Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt.

Slides:



Advertisements
Similar presentations
Module N° 4 – ICAO SSP framework
Advertisements

The Compliance & Risk Functions In Credit Unions What Supervisors need to know? Michael Mullen ILCU Learning Advisor.
Pursuing Effective Governance in Canada’s National Sport Community June 2011.
Internal Control–Integrated Framework
Auditing Governance Functions
Auditing, Assurance and Governance in Local Government
Lisanne Sison Director ERM Bickmore
IMFO Audit & Risk Indaba June 2012
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Core principles in the ASX CGC document. Which one do you think is the most important and least important? Presented by Casey Chan Ethics Governance &
Managed Funds Association’s Sound Practices for Hedge Fund Managers 2009 Edition.
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
Introduction to Enterprise Risk Management (ERM)
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
Session 2(b) Management of Deposit Insurance Funds – MALAYSIA Wan Ahmad Ikram Chief Financial Officer Malaysia Deposit Insurance Corporation (MDIC) 1.
Risk Assessment Frameworks
Internal Control and Internal Audit
Purpose of the Standards
Trinidad & Tobago Corporate Governance Code 2013
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
Corporate Ethics Compliance *
Control environment and control activities. Day II Session III and IV.
Irish League of Credit Unions, 2012 W E L O O K A T T H I N G S D I F F E R E N T L Y Risk Management for Credit Unions September 2013 Risk Management.
Internal Auditing and Outsourcing
Corporate Governance in Financial Institutions OCDE/IAIS/ASSAL Conference on Insurance Regulation & Supervision in Latin America Punta Cana, Dominican.
Governance of the Treasury Function CIPFA Scottish Treasury Management Forum Alan George, Regional Director 23rd February 2012.
Audits & Assessments: What are the Differences and How Do We Learn from the Results? Brown Bag March 12, 2009 Sal Rubano – Director, Office of the Vice.
Global Risk Management Solutions Risk Management and the Board of Director: Moving Beyond Concepts to Execution Anton VAN WYK Partner, Global Risk Management.
Improving Corporate Governance in Malaysian Capital Markets – The Role of the Audit Committee Role of the Audit Committee in Assessing Audit Quality.
Chapter 3 Internal Controls.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Implementing and Auditing Ethics Programs
Corporate Governance.  What is risk? ◦ Risks are uncertain future occurrences which, left unchecked, could adversely influence the achievement of a company’s.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
SOFTWARE PROJECT MANAGEMENT
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Chapter 3 Governance.
Developing an Investment Governance Framework
Kathy Corbiere Service Delivery and Performance Commission
Governance for SMEs Nigeria
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
SOLGM Wanaka Retreat Health and Safety at Work Act 2015 Ready? 4 February 2016 Samantha Turner Partner DDI: Mob:
PIC EU-28 Conference Paris, 26 – 27 November 2015 PIC An EU Approach Assurance Maps An Introductory workshop Nathan Paget United Kingdom.
Company LOGO. Company LOGO PE, PMP, PgMP, PME, MCT, PRINCE2 Practitioner.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Governance, risk and ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
RISK MANAGEMENT SYSTEM
Understanding the Principles and Their Effect on the Audit
Internal control - the IA perspective
Taking the STANDARDS Seriously
Internal Control Internal control is the process designed and affected by owners, management, and other personnel. It is implemented to address business.
An overview of Internal Controls Structure & Mechanism
Operational Risk Management
Presentation transcript:

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Protecting Your Deposits CDIC’s Experience in Implementing ERM J.P. Sabourin President and Chief Executive Officer CDIC April 2004

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Presentation Outline CDIC’s ERM definition CDIC’s rationale / objectives for implementing ERM CDIC’s ERM implementation approach  Initial steps  Work currently being undertaken  Future steps ERM benefits / value derived to date CDIC’s “Lessons Learned” in implementing ERM

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC CDIC ERM Definition ERM The comprehensive, systematic and disciplined process by which CDIC identifies, assesses, manages, monitors and reports on, at any point in time, the significant risks inherent in its objects, strategies, plans and affairs

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC ERM Rationale CDIC is subject to Treasury Board of Canada ERM Guidelines Risk Management is one of four components of the CDIC Standards “in control” framework

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC “In Control” Concept The demonstration that CDIC’s affairs are: Subject to effective governance Being managed in accordance with ongoing, appropriate and effective strategic and risk management processes Being conducted in an appropriate control environment and Significant weaknesses (related thereto) are being identified and appropriate and timely action is being taken to address them

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC ERM Objectives Demonstrate that: CDIC has identified / understands / is managing its significant risks Risk decisions are:  Explicitly integrated into CDIC’s strategic and day-to- day decision making  Subject to good corporate governance  Being supported by an appropriate control environment

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC ERM Objectives (cont’d) Facilitate: Validation of CDIC’s strategies / plans / initiatives Prioritization of CDIC’s strategies / plans / initiatives Effective resource allocation

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Initial ERM Implementation Steps Built an ERM foundation Conducted a corporate-level risk assessment Profiled corporate risk management culture

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC ERM Foundation Created CRO position to develop CDIC’s ERM approach / coordinate ERM implementation Developed ERM implementation plan Formed an executive management-level ERM Committee to validate ERM approach and results Formalized Board ERM policy

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC ERM Policy Formalizes ERM role of the CDIC Board / Management Forms one of 19 principles under the CDIC Board Governance Policy Developed to reflect:  CDIC’s statutory requirements  CDIC Standards  Other ERM “best practices”

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Board ERM Responsibilities Understand CDIC’s significant risks Establish RM policies related thereto Regularly review RM policies (evergreen) Obtain reasonable assurance re:  CDIC’s ERM process  Adherence with RM policies

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Management ERM Responsibilities Identify risks Assess their significance Develop RM policies for the Board Regularly review RM policies (evergreen) Manage risks within RM policies Report to the Board re:  Significant risks / management of significant risks  ERM process

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Corporate-Level Risk Assessment ERM Committee: Updated catalogue of inherent corporate risks / risk categories / definitions / risk examples / corporate risk management practices Assessed residual risk exposures (likelihood of occurrence of each risk taking into consideration risk management practices and its potential impact should it occur)

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Risk Assessment (cont’d) ERM Committee: Assessed each risk risk exposure as “reasonable”, “cautionary” or “concern” (including supporting rationale) Identified “owners” for each risk Where applicable, identified initiatives to enhance the management of each risk Validated that risk management initiatives are in line with Corporate Plan

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Corporate Risk Categories Insurance Risk: CDIC’s risk of loss (or costs incurred in the event of an intervention) associated with insuring deposits Financial Risk: The risk associated with managing CDIC’s assets and liabilities, both on- and off-balance sheet Operational Risk: The risk of loss, to which CDIC is exposed that is attributable to the possibility of disruptions in its operations caused by human performance, the inadequacy or failure of processes or technology, and external events Reputational Risk: The risk of impairment of the credibility of, and confidence in, CDIC

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Insurance Risk Insurance Power Risk: The risk that CDIC does not have the necessary powers to support the management of its insurance risk in accordance with CDIC’s statutory objects Underwriting Risk: The risk that CDIC accepts a new member institution with an unacceptable level of insurance risk Assessment Risk: The risk that CDIC does not systematically or promptly identify, member institutions that pose a potentially high level of insurance risk Intervention Risk: The risk that CDIC does not respond appropriately to members that pose an unacceptable level of insurance risk

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Financial Risk Liquidity Risk: The risk that funds will not be available to CDIC to honour its cash obligations (both on- and off- balance sheet) as they arise Market Risk: The risk of loss attributable to adverse changes in the values of financial instruments and other investments or assets owned directly or indirectly by CDIC, whether on- or off- balance sheet, as a result of changes in market rates or prices Credit Risk: The risk of loss attributable to counterparties failing to honour their obligations, whether on- or off- balance sheet, to CDIC

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Operational Risk People Risk: The risk resulting from inadequacies in the competencies, capacity or performance of CDIC personnel Information Risk: The risk that timely, accurate and relevant information is not available to facilitate informed decision making and/or the exercise of effective oversight Technology Risk: The risk that CDIC’s technology does not appropriately support the achievement of its objectives, strategies, plans and affairs (including the management of the risks related thereto)

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Operational Risk (cont’d) Process Risk: The risk resulting from the incorrect execution of, a breakdown in, or a gap in, a process, policy, procedure or control Compliance Risk: The risk that CDIC fails to comply with statutory requirements and relevant guidelines governing its affairs as a Crown corporation, and its internal policies Legal Risk: The risk that legal matters adversely impact CDIC’s ability to achieve its objects, strategies and plans Outsourcing Risk: The risk associated with CDIC engaging third parties to perform services on its behalf

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Operational Risk (cont’d) Business Continuity Risk: The risk that a disruption impacting CDIC’s personnel, information, premises, technology or operations will impede its ability to achieve its objects, conduct its affairs, or implement its strategies and plans Security Risk: The risk that CDIC fails to ensure the safety of its people, the security of its assets, and the security and confidentiality of its information

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Reputational Risk External Communication Risk: The risk of not communicating necessary information, or communicating in an inappropriate manner, or that communication is misinterpreted by the intended audience External Relationships Risk: The risk that dealings with external parties are not adequate to promote the interests of CDIC, or are conducted in an appropriate manner

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Significance Criteria Likelihood = probability of occurrence using a five-point qualitative scale Impact = potential impact (using a five-point qualitative scale) of an occurrence on CDIC’s:  Achievement of its mandate  Financial position  Reputation

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Corporate Risk Significance Map

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Risk Management Culture Management profiled CDIC’s corporate-level risk management culture  4 areas X 5 questions per area = 20 questions

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Management Understanding 1. We understand CDIC’s objects and strategies 2. CDIC has plans in place to achieve its objects and strategies 3. We know the major risks and challenges related to achieving CDIC’s objects and strategies 4. We understand our responsibilities, accountabilities and authorities 5. Realistic targets and indicators are in place to assess CDIC’s performance in achieving its objects and strategies

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Supporting Environment 6. CDIC’s management style and behaviour supports the open flow of information about the management of CDIC’s affairs and any significant risk issues 7. Risk identification, assessment and management are built into the management of CDIC’s affairs 8. CDIC’s Code of Conduct and Ethical Behaviour is practised throughout the organization 9. CDIC’s communication supports the management of its risks and the achievement of its objects and strategies 10. Performance assessments are aligned with the prudent, appropriate and effective management of CDIC’s risks

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Capability / Capacity 11. CDIC has sufficient personnel with the right knowledge and skills to achieve its objects and strategies 12. CDIC is appropriately structured to effectively and efficiently achieve its objects and strategies 13. CDIC has sufficient financial, technological and other resources to achieve its objects and strategies 14. Appropriate people make decisions about significant risks impacting CDIC’s affairs in a timely manner 15. CDIC has sufficient, relevant and timely information available to achieve its objects and strategies

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Implementing Change 16. CDIC’s environment is monitored regularly to see if we need to adjust our Corporate Risk Framework, strategies and plans 17. CDIC monitors its performance against its targets and indicators 18. Resource and information needs are reassessed as CDIC’s objects, strategies or plans change, or as risk issues are identified 19. Risk management practices are periodically assessed as to their continued appropriateness and effectiveness 20. Follow up procedures are in place to ensure that needed changes or actions occur

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Risk Assessment Methodology CDIC Management team individually interviewed to identify:  Inherent corporate risks  Risk management practices ERM Committee collectively:  Confirmed corporate risk catalogue  Assessed each risk  Assessed corporate risk management culture Results reported to CDIC Audit Committee Process validated by Internal Audit

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Current ERM Implementation Steps Developing ERM Board reporting package For each “Insurance Risk”:  Further documenting risk management practices  Developing Board policies / risk tolerances Further integrating ERM and strategic planning  Validating CDIC’s catalogue of corporate risks against its environmental scanning results

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Future ERM Implementation Steps Document risk management practices / develop Board policies for remaining risks Conduct risk (and risk management culture) assessments for remaining risks and for each business function Validate initial corporate risk (and risk management culture) assessments Initiate regular ERM Board reporting Fully coordinate ERM and strategic management  so that risk decisions are explicitly integrated into strategic and day-to-day decision making

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC ERM Benefits to Date Clarified Management’s collective understanding of risks and the risk management practices Evidenced that CDIC is aware of, and is managing its significant corporate risks Confirmed:  CDIC’s Corporate Plan is focused on the right initiatives  Resources are allocated to areas of greatest concern  A strong corporate risk management culture

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC ERM Lessons Learned Implementing ERM is like filming a long / complex movie  Hire a director (CRO)  Have a clear story (ERM implementation plan)  Engage studio executives (Board Governance / ERM Policy)  Engage actors (ERM Committee / Management)  Film one scene at a time (Corporate-level risk assessment)  Keep camera focused (ERM implementation plan)

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC More ERM Lessons Learned Risks are like an onion  They have many layers Each risk has many sub-risks - which in turn have many sub-risks  Cutting through too quickly can cause tears Don’t try to do everything at once - peel layer-by-layer It is easier to peel the outer layers before you peel the inner layers - CDIC started with a corporate-level risk assessment and is now conducting risk assessments at a more detailed level

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Closing Remarks ERM is not a “ one time ” project but a continuous process that needs to be:  Ingrained into your strategic and daily decision- making  Subject to effective corporate governance  Supported by an appropriate control environment It is complex - so keep it simple

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Questions?

Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Canada Canada Deposit Insurance Corporation Société d’assurance-dépôt du Canada CDIC Protecting Your Deposits CDIC’s Experience in Implementing ERM J.P. Sabourin President and Chief Executive Officer CDIC April 2004