Presentation is loading. Please wait.

Presentation is loading. Please wait.

Three Lines of Defense and Business Continuity February 18, 2016.

Similar presentations


Presentation on theme: "Three Lines of Defense and Business Continuity February 18, 2016."— Presentation transcript:

1 Three Lines of Defense and Business Continuity February 18, 2016

2 Mike Richardson, Director of Engineering and Project Delivery Alpa Parikh, Director of Internal Audit

3 Washington state’s oldest local energy company 1.1 million electric customers and more than 760,000 natural gas customers Over $3 billion in revenue and over 3,000 employees Headquartered in downtown Bellevue

4 Puget Sound Energy Headquarters

5 Wild Horse Wind and Solar Facility and Renewable Energy Center

6 Snoqualmie Falls Hydroelectric Project

7 Hopkins Ridge Wind Facility

8 Baker River Hydroelectric Project

9 9 Three Lines of Defense – A framework to promote clear accountability for risk taking, oversight and independent assurance within PSE 1 st Line – Business Lines Ensures quality products/services and does it right the first time. Delivers on the commitment of trust our customer expects. 2nd Line – Business Continuity, Enterprise Risk Management, etc. Helps the Company understand and fulfill requirements through policies, programs and training, while providing oversight of first-line activities. 3rd Line -- Internal Audit Services Brings independent testing and validations to ensure we’ve met requirements and delivered on commitments. Lines of DefenseRisks 2nd 3rd 1st

10 10 1 st Line of Defense 1 st Line – Business Lines Ensures quality products/services and does it right the first time. Delivers on the commitment of trust our customer expects. 2nd Line – Business Continuity, Enterprise Risk Management, etc. Helps the Company understand and fulfill requirements through policies, programs and training, while providing oversight of first-line activities. 3rd Line -- Internal Audit Services Brings independent testing and validations to ensure we’ve met requirements and delivered on commitments. Lines of DefenseRisks 2nd 3rd 1st

11 11 2 nd Line of Defense 1 st Line – Business Lines Ensures quality products/services and does it right the first time. Delivers on the commitment of trust our customer expects. 2nd Line – Business Continuity, Enterprise Risk Management, etc. Helps the Company understand and fulfill requirements through policies, programs and training, while providing oversight of first-line activities. 3rd Line -- Internal Audit Services Brings independent testing and validations to ensure we’ve met requirements and delivered on commitments. Lines of DefenseRisks 2nd 3rd 1st

12 12 3 rd Line of Defense 1 st Line – Business Lines Ensures quality products/services and does it right the first time. Delivers on the commitment of trust our customer expects. 2nd Line – Business Continuity, Enterprise Risk Management, etc. Helps the Company understand and fulfill requirements through policies, programs and training, while providing oversight of first-line activities. 3rd Line -- Internal Audit Services Brings independent testing and validations to ensure we’ve met requirements and delivered on commitments. Lines of DefenseRisks 2nd 3rd 1st

13 13 Internal Audit coordinates across the organization to ensure that risks both known and unknown are prepared for Senior Management 1 st Line of Defense Board of Directors 2 nd Line of Defense 3 rd Line of Defense Emerging Trends and Industry Expertise - Participates in forums and industry-specific trainings to independently identify risks to the Company. - Consults with external Subject Matter Experts and engages third-party audit support. Internal Audit and Consultation - Provides assurance to the Board of Directors that internal security risks are being reviewed and addressed. - Provides assurance to management that processes and controls are sufficient to mitigate identified risks. By reporting both to the Board of Directors and Senior Management, Internal Audit is able to coordinate across the organization.

14 14 NEW! Practice Guide: Internal Audit and the Second Line of Defense

15 15 Business Continuity Implementation 1.2012: Third-party firm benchmarked PSE’s Business Continuity Program 2.2013: Risk mitigation plan developed 3.2014: Business Continuity partnered with Internal Audit to validate plan aligns with Best Practice. Plan implementation begins 4.2015: Internal Audit confirms identified risks are mitigated

16 16 Risk and Program Scope Business Continuity Risk A failure to plan, respond to, and recover from human and naturally caused events that disrupt core business functions for an extended period of time. Scope of Business Continuity Program Reduce or eliminate risk through vigilant, continual preparation. Preparation requires a well-designed sustainable framework and methodology to assess risk and develop effective response strategies; tools to streamline processes; a culture of accountability and continuous improvement.

17 17 Best Practice Mature Program Attributes 1.Corporate sponsorship (Business Continuity Steering Committee) 2.Comprehensive business impact analysis 3.All-hazard plans for business units 4.Periodic exercises and after-action reviews 5.Periodic plan updates (incorporating after-action review findings) 6.Enterprise governance risk compliance tools (Archer eGRC) 7.IT Disaster Recovery (DR) plans and sequencing procedures 8.Facility availability 9.3 rd- party vendor availability 10.Identified risk and gaps have been accepted or plans in place to mitigate 11.Continuous improvement mentality

18 18 PSE Business Continuity Program Attributes 1.Corporate sponsorship (Business Continuity Steering Committee) 2.Comprehensive business impact analysis 3.All-hazard plans for business units 4.Periodic exercises and after-action reviews 5.Periodic plan updates (incorporating after-action review findings) 6.Enterprise governance risk compliance tools (Archer eGRC) 7.IT Disaster Recovery (DR) plans and sequencing procedures 8.Facility availability 9.3 rd- party vendor availability 10.Identified risk and gaps have been accepted or plans in place to mitigate 11.Continuous improvement mentality

19 Three Lines of Defense and Business Continuity February 18, 2016


Download ppt "Three Lines of Defense and Business Continuity February 18, 2016."

Similar presentations


Ads by Google