IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253

Slides:



Advertisements
Similar presentations
Internal Control Integrated Framework
Advertisements

Risk Management at Harvard – Panel Discussion Harvard IT Summit
Applying COSO’s Enterprise Risk Management — Integrated Framework
Lisanne Sison Director ERM Bickmore
IMFO Audit & Risk Indaba June 2012
Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Control and Accounting Information Systems
Agency Risk Management and Internal Control Standards Presentation to the Board of Visitors November 14, 2014.
COBIT 5 and COSO 2013: Comparing the Frameworks
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
CHAPTER 16 Auditing and corporate governance. Contents  Corporate governance  Independent directors  Chairman of the board and chief executive officer.
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Applying COSO’s Enterprise Risk Management — Integrated Framework
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
ERM for the Non-Risk Manager
Risk Assessment Frameworks
Board responsibility for internal control and risk management by Kiattisak Jelatianranat Chairman, The Institute of Internal Auditors of Thailand Director,
Establishing an Effective Enterprise risk management (ERM) program
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
ENTERPRISE RISK MANAGEMENT
Information Systems Controls for System Reliability -Information Security-
PAINTING THE FULL PICTURE
The Government Finance Officers Association
COSO Framework Update IIA Columbus Chapter May 17, 2013
COBIT® 5 for Risk Introduction
Information Technology Audit
The role of internal audit in enterprise-wide risk management (ERM)
1 Bölgesel Rekabet Edebilirlik Operasyonel Programı’nın Uygulanması için Kurumsal Kapasitenin Oluşturulmasına Yönelik Teknik Yardım Technical Assistance.
Chapter 3 Internal Controls.
RISK ASSESSMENT 2010/2011 M.J Ramakgolo. THE PURPOSE The aim of the risk assessment session is to develop the Strategic Risk Profile for the municipality.
Building a Corporate Risk Culture Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory Joost Houwen, CISA,
COSO: Current ERM Challenges and Our Responses RIMS 2012 Annual Conference April 17, 2012 by David Landsittel COSO Chairman.
Enterprise Risk Management
Chapter 5 Internal Control over Financial Reporting
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
Presented by Rolando C. Cabrera Risk Management Advisor Chairman of the Board, Risk and Insurance Management Association of The Philippines (RIMAP) An.
IRS Enterprise Risk Management (ERM)
Risk Management For the Board of The Law Society 16 February 2005.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
WHEN TITLE IS NOT A QUESTION N O ‘WE CAN’ Establishing Effective ERM of IT: Implementation and Operational Issues of the New ‘Risk IT Framework’ Robert.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Enterprise Risk Management Chapter One Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
© 2003 DelCreo, Inc. All rights reserved. | U.S. Toll-free 866.DELCREO | International 001/ |
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Chapter 9: Introduction to Internal Control Systems
Copyright: Internal Auditing: Assurance and Advisory Services, by The Institute of Internal Auditors Research Foundation, 247 Maitland Avenue, Altamonte.
CAS Spring Meeting June 2007 Introduction to ERM …The Measurements, Quadrants, Tools, and Solutions Prof. Mark C. Vonnahme Fox Family Clinical Professor.
Overview Scope Deliverables
Managing Uncertainty, Creating Opportunity Enterprise Risk Management J. Brown, CEO.
PIC EU-28 Conference Paris, 26 – 27 November 2015 PIC An EU Approach Assurance Maps An Introductory workshop Nathan Paget United Kingdom.
Five Risk Management Best Practices Scott Moss, CIS P/C Trust Director ERM – ISO
COSO’s Enterprise Risk Management (ERM) Framework.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
USDA 2016 Financial Management Training Transforming Shared Services
#127 – Risk Management Basics Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
An Overview on Risk Management
With current ethical challenges, is it safe to say Risk Management processes are responsive to an accountable government? CIGFARO- AUDIT &RISK INDABA.
COSO and ERM Committee of Sponsoring Organizations (COSO) is an organization dedicated to providing thought leadership and guidance on internal control,
Internal control - the IA perspective
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253 Enterprise Risk Management (ERM) 23 August 2007 Charles G. Gray

The material in this presentation is adapted from “Enterprise Risk Management – Integrated Framework” published by the Committee of Sponsoring Organizations (COSO) of the Treadway Commission, copyright 2004. Used by permission. (The name is derived from the name of the first chairman of the 1985 National Commission on Fraudulent Financial Reporting, James C. Treadway, EVP and General Counsel, Paine Webber, Inc., and former Commissioner of the SEC.)

ERM Defined “A process, effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.”

Why is ERM Important? Every entity, whether for-profit or not, exists to realize value for its stakeholders Value is created, preserved, or eroded by management decisions in all activities, from setting strategy to operating the enterprise day-to-day.

ERM and Value Creation ERM enables management to: Deal effectively with potential future events that create uncertainty Respond in a manner that reduces the likelihood of downside (negative) outcomes and increases the upside (positive).

The ERM Framework View objectives in the context of Strategy Operations Reporting Compliance Consider activities at all levels Enterprise-level Division or subsidiary Business unit processes

Portfolio View of Risk Management must consider how individual risks interrelate Develop a “portfolio view” from the perspective of Business unit level Entity level A “holistic” view of how various risk factors impinge on the enterprise

Components of the ERM Framework Internal environment Setting objectives Event identification Risk assessment Risk response Control activities Information and communication Monitoring

Internal Environment Establishes a philosophy regarding risk management Recognizes that unexpected as well as expected events may occur Establishes the enterprise “risk culture” Consider all other aspects of how the organization’s actions may affect its risk culture

Setting Objectives Applies when management considers risk strategy in the setting of objectives Forms the “risk appetite” – a high level view of how much risk management is willing to tolerate in pursuit of objectives Risk tolerance – acceptable level of variation around objectives aligned with risk appetite

Event Identification Differentiates risks and opportunities Events with negative impact are risks Events that may be positive represent offsets (opportunities), which management channels back to strategy setting Identify internal or external incidents that could affect achievement of objectives Addresses how internal and external factors interact to influence the risk profile

Risk Assessment Evaluate the extent to which potential events might impact objectives Assesses risk as to likelihood and impact Assess risk related to objectives Combination of both qualitative and quantitative assessment methodologies Relates time horizons to objective horizons Assesses risk on both inherent and residual basis

Risk Response Identify and evaluate possible responses to risk Evaluates options vis-à-vis risk appetite Cost vs. benefit Degree to which a response will reduce impact and/or likelihood Selects and executes response based on evaluation of the portfolio of risks and responses

Control Activities A strong system of internal control is essential to effective risk management Policies and procedures that help ensure that the risk responses, as well as other directives, are carried out Should occur throughout the organization, at all levels and in all functions Include application and general information technology controls

ERM Roles and Responsibilities Board of directors Senior management CEO, CIO, CFO, COO, other? Unambiguous and enthusiastic support Risk officers VP, chief risk officer, chief security officer Risk/security steering committee Internal auditors

Key Implementation Factors Organization design of the enterprise Establishing an ERM organization Performing risk assessments Determining the overall risk appetite Identifying risk responses Communication of risk evaluation results Monitoring Management oversight and periodic review

Risk Appetite What risks will the organization not accept? E.g., Damage to corporate image What risks will the organization take on new initiatives? E. g., New products What risks will the organization accept for competing objectives? Sacrifice profit for environmental issues (PR)

Risk Appetite - Definitions The amount of risk exposure or potential adverse impact from an event that the organization is willing to accept The level of risk an organization is prepared to be exposed to before it decides that action is necessary The level of risk you’re willing to live with before you do something about it The amount of risk you’re prepared to take in order to achieve objectives