Building a Corporate Risk Culture Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory 403.508.1370 Joost Houwen, CISA,

Slides:



Advertisements
Similar presentations
Risk Management at Harvard – Panel Discussion Harvard IT Summit
Advertisements

Internal Control–Integrated Framework
Lisanne Sison Director ERM Bickmore
IMFO Audit & Risk Indaba June 2012
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
STATE OF NEW YORK OFFICE OF THE STATE COMPTROLLER New York State Office of the State Comptroller Thomas P. DiNapoli, Comptroller Office of Operations John.
TECHNICAL VOCATIONAL EDUCATIONAL AND TRAINING COLLEGES AN INTRODUCTION TO THE IMPEMENTATION OF A COMPLIANT RISK MANAGEMENT PROCESS July 2014.
Introduction to Enterprise Risk Management (ERM)
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Applying COSO’s Enterprise Risk Management — Integrated Framework
ERM for the Non-Risk Manager
Risk Assessment Frameworks
Establishing an Effective Enterprise risk management (ERM) program
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
MARCH 2010Developed by Agency Human Resource Services, DHRM1 Organizational Design What Is It? Organizational Design is the creation of roles, processes,
Information Systems Controls for System Reliability -Information Security-
PAINTING THE FULL PICTURE
Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Information Technology Audit
COMMON CHALLENGES AND SOLUTIONS IN ERM IMPLEMENTATION TO IMPROVE MUNICIPAL CLEAN ADMINISTRATION PROCESS. M.J. RAMAKGOLO (CCSA)
Fall 2003 Auditing Update for Auditing and Assurance Services: An Integrated Approach.
The role of internal audit in enterprise-wide risk management (ERM)
1 Bölgesel Rekabet Edebilirlik Operasyonel Programı’nın Uygulanması için Kurumsal Kapasitenin Oluşturulmasına Yönelik Teknik Yardım Technical Assistance.
RISK ASSESSMENT 2010/2011 M.J Ramakgolo. THE PURPOSE The aim of the risk assessment session is to develop the Strategic Risk Profile for the municipality.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Stephen Vink Senior Vice President Group Risk Management and Internal Audit Lessons learned from ERM.
COSO: Current ERM Challenges and Our Responses RIMS 2012 Annual Conference April 17, 2012 by David Landsittel COSO Chairman.
Copyright T. Rowe Price. All rights reserved 1 Ms. Deborah D. Seidel of T. Rowe Price Financial Services Vice President and Manager of Compliance.
The Chicken or the Egg: A study of Risk Management and Strategic Planning Presented by Raven Henderson Raven Lane, LLC.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Internal Control in a Financial Statement Audit
BUSINESS PLUG-IN B15 Project Management.
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
Enterprise Risk Management & IT Compliance March 30, 2010 Presented by: Ken Rowe, Director Enterprise Systems Assurance & Chief Security Officer University.
IRS Enterprise Risk Management (ERM)
Risk Management For the Board of The Law Society 16 February 2005.
WHEN TITLE IS NOT A QUESTION N O ‘WE CAN’ Establishing Effective ERM of IT: Implementation and Operational Issues of the New ‘Risk IT Framework’ Robert.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Enterprise Risk Management Chapter One Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
1 Introducing Enterprise Risk Management (ERM) - The KOC Experience November 2012 Khaled Al-Awadhi Risk Management Team Kuwait Oil Company.
Project Management IV1021Fö5 Risk Management. Agenda Project Risk Project Risk Management The Risk Management Process Goal: get an understanding of basic.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
TREASURY REGULATIONS’ CHANGES AND POTENTIAL IMPACT
10.30 Alastair Brown Valtech Val Jonas Risk Decisions Group Paul Bamforth Asta Development Plc 1.30 Kelvin Kirby EPM Consulting Group 2.30.
Financial Management & Internal Control for Utility Companies Julia Barber, CPA and Sherman, Barber & Mullikin, CPAs Madison, IN
Risk Management and the Audit Plan abc CIPFA in the Midlands Audit Training Seminar Wednesday 24th November 2004 Tina Spiers.
Continual Service Improvement Methods & Techniques.
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
The Role of the CRO in ERM Networking Evening Colin Ledlie 12/05/08.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
F8: Audit and Assurance. 2 Audit and Assurance Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B:
Company LOGO Chapter4 Internal control systems. Internal control  It is any action taken by management to enhance the likelihood that established objectives.
1 Internal Audit’s Role in Enterprise Risk Management March 22, 2016 Chris Kalafatis, Manager, Risk Advisory Services.
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
An Overview on Risk Management
Chapter4 Internal control systems
ENTERPRISE RISK MANAGEMENT IN THE CASE OF THE FINANCIAL SERVICE SECTOR
Modern Systems Analysis and Design Third Edition
With current ethical challenges, is it safe to say Risk Management processes are responsive to an accountable government? CIGFARO- AUDIT &RISK INDABA.
Internal control - the IA perspective
Modern Systems Analysis and Design Third Edition
Modern Systems Analysis and Design Third Edition
Operational Risk Management
Presentation transcript:

Building a Corporate Risk Culture Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory Joost Houwen, CISA, CISSP, PCI QSA Western Canada Practice Leader IT Security

Agenda Fundamentals of Enterprise Risk Management Criteria of a Strong Risk Culture Practical ERM process Project Risk Management - Examples Summary and Question Period 2

What is risk management “Enterprise risk management is a process, effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.” Source: COSO Enterprise Risk Management – Integrated Framework,

What it really means Risk exists with all organizations and is an inevitable by–product of “doing business”. Successful businesses take prudent risks Some degree of risk is unavoidable and acceptable If not properly identified and managed, risk can threaten, maybe prevent the achievement of goals and objectives 4

ERM framework 5

Some key benefits Greater efficiency of operations and profitability More effective processes Improved decision making, especially with respect to setting corporate strategy Improved corporate governance Reduced risk exposure in key areas Better understanding of risk/reward or risk/opportunity 6

How to ensure your ERM program will fail Communicate the value of ERM in complex and difficult to understand terms Define risk differently within different departments and divisions Implement the program without top-level support Try to manage all risk on an ongoing basis Consider only net risk rather than gross (inherent) Ignore the need for a strong risk culture 7

Project management risks examples Information Technology Information technology (IT) projects both large and small remain a challenge to deliver successfully Larger projects tend to have a greater likelihood of failure or at least significant scope/cost ‘creep’ Typical risks associated with IT projects include: –Project management related risks (e.g. budget, schedule, staff) –User impact (e.g. lack of training) –Data loss (e.g. vendor/system unreliability) Often root causes tend to relate from lack of governance and unclear business outcomes 8

Project management risks examples Construction Controls Construction related projects are typically away from daily view, such as remote sites, but involve many individuals and third parties Some examples of construction project related risks are: –Safety and environmental risks –Cost management and inefficiency risks –Potential of fraud from internal parties or third parties –Project related risks (e.g. budget, schedule, staff) 9

Criteria of a strong risk culture "individual and group behavior within an organization that determines the way the company identifies, understands, discusses and acts on the risks" Owned by company leadership (action and words) Well defined and understood risk appetite Roles and responsibilities defined in context of risk A supported focus on risk appropriate decision making (process over results) Risk mitigation applied timely and consistently Formal documentation and reporting of risk activity Clearly understood approach to risk management 10

Conclusion Questions? Thank you 11 Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory Joost Houwen, CISA, CISSP, PCI QSA Western Canada Practice Leader IT Security