WYNYARD RISK MANAGEMENT POWERFUL SOFTWARE. CONNECTING THE DOTS.
2 Wynyard Group Solutions for Financial Services Wynyard Group Solutions for Financial Services 3 KNOW THE THREATS CONNECT THE DOTS UNCOVER THE TRUTH
Wynyard Group Solutions for Financial Services 1 POWERFUL SOFTWARE. CONNECTING THE DOTS. Modern work practices, irrespective of industry, business model, location, private or public sector require risk management principles to be deeply embedded into the core activities of employees individually and organisations collectively. Failure to implement adequate risk management practices can place employees, clients and citizens at risk and have significant potential consequences for organisations either through loss of business, imposition of fines or simply damaged brand reputation. Some of the common challenges faced by organisations today include: Information Security Corruption Regulatory Compliance Approximately 90% of all the data in existence has been created in the last two years which places businesses and governments under huge pressure to ensure they have robust systems and processes for managing data under their control. Concepts such as privacy by design have transitioned from being theoretical best practice to being an operational necessity. The introduction of the UK Bribery Act in 2010 coupled with the resurgence of enforcement under the Foreign Corrupt Practices Act has meant that it is no longer possible for global businesses or even governments to adopt a laissez faire attitude to corrupt practices by third party service providers either at home or abroad. Vetting and training of agents operating in emerging markets has shifted from a nice to have to become an essential component of tendering processes across the globe. Following the global financial crisis and disasters such as deep water horizon in the gulf of Mexico there has been a major shift in the importance attached to regulatory compliance. Across the world governments have reshaped regulations and the regulators that enforce them forcing businesses in particular to reprioritise regulatory compliance from being a peripheral support function to a core business practice. Wynyard Group has been working with governments and financial institutions all over the world for the last 20 years to manage risk through the use of world class risk management software. Wynyard Risk Management is highly configurable software that can be deployed to manage risk in a wide range of circumstances. Our team works with clients to design and configure solutions for their individual requirements. OPERATIONAL RISK WYNYARD S SOLUTION MITIGATION PEOPLE TESTS PROCESS OPERATIONAL RISK CONTROLS SYSTEMS EXTERNAL EVENTS KEY RISK INDICATORS TREATMENTS ACTION PLAN
2 Wynyard Group Solutions for Financial Services Wynyard Group Solutions for Financial Services 3 RISK MANAGEMENT SOLUTIONS FOR GOVERNMENT Wynyard Group has a long track record of providing a range of risk management solutions to both local and federal government agencies. Wynyard s history of working with government departments means that we acutely understand the operating environment faced by agencies that require efficient, effective software which can be implemented in a discreet manner. Wynyard has worked with the following types of government agencies: Law enforcement Defense Tax collection Social welfare Government implementations of Wynyard Risk Management: Threat and Vulnerability Assessment: Wynyard s Threat and Vulnerability Assessment solution enables government agencies to assess vulnerabilities and manage physical and cyber threats to assets, premises, processes, people and infrastructure. Wynyard s software assists management to make rapid informed decisions in high pressure situations by providing a comprehensive risk framework for assessing and highlighting risk. Information Security: Health care Local government Wynyard s Information Security and Data Protection solution was developed for government agencies to facilitate delivery of a structured, consistent, measurable and streamlined information security risk management approach across departments ensuring the personal details of citizens remain confidential. Operational Risk: Tertiary education Regulators Wynyard s Operational Risk solution for government agencies delivers a single, centralised framework for automating, managing and integrating risk controls across departments, ensuring the most critical operational risk initiatives are aligned with strategy. Wynyard s solution simplifies reporting to stakeholders through delivery of intuitive, personalised reports either scheduled or on-demand. CASE STUDY: GOVERNMENT TAXATION AGENCY MANAGING RISK IN THE COMPLEX WORLD OF TAX COLLECTION When this national government taxation agency first implemented Wynyard Risk Management (previously known as Enterprise Risk Assessor, ERA) as a software solution in their Corporate Risk and Assurance (CR&A) team for enterprise risk and project risk in the year 2000, it was considered a leader in the field of risk management within government. Thirteen years on, the agency was looking to expand its use of technology to incorporate the remaining assurance functions in the CR&A team, confident in the benefits a combined risk and assurance solution would bring. The agency has a complex mandate to collect revenue, collect and disperse social support programme payments, provide policy advice and administer major pieces of legislation. The agency is also the second largest government employer in the country, responsible for collecting 80% of all government revenues. Its size, scale and complexity meant that the use of spreadsheets to manage risk was resulting in operational inefficiency as staff struggled to manually consolidate data and provide multiple reports across the agency. The agency wanted risk management software to provide a single, integrated solution streamlining enterprise and project risk processes replacing the manual consolidation required when working with multiple spreadsheets across different departments within the agency. The CR&A team is responsible for formal reporting to a wide variety of internal stakeholders, including the board and risk and assurance committee, and with heavy involvement in the investment decision process, which meant they needed a solution which enabled them to: Consolidate and share information via a centralised database. Improve automation and reduce duplication by entering risk and control data once and only once. Decrease the time to produce consolidated reports across enterprise and project areas. Decrease error rate caused by manual entry and consolidation of data. Utilise the rich set of reporting tools including personalised dashboards, standard and customisable reports. Increase level of confidence surrounding analysis of risks. Centralise and improve visibility of all action items and their status. Leverage alert functions to assist in coordinating review and assessment of data. After considering a range of vendors the agency determined that they wanted to continue their partnership with Wynyard and deployed the software across the remainder of their CR&A team. A key strength of Wynyard s solution is that it is an enterprise class software application and has no limit to the number of risk registers that can be created and no limit on the data captured for each risk register, which makes it ideally placed to address the needs of large government departments. With the flexibility of scale offered by Wynyard Risk Management, and the agency s well established and robust strategy to manage risk, as well as rigorous cross-department processes already in place, managing changes to the future assurance environment is simple. In particular the agency is now well placed to act fast on ever-increasing compliance requirements, such as those surrounding the rapidly changing environment of government Information Communication and Technology strategies.
4 Wynyard Group Solutions for Financial Services Wynyard Group Solutions for Financial Services 5 RISK MANAGEMENT SOLUTIONS FOR FINANCIAL SERVICES AND INSURANCE Wynyard Risk Management is used by leading financial institutions and insurers to address some of the most complex risk environments possible. Wynyard s successful track record of implementing our software at global financial services corporations means that our team has developed a deep understanding of how financial institutions and insurance companies operate and critically how to address their risk management needs. Wynyard has worked with the following types of financial institutions and insurance companies: Banks Credit unions Finance companies Investment banks Stock exchanges Insurance (brokers / underwriters) Financial Services and Insurance implementations of Wynyard Risk Management Regulatory Compliance Wynyard Regulatory Compliance is a solution for financial services organisations and insurers to monitor compliance controls across their business. Wynyard s risk management software helps ensure compliance with industry specific and cross-industry regulations and show transparency in corporate governance practices. Operational Risk Wynyard Operational Risk is a solution that enables financial institutions and insurers to document, holistically visualise, monitor, control, test and audit the spectrum of operational risk across the organisation. Wynyard s solution is completely configurable for the risk management needs of each specific department or function, while also delivering a centralised framework for data collection, integrated internal reports or reporting to regulators. Information Security Forex exchanges / remitters Lottery and Gaming Wynyard Information Security is a comprehensive, configurable solution developed to enable financial institutions and insurance companies to deliver and monitor a structured, consistent, measurable and streamlined information security risk management approach across the organisation to ensure business and client information remains confidential. CASE STUDY: GLOBAL INSURANCE SYNDICATE MANAGING THE WORLD S MOST DIVERSE RISK PORTFOLIO As one of the world s best known brands in the specialist insurance market place, this syndicate executes risk management to the highest standard possible. The syndicate brings together parties from across the world to insure risk and handles the world s most complex, diverse and specialist insurance needs: from oil rigs, to celebrity body parts, to major airlines. The syndicate initially implemented Wynyard Risk Management (previously known as Methodware Kairos) to facilitate the risk control self-assessment process (RCSA), managed by their internal risk management team. The risk team was required to produce quarterly key reports and deliver them to individuals within the syndicate responsible for actioning identified risk and control procedures. Through the use of Wynyard s configurable workflow methods the software was able to generate the required reports for assessment by risk committees and ultimately resulted in risk mitigation actions being implemented by the syndicate. In early 2014, significant changes to the regulatory landscape meant that the syndicate had to re-evaluate their regulatory processes and looked for an expanded risk management software capability. A key attribute supporting an effective risk solution at the syndicate was the requirement for risk management to be decentralised, which allows for a higher degree of individual risk process ownership within each line of business. The risk management software also had to facilitate a consistent Operational Risk management (OpRisk) framework across not only every business unit, but also across multiple global offices. In addition to extending the focus and scope of risk management specifically for the regulatory changes, the syndicate also wanted a solution to enhance its risk appetite framework, making sure that the overall organisations governance practices and procedures would meet any broader demands of the business. After scoping a number of vendors the syndicate elected to upgrade to the latest version of Wynyard Risk Management in preparation for the changing regulatory environment. The syndicated stated that the ability to use a web interface facilitated easy access to the software from any location which made deploying risk management processes across such large, complex organisation simple. The syndicate commented that the software s intuitive user interface, combined with simple navigation tools ensure that everyone is able to use the system, without onerous training requirements. In particular the ability to create personalised views of data for each individual drives critical personal ownership across the organisation for actioning the risk management process. With substantial experience in risk management, the syndicate needed a system that they could configure independently, which would do the hard work, giving them confidence in their risk management framework. Finally, the syndicate was attracted by the ability of Wynyard s Risk Management software to create clear links between key risk indicators and risk appetite; automate the production of reports and surface control failures while linking them to risk assessments. The deployment of Wynyard Risk Management has ensured this global insurance syndicate has maintained and expanded its world class risk management standards.
6 Wynyard Group Solutions for Financial Services Wynyard Group Solutions for Financial Services 7 PRODUCT FEATURES Wynyard Risk Management is a highly configurable platform that provides organisations with a framework to mitigate risk. Designed for broad use within organisations, Wynyard Risk Management allows those who create the risk, to manage the risk regardless of their background or expertise. Risks, controls, loss events and key risk indicators can be documented and managed. Reporting to managers, regulators and stakeholders is streamlined through delivery of reports either scheduled or on-demand. Chartis designated Wynyard Risk Management as a category leader which certifies it as a best-in-class risk management platform capable of addressing the needs of large clients with complex risk management and technology requirements. Rapid and flexible deployment Flexible, rapid deployment either on-premise using customer hardware and infrastructure, or securely hosted in the cloud. Wynyard Risk Management is developed and deployed with a fully featured, personalised, complete web-based user interface, meaning no desktop software installation is needed. Single, flexible, extendable database At the heart of Wynyard s solution is a single, flexible, multidimensional integrated database, allowing the addition of fields, variables, rules and now object types - without coding or modifying the database structure. Product highlights Configurable and intuitive reports and dashboards The intuitive dashboard design allows data and tasks to be organised, progress to be tracked and results to be analysed across the organisation, improving operational efficiency and effectiveness. Processes are streamlined, so they are easy to understand, user-friendly and targeted. Dashboards may be published and data shared. Multiple dimension risk aggregation and materiality mapping Risks can be automatically aggregated, and multiple dimensions can be easily configured according to customer requirements. Qualitative and/or quantitative assessments and customer-specific assessment logic can be configured. Different materialities can be applied to different levels in the organisation. Heat maps show before and after risk mitigation allowing for simple navigation to key information. Wynyard Risk Framework RISK AREAS OBJECTIVES COMPLIANCE PROCESS Policy management and surveys Define, peer-review, and manage policies and procedures within the same integrated database. Individuals within an organisation can access and attest to the policies that are relevant to them and the organisation can survey employees and third parties for policy compliance and exceptions, risk-assess them, and link back to the process, risk and control framework(s). Automated workflow and alerts Wynyard s flexible system delivers workflows that are not hardcoded, are completely flexible and simple to update. Workflows may be personalised to every user and can range from simple to complex. Notifications include on-event and scheduled messages and emails, and data-driven alerts. AUDIT RISKS CONTROLS POLICY MANAGEMENT SURVEYS INCIDENTS TREATMENTS INDICATORS TESTS REVIEW NOTES FINDINGS
8 Wynyard Group Solutions for Financial Services Wynyard Group Solutions for Financial Services 9 WYNYARD RISK MANAGEMENT ARCHITECTURE DEPLOYMENT EXTERNAL BI / REPORTING TOOL On-premise Installation Wynyard Risk Management can be deployed as an on-premise solution. This option is often utilised by government clients operating in the security or intelligence sectors that have legislative controls around information storage. Wynyard professional services work with internal IT teams to ensure seamless implementation of Wynyard Risk Management. Cloud based solution Wynyard Risk Management can also be deployed in a hosted environment. This option is favoured by many of our clients because it is faster and cheaper to implement than an on-premise installation. Wynyard has access to a global network of secure cloud environments ensuring client data remains within national boundaries. DATABASE WYNYARD RISK MANAGEMENT (IIS APPLICATION) SSRS REPORTING MS REPORT BUILDER / VIRTUAL STUDIO EXECUTION ADMINISTRATION ATTESTATIONS APPLICATION USERS (BROWSER) SERVICE LAYERS AD / LDAP EMAIL DMS WCF SERVICE LAYER WEB LAYER RESTful layer Database Wynyard Risk Management (IIS Application) Wynyard Risk Management Client Reporting Stores the Wynyard Risk Management ( WRM ) configuration and data An IIS application server that communicates with the database to: Provide the interface with the Wynyard Risk Management Client (both End users and Administration) Process business rules Drive method execution Provides the ability to: Execute methods View and modify dashboards Run reports Configure the application and security Views based reporting for secure direct database access and enhanced SQL reporting BUSINESS LAYER MODEL LAYER DATA SERVICE LAYER RULES META MODEL TYPES/FIELDS CACHING MODEL SECURITY DASHBOARDS GENERIC DATA STORE CALCULATIONS DATA MODEL REVIEWS/DATA ITEMS ALERTS TEMPLATES/METHODS/ SCREENS SERVICE LOCATOR Technical Requirements Wynyard Risk Management Client Screen resolution 1024x768 pixels or higher A web browser that supports Microsoft Silverlight v5 Client or higher (refer to the Microsoft site for specific details). Wynyard recommends Microsoft Internet Explorer 8 or higher Microsoft Silverlight Wynyard Risk Management Server Recommended server specifications will be provided based on your requirements discussion with Wynyard Services REPORTS/BI SQL SERVER
10 Wynyard Group Solutions for Financial Services WYNYARD PROFESSIONAL SERVICES AND SUPPORT MODEL SCOTT JAMES Product Director Wynyard Group Scott James has been with Wynyard Group (and its predecessors) since the year 2000 and is responsible for the overall development of Wynyard Risk Management. Scott is a Chartered Accountant with many years of risk and audit experience gained at Wynyard Group and a Big 4 Accounting firm. He has worked extensively implementing risk products in organisations around the world, including in Asia, the Middle East, Europe, North America and Australasia. Wynyard solutions are fully supported by a robust and proven service delivery model, specifically developed to ensure a successful rollout. Wynyard s Professional Services Model enables the delivery of effective and high quality services beginning with requirements and solution design all the way through to live implementation. Our service delivery team consists of skilled and experienced staff who understand customer preferences and requirements, and apply their knowledge/skills in both simple as well as complex implementation scenarios. We adopt agile methodologies to deliver maximum value to our customers plus formalised entry and exit criteria for each phase to ensure robust project delivery. GRC is becoming increasingly complex as it is deployed across more parts of the business and involves more people. A tool that is both powerful and easy to use, is an important part of implementing a successful GRC environment Requirements gathering and security analysis SOLUTION DESIGN Solution design, data mapping and integration Define scope Solution pilot Dashboards THREAT ASSESSMENT ADVANCED CRIME ANALYTICS INVESTIGATIVE CASE MANAGEMENT Infrastructure and operation IMPLEMENTATION, OPERATION & SUPPORT Visualisation Support Install Migrate Test Train users Go live PROJECT MANAGEMENT SOLUTION CONFIGURATION Soft data models WYNYARD PLATFORM CHANGE MANAGEMENT Workflow, alerts and security
12 Wynyard Group Solutions for Financial Services Wynyard Group Solutions for Financial Services 13 TRAINING TEAM COMPOSTITION Wynyard adopts a train-the-trainer approach with its customers and offers the following training packages for all products. These can be modified and tailored to suit individual customer requirements. Wynyard provides expert maintenance and support services throughout the lifecycle of engagement with the customer. Our Professional and Technical Services teams are spread across the globe and come from a range of backgrounds that equip them with in-depth industry knowledge and expertise. Application Admin Training: Includes user setup and dayto-day administration of the software. Super User Training: Includes training in advanced product functionality aimed at frequent users of the software. Some members of Wynyard s global professional services and support team: Business User Training: This includes training for normal usage of the software. IT Training: This includes training around operational maintenance, backups, recovery, installation etc. SOLUTIONS ARCHITECTS: SOLUTIONS CONSULTANTS: Architectural design for Wynyard solutions to meet unique client specifications. Analysis and definition of customer requirements by conducting client requirements workshops, functional design documents and configuration of software solutions. Support regional Wynyard sales and services teams in pre-sales, solution design and solution implementation. Configuration of the Wynyard platform based on customer goals and preferences. Provides expertise to identify and translate system requirements into software design documentation. Designing, testing and implementing Wynyard solutions tailored to the specific needs of clients. Overall solution delivery of Wynyard solutions. TECHNICAL SERVICES AND SUPPORT CONSULTANTS: Implementation of Wynyard products at client site and post-implementation support. Providing application configuration and maintenance of Wynyard systems. On-site customer interaction and product training. Administering and diagnosing technical issues. WYNYARD SUPPORT SERVICES HELP DESK Wynyard Technical Services & Support (TSS) team provides application support to our global client base. Wynyard s experienced TSS consultants are supported by mature process and tools to provide improved support service levels. Customers can subscribe for 2nd line or 3rd line support to improve response and resolution time for user issues. Users can raise issues directly on a web based portal as well access Wynyard TSS consultants on our manned service desk number between 9 am and 5 pm UK business hours. The service is subject to maintenance windows and planned downtimes. Wynyard will provide monthly report on SLA performance and conduct periodic performance review of the support engagement.
14 Wynyard Group Solutions for Financial Services Wynyard Group Solutions for Financial Services 15 SERVICE COVERAGE The Maintenance and Support Services provided by Wynyard comprise of the following: Services Corrective Maintenance Software Updates Documentation Updates Help Desk Service Description Fixes to specific software faults which may include new versions of a program, patches or fixes, remedial software or workarounds, Wynyard reserving the right at all times to determine what is included and excluded in any corrective maintenance release. Interim updates to the software that may contain enhancements and bug fixes. Periodic or interim updates to software documentation. Help desk services are operated through the 24/7 customer portal or via email if the customer portal is unavailable; and is used for problem reporting, progressing resolution and general help. ABOUT WYNYARD GROUP Know the threats, connect the dots & uncover the truth. Wynyard Group is a market leader in risk management and crime fighting software used in investigations and intelligence operations by government agencies and financial organizations. Wynyard solutions help solve and prevent crime, defend against advanced persistent cyber threats and counter terrorism. Wynyard s powerful software platform combines big data, advanced crime analytics and tradecraft to identify persons of interest, stop offenders and protect victims. Wynyard has more than 100,000 users of its solutions and offices in the United States, United Kingdom, Canada, United Arab Emirates, Australia and New Zealand. For more information visit www.wynyardgroup.com Site Attendance Monthly Fault Report Critical Support Hours The attendance on site by a support consultant (at the client s cost) to assist in the provision of the maintenance and support services should it be deemed necessary by Wynyard. A monthly fault status report. 24 x 364 (excludes 25th of December). NORMAL SUPPORT HOURS All times based on the selected time zone: Toronto Arlington, VA London Dubai 08:00 18:00 Note: Category 1 faults are supported outside of normal support hours We also set categories of software faults, response times and action timetable for each category. The service levels relating to each category will be reviewed on an annual basis. Sydney Auckland Wellington Christchurch FEMALE TRAFFICKING PIRACY DRUGS Wynyard Group MIGRANT SMUGGLING Office locations FIREARMS COUNTERFEIT GOODS Contact us wynyardgroup.com advisor@wynyardgroup.com CYBER CRIME
16 Wynyard Group Solutions for Financial Services Wynyard Risk Management