COSO’s New ERM Exposure Draft: What You Should Know

Slides:



Advertisements
Similar presentations
Risk Management at Harvard – Panel Discussion Harvard IT Summit
Advertisements

Internal Control–Integrated Framework
Applying COSO’s Enterprise Risk Management — Integrated Framework
Lisanne Sison Director ERM Bickmore
Federal Audit Executive Council (FAEC) June 2012 Bi-Monthly Meeting Heather I. Keister Doris G. Yanger June 14, 2012 Green Book Update.
IMFO Audit & Risk Indaba June 2012
Strategy 2022: A Holistic View Tony Hayes International President ISACA © 2012, ISACA. All rights reserved.
It’s Time to Talk About Risk and Control
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
CHAPTER 16 Auditing and corporate governance. Contents  Corporate governance  Independent directors  Chairman of the board and chief executive officer.
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
Eliot M. Stenzel, CPA,CIA IIA Instructor for many years Risk Based Auditing.
Office of the Secretary of Defense – Comptroller Financial Improvement and Audit Readiness Directorate Unclassified 17 September 2014 GAO Revised “Green.
Applying COSO’s Enterprise Risk Management — Integrated Framework
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
COSO Framework Update IIA Columbus Chapter May 17, 2013
Information Technology Audit
Internal Auditing and Outsourcing
Challenges Faced in Developing Audit Plans and Programs 21 st March, 2013.
Fall 2003 Auditing Update for Auditing and Assurance Services: An Integrated Approach.
1 Bölgesel Rekabet Edebilirlik Operasyonel Programı’nın Uygulanması için Kurumsal Kapasitenin Oluşturulmasına Yönelik Teknik Yardım Technical Assistance.
Transitioning to the COSO 2013 Update.  Released on May 14, 2013  Designed to build upon the foundation of the 1992 Framework  Will supersede the 1992.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Building a Corporate Risk Culture Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory Joost Houwen, CISA,
COSO: Current ERM Challenges and Our Responses RIMS 2012 Annual Conference April 17, 2012 by David Landsittel COSO Chairman.
Internal Control in a Financial Statement Audit
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
ISO 9001:2008 to ISO 9001:2015 Summary of Changes
Enterprise Risk Management Chapter One Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Assurance in a Real Time Economy Alan Anderson, CPA Chair – AICPA Assurance Services Executive Committee Managing Principal – Assurance Services At LarsonAllen,
An Update of COSO’s Internal Control–Integrated Framework
CAS Spring Meeting June 2007 Introduction to ERM …The Measurements, Quadrants, Tools, and Solutions Prof. Mark C. Vonnahme Fox Family Clinical Professor.
Managing Uncertainty, Creating Opportunity Enterprise Risk Management J. Brown, CEO.
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
The Role of the CRO in ERM Networking Evening Colin Ledlie 12/05/08.
INTERNAL AUDIT & RISK MANAGEMENT ROLE IN PROVISION OF SUSTAINABLE SERVICES Institute of Municipal Finance Officers & Related Professions.
ERM and Information Risks July 2013 Advisory. 1 © KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent.
The International Professional Practices Framework
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
JMFIP Financial Management Conference
What is ISO 9001? ISO 9001 is a standard that sets out the requirements for a quality management system. It helps businesses and organizations to be more.
Mgt Project Portfolio Management and the PMO Module 8 - Fundamentals of the Program Management Office Dr. Alan C. Maltz Howe School of Technology.
Principles of Good Governance
An Overview on Risk Management
Defining a World-Class Finance Organization
Current IAASB Developments
ENTERPRISE RISK MANAGEMENT IN THE CASE OF THE FINANCIAL SERVICE SECTOR
With current ethical challenges, is it safe to say Risk Management processes are responsive to an accountable government? CIGFARO- AUDIT &RISK INDABA.
Understanding the Principles and Their Effect on the Audit
COSO and ERM Committee of Sponsoring Organizations (COSO) is an organization dedicated to providing thought leadership and guidance on internal control,
PEM PAL IA COP Internal Control Working Group COSO Principles
Risk Management in Plain English
Internal Audit & Enterprise Risk Management
Internal Control–Integrated Framework
COSO Internal Control s Framework
Internal control - the IA perspective
By Jeff Burklo, Director
Corporate Governance It is a system by which companies are managed and directed in the best interests of the owners and shareholders. It refers to the.
Understanding the current Public Sector landscape from an risk management point of view Applying the ethical responsibility to the Triple Bottom-line:
An Update of COSO’s Internal Control–Integrated Framework
Association of International Bank Audit
Taking the STANDARDS Seriously
- COSO Enterprise Risk Management Integrated Framework (2004)
- COSO Enterprise Risk Management Integrated Framework (2004)
Director, CPF Financial Services Limited
Lyn Provost, IAASB Member and Task Force Chair IAASB Meeting
Presentation transcript:

COSO’s New ERM Exposure Draft: What You Should Know Paul Sobel, CIA, QIAL, CRMA Vice President and CAE, Georgia-Pacific COSO Advisory Council member

COSO’s Fundamental Principle Mission COSO’s Mission is “To provide thought leadership through the development of comprehensive frameworks and guidance on enterprise risk management, internal control and fraud deterrence designed to improve organizational performance and governance and to reduce the extent of fraud in organizations.” COSO’s Fundamental Principle Good risk management and internal control are necessary for long term success of all organizations

Why Update the Framework Now? Concepts and practices have evolved Lessons learned Bar raised with respect to enterprise risk management Business and operating environments more complex, technologically driven, and global in scale Stakeholders more engaged, seeking greater transparency and accountability Risk discussions increasingly prominent at the board level

SEC Proxy Requirement… Provide Information About Board Leadership Structure and the Board's Role in Risk Oversight: The SEC approved rules relating to board leadership structure and the board's role in risk oversight. The rules require disclosure about: A company's board leadership structure, including whether the company has combined or separated the chief executive officer and chairman position, and why the company believes its structure is the most appropriate for the company at the time of the filing. In certain circumstances, whether and why a company has a lead independent director and the specific role of such director. The extent of the board's role in the risk oversight of the company.

Project Governance Advisory Council and Observers: COSO Board PwC Project Team Advisory Council Observers Advisory Council and Observers: Consists of over 25 professionals Provides input, expertise, feedback, insight, and ideas throughout the update. Obtains and synthesizes feedback from their respective constituency, organization, industry

Advisory Council Official Observers CRO’s FDIC Risk Luminaries OIG Risk Management, ERM University Professors Chief Audit Executives Accounting Firm Risk Practice Partners Board Members Public Sector Company Executives FDIC OIG GAO IMA IFAC RIMS ISACA China Ministry of Finance (Special) SEC - declined PCAOB determined to not be relevant given no audit requirements

Framework Update Approach 1 2 3 4 5 Assess Envision Design and Build Public Exposure Process Finalize

Foundational Concepts of ERM Every entity exists to provide value for its stakeholders All entities face uncertainty Uncertainty presents both risk and opportunity The challenge for management is to determine how much uncertainty to accept as it strives to grow stakeholder value ERM enables management to effectively manage uncertainty and associated risk and opportunity

Topics Included in the 2004 COSO ERM Framework… Aligning Risk Appetite and Strategy Enhancing Risk Response Decisions Reducing Operational Surprises and Losses Identifying and Managing Multiple and Cross-enterprise Risks Seizing Opportunities Improving Deployment of Capital

What is your ideal view of ERM? Baked in, embedded, not a bolt-on Accelerates growth and success Improves decision making and performance Discipline, not a process Ability to take on more risk Continuous, identifiable, structured

What are Three Strengths of the 2004 Framework? Linking risk to strategy setting Linkage to objectives Discussion of risk responses Linkage to internal control Evaluation/attestation criteria concept Discussion of board governance and oversight Due process

What are Three Significant Areas for Update and Revision? Update principles Revise definitions of risk, ERM and other key terms Improve its usefulness Consider introducing maturity models Review format, structure, length, complexity Emphasize the opportunity side of risk

What Should the Framework Do to Stay Relevant for the Next 10 years? Include maturity models Highlight sustainability Focus on governance Review principles Stay a framework Add update materials, papers

What Would Improve User Acceptance? Increased CEO and board engagement and buy-in Inclusion of case studies and examples of success Clearer value proposition Greater and more effective promotion Alignment to relevant regulatory requirements

What’s Likely to Stay the Same… Link to strategy and objectives An activity involving many people – board, management and others Ability to cascade down to subsidiary, division, function, etc. Risk identification, assessment, prioritization and response Control activities as a possible response, link to internal control An ability to assess effectiveness Monitoring to ensure effectiveness and value of efforts A definitive body of knowledge and thought leadership

What Might Be New… Risk governance and culture concepts Emphasis on integration into decision-making Integration with performance management Revised definitions and vocabulary – including uncertainly concept More focus on using and leveraging information More emphasis on value creation, preservation and realization Mission, vision and values discussion Many more examples including reporting examples Introduction of risk curves

Components and Principles Structure COSO 2013 Internal Control Framework

Possible COSO ERM Components Risk Governance and Culture Risk, Strategy and Objective Setting Risk in Execution Risk Information, Communication and Reporting Monitoring Enterprise Risk Management Performance

Currently, ERM is Defined as…. “A process effected by an entity’s board of directors, management and other personnel, applied in a strategic setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.”

Potential New Definition … “The culture, capabilities and practices, integrated with strategy-setting and its execution, that organizations rely on to manage risk in creating, preserving and realizing value.”

And Maybe- A New Graphic!

Bridging Between ERM and Internal Control Frameworks

Incrementalism… “How would you like to meet more of your objectives more of the time? “

Respond to the exposure draft!!! Some Key Take-Aways Everyone is doing ERM – can you do it better? You need the right Tone at the Top Analyze, understand and communicate your strategy better Tie it in to decision-making and performance, cascade it down Stay attuned to what’s on the horizon (emerging risks, change) Leverage information Keep it moving – it’s a journey Make it happens all the time – it’s part of all decision-making Respond to the exposure draft!!!

Thank You