Stephen Vink Senior Vice President Group Risk Management and Internal Audit Lessons learned from ERM.

Slides:



Advertisements
Similar presentations
Internal Control Integrated Framework
Advertisements

Risk Management at Harvard – Panel Discussion Harvard IT Summit
Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
Lisanne Sison Director ERM Bickmore
Chapter 10 Accounting Information Systems and Internal Controls
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
Prepared by Wa'el Bibi,CPA,CIA,CISA1 Internal Control Integrated Framework An Overview.. Bibi Consulting COSO’s Source: COSO’s Internal Control Integrated.
STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER New York State Office of the State Comptroller Thomas P. DiNapoli, Comptroller Office of Operations John.
Introduction to Enterprise Risk Management (ERM)
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
1 INTERNAL CONTROLS A PRACTICAL GUIDE TO HELP ENSURE FINANCIAL INTEGRITY.
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
Eliot M. Stenzel, CPA,CIA IIA Instructor for many years Risk Based Auditing.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Risk Assessment Frameworks
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
PAINTING THE FULL PICTURE
©2013 CliftonLarsonAllen LLP cliftonlarsonallen.com See CLA PowerPoint User Guide for instructions to insert an image or change the icon on the business.
Opportunities & Implications for Turkish Organisations & Projects
Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Chapter 4 Internal Controls McGraw-Hill/Irwin
The Importance of Transparency and Disclosure Presented by Brian S. Brown Seoul, Korea - March 1999 OECD Conference: Corporate Governance in Asia.
Central Piedmont Community College Internal Audit.
The role of internal audit in enterprise-wide risk management (ERM)
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
1 Bölgesel Rekabet Edebilirlik Operasyonel Programı’nın Uygulanması için Kurumsal Kapasitenin Oluşturulmasına Yönelik Teknik Yardım Technical Assistance.
OECD Guidelines on Insurer Governance
2007 Annual Meeting ● Assemblée annuelle 2007 Vancouver 2007 Annual Meeting ● Assemblée annuelle 2007 Vancouver Canadian Institute of Actuaries Canadian.
Chapter 3 Internal Controls.
Risk Management, Culture & Governance. Agenda  What is risk management?  A framework for risk management  Establishing a good risk culture  Getting.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Presented to President’s Cabinet. INTERNAL CONTROLS are the integration of the activities, plans, attitudes, policies and efforts of the people of an.
Building a Corporate Risk Culture Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory Joost Houwen, CISA,
COSO: Current ERM Challenges and Our Responses RIMS 2012 Annual Conference April 17, 2012 by David Landsittel COSO Chairman.
Copyright T. Rowe Price. All rights reserved 1 Ms. Deborah D. Seidel of T. Rowe Price Financial Services Vice President and Manager of Compliance.
The Chicken or the Egg: A study of Risk Management and Strategic Planning Presented by Raven Henderson Raven Lane, LLC.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Internal Control in a Financial Statement Audit
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
Enterprise Risk Management & IT Compliance March 30, 2010 Presented by: Ken Rowe, Director Enterprise Systems Assurance & Chief Security Officer University.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Northern Trust Company Global Risk Management
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Enterprise Risk Management Chapter One Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
© 2003 DelCreo, Inc. All rights reserved. | U.S. Toll-free 866.DELCREO | International 001/ |
1 Introducing Enterprise Risk Management (ERM) - The KOC Experience November 2012 Khaled Al-Awadhi Risk Management Team Kuwait Oil Company.
CAS Spring Meeting June 2007 Introduction to ERM …The Measurements, Quadrants, Tools, and Solutions Prof. Mark C. Vonnahme Fox Family Clinical Professor.
Vector INTERNAL CONTROL Mike Trigg. vector WHAT IS INTERNAL CONTROL? A key part of effective corporate governance Policies and processes to: - make operations.
Internal Audit & Internal Controls Companies Act 2013.
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
The Role of the CRO in ERM Networking Evening Colin Ledlie 12/05/08.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
Company LOGO Chapter4 Internal control systems. Internal control  It is any action taken by management to enhance the likelihood that established objectives.
ERM and Information Risks July 2013 Advisory. 1 © KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent.
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
USDA 2016 Financial Management Training Transforming Shared Services
RISK MANAGEMENT SYSTEM
ENTERPRISE RISK MANAGEMENT IN THE CASE OF THE FINANCIAL SERVICE SECTOR
Enterprise Risk MANAGEMENT workshop by Hadeel NASSAr (Facilitator)
With current ethical challenges, is it safe to say Risk Management processes are responsive to an accountable government? CIGFARO- AUDIT &RISK INDABA.
COSO and ERM Committee of Sponsoring Organizations (COSO) is an organization dedicated to providing thought leadership and guidance on internal control,
Internal Audit & Enterprise Risk Management
COSO Internal Control s Framework
Internal control - the IA perspective
Understanding the current Public Sector landscape from an risk management point of view Applying the ethical responsibility to the Triple Bottom-line:
CORPORATE DIRECTORS PROGRAMME
- COSO Enterprise Risk Management Integrated Framework (2004)
- COSO Enterprise Risk Management Integrated Framework (2004)
Presentation transcript:

Stephen Vink Senior Vice President Group Risk Management and Internal Audit Lessons learned from ERM

Agenda –Overview  Setting the context  What is ERM  What is “not” ERM  Visible impact of ERM –ERM in the region  Prior to global financial crisis  Post global financial crisis –Lessons learned from ERM implementations  Key issues that obstruct ERM implementations  How to overcome the key implementation issues 2

Overview 3 Setting the context What is ERM What is not ERM Visible impact of ERM

Setting the context 4 –ERM in corporate world can be compared with making money in share market over a period of time  Everyone wants to do it  Many falsely claim to do it - it is just losses that they have made  Those few who have done it, did it accidently and not over a period of time  Only a handful knows how to do it and have done it well over a period of time  People love to hear stories of it –Quite often discussed topic in many board rooms and various conferences “… a process, effected by an entity's board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.” Source: COSO Enterprise Risk Management – Integrated Framework. 2004

What is Enterprise Risk Management 5 –A process, ongoing and flowing through an entity –Effected by people at every level of an organization –Applied in strategy setting –Applied across the enterprise, at every level and unit, and includes taking an entity level portfolio view of risk –Designed to identify potential events that, if they occur, will affect the entity and to manage risk within its risk appetite –Able to provide reasonable assurance to an entity’s management and board of directors –Geared to achievement of objectives in one or more separate but overlapping categories Important COSO’s integrated framework is a guiding post and not the only approach to implement ERM, you can have your own approach customized to your requirements.

What is “NOT” Enterprise Risk Management 6 –NOT a one time activity –NOT the responsibility of your Risk Management Department / CEO / Board –NOT independent of business strategy / business –NOT to be run in silo –NOT applied to only part of the business –NOT about preparing heat map / bubble chart, a heat map is just the beginning. –NOT a system to prevent the potential events –NOT something that can be implemented in days –NOT something that gives immediate results after implementation

Visible impact of ERM (1/2) 7 The impact comes over a period of time and is not a matter of overnight success The impact comes in to phases depending on approach

Visible impact of ERM (2/2) 8 Kick-StartAccelerateSteady State Compliance with controls Risk driven decisions Improved communications on risk Initiative to create awareness of integrated risk approach Better utilization of capital External communications on risk management Safeguard shareholder value Improving shareholder value Improving governance

ERM in Middle East 9 Prior to global financial crisis Post global financial crisis

ERM in Middle East - Prior to global financial crisis 10 –ERM as an integrated framework was issued by COSO in September 2004 –Risk management was existing before COSO issued the framework  Mainly operated in silos  Not viewed as enterprise wide  Not linked with strategy  Viewed as control function only –The early adapters of ERM  Companies having parents in US / Europe / Australia  Public sector organizations more particularly in the energy sector  A handful private sector organizations –Key reasons for lower penetration of ERM in Middle East  Excess liquidity available in the system  Global boom - boom in real estate - boom in local businesses  Absence of shareholder activism / stakeholder activism  Family owned businesses - Corporate governance is nothing but as governed by families

ERM in Middle East – The financial crisis 11

ERM in Middle East - Post global financial crisis 12 –Impact of global financial crisis that created need for ERM  Liquidity constraints in the system  Global recession – local real estate and local business – you know better  Resulted in questions from shareholders / stakeholders regarding management of various risks at the enterprise level, regarding good corporate governance –Many private sector organizations have, either willingly or forced by regulator or forced by lenders, started taking various risk management initiatives –New awakening amongst regional central banks and other regulators

Lessons learned from ERM implementations 13 Key issues that impede ERM implementations How to overcome key implementation issues

Key issues that impede ERM implementation 14 –ERM objectives not aligned to corporate objectives –Creates friction / jeopardize the initiatives among groups / individuals –No insight / Insufficient commitment from the top management –Failure to set clear risk appetite –Delays the implementation / Failed implementation, i.e., no benefit –Inadequate conceptualization of ERM model / approach –Inadequate / Inappropriate model will not yield desired benefits suitable to “your” business needs –Managerial decisions does not embed risk in the process –Insufficient/inadequate risk management resources –Adequately knowledgeable resources needed for special jobs –Poor systems / Stone age tools will make implementation sub - optimal –Cultural mismatch –ERM brings in change management –Your organizational culture will be changed –Change management is not easy and not at all in Middle East –Organization’s culture not aligned with risk strategy

How to overcome key implementation issues 15 Risk transparency and insight Risk appetite and strategy Risk related business processes and decisions Risk organization and governance Risk culture Best Practices * for ERM implementations *Source: McKinsey

How to overcome key implementation issues 16 Risk transparency and insight Risk appetite and strategy Risk related business processes and decisions Risk organization and governance Risk culture Best Practices for ERM implementations 1.Prioritize risk heat map 2.Board to provide insight on big bets that really matter 3.Share information with risk management

How to overcome key implementation issues 17 Risk transparency and insight Risk appetite and strategy Risk related business processes and decisions Risk organization and governance Risk culture Best Practices for ERM implementations 1.Clear definition of risk appetite approved by board, with matching operational levers 2.Risk strategy linked with insights provided by the Board

How to overcome key implementation issues 18 Risk transparency and insight Risk appetite and strategy Risk related business processes and decisions Risk organization and governance Risk culture Best Practices for ERM implementations 1.Managerial decisions optimized by embedding risk considerations in the process 2.Strong links between RM function, key business units and other areas

How to overcome key implementation issues 19 Risk transparency and insight Risk appetite and strategy Risk related business processes and decisions Risk organization and governance Risk culture Best Practices for ERM implementations 1.Adequate changes in governance to fit in the risk management process 2.Adequate knowledgeable resources 3.Adequate Technology

How to overcome key implementation issues 20 Risk transparency and insight Risk appetite and strategy Risk related business processes and decisions Risk organization and governance Risk culture Best Practices for ERM implementations 1.Clear understanding of organization’s risk culture gaps 2.Alignment of culture with risk strategy

Ultimate Lesson Learnt 21 Enterprise risk management is a journey where you need to follow the direction provided by adequate knowledgeable resources and technology or else you could end up on the rocks