From Findings over KRIs to Process Control

Slides:



Advertisements
Similar presentations
COSO I COSO II. Meycor COSO, a Comprehensive Solution for Enterprise Risk Management (ERM)
Advertisements

Organizational Governance
Founded 1993 Primary focus – Enterprise Risk Management Solutions COMPANY PROFILE.
IMFO Audit & Risk Indaba June 2012
Control and Accounting Information Systems
Control and Accounting Information Systems
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
Presented by Muhamad Abrar Bahaman W. Fatimatul Akmar Md. Hassan
Investments Institute of Insurance and Risk Management (IIRM) Hyderabad, India 15 November 2005 Arup Chatterjee – Advisor International Association of.
The Use Test in Practice
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Risk Management at ANZ Banking Group Jun 18, 2008 Patrick Zhu Head of Retail Risk China Partnerships.
Minimizing Operational Risk & Optimizing Institutional Performance.
Measuring and Managing Operational Risk. 2 Assessing Operational Risk Exposure Required Process of Continuous Risk Assessment, Monitoring and Reporting.
Operational Risk Management Framework Control Self Assessment
ECM Base Compliance Input Messaging & Alert Compliance dashboard Compliance Monitoring Internal & External Audit Tracking Access Control Compliance & Financial.
1 Operational Risk Management Member Education Series Seminar Indian Institute of Banking & Finance Nagpur November 2005.
Euseden INTERNAL AUDIT & ASSURANCE SERVICES.
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Governance, Risk, and Compliance Bill Greene Senior Industry Director.
Risk Assessment – An Essential Standard
1 Solvency II Part 3: Other pillars Vesa Ronkainen Insurance Supervisory Authority, Finland
Session No. 3 ICAO Safety Management Standards ICAO SMS Framework
Consultancy.
DPE Shareholder Oversight & Risk Management
Risk Assessments/Risk Appetite Judith Gruenbaum 1.
OECD Guidelines on Insurer Governance
RISK ASSESSMENT 2010/2011 M.J Ramakgolo. THE PURPOSE The aim of the risk assessment session is to develop the Strategic Risk Profile for the municipality.
SMS Operation.  Internal safety (SMS) audits are used to ensure that the structure of an SMS is sound.  It is also a formal process to ensure continuous.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Overview of Credit Risk Management practices in banksMarketing Report 1 st Half 2009 Overview of Credit Risk Management practices – The banking perspective.
Enterprise Risk Management (ERM) ABN AMRO Business Unit North America (BU NA) Overview for ERM Committee April 11, 2007.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Internal Control in a Financial Statement Audit
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
Abcd Managing and measuring operational risk in an insurance company John Rowland Tillinghast General Insurance Spring Seminar May 2003 Scarman House.
Corporate Governance and Risk Management. Introduction Corporate Governance What does it mean? and Why does it matter? Risk Management Challenges of growth.
SANEDI. INDEX  KEY ACTIVITIES DURING FINANCIAL YEAR  DISCUSSIONS ON KEY ACTIVITIES  CONCLUSION  APPRECIATION.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Engin Ali ARTAN Industrial Engineering
Forward-Looking Bank Supervision 2010 Kansas City Region Regulatory Conference Call August 24, 2010.
CIA Annual Meeting LOOKING BACK…focused on the future.
2006 General Meeting Assemblée générale 2006 Chicago, Illinois 2006 General Meeting Assemblée générale 2006 Chicago, Illinois Canadian Institute of Actuaries.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Credit risk in banks - importance of appraisal and monitoring PRESENTED BY : KRATI VERMA (09bshyd0390)
SAFETY MANAGEMENT SYSTEM IN TURKISH STATE RAILWAYS (TCDD)
S3: Understanding the Business. Session objective To explain why understanding of the business of the entity is important for the auditor To explain why.
1  The objective of operational risk management is the same as for credit, market and liquidity risks that is to find out the extent of the financial.
PD 8 OSFI Capital Update Stuart Wason Senior Director Actuarial Division OSFI CIA Appointed Actuary Seminar September 18, 2009.
Revision N° 11ICAO Safety Management Systems (SMS) Course01/01/08 Module N° 9 – SMS operation.
PIC EU-28 Conference Paris, 26 – 27 November 2015 PIC An EU Approach Assurance Maps An Introductory workshop Nathan Paget United Kingdom.
F8: Audit and Assurance. 2 Audit and Assurance Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B:
1 Vereniging van Compliance Officers The Compliance Function in Banks Amsterdam, 10 June 2004 Marc Pickeur CBFA CBFA.
Outcomes of the FMC review Vania Tomeva, PIFC consultant July 2013, Tbilisi 1.
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
Non Financial Risk Senior Executive & Board Reporting Richard Pike.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
RISK MANAGEMENT SYSTEM
Legislative Compliance Management Insurance Industry Workshop 1 – 2 November 2005 Bangkok, Thailand Kim Norris Managing Director International Advisory.
Internal Control in a Financial Statement Audit
Governance, Risk, and Compliance Bill Greene Senior Industry Director
OHS Staff Introduction Training
Internal control - the IA perspective
CAYMAN ISLANDS MONETARY AUTHORITY
Robin Youll Office for National Statistics
Operational Risk Management
Presentation transcript:

From Findings over KRIs to Process Control F. Deliën - QPMC

Key Risk Indicators Early warning system. A lot of talk about them, but not a lot is actually been done to establish and monitor KRI across organisations. Some industries are doing more, i.e. Healthcare, Financial Drivers: Financial Services Authority (FSA) – UK regulator is pushing the use of KRI’s during its ‘Arrow’ visits. Principles of Sound Operational Risk Management. COSO ‘Enterprise Risk Management Integrated Framework’: Event Indicators – monitoring data correlation to events, e.g. correlation between borrowers late payment and eventual loan default Performance Indicators – relating different sets of data to one another, e.g. staff turnover rates by functional unit.

Principles of Sound Operational Risk Management Public disclosure of Risk exposure & Quality of Management Disclosure 10 Regular evaluation of strategies Policies, procedures & practices Role of Supervisors 9 Ensure Banks have effective framework in place 8 Risk Management: Identification, measurement, monitoring and control Contingency and Business Continuity Plans. 7 6 Policies, Processes and Procedures to mitigate Risks 5 Monitor Risk Profiles and Losses –KRIs 4 Identify & Assess Risks in – Products, activities, Processes systems by CRSA Mapping and KRIs etc Developing an Appropriate Risk Management Environment 3 Senior Management responsible for implementing the Framework 2 Framework subject to effective and comprehensive internal audit. 1 Board sets – strategy and framework plus oversight w w w . m e t h o d w a r e . c o m

Principle 4 Principle 4: Banks should identify and assess the operational risk inherent in all material products, activities, processes and systems. Banks should also ensure that before new products, activities, processes and systems are introduced or undertaken, the operational risk inherent in them is subject to adequate assessment procedures. 25. Amongst the possible tools used by banks for identifying and assessing operational risk are: Self-or Risk Assessment… Risk Mapping … Risk Indicators: risk indicators are statistics and/or metrics, often financial, which can provide insight into a bank’s risk position. These indicators tend to be reviewed on a periodic basis (such as monthly or quarterly) to alert banks to changes that may be indicative of risk concerns. Such indicators may include the number of failed … Measurement … Source - Basel Committee on Banking Supervision, Sound Practices for the Management and Supervision of Operational Risk. Feb 2003

Principles of Sound Operational Risk Management Public disclosure of Risk exposure & Quality of Management Disclosure 10 Regular evaluation of strategies Policies, procedures & practices Role of Supervisors 9 Ensure Banks have effective framework in place 8 Risk Management: Identification, measurement, monitoring and control Contingency and Business Continuity Plans. 7 6 Policies, Processes and Procedures to mitigate Risks 5 Monitor Risk Profiles and Losses – KRIs 4 Identify & Assess Risks in – Products, activities, Processes systems by CRSA. Mapping and KRIs etc Developing an Appropriate Risk Management Environment 3 Senior Management responsible for implementing the Framework 2 Framework subject to effective and comprehensive internal audit. 1 Board sets – strategy and framework plus oversight w w w . m e t h o d w a r e . c o m

Principle 5 Principle 5: Banks should implement a process to regularly monitor operational risk profiles and material exposures to losses. There should be regular reporting of pertinent information to senior management and the board of directors that supports the proactive management of operational risk. 27. In addition to monitoring operational loss events, banks should identify appropriate indicators that provide early warning of an increased risk of future losses. Such indicators (often referred to as key risk indicators or early warning indicators) should be forward-looking and could reflect potential sources of operational risk such as rapid growth, the introduction of new products, employee turnover, transaction breaks, system downtime, and so on. When thresholds are directly linked to these indicators an effective monitoring process can help identify key material risks in a transparent manner and enable the bank to act upon these risks appropriately. Source - Basel Committee on Banking Supervision, Sound Practices for the Management and Supervision of Operational Risk. Feb 2003

Key Risk Indicators Small number of KRI they track either at a corporate and/or business level. Attrition rates Attrition rates in key positions Worker injury Lost time injury No of ‘incidents’ Hazardous waste generated Airborne emissions Regulatory infringements System downtime Delivery Rates Essential they are - Measurable, Managed, & Monitored

Key Risk Indicators - ERA Standard module in all Solutions. Data can be imported from other systems, or manually entered. Dimensions can be captured to provide additional information, e.g. attrition rates by business function and/or position, regulatory breaches by location. Multiple boundaries can be set up for a KRI: Upper Bound – values above a certain value Benchmark - Lower Bound – values below a certain value eMail alerts can be set up to assign responsibility to key personnel – automated through C/S, manual through Std & MU.

Objectives / Processes Links Can be linked to risks – early warning system for risk materialising. Treatments are raised at the risk level if required – to put in place some mitigating action to stop the loss or near miss from happening again. KRIs can be linked to other KRIs. KRIs Treatments Risks Treatments Objectives / Processes Risk Events Risk Assessment Indicators Controls Test Plans Results Methodology Findings Resolver Ballot Analytics Engine Review Notes

Questions Materials available from QPMC website www.q-project.be/IIASWD