COSO: Current ERM Challenges and Our Responses RIMS 2012 Annual Conference April 17, 2012 by David Landsittel COSO Chairman.

Slides:



Advertisements
Similar presentations
Organizational Governance
Advertisements

Risk Management at Harvard – Panel Discussion Harvard IT Summit
Lisanne Sison Director ERM Bickmore
Course: e-Governance Project Lifecycle Day 1
Corporate Governance Chapter 2.
Chapter 10 Accounting Information Systems and Internal Controls
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
It’s Time to Talk About Risk and Control
The Development of Enterprise Risk Management and Supervision for Insurance Companies in Taiwan Dr. Huang, Tien-Mu Director General, Insurance Bureau Financial.
Introduction to Enterprise Risk Management (ERM)
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
1 Sarbanes-Oxley Section 404 June 29,  SOX 404 Background 3  SOX 404 Goals 4  SOX 404 Requirements 5  SOX 404 Assertions 6  SOX 404 Compliance.
Government Auditing Standards
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
Office of the Secretary of Defense – Comptroller Financial Improvement and Audit Readiness Directorate Unclassified 17 September 2014 GAO Revised “Green.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Operational Auditing--Spring Operational Auditing Spring 2011 Professor Bill O’Brien.
Applying COSO’s Enterprise Risk Management — Integrated Framework
Expanded Version of COSO a presentation by Steve Wadleigh Expanded Version of COSO a presentation by Steve Wadleigh Standards for Internal Control in the.
Auditing A Risk-Based Approach To Conducting A Quality Audit
Risk Assessment Frameworks
1 Audit, Control and Risk Management Budget Management and Financial Accountability Steven E. Jameson Lead Auditing Specialist, IAD March 2, 2004.
GOOD GOVERNANCE PRINCIPLES AND GUIDANCE for Not-for-Profit Organisations Promoting good governance and supporting directors and boards of not-for-profit.
COSO Framework Update IIA Columbus Chapter May 17, 2013
Chapter 4 Internal Controls McGraw-Hill/Irwin
Chicagoland IASA Spring Conference
COBIT® 5 for Risk Introduction
Fall 2003 Auditing Update for Auditing and Assurance Services: An Integrated Approach.
The role of internal audit in enterprise-wide risk management (ERM)
1 Bölgesel Rekabet Edebilirlik Operasyonel Programı’nın Uygulanması için Kurumsal Kapasitenin Oluşturulmasına Yönelik Teknik Yardım Technical Assistance.
Fraud & Internal Control Frank M. Klaus, CPA. Fraud Definition  Fraud is the misappropriation of assets for the benefit of an individual.  “Willful.
Chapter 3 Internal Controls.
1 Enterprise Risk Management (ERM) Program PNM Resources, Inc. March 29, 2007 Presentation to American Public Power Association March 2007 Austin, Texas.
Transitioning to the COSO 2013 Update.  Released on May 14, 2013  Designed to build upon the foundation of the 1992 Framework  Will supersede the 1992.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
Building a Corporate Risk Culture Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory Joost Houwen, CISA,
Chapter Three IT Risks and Controls.
Copyright T. Rowe Price. All rights reserved 1 Ms. Deborah D. Seidel of T. Rowe Price Financial Services Vice President and Manager of Compliance.
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
IRS Enterprise Risk Management (ERM)
Risk Management For the Board of The Law Society 16 February 2005.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
SUERF Annual Lecture Risk Management – A supervisor’s approach Gabriel Bernardino EIOPA Chairman Helsinki, 22 September 2011.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Berrydunn.com | GAIN CONTROL Enterprise Risk Management: from Resistance to Resilience NASACT 2014 Annual Conference Bill Brown, Principal, BerryDunn.
An Update of COSO’s Internal Control–Integrated Framework
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
1 Possible elements for the EGTT future programme of work on technologies for adaptation Mr. Jukka Uosukainen Chair Expert Group on Technology Transfer.
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
" The Importance of RM in strategic in sustainable service delivery How to avoid Service Delivery Protest ” Institute of Municipal Finance Officers & Related.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
Company LOGO Chapter4 Internal control systems. Internal control  It is any action taken by management to enhance the likelihood that established objectives.
ERM and Information Risks July 2013 Advisory. 1 © KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent.
USDA 2016 Financial Management Training Transforming Shared Services
JMFIP Financial Management Conference
Introduction Outline: Importance IT Governance
COSO and ERM Committee of Sponsoring Organizations (COSO) is an organization dedicated to providing thought leadership and guidance on internal control,
COSO’s New ERM Exposure Draft: What You Should Know
اطار الرقابة الداخلية و فقا للجنة دعم المنظمات COSO
Internal Audit & Enterprise Risk Management
A Framework for Control
Internal Control–Integrated Framework
COSO Internal Control s Framework
Internal control - the IA perspective
An Update of COSO’s Internal Control–Integrated Framework
Presentation transcript:

COSO: Current ERM Challenges and Our Responses RIMS 2012 Annual Conference April 17, 2012 by David Landsittel COSO Chairman

About COSO Formed in 1985 to sponsor a Commission to examine fraudulent financial reporting A joint initiative of five private sector organizations Sponsors: – American Accounting Association (AAA) – American Institute of Certified Public Accountants (AICPA) – Financial Executives International (FEI) – Institute of Management Accountants (IMA) – The Institute of Internal Auditors (IIA)

COSO’s Mission is “To provide thought leadership through the development of comprehensive frameworks and guidance on enterprise risk management, internal control and fraud deterrence designed to improve organizational performance and governance and to reduce the extent of fraud in organizations.” COSO’s Fundamental Principle Good risk management and internal control are necessary for long term success of all organizations Mission

COSO’s Three Areas of Focus 1.Enterprise Risk Management 2.Internal Control 3.Fraud Deterrence

: Treadway Commission Report 1992: Internal Control – Integrated Framework 1999: Fraud Study I - Fraudulent Financial Reporting: : Enterprise Risk Management Framework 2006: Guidance for Smaller Businesses on Internal Control over Financial Reporting 2009: Guidance on Monitoring Internal Control Systems Timeline 1996: Internal Control Issues in Derivatives 2010: Fraud Study II - Fraudulent Financial Reporting: : Recent ERM thought papers on current issues

COSO ERM Framework Issued in 2004 Fundamental characteristics – A portfolio view of risks at the entity-level – Risk identification, prioritization, and response – Managing risk within the entity’s risk appetite – Consideration of risks in formulation of strategy Widely but not universally used Implementation not as robust

Some Current ERM Challenges that Impact COSO Uneven support to adopt any formal risk management process Less than robust ERM implementation Difficulty “getting started” with ERM implementation Failure to consider low likelihood but high impact risks – overconfidence Inadequate board oversight of risk management – and regulatory pressure mounting for better oversight Immature development of risk appetite

COSO ERM Response Our objective – to assist stakeholders in moving up “maturity curve” of an effective ERM process 8

COSO ERM “Thought Papers” 9 1.“Effective Enterprise Risk Oversight: The Role of Board of Directors” – 09/ “Strengthening Enterprise Risk Management for Strategic Advantage” – 10/ “Board Risk Oversight – A Progress Report” – 12/ “COSO’s 2010 Report on ERM” – 12/ “Embracing Enterprise Risk Management: Practical Approaches for Getting Started” – 01/ “Developing Key Risk Indicators to Strengthen Enterprise Risk Management” – 01/ “Understanding and Communicating Risk Appetite” – 01/ “Enhancing Board Oversight: Avoiding Judgment Traps and Biases” – 03/2012 Coming Soon: – “COSO Enterprise Risk Management for Cloud Computing”

Outlines four areas contributing to effective ERM board oversight 1.Understanding risk appetite 2.Understanding how an entity’s portfolio of risks aligns with risk appetite 3.Understanding most significant risks and how management is responding 4.Understanding and assessing risk management processes 1. “Effective Enterprise Risk Oversight: The Role of Board of Directors”

Focuses on how management can work with board to enhance board’s oversight capabilities Discusses the four ERM focus areas noted on preceding slide, but from a management perspective 2. “Strengthening Enterprise Risk Management for Strategic Advantage”

3. “Board Risk Oversight – A Progress Report” Major findings: – Strong majority reports boards not executing mature/robust risk oversight processes – Overall dissatisfaction in the way risk is considered in context of enterprise’s strategy – Processes for monitoring and reporting of risks should be enhanced – Public companies report better processes than other enterprises

The state of ERM appears to be relatively immature, with a notable level of dissatisfaction with how organizations are currently overseeing enterprise-wide risks Reporting of top risk exposures to the board appears to be casual and unstructured Most respondents believe that the COSO ERM Framework is theoretically sound and describes key elements of a robust ERM process 4. “COSO’s 2010 Report on ERM: Current State of Enterprise Risk Oversight”

Describes how an organization can start to move from informal risk management to ERM Discusses the increasing importance of an enterprise focus on risks Examines perceived barriers to starting ERM and working through those barriers 5. “Embracing Enterprise Risk Management: Practical Approaches for Getting Started”

6. “Developing Key Risk Indicators to Strengthen Enterprise Risk Management” Emphasizes need for ERM processes that focus on forward looking information – i.e. key risk indicators or ”KRI’s” Illustrates how KRIs heighten board and management enterprise risk awareness Provides practical examples to help executives develop effective KRI’s

7. “Understanding and Developing Risk Appetite” Emphasizes that risk appetite is the amount of risk an organization is willing to accept in pursuit of its objectives Stresses that risk and strategy are intertwined – strategy must be formulated with due regard to risk appetite Points out that risk appetite should be communicated by management, embraced by the board, and integrated throughout the entity Emphasizes that well communicated risk appetite serves as a boundary around the amount of risk an organization might take on

8. “Enhancing Board Oversight: Avoiding Judgment Traps and Biases” Observes that the complexities of the global business environment place a premium on sound judgment and decision making Highlights some pitfalls and biases in judgment to which decision makers are vulnerable Details a five-step judgment process that board members and others can use to overcome common pitfalls and mitigate the effects of judgment bias

“COSO Enterprise Risk Management for Cloud Computing” – Coming Soon Emphasizes that cloud computing entails new business risks because it brings to organizations a different dimension of collaboration and human interaction et al Applies COSO ERM model to risk considerations Points out that for many organizations applying cloud computing with appropriate risk mitigation in place will bring multiple benefits

David Landsittel Thank You