ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is...

34
ERM 101 Lisanne Sison Director ERM Bickmore

Transcript of ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is...

Page 1: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

ERM 101

Lisanne SisonDirector ERMBickmore

Page 2: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)
Page 3: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM?

Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO) as “a process, effected by an entity’s board of directors, management and other personnel, applied in strategy-setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.”

Page 4: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM?

Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO) as “a process, effected by an entity’s board of directors, management and other personnel, applied in strategy-setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.”

Page 5: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)
Page 6: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

To help assist with the implementation of the ERM process, COSO developed the ERM Integrated Framework (2004), also known as the COSO Cube. This cube is an update to the initial COSO I framework developed in 1992:

Page 7: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

These are the high level goals that are aligned with and support the institution’s mission.

Page 8: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Relate to the ongoing management process and daily activities of the organization.

Page 9: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Relates to the protection of the organization’s assets and quality of financial reporting.

Page 10: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Relates to the organization’s adherence to applicable laws and regulations.

Page 11: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

The Internal Environment relates to the general culture, values and environment in which an organization or entity operates (e.g. – Tone at the top)

Page 12: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Objective Setting relates to the process management uses to set its strategic goals and objectives. Establishes the organization’s risk appetite and risk tolerance.

Page 13: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Event Identification is the process by which an organization identifies events that influence strategy and objectives, or could affect an organization’s ability to achieve its objectives.

Page 14: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Risk Assessment relates to the organization’s process of evaluating the impact and likelihood of events, and prioritizing related risks.

Page 15: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Risk Response relates to determining how management will respond to the risks an organization faces. Will they avoid the risk, share the risk, or mitigate the risk through updated practices and policies.

Page 16: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Control Activities represent policies and procedures that an institution implements to address the risks the organization chooses to accept.

Page 17: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Information and Communication relate to those practices that ensure that the right information is communicated at the right time to the right people.

Page 18: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Monitoring consists of ongoing evaluations to ensure controls are functioning as designed, and taking corrective action to enhance control activities if needed.

Page 19: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

ERM Life Cycle

Internal Environment Event Identification

Risk Response

Control Activities

Objective Setting

Information & Communication

Risk Assessment

Monitoring

Culture

Identify and prioritize risks

Evaluate options

Evaluate Performance

Goal setting

Confirm next steps

Implement

Page 20: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

What is ERM? (cont’d)

Each of these components are considered at multiple levels of the organization, rather than within a single function, unit, or department.

Page 21: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

ERM…

• Provides a comprehensive and systematic approach to more proactive and holistic risk management

• Provides a common lexicon of risk terminology, and provides direction and guidance for implementing ERM

• Requires that organizations examine their complete portfolio of risks, consider how those risks interrelate, and that management develops an appropriate risk mitigation approach to address these risks in a manner that is consistent with the organization’s strategy and risk appetite

Page 22: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

ERM is not…

• A silver bullet to prevent risks from occurring

• A methodology or a checklist of items that need to be completed that guarantee results

• The only way organizations can take a more proactive approach to managing risk

Page 23: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Other Frameworks

CoCo – Stands for “Criteria of Control” and is a risk management tool developed by the Canadian Institute of Chartered Accountants to assist managers and internal auditors in designing, assessing, and reporting on control systems of an organization

Page 24: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Other Frameworks (cont’d)

Cadbury Report – Published in 1992, this report sets out recommendations on the arrangement of company boards and accounting systems to mitigate corporate governance risks and failures.

Recommendations focus primarily on practices related to transparency and accountability at the top levels of an organization, (e.g. – Board of Directors members) rather than in throughout organization as a whole.

Page 25: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Other Frameworks (cont’d)

Australian and New Zealand Standard on Risk Management (AS/NZS 4360:2004, or ASNZS) – Considered by some to be the gold standard for all other risk management standards.

The ASNZS is widely used internationally, and is desirable for its simplicity. (Where the original draft of the COSO ERM Model ran about 154 pages, the ASNZS is only 23 pages.)

Page 26: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Other Frameworks (cont’d)

Below is a diagram of the ASNZS framework:

Page 27: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Other Frameworks (cont’d)

ISO 31000:2009 – Developed by the International Organization for Standardization (ISO) and based off the AS/NZS, ISO 31000 provides principles and generic guidelines on risk management. Provides a universally recognized paradigm for practitioners and companies employing risk management processes across different industries, subject matters and regions.

ISO 31000 is defined as “a process that provides confidence that planned objectives will be achieved within an acceptable degree of residual risk.”

Page 28: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

ISO 31000 Framework Overview

Page 29: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Where’s the Value???

• The biggest value in each of these frameworks lay in their promotion of continuous improvement, diligent management practices and ongoing monitoring.

Page 30: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Relevance (cont’d)

• Organizations are increasingly looking to expand their risk management functions to help reduce potential future losses through:

– Improved monitoring and reporting– Better risk identification and response– More risk-based decision making

Page 31: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Relevance (cont’d)

Based on a recent survey conducted by Towers Watson, the table below illustrates motivating factors to improving various risk management activities in the near term

Page 32: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Relevance (cont’d)

A survey conducted by RIMS and Marsh titled “Excellence in Risk Management VI (2009)”, lists the main barriers to adopting a more strategic approach to risk management as follows:

Page 33: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Questions?

Page 34: ERM 101 Lisanne Sison Director ERM Bickmore. What is ERM? Enterprise Risk Management (ERM) is defined by the Committee of Sponsoring Organizations (COSO)

Lisanne SisonBickmore

[email protected] (916) 244-1119