Managing Uncertainty, Creating Opportunity Enterprise Risk Management J. Brown, CEO.

Slides:



Advertisements
Similar presentations
Raising Entrepreneurial Capital
Advertisements

Appendix H: Risk training slides (sample). What is Risk? “ Risk is the effect of uncertainty on objectives ” AS/NZS ISO31000:2009.
Applying COSO’s Enterprise Risk Management — Integrated Framework
Lisanne Sison Director ERM Bickmore
IMFO Audit & Risk Indaba June 2012
Chapter 10 Accounting Information Systems and Internal Controls
Control and Accounting Information Systems
Own Risk & Solvency Assessment (ORSA): The heart of Risk & Capital Management John Spencer Director, Ultimate Risk Solutions.
CLOSERISKS Be CLOSE to RISKS Tashkent, April 2011 E NTERPRISE R ISK M ANAGEMENT E NTERPRISE R ISK M ANAGEMENT.
It’s Time to Talk About Risk and Control
Manulife Financial Corporation operates as John Hancock in the United States, and Manulife in other parts of the world. Enterprise Risk Management in Life.
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
Service Design – Section 4.5 Service Continuity Management.
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
Eliot M. Stenzel, CPA,CIA IIA Instructor for many years Risk Based Auditing.
A Portfolio Approach to Enterprise Risk Management Bruce B. Thomas November 11, 2002.
MODELING CORPORATE RISK AT FORD Freeman Wood Director Global Risk Management.
ENVIRONMENTAL MANAGEMENT PLAN
Applying COSO’s Enterprise Risk Management — Integrated Framework
Enterprise Risk Management in DHHS
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
ENTERPRISE RISK MANAGEMENT
Implementing an effective risk management strategy based upon knowledge Peter Scott.
Enterprise Risk Management:
Information Systems Controls for System Reliability -Information Security-
PAINTING THE FULL PICTURE
Opportunities & Implications for Turkish Organisations & Projects
The Government Finance Officers Association
Managing Uncertainty, Creating Opportunity Enterprise Risk Management J. Brown, CEO.
The role of internal audit in enterprise-wide risk management (ERM)
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
1 Enterprise Risk Management (ERM) Program PNM Resources, Inc. March 29, 2007 Presentation to American Public Power Association March 2007 Austin, Texas.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Enterprise Risk Management (ERM) ABN AMRO Business Unit North America (BU NA) Overview for ERM Committee April 11, 2007.
GRC - Governance, Risk MANAGEMENT, and Compliance
Enterprise Risk Management
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Enterprise Risk Management & IT Compliance March 30, 2010 Presented by: Ken Rowe, Director Enterprise Systems Assurance & Chief Security Officer University.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Corporate Governance and Risk Management. Introduction Corporate Governance What does it mean? and Why does it matter? Risk Management Challenges of growth.
Conducting Compliance Assessments and Building Internal Controls In Pharmaceutical R&D Third Annual Medical Research Summit – Session 2.01 Michael Swiatocha.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
DFA Capital Management Inc. DFA vs. ERM Is There A Difference? CAS Special Interest Seminar Understanding the Enterprise Risk Management Process San Francisco,
Enterprise Risk Management Chapter One Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Geneva Association/International Insurance Society Research Presentation, Chicago Enterprise Risk Management in the Insurance Industry Madhusudan.
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
Project Management IV1021Fö5 Risk Management. Agenda Project Risk Project Risk Management The Risk Management Process Goal: get an understanding of basic.
RISK MANAGEMENT : JOURNEY OR DESTINATION ?. What is Risk? “ Any uncertain event that could significantly enhance or impede a Company’s ability to achieve.
Presented to Managers. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an organization.
CAS Spring Meeting June 2007 Introduction to ERM …The Measurements, Quadrants, Tools, and Solutions Prof. Mark C. Vonnahme Fox Family Clinical Professor.
Governance for SMEs Nigeria
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
Five Risk Management Best Practices Scott Moss, CIS P/C Trust Director ERM – ISO
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
THE SUPERVISOR AS A FINANCIAL MANAGER
Draft - Enterprise Risk Management Risk Universe
RISK MANAGEMENT SYSTEM
An Overview on Risk Management
How can an Enterprise Risk Management (ERM), programme enable organizations achieve strategic objectives more effectively? Dr P S Sahota  
With current ethical challenges, is it safe to say Risk Management processes are responsive to an accountable government? CIGFARO- AUDIT &RISK INDABA.
COSO and ERM Committee of Sponsoring Organizations (COSO) is an organization dedicated to providing thought leadership and guidance on internal control,
MSCOA Risk management Inculcating ethical culture through
Sustainability Corporations, Capital Markets and Global Economy.
Understanding the current Public Sector landscape from an risk management point of view Applying the ethical responsibility to the Triple Bottom-line:
THE SUPERVISOR AS A FINANCIAL MANAGER
Managing IT Risk in a digital Transformation AGE
Operational Risk Management
Presentation transcript:

Managing Uncertainty, Creating Opportunity Enterprise Risk Management J. Brown, CEO

Basic Model of Value Creation 1. Idea 2. Develop 3. Execute 4. Monetize  How the Information Technology firm creates value  Absent uncertainty, the process simply repeats over time  Not a realistic view

Simplistic Model of Value Creation: Adding Uncertainty 1. Idea 2. Develop 3. Execute 4. Monetize Uncertainly exists and affects all processes, therefore adaptation is required The comprehensive and incisive approach to manage uncertainty is Enterprise Risk Management (ERM): Prevent or minimize disruptions to the value creation chain Improve ability of IT firms to achievestrategic objectives Help ensure survival of IT firm Adapt External Factors

What in this distinguishes IT firms from other services? 1. Idea 2. Develop 3. Execute 4. Monetize Successful execution of steps 1 through 3 gives rise to an “Intellectual asset” (in step 4) that must be protected ERN within the IT firm is different from ERM within other service firms because of substantial, inherent differences in the nature of Intellectual Property assets

What is Enterprise Risk Management (ERM)? Enterprise Risk Management (ERM) is a strategic business discipline that supports the achievement of an organization's objectives by addressing the full spectrum of its risks and managing the combined impact of those risks as an interrelated risk portfolio.

Principles of Enterprise Risk Management  Aligning risk appetite and strategy – Management considers the entity’s risk appetite in evaluating strategic alternatives, setting related objectives, and developing mechanisms to manage related risks.  Enhancing risk response decisions – Enterprise risk management provides the rigor to identify and select among alternative risk responses – risk avoidance, reduction, sharing, and acceptance.  Reducing operational surprises and losses – Entities gain enhanced capability to identify potential events and establish responses, reducing surprises and associated costs or losses.  Identifying and managing multiple and cross-enterprise risks – Every enterprise faces a myriad of risks affecting different parts of the organization, and enterprise risk management facilitates effective response to the interrelated impacts, and integrated responses to multiple risks.  Seizing opportunities – By considering a full range of potential events, management is positioned to identify and proactively realize opportunities.  Improving deployment of capital – Obtaining robust risk information allows management to effectively assess overall capital needs and enhance capital allocation.

Two types of Risk Insurable Risk Operational Risk

Components of ERM Define the risk criteria (e.g., any event that could impact profit by more than 1%) Risk identification (list of possible events, see our Excel chart, IT Risk Assessment) Risk analysis (essentially, impact X probability) Risk treatment, prioritize and: - Avoidance (eliminate, withdraw from or not become involved - Reduction (optimize – mitigate) - Sharing (transfer – outsource or insure) - Retention (accept and budget) Monitoring and review (continually improve the ERM process)

Risk Identification The entity as a while, and each department, faces risk. Each worker is responsible for the risks that affect his/her role and activities. Identify risks on two levels: 1.Corporate Risks: impact the whole organisation and high-level goals and objectives 2.Unit Risks: impact department goals and objectives Categorise risks based on type: Physical Technological Political Financial Operational (HR, IT, Process) Strategic Executive

Integration of ERM Embedded in all practices and processes in a way that it is relevant Should become part of, and not separate from, those organisational processes Embed into the policy development, business and strategic planning and change management process

Operational HRProcessIT FraudCapacityData Integrity Health & SafetyDesignSystem Availability Evacuation PlansExecutionDevelopment Attract/retainProduct QualityMaintenance top talentSupplierSecurity IP Rights Data breach Compliance EXECUTIVE Ethics Board E&O Kidnap, ransom Compliance Regulatory PHYSICAL Catastrophic loss (e.g., fire) Environmental Incidents Weather Asbestos TECHNOLOGICAL Obsolescence Opportunity Emerging STRATEGIC Financial viability Competition M&A Legal disputes Emerging technologies Commodity pricing/volatility Alliances Black Swan Macroeconomic FINANCIAL Tax Access to capital Interest rates Foreign exchange Repatriation of funds Cash Management POLITICAL Policy changes Regulations Enforcement Compliance Foreign government actions