Risk Management, Culture & Governance. Agenda  What is risk management?  A framework for risk management  Establishing a good risk culture  Getting.

Slides:



Advertisements
Similar presentations
Options appraisal, the business case & procurement
Advertisements

The Department of Energy Enterprise Risk Management Model
Risk Management at Harvard – Panel Discussion Harvard IT Summit
Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
Appendix H: Risk training slides (sample). What is Risk? “ Risk is the effect of uncertainty on objectives ” AS/NZS ISO31000:2009.
IMFO Audit & Risk Indaba June 2012
Chapter 10 Accounting Information Systems and Internal Controls
IRSHAD Fourth Objective Dubai Islamic Bank – Performance Management Systems.
Introduction to Risk Management 26 September 2014 Peter Fowler CPPD.
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
It’s Time to Talk About Risk and Control
Introduction to Enterprise Risk Management (ERM)
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Enterprise Risk Management in DHHS
Title slide PIPELINE QRA SEMINAR. PIPELINE RISK ASSESSMENT INTRODUCTION TO GENERAL RISK MANAGEMENT 2.
1 Risk management and Investigation Peter Roberts
Risk Assessment Frameworks
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
PAINTING THE FULL PICTURE
How can projects be controlled?
Corporate Governance: Beyond Compliance at a time of Recession Prof. Ashley G. Frank BA(Econ)[Magna Cum Laude], MDPA (Cum Laude], MBA, MCom [Cum Laude],
COBIT® 5 for Risk Introduction
Information Security Governance 25 th June 2007 Gordon Micallef Vice President – ISACA MALTA CHAPTER.
Challenges Faced in Developing Audit Plans and Programs 21 st March, 2013.
8 – 12 December 2008 Bruce Le Bransky MAFC / APEC / AFDC Shanghai Conference: Session 7.2: Challenges to Governance Structures.
Qantas Brand Refresh Kristy Dixon – Masters of Applied Project Management University of Adelaide 2013 Results of Risk Analysis Plan Hypothetical Project.
The role of internal audit in enterprise-wide risk management (ERM)
Equity Housing Group Risk Management. 05 August 2002 © MazarsEquity Housing Group: Risk Management 2 Agenda Introduction: what is Risk Management? The.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Stephen Vink Senior Vice President Group Risk Management and Internal Audit Lessons learned from ERM.
“ Heightened Expectations” for Corporate Governance AIBA 2 nd Annual Compliance Seminar June 14, 2012 Lester Miller, Senior International Advisor International.
Enterprise Risk Management (ERM) ABN AMRO Business Unit North America (BU NA) Overview for ERM Committee April 11, 2007.
Building Change Capability ‘To put in place the processes and people to support change within STFC’ Draft Blueprint Design v0.1 Project Manager: Steve.
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
Managing Risk for Opportunity. In the absence of certainty, the only way to maintain potentiality is to focus on excellent execution and demonstrable.
IRS Enterprise Risk Management (ERM)
Salisbury Diocese Board of Education1 Gill Hunter Adviser for School Development 2005 What Next? Using Your School Self-Evaluation.
Risk Management For the Board of The Law Society 16 February 2005.
Journeying with a Board Coach. Why seek external assistance? From experience, the reasons for engaging someone to work with your Board tend to fall into.
BPK Strategic Planning: Briefing for Denpasar Regional Office Leadership Team Craig Anderson Ahmed Fajarprana August 11-12, 2005.
Corporate Governance and Risk Management. Introduction Corporate Governance What does it mean? and Why does it matter? Risk Management Challenges of growth.
Assessing ERM Practices ERM Working Group North Carolina State University Raleigh, February 24 th 2006 Copyright © 2005 Standard & Poor's, a division of.
Risk Management Policy & Procedures An Overview for Staff Prepared by MSM Compliance Services Pty Ltd.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
1 Introducing Enterprise Risk Management (ERM) - The KOC Experience November 2012 Khaled Al-Awadhi Risk Management Team Kuwait Oil Company.
Governance and Commissioning Natalie White DCSF Consultant
Risk Management - “Local Government Pitfalls.” IMFO – Sustainability Workshop Risk Management 30 March
Strategies for Knowledge Management Success SCP Best Practices Showcase March 18, 2004.
The context for the revised guidance Alan Inglis Assistant Principal, John Wheatley College.
The Risk Management Process
Kathy Corbiere Service Delivery and Performance Commission
Governance for SMEs Nigeria
12-CRS-0106 REVISED 8 FEB 2013 APO (Align, Plan and Organise)
Vector INTERNAL CONTROL Mike Trigg. vector WHAT IS INTERNAL CONTROL? A key part of effective corporate governance Policies and processes to: - make operations.
Page: 1 Branding, Networking & Pitching Mike Tannenbaum, President Key Strategies, LLC
Five Risk Management Best Practices Scott Moss, CIS P/C Trust Director ERM – ISO
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
Enterprise Risk Management in the Construction Industry
Context and Problem Effects of Changes Strategy for Change Aim: To reduce the length of handover by standardising the quality of information transmitted.
Using Data to Drive Decision-Making
An Overview on Risk Management
Chris Lintern Co-operative Financial Services
11.1 Plan Risk Management The process of defining how to conduct risk management activities for a project Detailed risk planning enhances the overall probability.
With current ethical challenges, is it safe to say Risk Management processes are responsive to an accountable government? CIGFARO- AUDIT &RISK INDABA.
COBIT® 5 for Risk Introduction
Internal Audit & Enterprise Risk Management
COBIT® 5 for Risk Introduction
COBIT® 5 for Risk Introduction
Operational Risk Management
Presentation transcript:

Risk Management, Culture & Governance

Agenda  What is risk management?  A framework for risk management  Establishing a good risk culture  Getting risk a seat at the table  Providing the right risk information to stakeholders  ERM – what does the “E” stand for?

What is a risk? “The effect of uncertainty on objectives”. ISO 31000: 2009 Risk Management “Those things that may stop you meeting your objectives”. Susan Crago What is risk management? Risk Management = Objectives and Outcomes Management

LIKELIHOOD (The probability of the risk materialising in the next 12 months) LEVEL PROBABILITY RANGE Almost Certain (Level 5)80% - 100%Low MediumHigh Likely (Level 4)60% - 80%Low MediumHigh Possible (Level 3)40% - 60%Low Medium High Unlikely (Level 2)20% – 40%Low Medium Rare (Level 1)0% – 20%Low Medium (Level 1) (Level 2) (Level 3) (Level 4) (Level 5) CONSEQUENCE (assess as once off or accumulation of risks) What risk management is not!

Establish Context IdentifyAssessAction Monitor and Review Escalate, Communicate and Consult A framework for risk management

Establish Context A framework for risk management Identify What is our strategy and objectives? What issues have we experienced? What risks are we currently managing? What is going on in the external environment? What are the risks that could stop us meet objectives? What would cause those risks to occur? What controls do we currently have in place? Assess How likely is it that this risk will occur? If it does occur what will be the consequence? How effective are the controls to manage this risk?

A framework for risk management Prioritisation What will we do about the risk? Nothing or something? If something what is the best action to take? Action Monitor and Review Who needs to make the decision about this risk? Who needs to take any actions on this risk? Who needs to be aware of this risk? Escalate, Communicate and Consult Are we on track with managing this risk? Has something changed so we need to review this risk?

The sales pitch Value Proposition…. 1. Making informed decisions supports prioritisation and transparency of decision making 2. Meeting business unit objectives alignment to the business strategy and objectives highlights areas of potential focus 3. Preparing for the unexpected identifying uncertainties fewer shocks and unwelcome surprises

Good risk culture ??

Impacts of poor risk culture

Establishing a good risk culture

‘Values and culture drive people to do the right thing even when no one is looking … Although value and culture cannot always be measured quantitatively, they impact governance in powerful ways.’ John F Laker - APRA Chairman (27 February 2013) Establishing a good risk culture

Getting risk a seat at the table 3 lines of defence Own and manage risks Risk management embedded in processes Promote a strong risk culture Business Units (including Executive, Managers and All Staff) First Line of Defence Independent advice, oversight and monitoring Advocate a risk culture and raise awareness of Risk Establishment of Risk Management Framework Independent Risk Function Second Line of Defence Independent appraisal of the control infrastructure Oversight of the Risk Management Framework Internal Audit Third Line of Defence

Getting risk a seat at the table

Bendigo & Adelaide Bank Group’s Vision: “We aim to be Australia’s leading customer- connected banking group.”

Providing the right risk information to stakeholders “... integral to the effectiveness of risk governance, concerns the flow of information to the board. The lack of timely, relevant and comprehensive risk information [is] often a critical weakness.” John F Laker - APRA Chairman (27 February 2013)

Good risk governance Clear risk appetite and tolerances Escalation of new key risks Monitoring of actions for key risks Monitoring of testing of key controls Consistent across risk types Providing the right risk information to stakeholders

ERM – what does the “E” stand for?  Effective?  Efficient?  Engaging?  Enterprise?

Questions?