Governance, Risk Management and Compliance: Summary of Basic Concepts & Program Goals Bob Kotic Chief Financial Officer University of Sydney.

Slides:



Advertisements
Similar presentations
The PRR: Linking Assessment, Planning & Budgeting PRR Workshop – April 4, 2013 Barbara Samuel Loftus, Ph.D. Misericordia University.
Advertisements

Organizational Governance
Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
Member Training ALARM South East - November 2007 Abigail Simpson and Bob Ellison.
Auditing, Assurance and Governance in Local Government
IMFO Audit & Risk Indaba June 2012
Risk Management Policy & Procedures An Overview for Staff Prepared by MSM Compliance Services Pty Ltd.
Environmental Management System (EMS)
NORTHERN TERRITORY TREASURY Performance Development Framework (PDF) Review 2003 Original Treasury PDF Implemented 2009 November reviewed.
TECHNICAL VOCATIONAL EDUCATIONAL AND TRAINING COLLEGES AN INTRODUCTION TO THE IMPEMENTATION OF A COMPLIANT RISK MANAGEMENT PROCESS July 2014.
INTERNATIONAL BEST PRACTICES IN ON-SITE INSPECTIONS OF INSURERS Thomas E Power Senior Manager, Emerging Market Practice Bearing Point.
SEM Planning Model.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Risk Management at ANZ Banking Group Jun 18, 2008 Patrick Zhu Head of Retail Risk China Partnerships.
PwC Role of Internal Audit in Corporate Governance September 2010 Tumin Gültekin, Partner.
The Australian/New Zealand Standard on Risk Management
Quality evaluation and improvement for Internal Audit
Purpose of the Standards
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
Paradise Valley Community College Ways to Fit Security Risk Management to Your Environment Using the OCTAVE Methodology Tailoring OCTAVE at Maricopa Community.
BRIEFING TO THE PORTFOLIO COMMITTEE ON THE DPSA’S RISK MANAGEMENT STRATEGY PRESENTATION TO THE PORTFOLIO COMMITTEE 12 MAY
Preparing Scotland’s first Records Management Plan Ava Wieclawska Records Manager.
Vendor Risk: Effective Management is Essential
Chapter 4 Internal Controls McGraw-Hill/Irwin
Information Technology Audit
Internal Auditing and Outsourcing
1 CHCOHS312A Follow safety procedures for direct care work.
Project Human Resource Management
Governance of the Treasury Function CIPFA Scottish Treasury Management Forum Alan George, Regional Director 23rd February 2012.
The Evergreen, Background, Methodology and IT Service Management Model
DAA and GEP Orlando Audit & Compliance or Audit vs. Compliance.
From Conformance to Performance: Using Integrated Risk Management to achieve Organisational Health Ms Stacie Hall Comcover National Manager.
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
Risk Management Report to Audit Committee 26 September 2006 Lee Harris Assistant Chief Executive.
Chapter 3 Internal Controls.
1 Enterprise Risk Management (ERM) Program PNM Resources, Inc. March 29, 2007 Presentation to American Public Power Association March 2007 Austin, Texas.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Integrating Safety Management Systems – Opportunities for Improvement
Introduction to Internal Control Systems
Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt.
Internal controls. Session objectives Define Internal Controls To understand components of Internal Controls, control environment and types of controls.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Health and Safety Policy
Building Capability.  In order to successfully operate an architecture function within an enterprise, it is necessary to put in place appropriate organization.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Risk Management Policy & Procedures An Overview for Staff Prepared by MSM Compliance Services Pty Ltd.
© 2003 DelCreo, Inc. All rights reserved. | U.S. Toll-free 866.DELCREO | International 001/ |
Balance Between Audit/Compliance and Risk Management- Best Practices FIRMA 21 st National Training Conference Julia Fredricks, U.S. Chief Compliance Officer.
SMS Planning.  Safety management addresses all of the operational activities of the entire organization.  The four (4) components of an SMS are: 1)
RISK MANAGEMENT : JOURNEY OR DESTINATION ?. What is Risk? “ Any uncertain event that could significantly enhance or impede a Company’s ability to achieve.
Copyright  2005 McGraw-Hill Australia Pty Ltd PPTs t/a Australian Human Resources Management by Jeremy Seward and Tim Dein Slides prepared by Michelle.
New Frameworks for Strategic Enrollment Management Planning
TREASURY REGULATIONS’ CHANGES AND POTENTIAL IMPACT
S5: Internal controls. What is Internal Control Internal control is a process Internal control is a process Internal control is effected by people Internal.
Developing an Investment Governance Framework
Kathy Corbiere Service Delivery and Performance Commission
Risk Management for Small & Medium Sized Enterprises
12-CRS-0106 REVISED 8 FEB 2013 APO (Align, Plan and Organise)
Company LOGO. Company LOGO PE, PMP, PgMP, PME, MCT, PRINCE2 Practitioner.
RISK MANAGEMENT IN THE PUBLIC SECTOR CONVERGING MULTIPLE STAKEHOLDER’S EXPECTATIONS Organised by National Treasury Presented by WELEKAZI DUKUZA CEREBRO.
INTERNAL AUDIT & RISK MANAGEMENT ROLE IN PROVISION OF SUSTAINABLE SERVICES Institute of Municipal Finance Officers & Related Professions.
LRC Network Planning for Records Management improvement Kathryn Dan, GM University Records and Policy.
An Overview on Risk Management
Asset Management Accountability Framework
Risk Management and the role of the Audit Committee
Project Human Resource Management
Risk Management Policy & Procedures
Accountability and Internal Controls – Best Practices
Operational Risk Management
Presentation transcript:

Governance, Risk Management and Compliance: Summary of Basic Concepts & Program Goals Bob Kotic Chief Financial Officer University of Sydney

Questions that need Answers What are the greatest risks facing the University?What are the greatest risks facing the University? How does the University manage them?How does the University manage them? How do we monitor them?How do we monitor them?

Definitions Corporate Governance: The systems and processes by which the University is directed, controlled and held to accountCorporate Governance: The systems and processes by which the University is directed, controlled and held to account Risk: The potential for an event to occur that could have an effect on the Universitys objectives or operationsRisk: The potential for an event to occur that could have an effect on the Universitys objectives or operations Risk Management: The culture, processes and structures that are directed to the effective management of potential opportunities and adverse effectsRisk Management: The culture, processes and structures that are directed to the effective management of potential opportunities and adverse effects Compliance: The systems and processes that ensure conformity with business rules, policy and legislationCompliance: The systems and processes that ensure conformity with business rules, policy and legislation Governance Risk Management Compliance

Universitys Current Approach to Risk Management Silo approach to dealing with riskSilo approach to dealing with risk Specific administrative units have responsibility for specific risksSpecific administrative units have responsibility for specific risks –Hazard (Physical Risk) –Financial Threats –Acts of God OHS Staff Development Physical Security Legal Fraud Error Reporting Data Protection Academic Processes Insurance IT Security

Faculties Legal Physical Security Staff Development Fraud OHS IP Management Asset Management Data Protection Compliance

Program Goals Develop and implement an integrated approach to risk management and compliance and in turn, provide the framework to allow the University to demonstrate appropriate standards of governance.Develop and implement an integrated approach to risk management and compliance and in turn, provide the framework to allow the University to demonstrate appropriate standards of governance.

Program Goals contd Create a culture of risk awareness within the University which will promote the appropriate management of risk and compliance; minimising potential negative events and maximising the ability to seize opportunities.Create a culture of risk awareness within the University which will promote the appropriate management of risk and compliance; minimising potential negative events and maximising the ability to seize opportunities.

Program Objectives Identify major risks inherent in the Universitys operating environment & review the effectiveness of existing control measures.Identify major risks inherent in the Universitys operating environment & review the effectiveness of existing control measures. Develop new and more effective tools for monitoring and managing these risks.Develop new and more effective tools for monitoring and managing these risks. Develop a framework to connect the various disciplines currently managing risk to provide a consistent response to risks.Develop a framework to connect the various disciplines currently managing risk to provide a consistent response to risks. Align current activities, policies and procedures with the Universitys overall strategy and streamline deficient processes.Align current activities, policies and procedures with the Universitys overall strategy and streamline deficient processes.

Program Objectives contd Educate staff in the Universitys suite of policies, procedures and internal controls.Educate staff in the Universitys suite of policies, procedures and internal controls. Assign responsibilities for projects, activities, controls and compliance where there is no clear leader.Assign responsibilities for projects, activities, controls and compliance where there is no clear leader. Define key performance indicators and early warning systems to ensure quick response to risk.Define key performance indicators and early warning systems to ensure quick response to risk. Provide regular reporting to senior management, Senior Executive Group and the Audit & Risk Management Committee on risk management activities and internal controls.Provide regular reporting to senior management, Senior Executive Group and the Audit & Risk Management Committee on risk management activities and internal controls.

Common view of risk Understanding Dependencies Information Decisions, Direction, Controls Integrated Approach to Governance, Risk Management & Compliance Source: Barclays Bank Group Operational Risk

Benefits to the University Improved: Management Control & AdministrationManagement Control & Administration Decision MakingDecision Making Resource ManagementResource Management Ability to meet Strategic TargetsAbility to meet Strategic Targets Faculties Legal Physical Security Staff Development Fraud OHS IP Management Asset Management Data Protection Compliance Risk Management Controls

Typical Areas of Concern Alignment of current policies, procedures and processesAlignment of current policies, procedures and processes Strategic PlanningStrategic Planning Contracting/LitigationContracting/Litigation Consistency in TechnologyConsistency in Technology Consistency in Human ResourcesConsistency in Human Resources

Typical Areas of Concern contd Accountability for Legal ComplianceAccountability for Legal Compliance Management of assets (including acquisition and disposal)Management of assets (including acquisition and disposal) Provision of advice/consultancy agreementsProvision of advice/consultancy agreements Business ContinuityBusiness Continuity

Next Steps Identify the top operational risks to the UniversityIdentify the top operational risks to the University –Develop methodology to identify risks –the initial focus on risks and potential exposures that are currently controlled through central administrative support activities Select a risk area and complete full review to pilot an approachSelect a risk area and complete full review to pilot an approach Prioritise remaining risksPrioritise remaining risks

Next Steps contd Review the control measures relating to the administrative and financial processes that are currently in place to determine adequacyReview the control measures relating to the administrative and financial processes that are currently in place to determine adequacy Determine new procedures and control measures required and subsequent costsDetermine new procedures and control measures required and subsequent costs

Academic Support Administrative Support Risks identified & Control Measures developed Colleges College Risk Manager

Outcome List of top ten risks within the UniversityList of top ten risks within the University A risk treatment plan (control measures) by which each risk is managedA risk treatment plan (control measures) by which each risk is managed Risk and treatment plan assigned to a department/individualRisk and treatment plan assigned to a department/individual Performance measures that risks are reported againstPerformance measures that risks are reported against

Outcome contd Document as Risk Management PlanDocument as Risk Management Plan Communication and Training in new controls, policies and proceduresCommunication and Training in new controls, policies and procedures Structure within Colleges to assist with implementationStructure within Colleges to assist with implementation Set of procedures which can be audited to ensure complianceSet of procedures which can be audited to ensure compliance

Questions ?