Efficient risk management. Presentation to the Interdepartmental Accounting Group 2013 conference

Size: px
Start display at page:

Download "Efficient risk management. Presentation to the Interdepartmental Accounting Group 2013 conference"

Transcription

1 Efficient risk management Presentation to the Interdepartmental Accounting Group 2013 conference

2 Outline - Enterprise Risk Management a definition - The promise vs the reality. What s the problem? - What does a good risk management process look like? - Lessons for making it work - Questions and discussion 2

3 Context Enterprise risk management (ERM) - The method and process for the whole organisation to manage risk and seize opportunity to achieve objectives. Promise ERM should help the organisation achieve its objectives by helping to identify areas of highest or emerging priority and focus attention and resource on them Reality But ERM is not (usually) effectively supporting the Board, CEO or Senior Exec level in a practical and structured way Why not and how can we make it work? 3

4 The ERM Promise vs. Reality Promise Regular executive level conversation Insightful summary new information Gets the executive on the same page Exec takes collective responsibility Drives action on the highest priority areas Live feedback loop showing progress Embedded into normal BAU processes Quick and easy Reality Not fit for the executive, becomes irrelevant Death by register hundreds of data points No new information - themes, trends, aggregation No actions or feedback cycle Silos with no conversation across the organisation An overhead burden - a compliance activity Systems driven Lost in the jargon what are we doing again? 4

5 Complexity Standards Numerous standards and guidance materials APRA Prudential Standards CPS 220 Risk Management CPS 510 Governance AS/NZS ISO 31000:2009 Risk Management Principles and Guidelines Others Safety Risk Management, Better Practice Guide Risk Management Clinical Risk Management / Quality IT risk management standards COBIT - A Business Framework for the Governance and Management of Enterprise IT ITIL Framework Compliance & Risk Management The Foundation - Governance, Risk and Compliance Credit Risk Management (Basel), Guidelines on Recognition of an External Credit Assessment Institution, Submission to the Basel Committee on Banking Supervision Credit Risk Modelling: Current Practices and Applications

6 Complexity Models Numerous ERM models Risk Management Framework Risk Vision and Strategy Definition of Risk Strategy and the Principles for the Management of Risk Risk Management Framework Policy Overarching Framework Governing the Management of Risk Risk Appetite Statement Appetite setting process and articulation of bank-wide and operational limits Principal Risk Policies Policies for the Management, Measurement and Mitigation of Risk Liquidity & Funding Credit Risk Market Risk Risk Insurance Risk Pension Risk Model Risk Operational Risk Technology Risk Regulatory Risk Strategic and Reputation Risk Tax Risk Business Risk Control Standards Key Control Framework to optimise risk/reward Business Unit Operational Procedures Individual Risk Procedures for the Day-to-Day Management of Risk Framework and supporting documents owned by the Board Risk Management Policies owned by the Executive Owned and implemented by BU s Risk Strategy Risk Profile Risk Appetite Risk Mitigation Performance Optimisation Monitoring & Reporting Variance Analysis & Remediation 6

7 Complexity Systems Numerous vendors and products Vendor SAI Global SAS Cura Oracle Protecht Methodware Tickit Systems SAP IBM BearingPoint Convercent EMC Thomas Reuters Wynard MetricStream Protiviti Agiliance Lockpath Brinqa Product name Compliance 360 / Lawlex SAS Enterprise GRC Cura Haley WORMS Enterprise Risk Assessor Tickit On Demand SAP OpenPages GRC R2Go Convercent RSA Archer egrc Accelus Wynyard Risk Management MetricStream IT GRC Solution Governance Portal Agiliance RiskVision OpenGRC Keylight Brinqa Risk Analytics 7

8 So what is an alternative? Risk is a fundamental plank of the framework of internal control 8

9 So what is an alternative?... Go back to basics a top down approach Start with the objectives and the pay off Reinforce with design principles Collaborative design and implementation Support and build capacity and capability 9

10 Design Principles - example Vision / Aspiration Processes Key objectives / benefits: Facilitates insightful quarterly conversation at Executive level new information Provides simple visibility of relevant risks to management team - sharing Drives actions and has a visible impact on the risk profile Costs less than $X Key risks, their potential consequences, impacts and key controls need to be documented Enabling ICT systems to come after the practice is embedded into the culture People Systems Utilise a single set of definitions for key risk areas (categories) A single enterprise risk register Common language - one set of risk materiality definitions (consequence, likelihood, risk heatmap and risk treatment & escalation) Executive monitor enterprise-wide risk profile on a quarterly basis Audit and Risk Committee monitors the system of risk management and assurance Division Heads will own risks Divisions can design their own fit for purpose process so long as it uses the common language Structure Risk management function to: Maintain policy, process & templates Provide support & advice to divisions (training, assessment, facilitation, etc) Facilitate analysing, monitoring & reporting of top risks to Executive (quarterly) 10

11 Risk management function Collaborative design visualise a process Office of CEO Quarterly Risk Management Report Corporate Division Division X Division Y Key points Risk category outside of appetite / tolerance Emerging risk or trend New projects or actions Key trend or environmental change Insight and experience Possible new risk or category of risk Executive strategic discussion point Division Z Input Facilitate Aggregate Add insights Provide support and advice Own Policy & Procedure Output

12 Rare Unlikely Likelihood Possible Likely Almost certain Collaborative design - visualise an output Significant Minor Moderate Major Severe Delivery 1. Delivery category A 2. Delivery category B 3. Delivery category C 4. Delivery category D 5. Delivery category E 8 7 Key changes, movements, and trends: Movements away from target What has changed, new causes, etc. Enablers 6. Governance 7. Knowledge / systems management 8. People / culture 9. Program / project / contracts management 10. Resource management Movements towards target What has changed, new causes, etc. Consequence (Impact) Risk rating: L H Low High M VH Medium Very high x Current risk rating Steady trend x Target risk rating Downward trend Upward trend

13 The important stuff Success factors - Stakeholders CEO/Board buy-in Credible practitioners (executive agenda, facilitate Exec meeting) Agree the purpose simple and achievable promise vs reality! Agree design principles, output & process Allow flexibility, don t mandate anything you don t have to Be realistic about timeframes iterative Clever assignment of risk category owners can help sharing and reduce silos Aim to be part of conversational rhythm of the organisation Help the divisions succeed be part of the solution, take responsibility. 13

14 The important stuff Success factors - Technical Get the context right up front don t proceed until you do Invest in creating a single language, include divisions Invest in capability building don t lob policies, templates and wait Don t buy into general concerns get specific, focus on practical actions The two fundamental questions in risk facilitation: What could cause that to happen? What is at risk? Focus on Current vs. Target and what extra do we need to do (if anything) Remove mitigating controls from Exec & divisional reporting it s generally noise Invest in aggregation, themes, trends generate new information. 14

15 Questions? Contact details Joshua Chalmers

16 Outputs case study 16

17 Outputs case study (cont d) 17

18 Outputs case study (cont d) 18

Sample Corporate Risk Management Policy

Sample Corporate Risk Management Policy Sample Corporate Risk Management Policy This document provides a sample Risk Management policy which includes an overview of the key roles and responsibilities of the various stakeholders. Risk Oversight

More information

Strengthening Your Enterprise Risk Management Process

Strengthening Your Enterprise Risk Management Process Strengthening Your Enterprise Risk Management Process Belinda Mumma, Senior Consultant, Enterprise Risk Management Services bmumma@sollievo.com (866) 605-5664 x3400 Discussion Topics Definition of Enterprise

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy 2017-2019 Created by: Role Name Title Author / Editor Kevin McMahon Head of Risk Management & Resilience Lead Executive Margo McGurk Director of Finance & Performance Approved

More information

Embedding Operational Risk

Embedding Operational Risk Embedding Operational Risk Banking & Payments Federation Ireland Angela Calapa, Risk & Regulatory Director Areas of Challenge for Embedding Operational Risk Most banks face a significant number of challenges

More information

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector The Sector Skills Council for the Financial Services Industry National Occupational Standards Risk Management for the Financial Sector Final version approved April 2009 IMPORTANT NOTES These National Occupational

More information

ICAAP. Engaging the business in risk management. A presentation to FIDE Forum by Penny Fosker. 10 January towerswatson.com

ICAAP. Engaging the business in risk management. A presentation to FIDE Forum by Penny Fosker. 10 January towerswatson.com ICAAP Engaging the business in risk management A presentation to FIDE Forum by Penny Fosker 10 January 2013 1 Agenda What is an ICAAP and what s in it for me? Managing capital and risk or managing my business?

More information

ERM vs. Internal Audit

ERM vs. Internal Audit ERM vs. Internal Audit Differences and Overlaps Kuwait ERM Conference March 2015 Evolving expectations Risk Management Programs Organisations today are struggling with effectively managing risks across

More information

Certificate in Internal Audit 3

Certificate in Internal Audit 3 Certificate in Internal Audit 3 Risk Based Auditing- the next level Who should attend? Heads of Audit, Audit managers and senior auditors Auditors responsible for developing or implementing a risk based

More information

HCCA Audit & Compliance Committee Conference. February 29-March 1, Drivers of ERM. Enterprise Risk Management in Healthcare.

HCCA Audit & Compliance Committee Conference. February 29-March 1, Drivers of ERM. Enterprise Risk Management in Healthcare. Enterprise Risk Management in Healthcare Deloitte & Touche LLP Heather Hagan, Senior Manager Nancy Perilstein, Senior Manager February 29, 2016 Discussion Items Drivers of Enterprise Risk Management (ERM)

More information

Risk Management at Statistics Canada

Risk Management at Statistics Canada Risk Management at Statistics Canada Presentation to Workshop on Risk Management Practices in Statistical Organizations J. Mayda April 25 th, 2016 Introduction Statistics Canada has had a formal Integrated

More information

29/11/2017. Risk Management Policy

29/11/2017. Risk Management Policy 1 Purpose APA Group (APA) is Australia s leading energy infrastructure business delivering smart, reliable and safe solutions through our deep industry knowledge and interconnected infrastructure. Risk

More information

LEADING WITH GRC. The Return of the ERM Extending Beyond It s Past Scope. Brenda Boultwood, SVP Industry Solutions, MetricStream

LEADING WITH GRC. The Return of the ERM Extending Beyond It s Past Scope. Brenda Boultwood, SVP Industry Solutions, MetricStream LEADING WITH GRC The Return of the ERM Extending Beyond It s Past Scope Brenda Boultwood, SVP Industry Solutions, MetricStream The Return Of The Jedi Extending beyond its past scope June 7, 2017 In Today

More information

Aligning and Integrating ERM and Business Process. Federal ERM Summit September 9, :00-12:00

Aligning and Integrating ERM and Business Process. Federal ERM Summit September 9, :00-12:00 Aligning and Integrating ERM and Business Process Federal ERM Summit September 9, 2013 11:00-12:00 1 Agenda Defining Risk and ERM The ERM Value Proposition An Integrated ERM Framework Aligning ERM with

More information

ENTERPRISE RISK MANAGEMENT THE KEY TO BUSINESS SUCCESS By Phil Griffiths FCA

ENTERPRISE RISK MANAGEMENT THE KEY TO BUSINESS SUCCESS By Phil Griffiths FCA ENTERPRISE RISK MANAGEMENT THE KEY TO BUSINESS SUCCESS By Phil Griffiths FCA Chapter 1 Fundamentals of Enterprise Risk Management Risk management has become a vital ingredient in the entrepreneurial culture

More information

Risk Management Update ISO Overview and Implications for Managers

Risk Management Update ISO Overview and Implications for Managers Contents - ISO 31000 highlights 1 - Changes to key terms and definitions 2 - Aligning key components of the risk management framework 3 - The risk management process 4 - The principles of risk management

More information

Sample Strategy and Value Oversight Policy

Sample Strategy and Value Oversight Policy Sample Strategy and Value Oversight Policy This document provides a sample Strategy & Value Oversight policy which includes a high level overview of the key roles and responsibilities of the various participants.

More information

Treasury s Leading Role in Enterprise Risk Management

Treasury s Leading Role in Enterprise Risk Management Treasury s Leading Role in Enterprise Risk Management May 2015 Presented To Presented By Kevin Ruiz Principal 2015 Treasury Strategies, Inc. All rights reserved. Situation The Expanding Scope and Value

More information

Enterprise Risk Management Course outline

Enterprise Risk Management Course outline Enterprise Risk Management Course outline Day One: Understanding Enterprise Risk Management (ERM) What is ERM Explanation of ERM and why it is not fully understood The current economic crisis and how ERM

More information

Don t make the same mistake twice! Avoiding repeat violations of Reliability Standards

Don t make the same mistake twice! Avoiding repeat violations of Reliability Standards Don t make the same mistake twice! Avoiding repeat violations of Reliability Standards 17 November 2010 www.morganlewis.com www.ey.com Welcome to Don t Make the Same Mistake Twice! Avoiding Repeat Violations

More information

RSA Archer Compliance Management 5.2 Webcast

RSA Archer Compliance Management 5.2 Webcast RSA Archer Compliance Management 5.2 Webcast Marshall Toburen egrc Risk Solutions Manager RSA Archer 1 Agenda Introductory Comments 5.2 Enhancements Overview RSA Archer approach to Compliance Management

More information

Enterprise Risk Management Montana State Fund

Enterprise Risk Management Montana State Fund Enterprise Risk Management Montana State Fund Report to the Board January 28, 2011 Presented by: Mary Peter, Director of Enterprise Risk Management Enterprise Risk Management (ERM) Defined An integrated

More information

Role of Board of Directors in Risk Management. CPA Erick Audi Thursday, 15 th November 2018

Role of Board of Directors in Risk Management. CPA Erick Audi Thursday, 15 th November 2018 Role of Board of Directors in Risk Management Presentation by: CPA Erick Audi Thursday, 15 th November 2018 Uphold public interest Presentation Agenda Introduction & Definitions Legal Provisions/Guidelines

More information

CGEIT Certification Job Practice

CGEIT Certification Job Practice CGEIT Certification Job Practice Job Practice A job practice serves as the basis for the exam and the experience requirements to earn the CGEIT certification. This job practice consists of task and knowledge

More information

Risk Management Policy and Framework

Risk Management Policy and Framework Risk Management Policy and Framework Introductory Note to User: CompanyLongName There is no requirement in Australia for a non-publicly listed entity (other than a company regulated by APRA) to comply

More information

ORSA engaging the business in Solvency II. Colm Guiry, Naren Persad 20 February 2012

ORSA engaging the business in Solvency II. Colm Guiry, Naren Persad 20 February 2012 ORSA engaging the business in Solvency II Colm Guiry, Naren Persad 20 February 2012 What is the ORSA? slide 2 Existing and expected future guidance from EIOPA slide 3 Article 45 Framework Directive (July

More information

The current state of play. The future of risk in the Australian health sector

The current state of play. The future of risk in the Australian health sector The current state of play The future of risk in the Australian health sector Foreword David Roberts Global Health Executive Asia-Pacific Health Leader Welcome to the EY series on the future of risk in

More information

B U S I N E S S R I S K M A N A G E M E N T L T D

B U S I N E S S R I S K M A N A G E M E N T L T D B U S I N E S S R I S K M A N A G E M E N T L T D Governance, Risk and Compliance (GRC) After completing this course you will be able to Course Level Understand the requirements and benefits of GRC Develop

More information

Heightened standards for compliance risk management. Lines of defense compliance s role

Heightened standards for compliance risk management. Lines of defense compliance s role Heightened standards for risk management Lines of defense s role Post-financial crisis, the Office of the Comptroller of the Currency (OCC) developed a set of heightened expectations to enhance the risk

More information

Board Corporate Governance and Risk Committee

Board Corporate Governance and Risk Committee Policy Risk management Authorising Committee / Department: Responsible Committee / Department: Document Code: Board Corporate Governance and Risk Committee POL OPCEO Risk management Introduction The purpose

More information

Performance Risk Management Jonathan Blackmore, May 2013

Performance Risk Management Jonathan Blackmore, May 2013 Performance Risk Management Jonathan Blackmore, May 2013!@# Topics The world is changing How leading companies turn risk into results Back to basics 2 Company focus Market Risk Management an evolving journey

More information

IRM s Professional Standards in Risk Management PART 1 Consultation: Functional Standards

IRM s Professional Standards in Risk Management PART 1 Consultation: Functional Standards IRM s Professional Standards in Risk PART 1 Consultation: Functional Standards Setting standards Building capability Championing learning and development Raising the risk profession s profile Supporting

More information

The Urbis Academy Trust Risk Management Strategy

The Urbis Academy Trust Risk Management Strategy The Urbis Academy Trust Risk Management Strategy 1.0 Introduction 1.1 Risk management is the process whereby the School/Trust methodically addresses the risks attaching to its objectives and associated

More information

This policy establishes the approach to risk management at Sunshine Coast Council (Council) and outlines the guiding principles and framework.

This policy establishes the approach to risk management at Sunshine Coast Council (Council) and outlines the guiding principles and framework. Organisational policy Risk Management Policy Corporate Plan reference: Endorsed by Chief Executive Officer: Manager responsible for policy: A strong community In all our communitites, people are included,

More information

Sub-section Content. 1 Preliminaries - Post title: Head of Group Risk - Reports to: CRO - Division: xxx - Department: xxx - Location: xxx

Sub-section Content. 1 Preliminaries - Post title: Head of Group Risk - Reports to: CRO - Division: xxx - Department: xxx - Location: xxx Sub-section Content 1 Preliminaries - Post title: Head of Group Risk - Reports to: CRO - Division: xxx - Department: xxx - Location: xxx 2 Job Purpose - To assist in the maintenance and development of

More information

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance Sharon Hale and John Argodale May 28, 2015 2 From Dictionary.com Enterprise: A project undertaken or to be undertaken, especially one that is important or difficult or that requires boldness or energy

More information

Leveraging ERM to meet. and create business value. Management Flora Do, Senior Manager, Enterprise Risk Management

Leveraging ERM to meet. and create business value. Management Flora Do, Senior Manager, Enterprise Risk Management Leveraging ERM to meet regulatory requirements and create business value Susan Hwang, National Leader, Enterprise Risk Management Flora Do, Senior Manager, Enterprise Risk Management March 27, 2012 With

More information

ISACA. The recognized global leader in IT governance, control, security and assurance

ISACA. The recognized global leader in IT governance, control, security and assurance ISACA The recognized global leader in IT governance, control, security and assurance High-level session overview 1. CRISC background information 2. Part I The Big Picture CRISC Background information About

More information

Session 608 Tuesday, October 22, 2:45 PM - 3:45 PM Track: Industry Insights

Session 608 Tuesday, October 22, 2:45 PM - 3:45 PM Track: Industry Insights Session 608 Tuesday, October 22, 2:45 PM - 3:45 PM Track: Industry Insights Can Large Transformation Projects Work? Isabelle Baird Manager, Technology Consulting, PricewaterhouseCoopers LLP isabelle.baird@us.pwc.com

More information

MANAGING RISK AT SUNCORP

MANAGING RISK AT SUNCORP SUNCORP GROUP LIMITED CORPORATE GOVERNANCE MANAGING RISK AT SUNCORP 1 MANAGING RISK AT SUNCORP Managing risk is a key contributor to Suncorp Group's success. The Board and management recognise that an

More information

Governance Institute of Australia Ltd

Governance Institute of Australia Ltd Governance Institute of Australia Ltd Management Policy 1. Overview management is a key element of effective corporate governance. In view of this, Governance Institute of Australia Ltd (Governance Institute)

More information

Improve GRC Maturity through Combined Assurance

Improve GRC Maturity through Combined Assurance White Paper Improve GRC Maturity through Management External Assurance Providers Internal Assurance Providers Oversight Governance; Risks and Controls Figure 1: The Model What is Combined Assurance? With

More information

CEO GUIDE TO RISK. Management and governance of health and safety risk

CEO GUIDE TO RISK. Management and governance of health and safety risk CEO GUIDE TO RISK Management and governance of health and safety risk Help to keep your people safe, meet your due diligence duties and build a more resilient business RISK RELATIONSHIPS RESOURCES www.zeroharm.org.nz

More information

Guidance Note: Corporate Governance - Board of Directors. January Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Board of Directors. January Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Board of Directors January 2018 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance

More information

Risk Committee Charter ISSUE DATE: 15 NOVEMBER 2018 RISK COMMITTEE CHARTER. ISSUE DATE 15 NOVEMBER 2018 PAGE 1 OF 7

Risk Committee Charter ISSUE DATE: 15 NOVEMBER 2018 RISK COMMITTEE CHARTER. ISSUE DATE 15 NOVEMBER 2018 PAGE 1 OF 7 Risk Committee Charter ISSUE DATE: 15 NOVEMBER 2018 RISK COMMITTEE CHARTER. ISSUE DATE 15 NOVEMBER 2018 PAGE 1 OF 7 Introduction This is the Charter of the Risk Committee. The Risk Committee, appointed

More information

Practices in Enterprise Risk Management

Practices in Enterprise Risk Management Practices in Enterprise Risk Management John Foulley Risk Management Practices Head SAS Institute Asia Pacific What is ERM? Enterprise risk management is a process, effected by an entity s board of directors,

More information

Charter for Group Internal Audit. Approved by the Chairman on behalf of the Board of Directors on 18 January 2018.

Charter for Group Internal Audit. Approved by the Chairman on behalf of the Board of Directors on 18 January 2018. Charter for Group Internal Audit 2018 Approved by the Chairman on behalf of the Board of Directors on 18 January 2018. Charter for Group Internal Audit 2017 Table of contents 1. Introduction... 3 1.1 GIA

More information

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010 Catching Fraud During a Recession Through Superior Internal Controls FICPA s 25 th Annual Accounting Show J. Stephen Nouss September 29, 2010 1 Session Objectives Fraud Facts (2008 Association of Certified

More information

ASX announcement. CBA releases progress report on remedial action plan

ASX announcement. CBA releases progress report on remedial action plan ASX announcement CBA releases progress report on remedial action plan Wednesday, 10 October 2018: Commonwealth Bank of Australia (CBA) today released Promontory Australasia s first independent report into

More information

Enterprise Risk Management

Enterprise Risk Management BUSINESS RISK MANAGEMENT LTD Enterprise Risk Management Who should attend? Risk managers Managers and Directors responsible for the risk management function or process Senior Internal Auditors and audit

More information

Charter for Enterprise Risk Management

Charter for Enterprise Risk Management for Enterprise Risk Management Prepared by: Shannon Sinclair Version: 1.2 Document Id: Date: Release Date TABLE OF CONTENTS TABLE OF CONTENTS... i 1. Background... 1 2. Objectives... 1 3. Scope... 2 3.1

More information

HOW TO AVOID THE DANGER OF WEAK CONTROLS IN THIRD-PARTY RISK MANAGEMENT

HOW TO AVOID THE DANGER OF WEAK CONTROLS IN THIRD-PARTY RISK MANAGEMENT E-Guide HOW TO AVOID THE DANGER OF WEAK CONTROLS IN THIRD-PARTY RISK MANAGEMENT SearchSecurity S ecurity expert Michael Cobb explains how to put in place additional safeguards to protect the system and

More information

An integrated approach for assessing risk culture at financial institutions

An integrated approach for assessing risk culture at financial institutions An integrated approach for assessing risk culture at financial institutions House of Finance, Goethe University, Frankfurt Dr, Head of Enterprise Standards, What is risk culture? While there is no single

More information

The Kirkup report. Governance Project Mary Aubrey, Director of Governance May 2015

The Kirkup report. Governance Project Mary Aubrey, Director of Governance May 2015 The Kirkup report Governance Project Mary Aubrey, Director of Governance May 2015 The Governance Project group The Governance Project group Communication plan PLANNING PHASE Meetings held with the Heads

More information

SPECIMEN PAPER. 992 Risk Management in Insurance

SPECIMEN PAPER. 992 Risk Management in Insurance SPECIMEN PAPER 992 Risk Management in Insurance The following is a specimen coursework assignment question and answer. It provides a guide as to the style and format of coursework questions that will be

More information

Continuous Auditing. Human Action Metrics. By Santos Monroy April 2, 2009

Continuous Auditing. Human Action Metrics. By Santos Monroy April 2, 2009 Continuous Auditing Human Action Metrics By Santos Monroy Continuous Auditing: Human Action Metrics Sample Transaction Audit Process Improvement Continuous Auditing (CA) Interdependent Partnership Achieving

More information

Corporate Governance and Financial Markets

Corporate Governance and Financial Markets Corporate Governance and Financial Markets World Congress of Accountants Istanbul, Turkey 14 November 2006 Jerry Edwards Senior Advisor on Accounting and Auditing Policy Financial Stability Forum Basel,

More information

Implementing an Organisation Wide Testing Approach

Implementing an Organisation Wide Testing Approach Implementing an Organisation Wide Testing Approach Graham Thomas Independent Software Testing Consultant TESTNET Nieuwegein, NBC 16 th September 2008 ABSTRACT Over the last seven years I have been involved

More information

Control and Risk Management Policy

Control and Risk Management Policy Control and Risk Management Policy Contents 1. Purpose... 2 2. Scope of application... 2 3. Responsibilities... 2 4. Description of the process... 4 4.1. Identifying risks... 4 4.2. Risk assessment...

More information

More than 2000 organizations use our ERM solution

More than 2000 organizations use our ERM solution 5 STEPS TOWARDS AN ACTIONABLE RISK APPETITE Contents New Defining Pressures Risk Appetite and Risk Tolerance Benefits The 5 Best of Practices Risk Assessments Benefits of an Actionable Risk Appetite More

More information

Operational Risk Management

Operational Risk Management Operational Risk Management Aligning your organisation to harness risk David Walter General Manager, GRC & IAM EMEA 1 Session Abstract In this session you will learn: Challenges to effective Operational

More information

RISK MANAGEMENT REPORT

RISK MANAGEMENT REPORT RISK MANAGEMENT REPORT RISK POLICY STATEMENT Robust and effective management of risks is an essential and integral part of corporate governance. It helps to ensure that the risks encountered in the course

More information

Using Archer to Monitor Security Compliance at AT&T

Using Archer to Monitor Security Compliance at AT&T Using Archer to Monitor Security Compliance at AT&T Rebecca Finnin Director, Chief Security Office 1 Agenda Archer Overview What is it and why would you use it? Security Governance, Risk and Compliance

More information

Maximizing value from your lines of defense

Maximizing value from your lines of defense Insights on governance, risk and compliance December 2013 Maximizing value from your lines of defense A pragmatic approach to establishing and optimizing your LOD model Contents Introduction Are you getting

More information

Resource Management?

Resource Management? Resource Management? I ve got Excel and half a day a week thank you very much. What do I need to know? Presented by David Dunning, Director, Corporate Project Solutions Your Speaker Today David Dunning

More information

Certificate in Enterprise Risk Management

Certificate in Enterprise Risk Management Certificate in Enterprise Risk Management Who should attend? Risk managers Managers and Directors responsible for the risk management function or process Senior Internal Auditors and audit managers Other

More information

The 10 th Annual Management Accounting Conference

The 10 th Annual Management Accounting Conference The 10 th Annual Management Accounting Conference Navigating Risk Management Frameworks as a Management Accountant Travellers Beach Hotel and Club, Mombasa Wednesday, 26 th July 2017 Uphold. Public. Interest

More information

Risk Management and Assurance Strategy

Risk Management and Assurance Strategy Risk Management and Assurance Strategy Version 5.0 Policy number ULHT-MD-GOV-RM-STRAT Document author(s) Head of 2021 Programme Contributor(s) Approved by Policy Approval Group Date approved Date Published

More information

Risk culture. Building great organisations and growing your foundation for success CAPABILITY STATEMENT 2016

Risk culture. Building great organisations and growing your foundation for success CAPABILITY STATEMENT 2016 Risk culture Building great organisations and growing your foundation for success CAPABILITY STATEMENT 2016 What the regulators are saying about risk culture 2 3 An effective risk culture guides and facilitates

More information

How to Measure the Value of Your Internal Audit Group

How to Measure the Value of Your Internal Audit Group How to Measure the Value of Your Internal Audit Group Best practices to follow, pitfalls to avoid and success metrics to measure May 17, 2012 Agenda Strategic challenges: Implications for the enterprise

More information

Risk Management Implementation Plan

Risk Management Implementation Plan 41 07 Management Author: Dr Kevin Street; Interim Chief Officer Date: 20 November 2015 Version: 1 Sponsoring Executive Director: Rhiannon Beaumont-Wood Who will present: Kevin Street Date of Board / Committee

More information

Building Resiliency Across the Value Chain The Bigger Picture

Building Resiliency Across the Value Chain The Bigger Picture Building Resiliency Across the Value Chain The Bigger Picture DISCLAIMER This presentation is for informational purposes only. This document contains certain statements that may be deemed forward-looking

More information

On the road(map) again. Balancing the emerging regulatory requirements in the Middle East public sector

On the road(map) again. Balancing the emerging regulatory requirements in the Middle East public sector On the road(map) again Balancing the emerging regulatory requirements in the Middle East public sector 38 Deloitte A Middle East Point of View Fall 2014 Public Sector Final destination Governments in the

More information

RISK MANAGEMENT FRAMEWORK OF THE CGIAR SYSTEM

RISK MANAGEMENT FRAMEWORK OF THE CGIAR SYSTEM RISK MANAGEMENT FRAMEWORK OF THE CGIAR SYSTEM Approved by the System Council at its 5 th meeting (SC/M5/DP12) 10 November 2017 CGIAR System Organization Page 1 of 9 Introduction 1. The scope of CGIAR s

More information

"IT Governance Helping Business Survival

IT Governance Helping Business Survival "IT Governance Helping Business Survival Steve Crutchley CEO & Founder Consult2Comply www.consult2comply.com Introduction Steve Crutchley Founder & CEO of Consult2Comply 39 Years IT & Business Experience

More information

HSE Assurance Overview

HSE Assurance Overview HSE Assurance Overview Agenda 1 2 3 4 5 Assurance Framework Three Lines of Defense Model Interview Techniques Lessons Learned Documenting findings BHP Risk and Assurance Hierarchy 3 Assurance Model Life

More information

ISACA All Rights Reserved.

ISACA All Rights Reserved. Tichaona Zororo CIA, CISA, CISM, CRISC, CRMA, CGEIT, COBIT 5 Certified Assessor B.Sc. Honours Information Systems, PGD Computer Auditing Accredited COBIT 5 Trainer ISACA 2016. Business Value Value

More information

Risk appetite and assurance Do you know your limits?

Risk appetite and assurance Do you know your limits? Risk appetite and assurance Do you know your limits? Paul Day Partner Banking & Capital Markets Deloitte UK Tim Thompson Partner Quantitative Risk & Finance Deloitte UK Stephen Boyd Senior Manager Risk

More information

Strategic Risk Assessment. A first step for improving risk management and governance. COVER STORY. By Mark L. Frigo and Richard J.

Strategic Risk Assessment. A first step for improving risk management and governance. COVER STORY. By Mark L. Frigo and Richard J. Strategic Risk Assessment A first step for improving risk management and governance. By Mark L. Frigo and Richard J. Anderson December 2009 I STRATEGIC FINANCE 25 The recent economic environment and negative

More information

Risk Advisory Services Developing your organisation s governance for competitive advantage

Risk Advisory Services Developing your organisation s governance for competitive advantage Advisory Services Developing your organisation s governance for competitive advantage The Deloitte Advisory Platform of Services can help you to govern your strategic plan to guide your operations measure

More information

ERM: Risk Maps and Registers. Performing an ISO Risk Assessment

ERM: Risk Maps and Registers. Performing an ISO Risk Assessment ERM: Risk Maps and Registers Performing an ISO 31000 Risk Assessment Agenda Following a Standard? Framework First Performing a Risk Assessment Assigning Risk Ownership Data Management Questions? Following

More information

CORPORATE GOVERNANCE FRAMEWORK

CORPORATE GOVERNANCE FRAMEWORK CORPORATE GOVERNANCE FRAMEWORK 1 P a g e TABLE OF CONTENTS Page 1. Introduction 3 2. Purpose 3 3. Scope 4 4. Governance Principles 4 4.1 Role Players 4 4.2 Combined Assurance 4 5. Governance Structure

More information

A SHARED VISION OF NATIONAL APPROPRIATE MITIGATION ACTIONS (NAMAS) AS PART OF A 2015 INTERNATIONAL CLIMATE AGREEMENT

A SHARED VISION OF NATIONAL APPROPRIATE MITIGATION ACTIONS (NAMAS) AS PART OF A 2015 INTERNATIONAL CLIMATE AGREEMENT A SHARED VISION OF NATIONAL APPROPRIATE MITIGATION ACTIONS (NAMAS) AS PART OF A 2015 INTERNATIONAL CLIMATE AGREEMENT CCAP submission to European Commission stakeholder consultation June 2013 Dialogue.

More information

COSO Enterprise Risk Management Framework- Integrating Strategy and Performance

COSO Enterprise Risk Management Framework- Integrating Strategy and Performance www.pwc.com COSO Enterprise Risk Management Framework- Integrating Strategy and Performance October, 2017 Agenda 1 Introducing COSO 2 Why update the Framework now? 3 What has changed? 4 What does it mean

More information

DUBAL s ISO based ERM Program

DUBAL s ISO based ERM Program DUBAL s ISO 31000-based ERM Program Building a Harmonized, Proactive and Sustainable Approach to Risk Management October, 2013 Toby Shore Corporate Treasurer & Chief Risk Officer DUBAL Key Things To Discuss

More information

NATIONAL AUSTRALIA BANK LIMITED ACN BOARD RISK COMMITTEE CHARTER

NATIONAL AUSTRALIA BANK LIMITED ACN BOARD RISK COMMITTEE CHARTER NATIONAL AUSTRALIA BANK LIMITED ACN 004 044 937 BOARD RISK COMMITTEE CHARTER 1 Purpose of Charter This Charter sets out the authority, responsibilities, membership and terms of operation of the Board Risk

More information

Enterprise Risk Management Demystified

Enterprise Risk Management Demystified Enterprise Risk Management Demystified Charles W. Soucy, CPCU, CLU, ARM Joe C. Underwood, CPCU, ARM, AIC October 27, 2010 Agenda 1. What is it? A formal definition of ERM How it s different 2. Why do it?

More information

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM) The Intersection of Enterprise-wide Risk (ERM) and Business Continuity (BCM) Marc Dominus 2005 Protiviti Inc. EOE Agenda Terminology and Process Introductions ERM Process Overview BCM Process Overview

More information

Role Profile. Role Details. Grade 4 Business unit. Date produced or updated March 2017

Role Profile. Role Details. Grade 4 Business unit. Date produced or updated March 2017 Role Profile Role Details Role Title Risk Officer Permanent Grade Business unit Risk Reporting to Head of Risk Date produced or updated March 2017 Purpose of Role To support the Head of Risk and Risk Director

More information

UNF Finance and Audit Committee January 15, 2013

UNF Finance and Audit Committee January 15, 2013 Item 7 UNF Finance and Audit Committee January 15, 2013 Issue Office of Internal Auditing Audit Planning Methodology Proposed Action Report Background Information The purpose of this item is to present

More information

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk Title Description of document The sets out the process by which the Trust identifies, manages, reduces and mitigates risks to achieving the organisational objectives. It sets out the framework required

More information

HSE Integrated Risk Management Policy. Part 3. Managing and Monitoring Risk Registers Guidance for Managers

HSE Integrated Risk Management Policy. Part 3. Managing and Monitoring Risk Registers Guidance for Managers HSE Integrated Management Policy Part 3 Managing and Monitoring Registers Guidance for Managers HSE Integrated Management Policy Part 3 Managing and Monitoring Registers Guidance for Managers Identify

More information

Risk Management Policy Arvind Infrastructure Limited

Risk Management Policy Arvind Infrastructure Limited Risk Management Policy Arvind Infrastructure Limited 0 Risk management 1.1 Purpose Arvind Infrastructure Limited is committed to high standards of business conduct and to good risk management to: 1. achieve

More information

Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting

Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting July 17, 2017 Objectives Provide perspective on the evolution of Enterprise Risk Management (ERM) New 2017

More information

Strategic Risk Management -The Route to Business success

Strategic Risk Management -The Route to Business success BUSINESS RISK MANAGEMENT LTD Strategic Risk Management -The Route to Business success Attend this brand new seminar led by world renowned expert Phil Griffiths of Business Risk Management Ltd and learn

More information

Risk Management Strategy. Version: V3.0

Risk Management Strategy. Version: V3.0 Risk Management Strategy Version: V3.0 Date: October 2016 Classification: DCC Public Document Control (Document Control Heading) Revision History (Document Control Subtitle) Revision Date Summary of Changes

More information

Four Steps to incorporate risk management into your organization: Getting risk handling right

Four Steps to incorporate risk management into your organization: Getting risk handling right Four Steps to incorporate risk management into your organization: Getting risk handling right business goals c o m m u n i c a t i o n Preparation implementation roll out live e d u c a t i o n success

More information

Enterprise Risk Management: Materials [date]

Enterprise Risk Management: Materials [date] SLS SAMPLE DOCUMENT 07/09/17 [client logo] Enterprise Risk Management: Materials [date] Note: This document does not reflect or constitute legal advice. This is a sample made available by the Organizations

More information

Risk Management Developing an Effective Audit Plan

Risk Management Developing an Effective Audit Plan 2013 CliftonLarsonAllen LLP Risk Management Developing an Effective Audit Plan Association of Credit Union Internal Auditors P L n L e A l n o s a r n L o t f i l C 3 1 0 2 cliftonlarsonallen.com Discussion

More information

Our purpose, values and competencies

Our purpose, values and competencies Our purpose, values and competencies Last updated October 2013 The work we do and how we behave and carry out our work at The Pensions Regulator are driven by our purpose, values and competency framework.

More information

Managing Fraud Risk A Practical Guide For Directors And Managers

Managing Fraud Risk A Practical Guide For Directors And Managers Managing Fraud Risk A Practical Guide For Directors And Managers MANAGING FRAUD RISK A PRACTICAL GUIDE FOR DIRECTORS AND MANAGERS PDF - Are you looking for managing fraud risk a practical guide for directors

More information