Convergence of Internal Audit, Compliance, and Risk Management. Frank Bossle Executive Director- Office of Hopkins Internal Audits April 2014



Similar documents
Understanding Enterprise Risk Management. Presented by Dorothy Gjerdrum Arthur J Gallagher

Enterprise-Wide Risk Assessment

Enterprise Risk Management VCU Process

Attorney Perspectives: Enterprise Risk Management in a Time of Innovation

The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012

The Role of Internal Audit in Risk Governance

Maryland Association of Boards of Education Insurance Programs

University of Windsor Board of Governors. That the Board of Governors approve of the Enterprise Risk Management Framework.

Fraud Risk Management

ENTERPRISE RISK MANAGEMENT. J. Joseph Hoey, Ed.D. Bridgepoint Education CAIR 2015

RISK MANAGEMENT OVERVIEW 2011 RISK CONFERENCE SPONSORED BY THE FEDERAL RESERVE BANK OF CHICAGO AND DEPAUL UNIVERSITY

Introduction to Enterprise Risk Management at UVM DRAFT

Matthew E. Breecher Breecher & Company PC November 12, 2008

Risk Management Strategy and Policy. The policy provides the framework for the management and control of risk within the GOC

International Diploma in Risk Management Syllabus

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

APPLICATION OF THE KING III REPORT ON CORPORATE GOVERNANCE PRINCIPLES

Enterprise Risk Management

The PNC Financial Services Group, Inc. Business Continuity Program

Enterprise Risk Management Program

Enterprise Risk Management. Breaking Down the Barriers at Emory

Policy : Enterprise Risk Management Policy

Enterprise Risk Management (ERM) Process Overview. Office for Audit and Advisory Services

Risk Management Policy

POLICY. Number: Title: Enterprise Risk Management. Authorization

APPENDIX 50. Enterprise risk management - Risk management overview

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

Linking Risk Management to Business Strategy, Processes, Operations and Reporting

Fraud Prevention and Deterrence

Get More Out of Your Risk Assessment. Austin Chapter of the IIA

Enterprise Risk Management: Taking the First Steps

THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS

Organizational Change Management: A Best Practice to Effective ERM Implementation

APPLICATION OF KING III CORPORATE GOVERNANCE PRINCIPLES 2014

Managing Risk at Bank of America Corporation. Overview

Risk Management Policy Adopted by:

Using Strategic Risk Management to Gain Assurance and Communicate More Effectively

Governance Processes and Organizational Structures for Information Management

Audit, Risk Management and Compliance Committee Charter

The members of the Executive Risk Management Committee ( ERMC ) reviewed the proposed Policy and Charter and recommend their approval.

The Essentials of Enterprise Risk Management. Steven C. Tourek, Senior Vice President, General Counsel & Secretary, The Marvin Companies

Avondale College Limited Enterprise Risk Management Framework

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors

Audit Committee Charter

ENTERPRISE RISK MANAGEMENT FRAMEWORK

Risk Management Committee (Committee) Terms of Reference

Risk Management - Board & Management Responsibilities Murray Short, MBA, CPA CA Not-for-Profit Partner RLB LLP

OAC Presentation to UNESCO Member States

INFORMATION SECURITY STRATEGIC PLAN

AMTRAK CORPORATE GOVERNANCE: Implementing a Risk Management Framework is Essential to Achieving Amtrak s Strategic Goals

How To Plan A University Budget

Board Risk & Compliance Committee Charter

Terms of Reference - Board Risk Committee

CORPORATE GOVERNANCE

A&CS Assurance Review. Accounting Policy Division Rule Making Participation in Standard Setting. Report

FIRST REPUBLIC BANK DIRECTORS ENTERPRISE RISK MANAGEMENT COMMITTEE CHARTER

University of Rhode Island IT Governance

REPORT ON ETHICS COMPLIANCE 21/01/15

Board of Directors Meeting 12/04/2010. Operational Risk Management Charter

Accreditation Application Forms

Enterprise Risk Management Plan FY December 2014

C o m m i t t e e o f S p o n s o r i n g O r g a n i z a t i o n s o f t h e T r e a d w a y C o m m i s s i o n

Enterprise Risk Management

Developing an Effective Enterprise Risk Management Program

CVS HEALTH CORPORATION A Delaware corporation (the Company ) Audit Committee Charter Amended as of September 24, 2014

FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund

TO: Vice-Presidents DATE: April 28, 2009

STANDARDS OF SOUND BUSINESS AND FINANCIAL PRACTICES. ENTERPRISE RISK MANAGEMENT Framework

Department of Veterans Affairs VA Directive VA Enterprise Risk Management (ERM)

Enterprise Risk Management Task Force Report to UNC Board of Trustees. Trustee Sallie Shuping-Russell, Chair May 2015

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework

Don t Get Left in the Dust: How to Evolve from CISO to CIRO

Internal Auditing Guidelines

Office of Internal Audit Status Report BOARD OF TRUSTEES

Enterprise Risk Management Panel Discussion

Senior Academic and Administrative Officers Benefits: 7 weeks of PTO upon date of hire or transition to the position

Infrastructure Ontario Enterprise Risk Management Program. National Executive Forum Yellowknife, NWT May 2013

Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology

3 August 2012 Policy updated to reflect name changes and alignment with current Aurora Energy Group Policy standards.

UNITED STATES DEPARTMENT OF EDUCATION OFFICE OF INSPECTOR GENERAL

RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide

POL ENTERPRISE RISK MANAGEMENT SC51. Executive Services Department BUSINESS UNIT: Executive Support Services SERVICE UNIT:

ENTERPRISE RISK MANAGEMENT POLICY

Internal audit strategic planning Making internal audit s vision a reality during a period of rapid transformation

GENERAL MILLS, INC. AUDIT COMMITTEE CHARTER

Public Sector Pension Investment Board

Exam Name: Certified Information Security Manager

Solvency II New Framework for Risk Management Organisation. Dr. Maciej Sterzynski (Triglav Insurance, Ltd.) Matija Bitenc (Triglav Insurance, Ltd.

J u n e N a t i o n a l R e s e a r c h C o u n c i l C a n a d a. I n t e r n a l A u d i t, N R C. Audit of Risk Management.

Research Administration Training Program for Existing Staff Johns Hopkins University

FFIEC Cybersecurity Assessment Tool

BUSINESS CONTINUITY PLANNING

Click to edit Master title style

Affiliation Agreement with Eller Executive Education

Enterprise Risk Management, Compliance, Management Advisory Services: An Integrated Approach

Why Every Lawyer Should Understand the Importance of Enterprise Risk Management

ERM Program. Enterprise Risk Management Guideline

Risk Management & Business Continuity Manual

Implementing an Integrated City-wide Risk Management Framework

Enterprise Risk Management for International Schools

Transcription:

Convergence of Internal Audit, Compliance, and Risk Management Frank Bossle Executive Director- Office of Hopkins Internal Audits April 2014 1

Summary Plan to share with you the maturation process at Johns Hopkins University How the Internal Audit role has changed How three processes have become much more aligned: Risk Management Regulatory Compliance Internal Audit 2

History Office of Hopkins Internal Audits was formed in 2000 to provide internal audit services to both the University and the Johns Hopkins Health System At that time, we constructed the first audit universe and risk assessment. Realistically, this focused on auditable risk, not an allencompassing identification or prioritization of risks 3

Going It Alone Internal Audit projects focus on: Assessing the adequacy of control Testing control for effectiveness This often leads to discussions about acceptable levels of risk (and risk appetite) As there was no forum for institute wide agreement on risks, Internal Audit frequently had to negotiate issues on an ad-hoc basis 4

Emergence of Compliance Focus In 2005-6, JHU decided we needed a focus on compliance with laws and regulations An Institutional Compliance Oversight Committee was formed, with 10-12 high-level executives who owned key risks, such as HR, IT, Sponsored Research, Human Subjects, and Health & Safety A universe of 150 compliance topics was created, and assigned to risk owners 5

Examples of Regulatory Compliance Topics Student Research Clinical Administrative Student and Financial Aid Animal Care and Use Clinical Trials Health safety and Environment Human Subjects Billing Compliance Information Technology Conflicts of Interest in Research Post-award Administration Human Resources 6

Compliance Takes Hold Risk owners prioritized the inventory and selected the highest risk areas for self assessment Assessment based upon the Federal Sentencing Guidelines - steps to an effective compliance plan Subcommittee reviewed and challenged the assessment Institutional Compliance Oversight Committee reviewed the assessment and endorsed any recommended changes 7

Executive Leadership Engagement on Compliance Annual summary of compliance status and initiatives presented to the two Sr. Vice Presidents (CFO and Provost) Request support and/or funding for areas needing more emphasis Example: hiring an Export Control Officer 8

Emergence of Institutional Risk Management New Sr. Vice President of Finance and Admin had prior experience with ERM (or IRM) Trustees were requesting a broader focus on risks 2011 official kickoff of the formal IRM program General Counsel had prepared an infamous list of 62 risks facing JHU - this provided a starting point 9

Institutional Risk Management Primer Iterative Process: Identification and Prioritization Assessment of management controls Update for new risks Four types of risk: Strategic Operational Financial Compliance (some also add Reputational, but we consider this a secondary risk that arises from the others) 10

Risk Assessment IRM Process Risk Management Risk Framework Individual Risk Identification Quality of Current Controls Risk Mapping Risk Mitigation Analysis Risk Appetite Analysis Risk Mitigation Prioritization Mitigating Some Risks Monitoring Some Risks Revisit 11

Risk Assessment Likelihood of Occurrence Impact (if it did occur) Likelihood and Impact = Inherent Risk Quality of management controls Reduces inherent risk to residual risk 12

Risk and Risk Management Risk = Likelihood Impact Inherent Risk Managed Risk = Residual Risk Quality of Management Controls IRM ICOC 13

IRM in Operation Senior leaders (IRM Leadership Group) meets quarterly to provide input on their perceptions of highest and emerging risks Looking beyond the list of 62! Facilitated assessment identified 12 highest risks, with particular emphasis on the top 4 IRM Operations Group (middle to upper managers) meets monthly to discuss individual risks 14

Examples of Institutional Risks Faculty recruiting and retention International activities Threat to name and reputation IT Security Other more specialized risks applicable to JHU 15

Institutional Risk Management Program: Committees and Reporting Structure President Provost/Sr VP F&A President s Cabinet Deans and VPs Committee on Crisis Management Insurance Committee Board of Trustees Audit Committee IRM Leadership Group IRM Operations Group Board of Trustees Institutional Compliance Oversight Committee Joint Health, Safety & Environment Committee 16

The Glue JHU appointed a chief risk officer in 2012 Faculty member who did extensive work in crisis management, became interested in ERM as a concept, and linked up with the new Sr. VP Integrates crisis management, compliance, and IRM Has also assumed responsibility for Insurance and Health, Safety & Environment 17

IRM is now a two way street Academic exercise carried out to assess risks that have already been identified and prioritized Front line involvement in emerging and pressing risks, such as cyber attacks, student safety, government inquiries Provides real time update to IRM and executives on activities 18

Internal Audit Has Changed We do proactive/probe audits to: Confirm that areas we think are well-managed are Assess areas for which our understanding of the adequacy of management is weak Shine a spotlight on areas for which we have concerns Risk issues that emerge in audits are shared in the IRM forum 19

New Forum for Discussion about Adequacy of Controls CRO systematically convenes affected risk owners, to help reach agreement on adequacy of controls (instead of the old ad-hoc discussions) 20