State of the Art: Risk Management. Jeff M. Spivey, CPP President Security Risk Management



Similar documents
Matthew E. Breecher Breecher & Company PC November 12, 2008

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

International Diploma in Risk Management Syllabus

University of St. Gallen Law School Law and Economics Research Paper Series. Working Paper No June 2007

The PNC Financial Services Group, Inc. Business Continuity Program

The Role of the Board in Enterprise Risk Management

Accreditation Application Forms

Clarius Group Risk Management Policy and Framework

Enterprise Risk Management

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework

and Risk Tolerance in an Effective ERM Program

Cyber-Security Risk Management Framework (CSRM)

Developing an Effective Enterprise Risk Management Program

Introduction to Enterprise Risk Management at UVM DRAFT

2015 Report on the Current State of Enterprise Risk Oversight:

Sample risk committee charter

The College of New Jersey Enterprise Risk Management and Higher Education For Discussion Purposes Only January 2012

Governance and Risk Management in the Public Sector. Fernando A. Fernandez Inter-American Development Bank (202)

Policy : Enterprise Risk Management Policy

The PNC Financial Services Group, Inc. Business Continuity Program

OWN RISK AND SOLVENCY ASSESSMENT AND ENTERPRISE RISK MANAGEMENT

Risk Profile, Appetite, and Tolerance: Fundamental Concepts in Risk Management and Reinsurance Effectiveness

Enterprise Risk Management (ERM): In Action. January Co-presented by: Michael Yip, Marsh Risk Consulting Norma Essary, DFW International Airport

The State of Enterprise Risk Management for Power Companies. January 17, 2013

How To Understand The Role Of An Internal Audit

Risk Based Internal Auditing & Enterprise Risk

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

RISK MANAGEMENT FRAMEWORK. 2 RESPONSIBLE PERSON: Sarah Price, Chief Officer

A structured approach to Enterprise Risk Management (ERM) and the requirements of ISO 31000

Cybersecurity The role of Internal Audit

Dealing with Predictable Irrationality. Actuarial Ideas to Strengthen Global Financial Risk Management. At a macro or systemic level:

Department of Veterans Affairs VA Directive VA Enterprise Risk Management (ERM)

The Role of Internal Audit in Risk Governance

Framing the future of corporate governance Deloitte Governance Framework

APPLICATION OF KING III CORPORATE GOVERNANCE PRINCIPLES 2014

Project Governance a board responsibility. Corporate Governance Network

APPLICATION OF THE KING III REPORT ON CORPORATE GOVERNANCE PRINCIPLES

APPENDIX 50. Enterprise risk management - Risk management overview

Improving Financial Performance, Governance and Compliance

Enterprise Risk Management

Placing a Value on Enterprise Risk Management ADVISORY

Be Prepared. For Anything. Cyber Security - Confronting Current & Future Threats The role of skilled professionals in maintaining cyber resilience

Strategic Risk Management for School Board Trustees

IFAD Policy on Enterprise Risk Management

11/12/2013. Role of the Board. Risk Appetite. Strategy, Planning and Performance. Risk Governance Framework. Assembling an effective team

ENTERPRISE RISK MANAGEMENT POLICY

The Upside of Risk: Enterprise Risk Management and Public Real Estate Companies

Transforming risk management into a competitive advantage kpmg.com

ENTERPRISE RISK MANAGEMENT FOR BANKS

ENTERPRISE RISK MANAGEMENT FRAMEWORK

The Changing Landscape for Trade Compliance Enterprise Risk (and Opportunity) Management

A Risk-Based Audit Strategy November 2006 Internal Audit Department

Framework for Enterprise Risk Management

Guidance Note: Corporate Governance - Board of Directors. March Ce document est aussi disponible en français.

Enterprise Risk Management: COSO, New COSO, ISO Review of ERM

fmswhitepaper Why community-based financial institutions should practice enterprise risk management.

Time to Invest in Short-Term Bonds?

U.S. CFO Program The Four Faces of the CFO Deloitte Touche Tohmatsu

Applying Integrated Risk Management Scenarios for Improving Enterprise Governance

FlyntGroup.com. Enterprise Risk Management and Business Impact Analysis: Understanding, Treating and Monitoring Risk

Take the right steps 9 principles for building the Risk Intelligent Enterprise

Enterprise Risk Management (ERM) for Smaller Insurance Companies

Enterprise Risk Management: Taking the First Steps

Enterprise Risk Management: From Theory to Practice

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors

Applying Risk Assessment to Your Audit Plan Break-out Session T3, Tuesday, October 26 2:00-2:50pm

INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS

Much attention has been focused recently on enterprise risk management (ERM),

Risk Management Policy Adopted by:

Risk Management Practices in the Public and Private Sector: Executive Summary

DTCC RISK COMMITTEE CHARTER

Business Continuity Management

Enterprise Risk Management (ERM) Online References

Board oversight of risk: Defining risk appetite in plain English

ENTERPRISE RISK MANAGEMENT POLICY

STANDARDS OF SOUND BUSINESS AND FINANCIAL PRACTICES. ENTERPRISE RISK MANAGEMENT Framework

Corporate Governance of Banks: A Credit Rating Agency s Approach. presented by Janet Holmes

Integrated Risk Management:

Building a Disaster Recovery Program By: Stieven Weidner, Senior Manager

Enterprise Risk Management in Colleges and Universities

STRESS TESTING GUIDELINE

How To Save Money At The University Of California

Enterprise risk management and business continuity management Together at last

Guiding Principles for Implementing Enterprise Risk Management (ERM)

2nd Edition Board Effectiveness What Works Best

Beyond risk identification Evolving provider ERM programs

Saldanha Bay Municipality. Risk Management Strategy. Inclusive of, framework, procedures and methodology

Risk Assessment & Enterprise Risk Management

Enterprise Risk Management A View. Clive Kelly CRO Zurich Insurance plc/zfs Europe (GI)

Transcription:

State of the Art: Risk Management Jeff M. Spivey, CPP President Security Risk Management

Risk Management Jeff Spivey, CPP President Security Risk Management, Inc.

Challenge the traditional assumptions about risk and risk management based on models inappropriate for the 21st century enterprise

Awareness Uncertainty Horizon Scanning Enterprise Risk Management Holistic Agility

McKinsey

"Real Innovation in Technology Involves a Leap Ahead April 1, 2010

July 13, 2009 Justice Department is Creating Barriers to Companies Trying to Create New Technologies

Learning to Manage what we Don t Know

the Future February 7, 2010

Uncertainty & Complexity

conventional risk management has failed

New Era of Risk Management New Congressional Report: A Call to Action for ERM Regulation Yesterday the Congressional panel overseeing the Troubled Asset Relief Program (TARP) program released a scathing report of the regulatory failures that led to the current financial crisis, Congressional Oversight Panel Special Report on Regulatory Reform. The report concluded The regulatory system not only failed to manage risk, but also failed to require disclosure of risk through sufficient transparency. Steve Minsky, Logic Manager

SEC Ruling The newly proposed SEC ruling goes beyond the executive level to target risk management competency at all employee levels that materially impact the company.

Boards will soon be required by the SEC to report in depth on how their organizations identify risk, set risk tolerances, and manage risk/reward tradeoffs throughout the enterprise. Intended to address the current problem, isolation of the risk management process from both the front line and the board at most organizations. SEC Ruling

The Role of ERM in the Convergence of Security Functions- Deloitte www.aesrm.org

Explain the difference between information security and information risk management

Justify the introduction of the risk office and the position of the chief risk officer

Vice President and Chief Risk Officer Insurance Risk Manager ERM Director Corporate Credit Risk Manager ERM Manager ERM Manager FES Commodity Risk Mg. Director Staff Staff Staff

Why ERM Is Important Every entity, whether for-profit or not, exists to realize value for its stakeholders. Value is created, preserved, or eroded by management decisions in all activities, from setting strategy to operating the enterprise day-to-day. COSO

Today s organizations are concerned about: Risk Management Governance Control Assurance (and Consulting)

ERM Defined: a process, effected by an entity's board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives. Source: COSO Enterprise Risk Management Integrated Framework. 2004. COSO.

Why ERM Is Important ERM supports value creation by enabling management to: Deal effectively with potential future events that create uncertainty. Respond in a manner that reduces the likelihood of downside outcomes and increases the upside.

The ERM Framework Entity objectives can be viewed in the context of four categories: Strategic Operations Reporting Compliance

The ERM Framework ERM considers activities at all levels of the organization: Enterprise-level Division or subsidiary Business unit processes

Internal Environment Establishes a philosophy regarding risk management. It recognizes that unexpected as well as expected events may occur. Establishes the entity s risk culture. Considers all other aspects of how the organization s actions may affect its risk culture.

Risk tolerance the acceptable level of variation around objectives, is aligned with risk appetite.

IS a RISK AN OPPORTUNITY?

Manage and Capitalize on Business Risk Enterprises achieve return by taking risks Some try to eliminate the very risks that drive profit Guidance was needed on how to manage risk effectively

Treating a RISK REITA- E

Risk Intelligence Involves identifying those incidents, occurring internally or externally, that could affect strategy and achievement of objectives. Addresses how internal and external factors combine and interact to influence the risk profile.

Risk Intelligence Challenging basic business assumptions can help identify "Black Swans" and provide first-mover advantage Defining the corporate risk appetite and risk tolerances can help reduce The risk of ruin. Taking a longer-term perspective can aid in identifying the potential unintended consequences of short-term decisions.

Risk Intelligence Anticipating potential causes of failure can improve chances of survival and success through improved preparedness. Factoring in velocity and momentum can improve speed of response and recovery. Verifying sources and the reliability of information can improve insights for decision making and thus decision quality.

"Risk intelligence is dynamic. There is no set of rules to follow, no permanent certification, no way to insulate the organization from the forms that uncertainty and turbulence will take in the future. Rather, there is only a path to creating value and managing risks that enables better decisions. Fred Funston, Intelligent Enterprise"

These are important Risk Culture Risk Intelligence (The Intelligent Enterprise) Risk Tolerance Exploiting Risks

Risk Management Innovation Dave Snowden suggest there are three necessary conditions for innovation to take place. Starvation of familiar resource, forcing you to find new approaches, doing things in a different way; Pressure that forces you to engage in the problem; Perspective Shift to allow different patterns and ideas to be brought into play.

Thank You! Jeff M. Spivey, CPP JSpivey@srmsig.com Jeff.Spivey@riskiq.com 704-521-8401