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS ACCELUS RISK MANAGEMENT SOLUTIONS

Renewable Energy Solutions

Solutions. Master Data Governance Model and the Mechanism

Implementing an Integrated City-wide Risk Management Framework

Take the right steps 9 principles for building the Risk Intelligent Enterprise

ENTERPRISE RISK MANAGEMENT POLICY

OPTIMUS SBR. Optimizing Results with Business Intelligence Governance CHOICE TOOLS. PRECISION AIM. BOLD ATTITUDE.

Applying Integrated Risk Management Scenarios for Improving Enterprise Governance

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

ORACLE ENTERPRISE GOVERNANCE, RISK, AND COMPLIANCE MANAGER FUSION EDITION

Internal audit value optimization for insurance organizations

Analyzing Risks in Healthcare. February 12, 2014

Operational Risk Management in a Debt Management Office

TTC AUDIT COMMITTEE REPORT NO.

ENTERPRISE PROJECT MANAGEMENT OFFICE

STAFF REPORT ACTION REQUIRED

TABLE OF CONTENTS BACKGROUND AND INTRODUCTION... 5 PURPOSE... 5 SCOPE... 6 RISK ASSESSMENT PROCESS... 6

International Diploma in Risk Management Syllabus

Fraud Prevention and Deterrence

Key Components of Enterprise Risk Management (ERM) Framework

Risk Management Solution for NPO

GAINING CONTROL: Building Your Existing Framework into an ERM Model

Module 6 Essentials of Enterprise Architecture Tools

Developing an Effective Enterprise Risk Management Program

Performing a Compliance Risk Assessment for Compliance Auditing & Monitoring in Healthcare Organizations

Enterprise Risk Management

Contractor Prequalification and Verification Services

Auditing Capital Projects and Project Controls. March 2013

Enterprise Risk Management in UNHCR

Risk management for external beam radiotherapy Recommendations (draft)

Global Technology Audit Guide. Auditing IT Governance

Specialists in Strategic, Enterprise and Project Risk Management. Enterprise Risk Management. the effect of uncertainty on objectives.

QUALITY ASSURANCE IN EXTREME PROGRAMMING Plamen Balkanski

Fraud Risk Management

Review of Toronto Transit Commission Bus Maintenance and Shops Department, Phase Two Audit Progress on Implementation of Audit Recommendations

Agile Master Data Management TM : Data Governance in Action. A whitepaper by First San Francisco Partners

Placing a Value on Enterprise Risk Management ADVISORY

Advanced Analytics for Better Insights. Part of the Insurance series: Benefits of a New Policy Administration System: Why Going Live is Not Enough

Risk Management Strategy & Implementation Plan

How To Transform It Risk Management

Governance, Risk, and Compliance (GRC) White Paper

Appendix 1: Performance Management Guidance

MAGENTA KEYLINE IS A CUTTER GUIDE, DO NOT PRINT. PLEASE SET TRAPPING THROUGHOUT

Enterprise Risk Management in a Highly Uncertain World. A Presentation to the Government-University- Industry Research Roundtable June 20, 2012

BE 2015 A BUSINESS EXCELLENCE INITIATIVE EXCELLENCE IN CUSTOMER MANAGEMENT SELF ASSESSMENT QUESTIONNAIRE

Energy Procurement & Sustainability Services Strategy at every stage of your energy and sustainability life cycle

IT Insights. Managing Third Party Technology Risk

NASCIO Recognition Award Nomination IT Project and Portfolio Management

UNITED NATIONS OFFICE FOR PROJECT SERVICES. ORGANIZATIONAL DIRECTIVE No. 33. UNOPS Strategic Risk Management Planning Framework

Enhancing Audit Technology Effectiveness Key Insights from TeamMate s 2014 Global Technology Survey

NEW MEXICO ECONOMIC DEVELOPMENT DEPARTMENT STATE EXPENDITURES FOR BUSINESS INCUBATORS ACT REQUEST FOR INCUBATOR CERTIFICATION

Developing a robust cyber security governance framework 16 April 2015

Introduction to Resource Management. Resource Management Seminar: Second Session Rome, 27 January 2015

Wealth Advisory Services Winning with clients

Transcription:

STAFF REPORT INFORMATION ONLY Introduction to TTC s Enterprise Risk Management (ERM) Program Date: September 11, 2015 To: From: TTC Audit and Risk Management Committee Chief Executive Officer SUMMARY This is the inaugural meeting for the Audit & Risk Management Committee (ARM), the attached presentation is an introduction to TTC s Enterprise Risk Management Program. Financial Summary This report has no financial impact. Contact Mohamed Ismail, Principal Risk Advisor Toronto Transit Commission Tel: 416 393-2935 Email: Mohamed.Ismail@ttc.ca Attachments TTC Enterprise Risk Management (ERM) Program Staff Report for information on TTC Enterprise Risk Management (ERM) Program 1

TTC ENTERPRISE RISK MANAGEMENT (ERM) PROGRAM

CONTENT 1. Why Do We Need Risk Management? 2. TTC ERM Program Plan and Approach 3. TTC ERM Platform- First Priority 4. ERM & Audit 5. Next Meeting Page 2

WHY DO WE NEED RISK MANAGEMENT?

BACKGROUND Formal project risk management Vehicle procurement risk management HIRA (Hazard Identification & Risk Assessment) Fragmented efforts Page 4

RISK MANAGEMENT Learn from mistakes Historical Data RCA Hindsight Insight Are Controls in Place? Are they adequate? Are they effective? Test the system Challenge assumptions Think outside the box Foresight Page 5

WHY RISK MANAGEMENT? Oversight Central system for the management of enterprise risks A consistent methodology for risk informed decision making and capital allocation Ability to direct resources to risks of greatest significance or impact Less Surprises! Page 6

OPTIMAL RISK-TAKING Page 7

RISK MANAGEMENT PROCESS Page 8

PLAN & APPROACH

ERM OBJECTIVES Integrate risk management into the TTC`s culture and business processes Monitor and diligently maintain the integrity and effectiveness of risk controls Communicate and provide visibility to risk Inform strategic decision making including the prioritization of capital Page 10

TTC ERM ROADMAP Driven by international best practices, APTA s audit report, and feedback received from the Auditor General, the TTC has developed an ERM Roadmap to Maturity. Page 11

TTC ERM FEEDBACK APTA: APTA is very much encouraged that TTC is moving in what we see as the right direction on managing commission risk which will include some safety risk at the higher levels. Page 12

TTC ERM FEEDBACK Auditor General City of Toronto: There are a number of existing software applications to facilitate enterprise risk management. To our knowledge, (within the city) only the TTC has acquired a software platform to facilitate monitoring, communication, and reporting of their ERM program. Page 13

APPROACH Focus on significant risks Top down & bottom up Detailed analysis & tracking Clear risk and control ownership Page 14

APPROACH Cover the entire organization between 2015-2017 ERM Program status at the end of 2017 Safety risk: department or group levels with safety staff Approached, educated and trained all TTC groups and departments Business risk: department level risk workshops Every group and department would have an assigned risk champion Corporate risk: group level workshops Top risks identified and the majority would be analyzed Page 15

TTC ERM PLATFORM - FIRST PRIORITY

BENEFITS Provides a central system for the management of enterprise risks Manages risk ownerships and control accountability Monitors control effectiveness Provides a platform for risk communication and reporting Facilitates effective performance monitoring, measurement and review Provides a proven, logical structure to qualitative risk assessment Page 17

SOFTWARE EXAMPLE Page 18

RISK ANALYSIS EXAMPLE Page 19

RISK DASHBOARD EXAMPLE Page 20

TOP RISKS UPDATE (EXAMPLE) Page 21

ERM & AUDIT

INTERFACE OF INTERNAL AUDIT & ERM Internal Audit will use the TTC risk register as a source for the risk-based audit plan Internal Audit will work with RMO to add risks of significance that are not already identified Internal Audit will request verification or evaluation of risk assessments not deemed reasonable Audit findings will be fed back into the ERM Page 23

NEXT MEETING

NEXT MEETING Risk Governance How TTC scores risk TTC s Risk Appetite TTC s Top Risks Page 25

THANK YOU Questions? Page 26