The Department of Energy Enterprise Risk Management Model

Slides:



Advertisements
Similar presentations
COSO I COSO II. Meycor COSO, a Comprehensive Solution for Enterprise Risk Management (ERM)
Advertisements

1 of 21 Information Strategy Developing an Information Strategy © FAO 2005 IMARK Investing in Information for Development Information Strategy Developing.
EMS Checklist (ISO model)
Risk Management at Harvard – Panel Discussion Harvard IT Summit
Draft Change Management Strategy Framework and Toolkit An Overview TAU Workshop: Vulindlela Academy (DBSA) 12 April 2012 Presenter: Dr Patrick Sokhela.
Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
Appendix H: Risk training slides (sample). What is Risk? “ Risk is the effect of uncertainty on objectives ” AS/NZS ISO31000:2009.
Internal Control–Integrated Framework
PROJECT RISK MANAGEMENT
Chapter 10 Accounting Information Systems and Internal Controls
Control and Accounting Information Systems
Office of the Secretary of Defense – Comptroller Financial Improvement and Audit Readiness Directorate Unclassified 17 September 2014 GAO Revised “Green.
Projmgmt-1/33 DePaul University Project Management I - Risk Management Instructor: David A. Lash.
Action Implementation and Monitoring A risk in PHN practice is that so much attention can be devoted to development of objectives and planning to address.
The Australian/New Zealand Standard on Risk Management
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
B&O Committee May 2015 iTRAK - Change Management An Agency Adapting to Change.
Office of Inspector General (OIG) Internal Audit
10.1 Identify Stakeholders
Benefits for using a standardised risk management framework to risk assess Infection Prevention and Control Sue Greig Senior Project Officer National.
Project Risk Management Risk Mitigation. Risk Management  The prime objective of risk management is to minimize the impact and probability of the occurrence.
Purpose of the Standards
PAINTING THE FULL PICTURE
Privileged and Confidential Strategic Approach to Asset Management Presented to October Urban Water Council Regional Seminar.
Codex Guidelines for the Application of HACCP
Managing a Training Program Why train? Who will attend the training? What are the learning objectives? Strategies? Coverage? How will the training program.
Module 8: Risk Management, Monitoring and Project Control We would like to acknowledge the support of the Project Management Institute and the International.
PRM 702 Project Risk Management Lecture #28
Project Risk Management. The Importance of Project Risk Management Project risk management is the art and science of identifying, analyzing, and responding.
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
RISK ASSESSMENT 2010/2011 M.J Ramakgolo. THE PURPOSE The aim of the risk assessment session is to develop the Strategic Risk Profile for the municipality.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Presented to President’s Cabinet. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an.
A Proposed Risk Management Regulatory Framework Commissioner George Apostolakis Presented at the Organization of Agreement States 2012 Annual Meeting Milwaukee,
Risk Management - the process of identifying and controlling hazards to protect the force.  It’s five steps represent a logical thought process from.
NIST Special Publication Revision 1
Chapter 5 Internal Control over Financial Reporting
Internal Control in a Financial Statement Audit
Session 5 Integrating CLAS Into Policy and Practice CLAS Training [ADD DATE] [ADD PRESENTER NAME] [ADD ORGANIZATION NAME]
FHWA Reorganization Update Program Performance Management Standing Committee on Performance Management Meeting Detroit, MI October 14, 2011 Peter Stephanos.
Cross-cutting Issues And other things your project document must include.
IRS Enterprise Risk Management (ERM)
Software Project Management
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
SacProNet An Overview of Project Management Techniques.
Engin Ali ARTAN Industrial Engineering
MANAGING BUSINESS RISKS AN OVERVIEW CSU, Northridge January, 2004 Chris Brady University Risk Manager.
IT Risks and Controls Revised on Content Internal Control  What is internal control?  Objectives of internal controls  Types of internal controls.
Project Risk Management Planning Stage
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Presented to Managers. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an organization.
TREASURY REGULATIONS’ CHANGES AND POTENTIAL IMPACT
The Risk Management Process
What is project management?
Laboratory Operations Board
Overview PRINCE Hogeschool Rotterdam. 2 Project definition  A project is a temporary organization that is created for the purpose of delivering.
Page 1 Portfolio Committee on Water and Environmental Affairs 14 July 2009.
Five Risk Management Best Practices Scott Moss, CIS P/C Trust Director ERM – ISO
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
ON “SOFTWARE ENGINEERING” SUBJECT TOPIC “RISK ANALYSIS AND MANAGEMENT” MASTER OF COMPUTER APPLICATION (5th Semester) Presented by: ANOOP GANGWAR SRMSCET,
Risk Assessment: A Practical Guide to Assessing Operational Risk
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
JMFIP Financial Management Conference
An Overview on Risk Management
Chap IV : Managing Risk to Enhance Stakeholder Value
Monitoring and Evaluation Systems for NARS organizations in Papua New Guinea Day 4. Session 12. Risk Management.
HUMAN RESOURCE GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE
Portfolio, Programme and Project
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

The Department of Energy Enterprise Risk Management Model Using the Risk Assessment Tool to Prepare a Justification Memorandum for the Development and Revision of Departmental Directives

Enterprise Risk Management (ERM) Model - Background On January 14, 2011, Secretary Chu issued a memorandum outlining goals for improving mission execution. An Integrated Management System (IMS) Team consisting of both Federal managers, subject matters experts and contractors has been engaging leadership across the Department to develop a plan for creating and implementing an Enterprise Risk Management (ERM) Model. The benefit of ERM is that it will better equip the Department to manage performance and make risk-informed decisions.

Enterprise Risk Management (ERM) Model - Principles The Department will defer to external standards or regulations whenever possible to enable our contractors to remain competitive and equipped to best manage our laboratories. DOE will only develop Department-specific requirements when external standards or regulations cannot adequately manage risk and performance within DOE. All DOE developed requirements documents, or directives, that cut across the Departmental Elements lines of authority must utilize the ERM Model which will ensure the Department makes decisions that are risk-informed rather than risk-adverse.

Five Steps of the ERM Review Process Risk Identification. What can go wrong? List all possible events that could occur in a subsystem if there are no controls. Once risks are identified, combine like risks according to the following key areas impacted by the risks: people, mission, physical assets, financial assets, and customer/stakeholder trust. Risk Analysis. What is the likelihood and impact? Rate risks according to probability and impact. Requirements Identification. What is in place to prevent it? List all controls that would exist without DOE subsystem-specific controls. Controls Identification. What else is needed to control the risk? Where there is a significant or extreme risk rating, list gaps between existing risks and existing controls. Risk Registry. What documentation is needed so that the logic and conclusions are clear? Create a register that documents the results of the risk evaluation, including the events, probabilities, impacts, and risk management strategy.

Risk Identification and Analysis For each subsystem a group of senior level staff and subject matter experts complete the following- Risk Identification. What can go wrong? What events can have an impact on people, mission, physical assets, financial assets, and customer/stakeholder trust? A risk can also be a missed opportunity for improving effectiveness and efficiency. Risk Analysis. Look at the subsystem in the context of existing external controls. If there were no DOE-specific controls what is the probability and impact of specific risks?

Requirements Identification Cost Effective Risk Management What is the most effective method for bringing risk down to an acceptable level? Are the controls most expensive than the risk? 3. Requirements Identification. What is in place to prevent it? List all controls that would exist without DOE subsystem-specific controls. Controls Identification. What else is needed to control the risk? Where there is a significant or extreme risk rating, list gaps between existing risks and existing external controls. Defer to existing external controls and standards whenever possible. Minor – risk acceptance may be preferred Moderate – existing controls may be adequate Significant – may need to add more controls Extreme – more controls likely needed

Risk Register Risk Registry Clearly document the analysis of identified risks, existing controls, and proposed controls to address any serious gap between existing controls and risk. Risk Mitigation Options – Acceptance, Monitoring, Mitigation, and Avoidance Evaluate the costs of various mitigation techniques compare the cost/benefit of the risk Risk/ Opportunity Risk Level Potential Cost/Benefit External Control(s) Proposed Mitigation Technique Internal Control (if needed) Identify specific risks and their risk level Minor, Moderate, Significant and Extreme – based on the probability and impact chart. Give a rough estimate of the magnitude of the cost/benefit of the risk/opportunity without DOE-specific controls. List all external controls that help address the risks and opportunity identified. Based on any gap between the risk/opportunity and existing controls, what strategy should DOE adopt? List all internal controls needed to effectively and efficiently address gaps between risks and external controls.

Sample Risk Analysis Please note: The sample above has been tweaked for instructional purposes.

Why is ERM important? Integrated Strategy - ERM is important because it supports the Department’s strategy and our Management Principles including, “we will manage risk in fulfilling our mission”. Consistency- Systematic approach for management and operations – how we make decisions, govern how we establish and implement requirements, and how we hold ourselves accountable . Better Communication - ERM will provide that framework for clearly articulate the processes we use for program execution, and governance. Clear and Concrete Measures of Performance - It will improve efficiency and allow DOE to consistently speak with one voice to our contractors, customers, and stakeholders.

Identify Requirements Path Forward Program Secretarial Officers can submit a request to the DRB to evaluate a subsystem The DRB develops a Risk Assessment Team Risk Assessment Team completes the ERM risk assessment tool Writer develops/revises a directive incorporating any DOE-specific controls needed after the risk analysis Regularly evaluate the effectiveness of the chosen risk mitigation techniques Identify Risk Analyze Risk Identify Requirements Identify Controls Risk Registry