‘The Governance Profession’

Slides:



Advertisements
Similar presentations
Organizational Governance
Advertisements

Governance, Risk, Compliance & Trust Presentation to KPMG May 20, 2009 By Alex Todd
Internal Control–Integrated Framework
Auditing Governance Functions
Welcome! Internal Auditing CHAPTER 1. Definition Internal auditing is an independent, objective, assurance and consulting activity designed to add value.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
Service Design – Section 4.5 Service Continuity Management.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
Oceg © 2011 Driving Principled Performance An Overview of the OCEG GRC Capability Model.
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
Control environment and control activities. Day II Session III and IV.
Internal Auditing and Outsourcing
C H A P T E R 2 Stakeholder Relationships, Social Responsibility, and Corporate Governance.
Global Risk Management Solutions Risk Management and the Board of Director: Moving Beyond Concepts to Execution Anton VAN WYK Partner, Global Risk Management.
Presented to President’s Cabinet. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an.
PRMIA Toronto Chapter Event The ALPHA and BETA of Corporate Governance and Risk Oversight Tuesday, March 8, 2011 Alex Todd TE Research A division of Trust.
GRC - Governance, Risk MANAGEMENT, and Compliance
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
Implementing and Auditing Ethics Programs
General Principles for the Procurement of Goods and Services Asst. Prof. Muhammad Abu Sadah.
Copyright © Houghton Mifflin Company. All rights reserved.
RISK MANAGEMENT : JOURNEY OR DESTINATION ?. What is Risk? “ Any uncertain event that could significantly enhance or impede a Company’s ability to achieve.
[Hayes, Dassen, Schilder and Wallage, Principles of Auditing An Introduction to ISAs, edition 2.1] © Pearson Education Limited 2007 Slide 7.1 Internal.
IT Risks and Controls Revised on Content Internal Control  What is internal control?  Objectives of internal controls  Types of internal controls.
Presented to Managers. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an organization.
Chapter 3 Governance.
Managing Uncertainty, Creating Opportunity Enterprise Risk Management J. Brown, CEO.
Alex Ezrakhovich Process Approach for an Integrated Management System Change driven.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
F8: Audit and Assurance. 2 Audit and Assurance Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B:
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
Business Ethics 1 كلية العلوم والدراسات الانسانية بالغاط Chapter 3: Stakeholder Relationships, Social Responsibility, and Corporate Governance.
Company LOGO Chapter4 Internal control systems. Internal control  It is any action taken by management to enhance the likelihood that established objectives.
1Third Party Assurance Optimization and Control RationalizationCopyright © 2016 Deloitte Development LLC. All rights reserved. Third-Party Assurance (TPA)
What is ISO Certification? Information is a valuable asset that can make or break your business. When properly managed it allows you to operate.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Risk Management Dr. Clive Vlieland-Boddy. Managements Responsibilities Strategy – Hopefully sustainable! Control – Hopefully maximising profits! Risk.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
JMFIP Financial Management Conference
An Overview on Risk Management
ENTERPRISE RISK MANAGEMENT IN THE CASE OF THE FINANCIAL SERVICE SECTOR
CAPACITY BUILDING PROGRAMME ON BOARD INDUCTION AND EVALUATION
IIASA Governance Review
Copyright © Houghton Mifflin Company. All rights reserved.MGT437
6th Asian Roundtable on Corporate Governance Theme II, Session 2 Ensuring Capacity, Integrity and Accountability of Regulators and Supervisors Jaweria.
Understanding the Principles and Their Effect on the Audit
INTRODUCTION TO CORPORATE GOVERNANCE.
Audit & Risk Management
OECD - Introduction It is an organisation of those countries which describe themselves as Democratic and have Market economy. Its HQ is in Paris, France.
HUMAN RESOURCE GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE
INTRODUCTION TO ISO 9001:2015 FOR IMPLEMENTATION Varinder Kumar CISA, ISO27001 LA, ISO 9001 LA, ITIL, CEH, MEPGP IT, Certificate course in PII & Privacy.
Advanced Management Control and Sustainable Development
Internal control - the IA perspective
Malaysian Association of Company Secretaries
Internal Audit Strategy Survey Results & Discussion
Information Security Risk Management
UNDERSTANDING….. THE GRC FRAMEWORK.
Sustainability Corporations, Capital Markets and Global Economy.
Chapter 8 Developing an Effective Ethics Program
Adding Value Across the Board
Prepared by: Yazan Metwalli(148371) Moyad Habiballah(137535)
Internal Controls Policies and Procedures
Managing IT Risk in a digital Transformation AGE
GRC - A Strategic Approach
The Corporate Social Audit Corporate Sustainability
COBIT 5 and GRC Date.
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

‘The Governance Profession’

FCS Waweru G. Mathenge

BHUBANESWAR, ODISHA, INDIA GOLDEN JUBILEE YEAR NATIONAL CONVENTION OF COMPANY SECRETARIES (46TH EDITION) AND INTERNATIONAL CONFERENCE (6TH EDITION) AUGUST 30 – SEPTEMBER 01, 2018 BHUBANESWAR, ODISHA, INDIA ‘The Governance Profession’ ‘The Governance Profession’

‘The Governance Profession’ Theme: ‘A Journey of 50 Glorious Years – Connecting from Grassroots to Global’ TOPIC: GRC – A STEP AHEAD TO MEET GROWING STAKEHOLDER EXPECTATIONS ………………………………………. ‘The Governance Profession’

‘The Governance Profession’ INTRODUCTION Traditionally, Governance, Risk Management and Compliance have been seen as three separate and distinct disciplines, frameworks or processes within organizations. The three disciplines essentially serve to “keep the train on the rails as it travels to its destination”. They ensure that the organization moves towards achieving its objectives in a manner that well structured and guided, mitigates risks and meets obligations to and expectations of stakeholders. ‘The Governance Profession’

‘The Governance Profession’ DEFINITIONS GOVERNANCE The system by which companies are directed and controlled. (Cadbury) The relationships among the management, Board of Directors, controlling shareholders, minority shareholders and other stakeholders (IFC) Corporate governance involves a set of relationships between a company’s management, its board, its shareholders and other stakeholders. Corporate governance also provides the structure through which the objectives of the company are set, and the means of attaining those objectives and monitoring performance are determined. (OECD) ‘The Governance Profession’

‘The Governance Profession’ Corporate Governance is the exercise of ethical and effective leadership by the governing body towards the achievement of the following governance outcomes: ethical culture, good performance, effective control and legitimacy.(King IV) The framework of rules and practices by which a board of directors ensures accountability, fairness, and transparency in a company's relationship with its all stakeholders (financiers, customers, management, employees, government, and the community). ‘The Governance Profession’

‘The Governance Profession’ RISK MANAGEMENT Risk is a probability or threat of damage, injury, liability, loss, or any other negative occurrence that is caused by external or internal vulnerabilities, and that may be avoided through preemptive action. Risk Management is “the identification, analysis, assessment, control, and avoidance, minimization, or elimination of unacceptable risks. An organization may use risk assumption, risk avoidance, risk retention, risk transfer, or any other strategy (or combination of strategies) in proper management of future events. ‘The Governance Profession’

‘The Governance Profession’ RISK MANAGEMENT Risk management is the set of processes through which management identifies, analyzes, and, where necessary, responds appropriately to risks that might adversely affect realization of the organization's business objectives. The response to risks typically depends on their perceived gravity, and involves controlling, avoiding, accepting or transferring them to a third party. Types of risks faced by organizations include technological risks, commercial/financial risks, information security risks, legal risks and regulatory compliance risks. ‘The Governance Profession’

‘The Governance Profession’ COMPLIANCE Compliance means the certification or confirmation that an person or organization, in the performance of its functions, meets the requirements of accepted practices, legislation, prescribed rules and regulations, specified standards, or the terms of a contract. ‘The Governance Profession’

‘The Governance Profession’ COMPLIANCE Compliance means conforming with stated requirements. At an organizational level, it is achieved through management processes which identify the applicable requirements (defined for example in laws, regulations, contracts, strategies and policies), assess the state of compliance, assess the risks and potential costs of non-compliance against the projected expenses to achieve compliance, and hence prioritize, fund and initiate any corrective actions deemed necessary. ‘The Governance Profession’

‘The Governance Profession’ AN INTEGRATED APPROACH TO GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE (GRC) Governance, risk management, and compliance are three related facets that help assure an organization reliably achieves objectives, addresses uncertainty and acts with integrity. (Scott L. Mitchell, 2004). GRC is a discipline that aims to synchronize information and activity across governance, risk management and compliance in order to operate more efficiently, enable effective information sharing, more effectively report activities and avoid wasteful overlaps. ‘The Governance Profession’

‘The Governance Profession’ AN INTEGRATED APPROACH TO GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE (GRC) OCEG defines GRC as a "system of people, processes, and technology that enables an organization to: Understand and prioritize stakeholder expectations. Set business objectives that are congruent with values and risks. Achieve objectives while optimizing risk profile and protecting value. Operate within legal, contractual, internal, social, and ethical boundaries. Provide relevant, reliable, and timely information to appropriate stakeholders. Enable the measurement of the performance and effectiveness of the system." ‘The Governance Profession’

‘The Governance Profession’ AN INTEGRATED APPROACH TO GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE (GRC) If not integrated, if tackled in a traditional "silo" approach, most organizations must sustain unmanageable numbers of GRC-related requirements due to changes in technology, increasing data storage, market globalization and increased regulation. Internal and external stakeholders demand not only high performance, but also transparency into business operations. ‘The Governance Profession’

‘The Governance Profession’ AN INTEGRATED APPROACH TO GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE (GRC) Integrating GRC capabilities does not mean creating a mega-department of GRC and doing away with decentralized or programmatic approaches to risk and compliance management. Nor does it necessarily call for the use of only one GRC technology system. Rather, it is about establishing an approach that ensures the right people get the appropriate and correct information at the right times, that the right objectives are established, and that the right actions and controls necessary to address uncertainty and act with integrity are put in place. When business activities are siloed with their own information kept separate, it is highly likely that wrong or counter-productive objectives will be established, sub-optimal strategies will be selected, and performance will not be optimized. (OCEG) ‘The Governance Profession’

‘The Governance Profession’ FORCES DRIVING GRC Business complexity, along with increased regulatory and market scrutiny, is driving organizations to adopt a structured approach to governance, risk and compliance (GRC). The goal is to effectively define, manage and monitor the external and internal business environments. ‘The Governance Profession’

‘The Governance Profession’ EXTERNAL FORCES DRIVING GRC (Forrester Research) Political environment. Economic environment. The regulatory and legal risk environment. Adoption of principles-based regulation Rapidly increasing litigation, fines and settlements. Increased scrutiny by financial markets. Technological advancements and disruptions – cyber risks, social media Stakeholder expectations: ethical leadership, corporate citizenship, sustainable development, stakeholder inclusivity, integrated thinking and integrated reporting. ‘The Governance Profession’

‘The Governance Profession’ THE INTERNAL ENVIRONMENT (Forrester Research) Dynamic and complex nature of business Distributed nature of business Intricate web of business partner relationships Ineffectiveness of the scattered approach to risk and compliance ‘The Governance Profession’

‘The Governance Profession’ TRENDS IN GOVERNANCE, RISK AND COMPLIANCE (Forrester Research) ORGANIZATIONAL TRENDS A single view of risk and compliance oversight A foundation of ethics built upon culture and principles A development of risk and regulatory intelligence processes. A standardization of business processes, policies and controls. Embracing corporate social responsibility (CSR). Business partner management of risk and compliance The leveraging of risk-consulting services. ‘The Governance Profession’

‘The Governance Profession’ TRENDS IN GOVERNANCE, RISK AND COMPLIANCE TECHNOLOGY TRENDS The evolution of technology used for GRC Entrance of the software heavyweights Structuring the GRC technology ecosystem Enhancing risk and regulatory intelligence Developing the central corporate policy management portal Using business process management and rules engines for continuous controls Outsourcing of compliance monitoring ‘The Governance Profession’

‘The Governance Profession’ BENEFITS OF INTEGRATED GOVERNANCE, RISK AND COMPLIANCE (Forrester Research) Higher quality information—Integrating GRC information allows management to make more intelligent decisions more rapidly. Process optimization—Non-value-added activities are eliminated and value-added activities are streamlined to reduce lag time and undesirable variation. Better capital allocation—Identification of areas of redundancy and inefficiency allows financial and human capital to be allocated more effectively. ‘The Governance Profession’

‘The Governance Profession’ BENEFITS OF INTEGRATED GOVERNANCE, RISK AND COMPLIANCE Improved effectiveness—The net effect of all the activities above means GRC activities are directed to the appropriate people and departments. Protected reputation—When risks are managed more effectively, company reputation is enhanced. Reduced costs—Lower costs contribute to the overall ROI gains represented by effective GRC activities. ‘The Governance Profession’

ADDRESS PHONE THANK YOU WEBSITE