Miles CPA Review: BEC Q Updates for 2017 Edition

Similar documents
1.3) Enterprise Risk Management (ERM)

ERM Retooled: Driving Performance by Revising and Enhancing Risk Management Governance Wipfli LLP

Gleim CPA Review Updates to Business Environment and Concepts 2018 Edition, 1st Printing March 2018

Next-generation enterprise risk management

COSO ERM: Integrating with Strategy and Performance. Michael Parkinson

Gleim CIA Review Updates to Part Edition, 1st Printing June 2018

From the cube to the rainbow double helix: a risk practitioner s guide to the COSO ERM Frameworks

From the cube to the rainbow double helix: a risk practitioner s guide to the COSO ERM Frameworks

PRACTICE. Reframing risk BY MARK BUTTERWORTH

COSO Enterprise Risk Management Framework- Integrating Strategy and Performance

Enterprise Risk Management Aligning Risk with Strategy and Performance COSO ERM Framework Update

Strengthening Your Enterprise Risk Management Process

Reimagining the Risk Intelligent Enterprise

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance

Enterprise risk management Protecting and enhancing value Advisory

Enterprise Risk Management. Applying enterprise risk management to environmental, social and governance-related risks.

IIROC Strategic Plan

Are you prepared for this Challenge? The new COSO Enterprise Risk Management Framework

9/17/2017. An Overview of COSO s New Framework and Implementation Guidance SPEAKER. Laura Harden, CPA History

Emerging Trends in Auditing ERM COSO ERM 2017

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

20 Years in the Making. Meet the New ICIF: Revisions to COSO s Internal Control Integrated Framework. Dr. Sandra Richtermeyer COSO Board Member

Performance Risk Management Jonathan Blackmore, May 2013

Strategic Plan The OSC: A 21 st Century Securities Regulator

CARNEGIE MELLON UNIVERSITY

COSO ERM: Integrating with Strategy and Performance. Paul J. Sobel COSO Chairman Chief Risk Officer Georgia-Pacific

INTEGRATED RISK MANAGEMENT

The Current State of Risk Management Maturity for Belgian Organizations kpmg.com/be

THREE-YEAR STRATEGIC PLAN UPDATE v1

Enterprise Risk Management

How to enable revenue growth in the digital age

COSO ERM: Integrating with Strategy and Performance. Paul J. Sobel, CIA, QIAL, CRMA COSO Chairman

FINANCE & BUSINESS AT PENN STATE...

Risk Advisory SERVICES. A holistic approach to implementing effective governance, managing risk and maintaining compliance

Internal Control Integrated Framework. An IAASB Overview September 2016

Internal Control Integrated Framework. An IAASB Overview September 2016

SAMPLE BEC SuperfastCPA Review Notes

Enterprise Risk Management Aligning Risk With Strategy and Performance

POSITION PROFILE FOR THE CHIEF OF THE WINNIPEG POLICE SERVICE. Last updated October, 2015

Modernizing compliance: Moving from value protection to value creation

The Path to Clinical Enterprise Maturity DEVELOPING A CLINICALLY INTEGRATED NETWORK

Supply Management Three-Year Strategic Plan

It starts today. Chief Executive Officer s Message

Visionary Leadership. Systems Perspective. Student-Centered Excellence

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II

Managing capital. The essential guide for growth oriented companies

Risk Management in the 21 st Century Ameren Business Risk Management

Internal controls over financial reporting

Navigating your business journey to successfully scale and grow. RESEARCH EXECUTIVE SUMMARY

A Framework for Audit Quality

ORGANIZATIONAL CULTURE

Ed.D. in Organizational Leadership Core Leadership Understandings. Program Competencies

Core Values and Concepts

Extended Enterprise Risk Management

pwc.co.uk Enterprise Risk Management

OBSI Strategic Plan

Risk Management Culture: The Linkage Between Ethics & Compliance and ERM September 14, 2009

Practices for Effective Local Government Leadership

Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting

ITS STRATEGIC PLAN. ITS Strategic Plan

Embracing Opportunity Demands an Internal Audit Transformation

CGEIT Certification Job Practice

Internal controls over financial reporting

Management Accounting Concepts

2013 COSO Internal Control Framework Update. September 5, 2013

Brand Knowledge & Advocacy: Understanding the brand s essence, values and vision to build advocacy among stakeholders

Enterprise Risk Management

Taking ERM to a. 6 GRC Today / October 2015

The Future of Internal Auditing:

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad

Enterprise Risk Management: Developing a Model for Organizational Success. White Paper

Is the future of your workforce ready now? February 2017

Today we will discuss

SK MANAGEMENT SYSTEM.

Industry Perspective Keys to digital transformation success

INTEGRITY MANAGEMENT CONTINUOUS IMPROVEMENT. Foundation for an Effective Safety Culture

ASTON STRATEGY to 2023

Operational Transaction Services

Corporate Governance Principles for Unlisted Companies: the Why and How?

Four Strategies for Enabling Innovation in the Face of Risk and Compliance. By John A. Epperson and Clayton J. Mitchell

Introduction. The Assessment consists of:

Where did that risk come from?

Developing a Credit Union CSR Policy

Position Title: Finance Director

Enterprise risk management Protecting and enhancing value Advisory

DEFENSE THREAT REDUCTION AGENCY STRATEGIC PLAN FY

Financial Management in the Federal Government:

Achieving Results Through

Enterprise Risk Management Montana State Fund

Fujitsu Future Insights. Global Digital Transformation Survey Report Real digital. Success factors for digital transformation

PREVIEW. Business Information Management. BiSL Next - a framework for. [Date] Brian Johnson

Exceptional vs. Average: What Top Leaders Do Best

Role of Board of Directors in Risk Management. CPA Erick Audi Thursday, 15 th November 2018

Big Data, Better Vision: The Agile CFO

Enterprise Risk Management 2016

Core Values and Concepts

Enterprise Risk Management (ERM) - Impact of 2017 COSO ERM Model

Finance Division. Strategic Plan

Finance Division Strategic Plan

Transcription:

Miles CPA Review Miles CPA Review: BEC Q2 2018 Updates for 2017 Edition Summary of updates: - New version CPA exam structure (w.e.f. April 2017) Time management on the exam - BEC-1.3 Enterprise Risk Management [2017 Framework] tested on CPA exams from Q2 2018 onwards 1

Break: 15 min Break: 15 min Break: 15 min Break: 15 min Miles CPA Review New version CPA exam structure (w.e.f. April 2017): MCQ testlets 50% weightage Recommended time: Testlet #1: 50 mins Testlet #2: 50 mins TBS/WCT testlets 50% weightage Recommended time: Testlet #3: 35 mins Testlet #4: 50 mins Testlet #5: 55 mins FAR Testlet #1 33 MCQs Testlet #2 33 MCQs Testlet #3 2 TBSs Testlet #4 3 TBSs Testlet #5 3 TBSs AUD Testlet #1 36 MCQs Testlet #2 36 MCQs Testlet #3 2 TBSs Testlet #4 3 TBSs Testlet #5 3 TBSs REG Testlet #1 38 MCQs Testlet #2 38 MCQs Testlet #3 2 TBSs Testlet #4 3 TBSs Testlet #5 3 TBSs BEC Testlet #1 31 MCQs Testlet #2 31 MCQs Testlet #3 2 TBSs Testlet #4 2 TBSs Testlet #5 3 WCTs * MCQ - Multiple Choice Question TBS - Task Based Simulation WCT - Written Communication Task 2

Miles CPA Review 1.3) Enterprise Risk Management (ERM) I) Overview of ERM COSO published the Enterprise Risk Management - Integrated Framework in 2004. In Sep 2017, the framework was updated and now titled Enterprise Risk Management - Integrating with Strategy and Performance. The framework: 2017 Framework Defines ERM as: The culture, capabilities, and practices, integrated with strategy-setting and its performance, that organizations rely on to manage risk in creating, preserving, and realizing value Provides a framework for boards and management in entities of all sizes, and builds on the current level of risk management that exists in the normal course of business Highlights the importance of considering risk in both the strategy-setting process and in driving performance Demonstrates how integrating ERM practices throughout an entity helps to accelerate growth and enhance performance Also contains principles that can be applied - from strategic decision-making through to performance Management s Guide to ERM - Management holds overall responsibility for managing risk to the entity, but it is important for management to go further: to enhance the conversation with the board and stakeholders about using ERM to gain a competitive advantage. That starts by deploying ERM capabilities as part of selecting and refining a strategy Through this process, management will gain a better understanding of how the explicit consideration of risk may impact the choice of strategy ERM enriches management dialogue by adding perspective to the strengths and weaknesses of a strategy as conditions change, and to how well a strategy fits with the organization s mission and vision ERM allows management to feel more confident that they ve examined alternative strategies and considered the input of those in their organization who will implement the strategy selected Once strategy is set, ERM provides an effective way for management to fulfill its role, knowing that the organization is attuned to risks that can impact strategy and is managing them well Applying ERM helps to create trust and instill confidence in stakeholders in the current environment, which demands greater scrutiny than ever before about how risk is actively addressing and managing these risks Questions for management - Can all of management - not just the chief risk officer - articulate how risk is considered in the selection of strategy or business decisions? Can they clearly articulate the entity s risk appetite and how it might influence a specific decision? The resulting conversation may shed light on what the mindset for risk taking is really like in the organization. 3

Miles CPA Review Board s Guide to ERM - Every board has an oversight role, helping to support the creation of value in an entity and prevent its decline. Traditionally, ERM has played a strong supporting role at the board level. Now, boards are increasingly expected to provide oversight of ERM ERM framework supplies important considerations for boards in defining and addressing their risk oversight responsibilities. These considerations include: Culture & Governance Risk Management leading to Performance Information, communications & reporting Monitoring (i.e., Review & Revision) Enterprise Strategy & Objective-setting The board s risk oversight role may include, but is not limited to: Reviewing, challenging, and concurring with management on: Proposed strategy and risk appetite Alignment of strategy and business objectives with the entity s stated mission, vision, and core values Significant business decisions including M&A, capital allocations, funding, and dividendrelated decisions Response to significant fluctuations in entity performance or the portfolio view of risk Responses to instances of deviation from core values Approving management incentives and remuneration Participating in investor & stakeholder relations Over the longer term, ERM can also enhance enterprise resilience (i.e., the ability to anticipate and respond to change) Helps organizations identify factors that represent not just risk, but change, and how that change could impact performance and necessitate a shift in strategy Provides the right framework for boards to assess risk and embrace a mindset of resilience By seeing change more clearly, an organization can fashion its own plan; e.g., should it defensively pull back or invest in a new business? Few facts relating to ERM (based on few misconceptions about ERM): ERM is not a function or department - It is the culture, capabilities, and practices that organizations integrate with strategy-setting and apply when they carry out that strategy, with a purpose of managing risk in creating, preserving, and realizing value ERM is more than a risk listing (i.e., taking an inventory of all the risks within the organization) - It is broader and includes practices that management puts in place to actively manage risk ERM addresses more than I/C - It also addresses other topics such as strategy-setting, governance, communicating with stakeholders, and measuring performance. Its principles apply at all levels of the organization and across all functions ERM is not a checklist - It is a set of principles on which processes can be built or integrated for a particular organization, and it is a system of monitoring, learning, and improving performance ERM can be used by organizations of any size - If an organization has a mission, a strategy, and objectives - and the need to make decisions that fully consider risk - then ERM can be applied. It can and should be used by all kinds of organizations, from small businesses to communitybased social enterprises to government agencies to Fortune 500 companies 4

Miles CPA Review Benefits of ERM - All organizations need to set strategy and periodically adjust it, always staying aware of both ever-changing opportunities for creating value and the challenges that will occur in pursuit of that value. To do that, they need the best possible framework for optimizing strategy and performance. That s where ERM comes into play. Organizations that integrate ERM throughout the entity can realize many benefits (few of which are listed below), which highlight the fact that risk should not be viewed solely as a potential constraint or challenge to setting and carrying out a strategy. Rather, the change that underlies risk and the organizational responses to risk give rise to strategic opportunities and key differentiating capabilities. Benefits of ERM include, but are not limited to: Increasing the range of opportunities - By considering all possibilities (both positive and negative aspects of risk), management can identify new opportunities and unique challenges associated with current opportunities Identifying and managing risk entity-wide - Every entity faces myriad risks that can affect many parts of the organization. Sometimes a risk can originate in one part of the entity but impact a different part. Consequently, management identifies and manages these entity-wide risks to sustain and improve performance Increasing positive outcomes and advantage while reducing negative surprises - ERM allows entities to improve their ability to identify risks and establish appropriate responses, reducing surprises and related costs or losses, while profiting from advantageous developments Reducing performance variability - For some, the challenge is less with surprises and losses and more with variability in performance. Performing ahead of schedule or beyond expectations may cause as much concern as performing short of scheduling and expectations. ERM allows organizations to anticipate the risks that would affect performance and enable them to put in place the actions needed to minimize disruption and maximize opportunity Improving resource deployment - Every risk could be considered a request for resources. Obtaining robust information on risk allows management, in the face of finite resources, to assess overall resource needs, prioritize resource deployment and enhance resource allocation Enhancing enterprise resilience - An entity s medium- and long-term viability depends on its ability to anticipate and respond to change, not only to survive but also to evolve and thrive. This is, in part, enabled by effective ERM. It becomes increasingly important as the pace of change accelerates and business complexity increases 5

Miles CPA Review The Role of Risk in Strategy Selection Strategy selection is about making choices and accepting trade-offs. So it makes sense to apply ERM to strategy as that is the best approach for making well-informed choices Risk is a consideration in many strategy-setting processes. But risk is often evaluated primarily in relation to its potential effect on an already-determined strategy. In other words, the discussions focus on risks to the existing strategy: We have a strategy in place, what could affect the relevance and viability of our strategy? But there are other questions to ask about strategy, which organizations are getting better at asking: Have we modeled customer demand accurately? Will our supply chain deliver on time and on budget? Will new competitors emerge? Is our technology infrastructure up to the task? These are the kinds of questions that executives grapple with every day, and responding to them is fundamental to carrying out a strategy However, the risk to the chosen strategy is only one aspect to consider. Per ERM framework, there are two additional aspects to ERM that can have far greater effect on an entity s value: Possibility of strategy not aligning with an organization s mission, vision, and core values Mission, vision, and core values have been demonstrated to matter - and they matter most when it comes to managing risk and remaining resilient during periods of change A chosen strategy must support the organization s mission and vision. A misaligned strategy increases the possibility that the organization may not realize its mission and vision, or may compromise its values, even if a strategy is successfully carried out. Therefore, ERM considers the possibility of strategy not aligning with the mission and vision of the organization Implications from the strategy chosen as each alternative strategy has its own risk profile The board of directors and management need to determine if the strategy works in tandem with the organization s risk appetite, and how it will help drive the organization to set objectives and ultimately allocate resources efficiently ERM has typically helped many organizations identify, assess and manage risks to strategy. But the most significant causes of value destruction are embedded in the possibility of the strategy not supporting the entity s mission and vision, and the implications from the strategy ERM enhances strategy selection. Choosing a strategy calls for structured decision-making that analyzes risk and aligns resources with the mission and vision of the organization The figure below illustrates these considerations in the context of mission, vision, core values, and as a driver of an entity s overall direction and performance 6

Miles CPA Review II) Components of ERM = {CRIME} Under COSO s ERM updated 2017 Framework, ERM consists of 5 components {CRIME}: C "C" is the foundation for CRIME Culture & Governance E Enterprise Strategy & Objective-setting R Risk & Performance M Monitoring (i.e., Review & Revision) I Information, Communication & Reporting The 5 inter-related components in the updated Framework are supported by a set of 20 principles. These principles cover everything from governance to monitoring. They re manageable in size, and they describe practices that can be applied in different ways for different organizations regardless of size, type, or sector. Adhering to these principles can provide management and the board with a reasonable expectation that the organization understands and strives to manage the risks associated with its strategy and business objectives. The 20 principles are: Culture & Governance Risk & Performance Information, Communication & Reporting Monitoring (i.e., Review & Revision) Enterprise Strategy & Objective-setting - Exercises Board Risk Oversight - Establishes Operating Structures - Defines Desired Culture - Demonstrates Commitment to Core Values - Identifies Risk - Assesses Severity of Risk - Prioritizes Risks - Implements Risk Responses - Develops Portfolio View - Leverages Information and Technology - Communicates Risk Information - Reports on Risk, Culture, and Performance - Assesses Substantial Change - Reviews Risk and Performance - Pursues Improvement in ERM - Analyzes Business Context - Defines Risk Appetite - Evaluates Alternative Strategies - Formulates Business Objectives - Attracts, Develops, and Retains Capable Individuals 7

Miles CPA Review Culture & Governance Together form the basis for all other ERM components Governance sets the organization s tone, reinforcing the importance of, and establishing oversight responsibilities for, ERM Culture is reflected in decision-making and pertains to ethical values, desired behaviors, and understanding of risk in the entity Principles (as per the updated 2017 framework): Exercises Board Risk Oversight - The board of directors provides oversight of the strategy and carries out governance responsibilities to support management in achieving strategy and business objectives Establishes Operating Structures - The organization establishes operating structures in the pursuit of strategy and business objectives Defines Desired Culture - The organization defines the desired behaviors that characterize the entity s desired culture Organization s culture reflects its core values, behaviors, and decisions; and influences how the organization applies the ERM framework: how it identifies risk, what types of risk it accepts, and how it manages risk Many factors shape entity culture - Internal factors include the level of judgment and autonomy provided to personnel, how entity employees interact with each other and their managers, the standards and rules, the physical layout of the workplace, and the reward system in place - External factors include regulatory requirements and expectations of customers, investors, and other elements All these factors influence where the entity positions itself on the culture spectrum, which ranges from risk averse to risk aggressive Nuclear power plant Private equity fund - The closer an entity is to the risk aggressive end of the spectrum, the greater is its propensity for and acceptance of the differing types and greater amount of risk to achieve strategy and business objectives Changes within the organization and external influences may cause an entity s culture to shift (e.g., change in leadership, M&As, growth from start-up to mature organization) Demonstrates Commitment to Core Values - The organization demonstrates a commitment to the entity s core values; also, embraces a risk-aware culture, enforces accountability, and keeps communication open (and free from retribution) Attracts, Develops, and Retains Capable Individuals - The organization is committed to building human capital in alignment with the strategy and business objectives 8

Miles CPA Review Risk & Performance Need to identify & assess risks that may impact the achievement of strategy and business objectives. Risks are prioritized by severity in the context of risk appetite. The organization then selects risk responses and takes a portfolio view of the amount of risk it has assumed. The results of this process are reported to key risk stakeholders Principles (as per the updated 2017 framework): Identifies Risk - The organization identifies risk that impacts the performance of strategy and business objectives Assesses Severity of Risk - The organization assesses the severity of risk Prioritizes Risks - The organization prioritizes risks as a basis for selecting responses to risks Implements Risk Responses - The organization identifies and selects risk responses Develops Portfolio View - The organization develops and evaluates a portfolio view of risk Information, Communication & Reporting ERM requires a continual process of obtaining and sharing necessary information, from both internal and external sources, which flows up, down, and across the organization Principles (as per the updated 2017 framework): Leverages Information Systems - The organization leverages the entity s information and technology systems to support ERM Communicates Risk Information - The organization uses communication channels to support ERM Reports on Risk, Culture, and Performance - The organization reports on risk, culture, and performance at multiple levels and across the entity Monitoring (i.e., Review & Revision) By reviewing entity performance, an organization can consider how well the ERM components are functioning over time and in light of substantial changes, and what revisions are needed Principles (as per the updated 2017 framework): Assesses Substantial Change - The organization identifies and assesses changes that may substantially affect strategy and business objectives Reviews Risk and Performance - The organization reviews entity performance and considers risk Pursues Improvement in ERM - The organization pursues improvement of ERM 9

Miles CPA Review Enterprise Strategy & Objective-setting In the strategic planning process, ERM, strategy, and objective-setting work together A risk appetite is established and aligned with strategy; Business objectives put strategy into practice while serving as a basis for identifying, assessing, and responding to risk Principles (as per the updated 2017 framework): Analyzes Business Context - The organization considers potential effects of business context on risk profile Defines Risk Appetite - The organization defines risk appetite in the context of creating, preserving, and realizing value Evaluates Alternative Strategies - The organization evaluates alternative strategies and potential impact on risk profile Formulates Business Objectives - The organization considers risk while establishing the business objectives at various levels that align and support strategy 10

Miles CPA Review III) Assessing ERM An organization should have a means to reliably provide to the entity s stakeholders with a reasonable expectation that it is able to manage risk to an acceptable amount. It does this by assessing the ERM practices that are in place. Such assessment is voluntary, unless required otherwise by legislation or regulation ERM framework provides criteria for conducting an assessment and determining whether the ERM culture, capabilities, and practices collectively manage the risk of not achieving the entity s strategy and supporting business objectives During an assessment, the organization considers whether: The components and principles relating to ERM are present and functioning The components relating to ERM are operating together in an integrated manner The controls necessary to put into effect relevant principles are present and functioning In these three considerations, being "present" means the components, principles, and controls exist in the design and implementation of ERM to achieve strategy and business objectives. Being "functioning" means they continue to operate to achieve strategy and business objectives. And "operating together" refers to the interdependencies of components and how they function cohesively. Organizations may place different emphasis on specific principles and apply them differently, depending on the benefits an organization seeks to attain through ERM. When these components, principles, and supporting controls are present and functioning, the organization can reasonably expect that ERM is helping the entity create, preserve, and realize value. Different approaches are available for assessing ERM When the assessment is performed to communicate to external stakeholders, it would be conducted considering the principles set out in the framework When assessing ERM for internal purposes, some organizations may choose to use some form of maturity model in completing this evaluation, recognizing that the model must be tailored to address the complexity of the business Factors that add complexity may include, among other things, the entity s geography, industry, nature, extent and frequency of change within the entity, historical performance and variation in performance, reliance on technology, and the extent of regulatory oversight During an assessment, management may also review the suitability of those capabilities and practices, keeping in mind the entity s complexity and the benefits the organization seeks to attain through ERM 11

Miles CPA Review IV) ERM - Looking into the future There is no doubt that organizations will continue to face a future full of volatility, complexity, and ambiguity. ERM will be an important part of how an organization manages and prospers through these times. Regardless of the type and size of an entity, strategies need to stay true to their mission. And all entities need to exhibit traits that drive an effective response to change, including agile decision-making, the ability to respond in a cohesive manner, and the adaptive capacity to pivot and reposition while maintaining high levels of trust among stakeholders. As we look into the future, there are several trends that will have an effect on ERM. Just four of these are: Dealing with the proliferation of data - As more and more data becomes available and the speed at which new data can be analyzed increases, ERM will need to adapt. The data will come from both inside and outside the entity, and it will be structured in new ways. Advanced analytics and data visualization tools will evolve and be very helpful in understanding risk and its impact both positive and negative Leveraging artificial intelligence and automation - Many people feel that we have entered the era of automated processes and artificial intelligence. Regardless of individual beliefs, it is important for ERM practices to consider the impact of these and future technologies, and leverage their capabilities. Previously unrecognizable relationships, trends and patterns can be uncovered, providing a rich source of information critical to managing risk Managing the cost of risk management - A frequent concern expressed by many business executives is the cost of risk management, compliance processes, and control activities in comparison to the value gained. As ERM practices evolve, it will become important that activities spanning risk, compliance, control, and even governance be efficiently coordinated to provide maximum benefit to the organization. This may represent one of the best opportunities for ERM to redefine its importance to the organization Building stronger organizations - As organizations become better at integrating ERM with strategy and performance, an opportunity to strengthen resilience will present itself. By knowing the risks that will have the greatest impact on the entity, organizations can use ERM to help put in place capabilities that allow them to act early. This will open up new opportunities. In summary, ERM will need to change and adapt to the future to consistently provide the benefits outlined in the Framework. With the right focus, the benefits derived from ERM will far outweigh the investments and provide organizations with confidence in their ability to handle the future 12

Miles CPA Review Summary of COSO Framework Components Internal Control Framework - 2013 ERM Framework - 2017 C Control Environment C Culture & Governance R Risk Assessment R Risk & Performance I Information & Communication I Information, Communication & Reporting M Monitoring M Monitoring (Review & Revision) E Existing Control Activities E Enterprise Strategy & Objective-setting 13

Miles CPA Review (This page is left blank for any reference notes on Enterprise Risk Management) 14