Risk, Risk Assessments and Risk Management. Christopher Bowler CPA, CISA August 10, 2015



Similar documents
Risk Management Basics - ISO Standard. Louis Kunimatsu, CRISC IT Security & Strategy, Ford Motor Company

ENTERPRISE RISK MANAGEMENT FRAMEWORK

Fraud Risk Management

Risk management systems of responsible entities

Enterprise Risk Management & Information Technology

Enterprise Risk Management: Taking the First Steps

ISO 31000: ISO/IEC & ISO Guide 73: New Standards for the Management of Risk

A&CS Assurance Review. Accounting Policy Division Rule Making Participation in Standard Setting. Report

Risk Management Primer

When Recognition Matters WHITEPAPER ISO RISK MANAGEMENT PRINCIPLES AND GUIDELINES.

Enterprise Risk Management in Colleges and Universities

Enterprise Risk Management Framework Strengthening our commitment to risk management

Avondale College Limited Enterprise Risk Management Framework

How To Understand The Role Of An Internal Audit

Improving Financial Performance, Governance and Compliance

Risk and Contingency Planning. Today s Topics. Key Terms. A Vital Component of Your ICD-10 Program

Performance Measures for Internal Auditing

Applying Integrated Risk Management Scenarios for Improving Enterprise Governance

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework

PRINCE2:2009 Glossary of Terms (English)

Operational Risk Management - The Next Frontier The Risk Management Association (RMA)

Matthew E. Breecher Breecher & Company PC November 12, 2008

Disclosure to Promote the Right To Information

Analyzing Risks in Healthcare. February 12, 2014

Board of Directors Meeting 12/04/2010. Operational Risk Management Charter

Enterprise-Wide Risk Assessment

and Risk Tolerance in an Effective ERM Program

Linking Risk Management to Business Strategy, Processes, Operations and Reporting

PMI Risk Management Professional (PMI-RMP) Exam Content Outline

Integrated Risk Management:

Sempra Energy Utilities response Department of Commerce Inquiry on Cyber Security Incentives APR

Developing an Effective Enterprise Risk Management Program

Subject ST9 Enterprise Risk Management Syllabus

The Role of Internal Audit in Risk Governance

A Risk Management Standard

Board oversight of risk: Defining risk appetite in plain English

Clarius Group Risk Management Policy and Framework

RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide

VENDOR MANAGEMENT. General Overview

Risk Management Framework

P3M3 Portfolio Management Self-Assessment

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

CDC UNIFIED PROCESS PRACTICES GUIDE

Procurement Programmes & Projects P3M3 v2.1 Self-Assessment Instructions and Questionnaire. P3M3 Project Management Self-Assessment

Enterprise Risk Management

Policy : Enterprise Risk Management Policy

IT Sourcing. White Paper IT Advisory

The PNC Financial Services Group, Inc. Business Continuity Program

COSO Internal Control Integrated Framework (2013)

CDC UNIFIED PROCESS PRACTICES GUIDE

Stepping Through the Info Security Program. Jennifer Bayuk, CISA, CISM

ENTERPRISE RISK MANAGEMENT POLICY

Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE

Risk Assessment & Enterprise Risk Management

IT Insights. Managing Third Party Technology Risk

Citation for published version (APA): Berthing, H. H. (2014). Vision for IT Audit Abstract from Nordic ISACA Conference 2014, Oslo, Norway.

Integration of Risk Management and Internal Audit. Chartered Institute of Management Accountants, New Zealand

UNLOCKING OUTSOURCING

Risk Management Policy

Sound Transit Internal Audit Report - No

STANDARD. Risk Assessment. Supply Chain Risk Management: A Compilation of Best Practices

How to Develop Successful Enterprise Risk and Vendor Management Programs

ENTERPRISE RISK MANAGEMENT FRAMEWORK

Understanding Enterprise Risk Management. Presented by Dorothy Gjerdrum Arthur J Gallagher

Internal audit value optimization for insurance organizations

UNITED NATIONS OFFICE FOR PROJECT SERVICES. ORGANIZATIONAL DIRECTIVE No. 33. UNOPS Strategic Risk Management Planning Framework

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

Project Risk Management

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard

Risk Management Policy Adopted by:

GET YOUR INTERNAL AUDIT RISK ASSESSMENT RIGHT THIS YEAR NOAH GOTTESMAN

Enterprise Risk Management

Certified ScrumMaster (CSM) Content Outline and Learning Objectives January 2012

fmswhitepaper Why community-based financial institutions should practice enterprise risk management.

Saldanha Bay Municipality. Risk Management Strategy. Inclusive of, framework, procedures and methodology

The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012

Scenario Analysis Principles and Practices in the Insurance Industry

PART B INTERNAL CAPITAL ADEQUACY ASSESSMENT PROCESS (ICAAP)

ISO and Risk Management

Virginia Government Finance Officers Association Spring Conference May 28, Cloud Security 101

International Diploma in Risk Management Syllabus

Quality Manual ISO 9001:2015 Quality Management System

Adaptive Management: Process. Adaptive Management Set-Up Phase Step 5: Monitoring Program. Roles of Monitoring in Adaptive Management

Fraud Prevention and Deterrence

Risk Management Within an Organisation

IS&T Project Management: Project Management 101. June, 2006

Implementing Portfolio Management: Integrating Process, People and Tools

Incorporating Risk Assessment into Project Forecasting

Certified ScrumMaster (CSM) Content Outline and Learning Objectives January 2012

Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS.

IT Outsourced Services. Preliminary Survey

Hedge fund launch considerations Reaching new boundaries. Investment Management

Information Security Managing The Risk

Transcription:

+ Risk, Risk Assessments and Risk Management Christopher Bowler CPA, CISA August 10, 2015

+ Agenda A Few Thoughts Fundamentals of Risk Assessments Fundamentals of Risk Management Assessments vs. Management Questions

+ Learning Objectives Gain a working understanding of: The Fundamentals of an Effective Enterprise Risk Assessment Process The Fundamentals of an Effective Enterprise Risk Management Function

+ A Few Thoughts Successful Enterprises have unique goals and objectives grow and develop at its own pace maintain an individual identity in the market have a unique way of achieving objectives operate within a unique risk environment

+ A Few Thoughts View of Risk is unique to every organization and individual has both up and down sides is a function of change accumulates in processes over time it is often best understood in hindsight

+ A Few Thoughts Discipline vs. Structure disciplined people don t need hierarchy disciplined thoughts don t need bureaucracy disciplined actions don t need excessive controls

+ Risk Assessment Scope Enterprise Risk Classifications Strategic Financial Operational Compliance Entry/Exit Product/Services Market/Location Competition Brand/Reputation Credit Liquidity Investment Exchange Rates Counter Party Qualified Personnel Transaction Processing Internal Reporting Vendor Management Laws & Regulations Covenants & Obligations External Reporting Paid To Take Paid To Manage Paid To Mitigate

+ Risk Assessment Planning Use size & complexity as a guide: Organizational hierarchy and structure Level of Board oversight Number of employees Geographic proximity of locations Reliance on key employees Complexity of support systems Nature of products and services The ability to determine a clear cost-benefit

+ Risk Assessment Approach Focuses on Business Objectives Considers External and Internal Risks Recognizes the Upsides and Downsides of Risk Qualitative or Quantitative Scalable from Project to Enterprise Is Time Bound Management Activities Risk Response Inherent Risk Residual Risk

+ Risk Assessment Results Establishes a realistic baseline risk profile: Takes credit for the activities in place A baseline for resource allocation Agree scope, timing and nature of risk response activities Differentiate risk response and process change activities Does not require gold standard practices

+ Real Life Risk Management

+ Risk Management Activities Principles of Risk Management 1) Creates Value 2) Aligns with Business Objectives 3) Integral Part of Organizational Processes 4) Part of the Decision Making Process 5) Explicitly Addresses Uncertainty 6) Systematic, Structured and Timely 7) Based on Best Available Information 8) Tailored to the Entity 9) Considers Human and Cultural Factors 10) Transparent and Inclusive 11) Dynamic: Iterative and Responsive to Change 12) Facilitates Continual Improvement Source ISO 31000

+ Risk Management Activities A framework to address layers and boundaries of the entity The three essential elements of any risk management function These elements vary in capabilities and effectiveness People Technology Practices

+ Risk Management Activities Assumptions Activities must be based on business objectives Perceived and real risk conditions can interfere in achieving these objectives There is a finite set of resources available to achieve these objectives Transparency and visibility are key Risk management decisions may have to be explained to stakeholders

+ Risk Management Activities Risk Management Framework Mandate and Commitment Create Framework Continual Process Improvement Implement Processes Monitor and Review Processes Source ISO 31000

Communication and Consultation + Risk Management Activities Risk Management Model Establish Risk Context Risk Assessment Identification Analysis Evaluation Monitoring and Review Risk Treatment Source ISO 31000 Source: ISO 31000

+ Risk Management Activities Risk Context Organizational business objectives and goals Nature of operational environment Governance and risk management practices Industry and regulatory specific requirements Stakeholder perceptions and values Capabilities of people practices and systems

Risk Level + Risk Management Activities Risk Context Very High Failure Tolerance Appetite 0 Time

+ Risk Management Activities Communication and Consultation Improves the transparency of the process and builds consensus for risk management plans Clarifies roles and responsibilities for risk management activities Recognizes the interests of various stakeholders Ensures that risks are adequately identified Considers the appropriate change management requirements Promotes a culture that recognizes the appropriate treatment and value of risk taking activities

+ Risk Management Activities Monitoring and Review Provides feedback for: Risk factors associated with business objectives and goals Identification of changing or emerging risks Allocation of risk management resources Identification of events that trigger the need for new assessment activities Measurement of risks associated with internal and external reporting

+ Risk Management Activities Risk Treatment Modify change/process improvement Monitor watch/wait and prepare to respond Transfer insure or outsource Exit remove the source of the risk

+ Risk Management Activities Challenges Dynamic objectives and goals Refining the risk universe to relevant risks Risk tolerances and acceptable risk taking Organizational boundaries Visibility and transparency Integration efforts

+ Compare and Contrast Risk Assessment At point in time Qualitative or quantitative Often measured against external standards Historical and structured Time bound baseline Risk Management Continuous activities Continual improvement More quantitative(upper and lower limits) Forward looking & dynamic Supports the decision process in real-time

+ Questions? - Dr. Seuss