Trusting your organisation UK Card Fraud Conference 2012 Keith Dewey, 28 March 2012.

Slides:



Advertisements
Similar presentations
Module N° 4 – ICAO SSP framework
Advertisements

Rizwan Chughtai. Risk exposure arising from business activities Need to effectively manage because of Potential business losses Ensure business continuity.
Internal Control–Integrated Framework
Debt Management Strategy: Governance and Transparency
Sharing Good Practice in Quality
IMFO Audit & Risk Indaba June 2012
Strategy 2022: A Holistic View Tony Hayes International President ISACA © 2012, ISACA. All rights reserved.
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
ISEB Qualifications an evolving framework for the future.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Risk Management at ANZ Banking Group Jun 18, 2008 Patrick Zhu Head of Retail Risk China Partnerships.
Viewpoint Consulting – Committed to your success.
IS Audit Function Knowledge
1 Methodology for customer relationship management Author : Ricardo Chalmeta From : The Journal of Systems and Software (2006) Report : Yu-Juan Chiu Date.
Office of Inspector General (OIG) Internal Audit
Purpose of the Standards
Lecture 8 Understanding entity and its environment
Click to add text © 2010 IBM Corporation OpenPages Solution Overview Mark Dinning Principal Solutions Consultant.
The Crown and Suppliers: A New Way of Working People & Security15:35 – 16:20 Channels & Citizen Engagement Social Media ICT Capability Risk Management.
Client-Specific, Operational Risk Management, Solution- Building Workshops The following pages show a list of workshops that may be provided individually.
Governance, Risk, and Compliance Bill Greene Senior Industry Director.
Internal Auditing and Outsourcing
Internal auditing for credit unions Nuala Comerford, Chair IIA Irish Region Committee Pamela McDonald Council Member IIA Credit Union Summer School Thursday,
1 Jon Whitfield Agency CEO Head of Government Internal Audit.
Audit objectives, Planning The Audit
Operational Excellence and Sustainable Performance Improvement Date: 9 June, 2009.
© 2007 KPMG, the Malaysian member firm of KPMG International, a Swiss cooperative. All rights reserved. 1 Differing Roles of Internal Auditor and Risk.
Workshop on Implementing Audit Quality Practices March 2006 Building Quality into the Financial Audit Process The NAO’s experience Gareth Caller.
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
Opportunities to Improve Complaints Management Samantha Sheen, Senior Manager, Ernst & Young 16 August 2006 Risk Advisory Services e.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Building our Future: Programme Board TOR PURPOSE To be the governing forum for the design & effective delivery of the Building our Future Programme To.
Wealth Management Craig Coleman Managing Director Australia and New Zealand Banking Group Limited 24 August 2001.
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
Copyright  2005 McGraw-Hill Australia Pty Ltd PPTs t/a Australian Human Resources Management by Jeremy Seward and Tim Dein Slides prepared by Michelle.
Kathy Corbiere Service Delivery and Performance Commission
Quality Assurance. Define Quality (product & service) Exceeds the requirements of the customer. General excellence of standard or level. A product which.
Protect Association Meeting FCA s166 Skilled Person Reviews 4 March 2016 Mark Davies Associate Director Financial Services Group T: E:
1 PCAOB UPDATE and TRENDS IN GRC Dr. Sridhar Ramamoorti FEI CGRC Meeting, Oracle HQ San Francisco March 20, 2015.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
Prepared for Auditor’s Report to the Board of Education June 30, 2015.
Three Lines of Defense and Business Continuity February 18, 2016.
F8: Audit and Assurance. 2 Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B: Internal audit Section.
AUDIT STAFF TRAINING WORKSHOP 13 TH – 14 TH NOVEMBER 2014, HILTON HOTEL NAIROBI AUDIT PLANNING 1.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Internal Audit White Paper
Government Internal Audit Career
An Overview on Risk Management
Risk Management and the Treasury Function
ENTERPRISE RISK MANAGEMENT IN THE CASE OF THE FINANCIAL SERVICE SECTOR
IIASA Governance Review
Audit Planning, Types of Audit Tests and Materiality
Governance, Risk, and Compliance Bill Greene Senior Industry Director
Auditor’s Report to the Board of Education
The view from the ‘regulator’
Following Up on Internal Audit Reports Workshop on IIA Standard 2500
Strawman Best Practice IIA Change Forum June 2017
GA Flight Examiners Seminar
SELECT COMMITTEE ON TRADE & INTERNATIONAL RELATIONS
2017 Administration and Finance Conference
the foundation for achieving our missions
Academic Relations Chapter Outreach Toolkit
Cyber Security in a Risk Management Framework
Data Governance & Management Skills and Experience
Internal Audit’s Role in Preventing Fraud and Corruption
An overview of Internal Controls Structure & Mechanism
Strategic Management and
Strategic Management and
Presentation transcript:

Trusting your organisation UK Card Fraud Conference 2012 Keith Dewey, 28 March 2012

UK Card Fraud Conference 2012 Trusting your organisation Page 2 Introduction Trusting Your Organisation Effective Fraud Management engages the whole business A centralised approach must create direction and ownership The business components must know what to do The activities must be performed correctly and effectively Effective Fraud Management engages the whole business A centralised approach must create direction and ownership The business components must know what to do The activities must be performed correctly and effectively Frameworks for the holistic picture Some case studies from our experience Frameworks for the holistic picture Some case studies from our experience

UK Card Fraud Conference 2012 Trusting your organisation Page 3 About Ernst & Young Fraud Management FS Fraud Management Systems and Controls Policies and Procedures Strategy & Approach Technology Enablement IT Security Deployment & Review Investigations Remediation Performance Improvement Partnering with clients to support their business

UK Card Fraud Conference 2012 Trusting your organisation Page 4 Common Fraud Management Framework Governance Operational Systems Reporting Analytics Risk and Control Assessment Strategy Processes Operational Integration Internal and External Intelligence Assurance Deter Prevent Detect Investigate Remediate Data Management Customer Proposition

UK Card Fraud Conference 2012 Trusting your organisation Page 5 Common Fraud Management Framework Revenue and Profit Governance Operational Systems Reporting Analytics Risk and Control Assessment Strategy Processes Operational Integration Internal and External Intelligence Assurance Deter Prevent Detect Investigate Remediate Data Management Customer Proposition

UK Card Fraud Conference 2012 Trusting your organisation Page 6 Common Fraud Management Framework Management Approach Governance Operational Systems Reporting Analytics Risk and Control Assessment Strategy Processes Operational Integration Internal and External Intelligence Assurance Deter Prevent Detect Investigate Remediate Data Management Customer Proposition

UK Card Fraud Conference 2012 Trusting your organisation Page 7 Common Fraud Management Framework Lifecycle Governance Operational Systems Reporting Analytics Risk and Control Assessment Strategy Processes Operational Integration Internal and External Intelligence Assurance Deter Prevent Detect Investigate Remediate Data Management Customer Proposition

UK Card Fraud Conference 2012 Trusting your organisation Page 8 Common Fraud Management Framework Process Governance Operational Systems Reporting Analytics Risk and Control Assessment Strategy Processes Operational Integration Internal and External Intelligence Assurance Deter Prevent Detect Investigate Remediate Data Management Customer Proposition

UK Card Fraud Conference 2012 Trusting your organisation Page 9 Common Fraud Management Framework Technology Governance Operational Systems Reporting Analytics Risk and Control Assessment Strategy Processes Operational Integration Internal and External Intelligence Assurance Deter Prevent Detect Investigate Remediate Data Management Customer Proposition

UK Card Fraud Conference 2012 Trusting your organisation Page 10 Common Fraud Management Framework Consistency Governance Operational Systems Reporting Analytics Risk and Control Assessment Strategy Processes Operational Integration Internal and External Intelligence Assurance Deter Prevent Detect Investigate Remediate Data Management Customer Proposition

UK Card Fraud Conference 2012 Trusting your organisation Page 11 Case Study 1 - Governance Trust was placed in each function to perform their role High credit losses, low fraud, low recoveries Fraud losses erratic What we saw Increased centralised oversight and integration Shared understanding of risks and controls Ensuring the right staff are doing the right job correctly Managing functional overlaps and gaps Opportunities

UK Card Fraud Conference 2012 Trusting your organisation Page 12 Case Study 2 - Investigations Trust was solely placed in Internal Audit to manage fraud Cases were approved for investigation by the board Low fraud reported (gross, recoveries, net) What we saw Utilisation of the “3 lines of defence” model Independent training and process review Redefine, analyse, investigate and report fraud losses and costs Cross functional integration and delivery of cultural change Proactive data utilisation – structured and unstructured sources Opportunities

UK Card Fraud Conference 2012 Trusting your organisation Page 13 Case Study 3 – IT Architecture Trust was placed in the IT solution Extensive industry benchmarking and vendor selection Adoption of “best of breed” prevention systems Losses and costs far exceeded those of competitors What we saw Enhance data management – availability and quality Build insight (analytics and reporting), configuration & optimisation Strategic systems review – what is needed, where and why Attune functions – IT, Ops, Risk, Compliance – cultural change Total cost analysis and programme support Opportunities

UK Card Fraud Conference 2012 Trusting your organisation Page 14 Case Study 4 – System Security Trust was placed in the prevention controls Rapid development of online customer proposition Extensive penetration testing to create “secure” IT solution Considerable and erratic fraud losses What we saw Additional data capture and collation to identify root causes Formal, multi-function fraud risk and control assessment Enhanced detection and monitoring controls Cross platform analytics (CRM value add) Greater integration between Business, IT and IT Security functions Opportunities

UK Card Fraud Conference 2012 Trusting your organisation Page 15 Case Study 5 – Third Parties Trust was placed in the extended organisation Highly secured loan offering Extensive use of third parties for remote sales Complex chains of resellers Customers managed through brokers What we saw Multidimensional performance analytics (long term measures) Profitability based incentives over referral rates Extensive due diligence and third party training Enhanced Know Your Intermediary process Revised go-to-market approach and control via online portal Opportunities

UK Card Fraud Conference 2012 Trusting your organisation Page 16 Trusting appropriately, with controls ManagementStaffIntermediaries CustomerForesight Insight Systems DataAnalytics

UK Card Fraud Conference 2012 Trusting your organisation Page 17 Questions and Comments Keith Dewey Senior Manager Financial Service Advisory +44 (0) (0) Trusting Your Organisation

UK Card Fraud Conference 2012 Trusting your organisation Page 18 ► The information in this pack is intended to provide only a general outline of the subjects covered. It should not be regarded as comprehensive or sufficient for making decisions, nor should it be used in place of professional advice. ► Accordingly, Ernst & Young accepts no responsibility for loss arising from any action taken or not taken by anyone using this pack. ► The information in this pack will have been supplemented by matters arising from any oral presentation by us, and should be considered in the light of this additional information. ► If you require any further information or explanations, or specific advice, please contact us and we will be happy to discuss matters further. Important Information