Forget Chicken Little The Sky is Falling: Current Enterprise Risk Management Strategies for Product Recalls and Corporate Compliance Matters



Similar documents
Introduction to Enterprise Risk Management at UVM DRAFT

Progress Report: Integrating Enterprise Risk Management Analysis Into Corporate Credit Ratings

Products Liability: Putting a Product on the U.S. Market. Natalia R. Medley Crowell & Moring LLP 14 November 2012

PROTIVITI FLASH REPORT

The Upside of Risk: Enterprise Risk Management and Public Real Estate Companies

Enterprise-Wide Risk Assessment

SUPPLEMENT. Product Safety The CEO s Duty to Report Defects Immediately to the Government Managing the Recall that May Follow

Industrial Security & Compliance Using the Holistic Lifecycle Model

Professional. Compliance & Ethics. 19 The cost of unethical behavior. 33 Graduate degrees in Compliance: Training the next generation

Aligning Compliance Program Priorities with Business Objectives

Linking Risk Management to Business Strategy, Processes, Operations and Reporting

The Value of Vulnerability Management*

ENTERPRISE RISK MANAGEMENT AN OVERVIEW. November 2011

Managing Risk at Bank of America Corporation. Overview

Main Page Search August 25, 2010

Clarius Group Risk Management Policy and Framework

Any business relationship between a bank and another entity, by contract or otherwise

Policy : Enterprise Risk Management Policy

University of St. Gallen Law School Law and Economics Research Paper Series. Working Paper No June 2007

State of Minnesota. Enterprise Security Strategic Plan. Fiscal Years

The Effect of Product Safety Regulatory Compliance

How to Assess Legal Risk Management Practices

MASSIVE NETWORKS Online Backup Compliance Guidelines Sarbanes-Oxley (SOX) SOX Requirements... 2

Risk Assessment & Enterprise Risk Management

Beyond risk identification Evolving provider ERM programs

University of Windsor Board of Governors. That the Board of Governors approve of the Enterprise Risk Management Framework.

Cyber security Building confidence in your digital future

Sample Financial institution Risk Management Policy 2011

Enterprise Risk Management

Capital Requirements Directive Pillar 3 Disclosure. December 2015

RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide

Office of Compliance and Ethics Introductory Report. Lynette Fons, Chief Compliance Officer

Distributor Liability Contract Risk Management THOMAS DOUGLASS APRIL 15, 2015

CONSENT OF DEFENDANT GOLDMAN, SACHS & CO.

Meaningful Use and Security Risk Analysis

risk management & crisis response Building a Proactive Risk Management Program

Enterprise Risk Management: Taking the First Steps

New Summer Course. Drug Product Liability Litigation: Principles and Practice

RISK MANAGEMENT FRAMEWORK. 2 RESPONSIBLE PERSON: Sarah Price, Chief Officer

What We Hope to Accomplish Today

Fines, Penalties and Staying Out of Jail

How To Use Risk It

2015 Report on the Current State of Enterprise Risk Oversight:

ERM Program. Enterprise Risk Management Guideline

Enterprise Risk Management, Compliance, Management Advisory Services: An Integrated Approach

Cyber Risks Connect With Directors and Officers

Guiding Principles for Implementing Enterprise Risk Management (ERM)

Case 3:13-cv DRD Document 1 Filed 05/06/13 Page 1 of 14 IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF PUERTO RICO

Enterprise Risk Management (ERM): In Action. January Co-presented by: Michael Yip, Marsh Risk Consulting Norma Essary, DFW International Airport

IDENTIFYING AND RESPONDING TO DATA BREACHES

RISK MANAGEMENT REPORTING GUIDELINES AND MANUAL 2013/14. For North Simcoe Muskoka LHIN Health Service Providers

Understanding Enterprise Risk Management. Presented by Dorothy Gjerdrum Arthur J Gallagher

IFAD Policy on Enterprise Risk Management

IIA POSITION PAPER: THE ROLE OF INTERNAL AUDITING IN ENTERPRISE-WIDE RISK MANAGEMENT

Reflections on Ethical Issues In the Tripartite Relationship

Operational Risk Management - The Next Frontier The Risk Management Association (RMA)

Fraud and Abuse in the Sale and Marketing of Drugs

In respect of Angola and Equatorial Guinea there is some evidence that payments may have been made directly or indirectly to government officials;

How ERM programs evolve

Tying It All Together: Practical ERM Integration. Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation

Risk Management Policy Adopted by:

Third Party Risk Management 12 April 2012

How to Develop Successful Enterprise Risk and Vendor Management Programs

RISK MANAGEMENT OVERVIEW 2011 RISK CONFERENCE SPONSORED BY THE FEDERAL RESERVE BANK OF CHICAGO AND DEPAUL UNIVERSITY

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework

The Legal Aspects of Regulatory Compliance

Data Breach Cost. Risks, costs and mitigation strategies for data breaches

Corporate Governance and Enterprise Risk Management Derek Jackson, Senior Manager 5 September 2005

UDAAP & UBIT: Legal Issues Affecting the Student Loan Industry

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

AUDIT COMMITTEE TERMS OF REFERENCE

Cyber Security and Privacy Services. Working in partnership with you to protect your organisation from cyber security threats and data theft

Setting Up Your Business in the US: Legal Considerations

Overview. Introduction To The Revised GPSD

GALLAGHER CYBER LIABILITY PRACTICE. Tailored Solutions for Cyber Liability and Professional Liability

Cyber and Privacy Risk What Are the Trends? Is Insurance the Answer?

Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements

FAIR TRADING (FEES) AMENDMENT REGULATION (No. 1) 2002

Foreign Corrupt Practices Act:

Risk Management Strategy and Guidelines

Meetings of Public Bodies CHAPTER 13D OPEN MEETING LAW

Fraud Prevention, Detection and Response. Dean Bunch, Ernst & Young Fraud Investigation & Dispute Services

Understanding Your Ethics & Code of Conduct Training Requirements. May 29, 2008

Session 1B DON T LET THEM EAT YOUR LUNCH The Prevention Method for Cyber Risk!

Fraud Risk Management

ENTERPRISE RISK MANAGEMENT FRAMEWORK

Focus on Forensics. Providing valuable insights to corporate decision-makers and their legal counsel May 2009

Blending Corporate Governance with. Information Security

Barbara Ruona, et al., v. Bayer Corporation et al., Case No

Risk Management Policy and Framework

Placing a Value on Enterprise Risk Management ADVISORY

Robert V. Prongay (#270796) 3 Casey E. Sadler (#274241) 1925 Century Park East, Suite 2100 Los Angeles, California Telephone: (310)

STRATEGIES FOR KEEPING A WHISTLEBLOWER IN-HOUSE. By Susan Goetz Markel

Balance Sheet Integrity The Utopian Close: Creating a low risk, highly effective financial close

G. Recalls.

RISK MANAGEMENT POLICY

WILLIS SPECIAL REPORT: 10K DISCLOSURES HOW RETAIL COMPANIES DESCRIBE THEIR CYBER LIABILITY EXPOSURES

Sempra Energy Utilities response Department of Commerce Inquiry on Cyber Security Incentives APR

Cyber Risk, Legal And Regulatory Issues, And Insurance Mitigation ISACA Pittsburgh Information Security Awareness Day

PROJECT RISK MANAGEMENT

Transcription:

Forget Chicken Little The Sky is Falling: Current Enterprise Risk Management Strategies for Product Recalls and Corporate Compliance Matters Mark Kaster Dorsey & Whitney LLP Carol Peterson 3M Company Peter Sipkins Dorsey & Whitney LLP Peter Janzen Land O Lakes, Inc. Robert Kleiber Dorsey & Whitney LLP

Enterprise Risk Management: Agenda Introduction to Enterprise Risk Management What is an ERM? Who is using ERM? How and why do companies use ERM? What is the role of counsel in ERM development and implementation? What are the legal challenges? Comments on ERM - product safety perspective Comments on ERM - food safety perspective ERM and Public Relations Considerations Hypothetical Case Studies Food recall example Product recall example Toy recall example Product Liability Considerations Q&A

What is Enterprise Risk Management? Enterprise Risk Management is a process to identify and analyze risk from an integrated, company-wide perspective. An organization-wide process Risk control at all points of the company Focus on the big picture A process to identify, understand and acknowledge risk (upside and downside) exposure to the company Create a plan to manage and mitigate those risks

How Does ERM Define the Concept of Risk? ERM broadly classified in the following 4 categories: Hazards: recalls Financial: reporting Strategic: Operational: Compliance and liability actions; product Personal injury and property damage Business interruption Cash flow, credit, ratings, disclosures, Markets and competition Technology Capital Regulatory trends Business operations Management structure Information technology Information reporting

ERM helps a company: Why Invest in ERM? Identify and manage risks Align risk strategies Enhance risk response decisions Minimize surprises and losses Allow for proactive engagement and integrated response across the company Seize opportunities, redirect capital, deal effectively with future events that create uncertainty Respond to reduce adverse outcomes and increase upside potential

ERM by the Numbers ERM is becoming more common, expanding from financial sector to other sectors. In 2007, a survey over 60 large industrial manufacturers found: 65% agreed that ERM programs help their organization be more successful 65% felt that a more efficient ERM program would help their organization remain competitive Higher-level management is often responsible for ERM program. 47% cited CFO as the primary executive in charge of ERM; 13% cited CEO; 13% cited General Counsel; 10% Chief Risk Officer. 40% said ERM was transparent to their Board of Directors Audit Committee 33% said ERM program was very effective; 42% mixed feelings; 13% said ineffective. Source: PwC, Manufacturing Barometer, 3Q, 2007

ERM Details In May 2008, Standard & Poor s announced it will begin (starting in 2010) to include a review of ERM at non-financial companies in its ratings process. An S&P July 2009 Progress Report found that ERM programs vary widely across companies. Some preliminary conclusions: Companies find it hard to ensure uniform behavior across the enterprise Inability to provide clear examples of definitions for risk tolerance or risk appetite Silo-based risk management, (focus only at the operational manager level) is prevalent. Link between transparency, disclosure and company confidence about ERM

Sarbanes-Oxley Why is ERM important to your Company? Increased Transparency and Reporting Corporate Shareholder Actions Enhanced Enforcement and Penalties Potential for Criminal Enforcement Corporate Diligence and Board Responsibilities Bottom Line: Poor Risk Management has a Cost: Poor governance Market opinion Negative impact on cost of capital Share price

What are the Long-Term Benefits of an ERM Program for your Company? Reduces operational and compliance issues/surprises Early warning system to respond to corporate threats Allows for quick response to identify and correct deficiencies and improve performance Reduces fines and penalties in enforcement actions Improves decision-making processes Improves capital allocation and credit rating Reduces cost of insurance Responds to Board/Audit Committee needs Establishes a culture of risk management

Some Questions to Ask To Get you Started What are the top risks for your company? How big are the risks and how likely are they to occur? What is the company doing about these risks? Who within the organization is responsible for risk management? How do you measure the success of risk management? How would a loss from a top risk category affect the company? What discussions about ERM have taken place at the Board level? Can you think of an example of how your company recently responded to a risk in your industry? How did the risk affect your company as compared to others?

Next Steps How to Begin an ERM Program Don t need to start from scratch - You already have some components Formalize the program Establish context for the company and make the business case for implementing an ERM program Set ERM objectives Articulate Strategic Goals Establish an ERM infrastructure - Assign Leadership Identify Risks Assess Gaps and Vulnerabilities Analyze and Quantify Risks Assess and Prioritize Determine Risk Response Strategies Develop Effective Communications Across the Company Manage and Exploit Risks Monitor and Review

Managing Emerging Risks: Case Studies on ERM as applied to Product Recalls and Product Liability Comments on ERM - product safety perspective Comments on ERM - food safety perspective Hypothetical Case Studies Food recall example Product recall example Toy recall example

Case Study #1: Setton Pistachio and the Pistachio Industry Case Study The 2009 Pistachio Recall Salmonella FDA The pistachio industry s response What If... Initial contact was different? Distribution was different? All retailers needed to be reached? Consumers had already bought the product? Public relations had occurred at a later time? What about... The attorneys? Insurance?

Case Study #2: ACME Device Co. Case Study FDA s Device Reclassification and Recall Class I device reclassified to a Class III device. Recall required, otherwise a violation of Federal Food, Drug and Cosmetic Act (FDCA) What If... Liability was higher? Public statements were necessary? ACME disagreed with the FDA s reclassification? The device remained in the patient post-surgery? What about... Dissatisfied customers?

Case Study #3: XYZ Toy Company Case Study - Leading Manufacturing and Importer of Toys Emerging Risks on the radar New product safety regulations and mandates Product recalls Access to safe raw materials and quality factories Substantial increase in testing costs Inflation and costs of production What if Product safety teams started at the design level Product recall response team Product reformulations and raw material quality What about Enhanced internal controls and risk management?

Communications Considerations What is the issue? Is the impact to us primary or secondary? Reaching each constituency Prioritizing the recipients What s the message Is it different for different audiences? Will that work in the age of social media? Who does the talking to each? Who is your face? Be prepared Plan, test, practice, plan some more

The importance of ERM in Product Recalls and Product Liability -- Direct and Indirect Costs The Costs of Product Recalls and Product Liability Lawsuits Compensatory Damages: The theory behind compensatory damages is to award the plaintiff an amount to make him or her whole. Punitive Damages: In addition, if the conduct was willful, the jury may award punitive damages to punish the defendant. The bigger the defendant the more it will take to send the message. Litigation Costs: The costs of litigation exist irrespective of the result. Costs include attorney fees, expert witnesses, forensic testing, etc. Product Recall and Government Action: A product liability case may trigger an obligation to recall the product since the manufacturer is now on notice. Pile On Lawsuits: Other plaintiffs may try to ride the coattails of the first plaintiff. The case may spawn a class action lawsuit on behalf of every consumer who has purchased the product. A recent innovation is shareholder lawsuits based on product failures. Media/Industry Exposure: Further damage may result from bad publicity.

CONCLUSION The ERM Value Chart Reduce Costs Decrease Liabilities Increase Revenues Capture Value ERM programs can help you to manage emerging risks and avoid or lessen the impact of risks at your company. The objective is not simply a paper risk management exercise, but rather a springboard for ongoing discussion regarding the benefits of a risk management program for your company.