12016-02-18 Swedish Risk Management System. 22016-02-18 Internal management and control Aiming to Transport Administration with reasonable certainty to.

Slides:



Advertisements
Similar presentations
Module N° 3 – ICAO SARPs related to safety management
Advertisements

AASHTO Internal Audit Conference 2012 – Phoenix Daniel Fodera, CMQ/OE Program Management Improvement Team Federal Highway Administration.
Roadmap for Sourcing Decision Review Board (DRB)
IMFO Audit & Risk Indaba June 2012
Control and Accounting Information Systems
October In May 2000, Walkerton’s drinking water system became contaminated with deadly bacteria, primarily Escherichia coli O157:H7.1 Seven people.
It’s Time to Talk About Risk and Control
ACG 6415 SPRING 2012 KRISTIN DONOVAN & BETH WILDMAN IT Security Frameworks.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
Service Design – Section 4.5 Service Continuity Management.
IT Strategic Planning Project – Hamilton Campus FY2005.
COMP8130 and COMP4130 Adrian Marshall Verification and Validation Risk Management Adrian Marshall.
The Australian/New Zealand Standard on Risk Management
Third Edition Dr. Wasim Al-Habil. Chapter Strategic Management in the Public Sector.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
1 Risk management and Investigation Peter Roberts
Risk Assessment Frameworks
61 What is hazard risk management?. 62 Emergency risk management is “a systematic process that produces a range of measures that contribute to the well.
Session 3 – Information Security Policies
How can projects be controlled?
Chapter 11.  The board is ultimately responsible for risk management  Oversee strategic risks, operational risks, and financial risks  Many federal.
Privileged and Confidential Strategic Approach to Asset Management Presented to October Urban Water Council Regional Seminar.
Control environment and control activities. Day II Session III and IV.
Information Technology Audit
Session No. 3 ICAO Safety Management Standards ICAO SMS Framework
What is Business Analysis Planning & Monitoring?
Information Security Compliance System Owner Training Richard Gadsden Information Security Office Office of the CIO – Information Services Sharon Knowles.
 This presentation looks at: › What is risk management › How to identify risks › How to implement an effective risk management policy to increase your.
Qantas Brand Refresh Kristy Dixon – Masters of Applied Project Management University of Adelaide 2013 Results of Risk Analysis Plan Hypothetical Project.
Copyright 2005 Welcome to The Great Lakes TL 9000 SIG TL 9000 Requirements Release 3.0 to Release 4.0 Differences Bob Clancy Vice President, BIZPHYX,
Postgraduate Educational Course in radiation protection and the Safety of Radiation sources PGEC Part IV The International System of Radiation Protection.
Risk Management Report to Audit Committee 26 September 2006 Lee Harris Assistant Chief Executive.
Implementing and Auditing Ethics Programs
Basics of OHSAS Occupational Health & Safety Management System
Organize to improve Data Quality Data Quality?. © 2012 GS1 To fully exploit and utilize the data available, a strategic approach to data governance at.
EQARF Applying EQARF Framework and Guidelines to the Development and Testing of Eduplan.
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
COBIT - IT Governance.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Roles and Responsibilities
Implementing and Auditing Ethics Programs
GBA IT Project Management Final Project - Establishment of a Project Management Management Office 10 July, 2003.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
1 Introducing Enterprise Risk Management (ERM) - The KOC Experience November 2012 Khaled Al-Awadhi Risk Management Team Kuwait Oil Company.
“Integrating Property Management with Emergency Recovery” Ivonne Bachar, CPPM CF Director, Property Management Office Stanford University
Management System Part I: Quality System. Management system Objectives To understand the importance of a management system to ensure effectiveness of.
Example Incident Mgmt Initiation No recording of Incidents Users can approach different departments Solutions of previous incidents are not available.
DOE ASSET MANAGEMENT PLAN
SAFETY MANAGEMENT SYSTEM IN TURKISH STATE RAILWAYS (TCDD)
The Risk Management Process
Organization and Implementation of a National Regulatory Program for the Control of Radiation Sources Management Systems Part I.
12-CRS-0106 REVISED 8 FEB 2013 APO (Align, Plan and Organise)
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Support to the Ministry of Finance of Albania regarding Improved Financial Management and Control of Public Funds Swedish Transport Administration.
Risk Management and the Audit Plan abc CIPFA in the Midlands Audit Training Seminar Wednesday 24th November 2004 Tina Spiers.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
PIC EU-28 Conference Paris, 26 – 27 November 2015 PIC An EU Approach Assurance Maps An Introductory workshop Nathan Paget United Kingdom.
>> The concept of strategic planning Kirsten Wismer Director of Macroeconomic Statistics.
Alex Ezrakhovich Process Approach for an Integrated Management System Change driven.
Dolly Dhamodiwala CEO, Business Beacon Management Consultants
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
Business Continuity Planning 101
Safety Management Systems Session One APTA Webinar March 22, 2016.
Safety Management Systems Session Four Safety Promotion APTA Webinar June 9, 2016.
Building the Foundation of Compliance
Building the Foundation of Compliance
Taking the STANDARDS Seriously
Presentation transcript:

Swedish Risk Management System

Internal management and control Aiming to Transport Administration with reasonable certainty to meet regulatory requirements of the regulation on the business: Conducted efficiently; Conducted in accordance with applicable law and obligations; Reported in a reliable and accurate manner; Be economical well with state funds Means that: Clearly delegate responsibility and authority, and establish procedures and rules for the operation. In order to secure ongoing work, the following must be integrated into business management: -Implement a proven business analysis (risk analysis) -Take control measures to manage the risks -Systematically and regularly monitor and assess ISK

Common management philosophy Common governance common work common working common tools Financial management Rule Control Objectives and results Shared values Project Manage ment areas ongoing operations Process-oriented approach, risk management etc. Models, systems, etc. Overall control and management framework Internal Governance and Control Transport Administration Rules

Lines of responsibilities for Internal management and control / Risk Management The line organization, Support functions Risk Ownership Own risk and risk management activities Internal control; safety, emergency and security, Information, etc. Risk Management functions Establishes and instructions framework for risk assessment and follow-up Internal audit; quality audit, Audit activities Audit functions Testing and validation of effectiveness of risk management and control Common concepts and definitions Common methods and tools Joint monitoring and reporting structure Common support schemes First line of responsibility Second line of responsibilityThird line of responsibility

Business analysis – Manage and control – Board of Directors’ assurance Transport Adm. process work Follow up Board of Directors’ Assurance of internal control Transport Adm. Business analysis Risks and opportunities for internal control Transport Adm. strategy and governing criteria for internal control and risk management May: DG approval June: passed by the Board Whole year: STA implements measures In connection with the annual report Transport Adm. Guideline for risk management Internal and external audit based on operational analysis and review system

Content in the Transport Adm. strategy and governing criteria Risk strategy Formalities Transport Adm. Business analysis Executive management’s acceptance criteria in the form of a risk assessment matrix and opportunities matrix covering the entire operations Criteria for escalation Event, incident and crisis management

Consolidated risk matrix and profile The top evaluation support are used as an aid to: evaluate and rank decide if risks and serious incidents that occur should be escalated to higher organizational level Issued by executive management as the basic premises for the risk and opportunities assessments.

Consolidated opportunities matrix and profile

Content in the Transport Adm. Business analysis The overall working process for Internal management & control Highly prioritised risks and opportunities, aggregated from the entire organization

consequence Very serious Minor Probability Low Very high 5MåttligAllvarlig Mycket allvarlig 4Måttlig Allvarlig Mycket allvarlig 3LågMåttlig Allvarlig 2LågMåttlig Allvarlig 1Låg Måttlig Examples of presentation of the risks No. Board Risk Management Risks 12N 12G Change of risk New risk

Risk management process integrated into the planning and follow up Risk Monitoring and Communications Risk assessment Risk identification Risk analysis Risk Evaluation Risk treatment Documentation / Risk Register Risk Monitoring and Communications MissionReporting Input values Risk Profiler / Basis for risk reports Project, management and ongoing operations SocietyTrafficMajor projectsProfit centers Top Management Mission Reporting Investment Key functions

Swedish Road Administration Transport Adm. strategy and governing criteria Risk Management in: Balanced Scorecard Project Working processes Safety (IT-security, Working, Environmental, Offices etc.) Normal Condition / Serious Condition / Crisis Crisis Management Transport Adm. Business analysis Risks and opportunities for internal management and control

Risk Management - Balanced Scorecard - Government Focus Critical Goals Financial Focus Critical goals Co-worker Focus Critical Goals Work approaches focus Critical Goals Customer Focus Critical Goals VISION Risk Analysis Plan for Action

Infrastructural project Strategic Planning Physical Planning Construction Roads in use (maintenance) Riskprofile deliveries to risk owners (contractor, consultant, municipality, project sponsor, etc.) and demands for supplier’s own risk management. Deliveries

Working method risk management of the organization's processes Step 4 Establish requirements for the process Step 4 Establish requirements for the process Step 2 Identify stakeholders and their interests Step 2 Identify stakeholders and their interests Step 1 identify process Step 1 identify process Step 6 Analyze / identify improvement needs Step 6 Analyze / identify improvement needs Step 5 Goals and metrics to measure process Step 5 Goals and metrics to measure process Step 3 Mapping Process Step 3 Mapping Process Determining input values Risk Assess (identify, analyze, evaluate)) Risk treat and follow up Process Analysis - problem analysis - Analysis of the contact surfaces with customer - Value Analysis - Liability Analysis Process Analysis - problem analysis - Analysis of the contact surfaces with customer - Value Analysis - Liability Analysis Risk, threat and vulnerability analyzes Goals and Results, Projects, Management, Operating activities Process

Road Using Phase – One Possible Approach The map shows prioritization of the links based on the road user perspective, which causes most public economy damage if not operational (has high traffic volume and long reserve alternative road). Investigate probability for hazards (e.g. snowstorms, windstorms, landslides, fog, accidents) for the highest prioritized links. Complete with e.g. source of water supply, dangerous goods transportation, hospitals. Evaluate, rank the risks and carry out risk reduction measures.

Known knowns… and unknown unknowns known unknowns… The world – as we knows it… ACCIDENTS

Unexpected or not?

Hazard within the transport system Hazard from surroundings Hazard from the transport system Crisis Management – Main Scenarios