enterprise risk management seminar presenters
play

Enterprise Risk Management Seminar Presenters Marcus Harwood - PowerPoint PPT Presentation

Enterprise Risk Management Seminar Presenters Marcus Harwood Christine DiMenna Partner Principal blumshapiro blumshapiro cdimenna@blumshapiro.com mharwood@blumshapiro.com 860.570.6439 860.570.6474 2 Agenda Discuss recent ERM trends


  1. Enterprise Risk Management Seminar

  2. Presenters Marcus Harwood Christine DiMenna Partner Principal blumshapiro blumshapiro cdimenna@blumshapiro.com mharwood@blumshapiro.com 860.570.6439 860.570.6474 2

  3. Agenda » Discuss recent ERM trends with boards and executives » Learn about a four-step ERM methodology » Explore how you can create your own ERM process » Discover how ERM can be used to explore and create exciting possibilities 3

  4. Enterprise Risk Management (ERM) » What is ERM? ‒ Important strategic tool that helps Management and the Board of Trustees evaluate risks that might impact the organization’s long-term strategic success ‒ Business strategy and process that helps to identify, assess and prepare for issues that may interfere with an organization’s overall operations 4

  5. Enterprise Risk Management (ERM) » What is the goal? ‒ Identify and prioritize the core risks (internal/external) to the organization and create a set of tasks/activities to minimize the effects of those risks 5

  6. Recent » Ownership of ERM is changing Trends » Organizations are realizing the value » Boards are recognizing ERM as a best practice » ERM is being integrated with other business processes » Alignment with strategic plan » Increasing collaboration 6

  7. blumshapiro’s Four Step Methodology Reevaluate Risks & Prioritizations Phase I Phase II Phase III Phase IV Risk Governance Risk Identification Risk Mitigation & Risk Monitoring & Structure & Prioritization Testing Tracking » » Identify/confirm risk Ongoing monitoring of due » » Confirm ERM steering Identify/confirm core ERM mitigation strategies for dates of risk mitigation tasks committee categories » high/medium risks Ongoing monitoring of » » Confirm governance Identify risk owners to » Assess design effectiveness emerging risks structure/approach interview » » » of risk mitigation plans Develop quarterly reports of Develop/confirm risk Initiate focus » Test operating effectiveness risk mitigation results management policy and group/individual interviews of risk mitigation plans standards with risk owners » Review results with ERM » » Develop/confirm Send risk surveys to risk steering committee communication policy and owners » standards Develop/confirm ERM risks » Develop/confirm ERM by category » process and approach ERM steering committee prioritizes risk » Final review/approval of risk matrix 7

  8. Phase I: Risk Governance Structure Confirm Develop/Confirm Confirm ERM Confirm Develop/Confirm Governance Risk Management Communication ERM Process & Structure & Management Team Standards/Policy Approach Approach Policy Standards Facilitated Meetings Deliverables » List of ERM steering committee members (name, position, email, phone number) » Documented governance structure and approach used by ERM steering committee » Documented risk management policy standards » Document communication policy standards » Document ERM process and approach 8

  9. Phase II: Risk Identification & Prioritization Identify Risk Develop/Confirm Owners to ERM Risks by Interview Category Initiate Focus Identify/Confirm Final Group/Individual Core ERM Review/Approval Interviews with categories of Risk Matrix Risk Owners Send Risk ERM Steering Surveys to Risk Committee Owners Prioritizes Risk Phase IV: Emerging Risks 9

  10. Phase II » List of ERM categories Deliverables » List of risk owners to interview » Memorandum to risk owners apprising them of the goals/objectives of the ERM project » Risk survey based on interviews (to be determined) » List of ERM risks, prioritized by category (risk matrix/register) » Risk heat map » Steering committee sign-off of prioritized ERM risks 10

  11. EXECUTIVE SUMMARY Example

  12. ERM Enterprise Risk Management (ERM) is the discipline by which an organization in any industry assesses, controls, exploits, finances, and monitors risks from all sources. Overview ERM helps to address the needs of management and Boards, who want to understand the broad spectrum of risks facing complex organizations to ensure they are appropriately managed. Organization ERM Project Facts All Risks Impact the Organization’s Reputation » 12 individual or department interviews were held, including key Adverse Event Loss of Trust team members •Negative events can •The Community impact the » trusts the 47 risks were identified perception of the Organization Organization » The leadership team met and rated risks online Philanthropy Outcomes » Risks were rated based on impact •The region expects •Organization needs and probability lasting to create innovative philanthropic community » Final risk ratings reviewed to ensure solutions outcomes consistency » Heat map developed; risks clustered to center right half 12

  13. Heat Map Organization ERM Risk Assessment 5 4.5 4 46 5 3.5 28 42 Probability/Likelyhood 34 33 11 16 45 3 18 15 25 4 1 32 20 37 47 44 26 35 36 2.5 31 21 40 43 30 38 19 9 12 23 29 27 3 2 22 41 6 39 8 10 7 2 14 17 1.5 24 13 1 1 0.5 0 0 0.5 1 1.5 2 2.5 3 3.5 4 4.5 5 Impact 13

  14. ERM Top Risks by Combined Risk Ratings Briefing Based on the ERM project, the following risks have been identified as most critical to the Organization. The Leadership Team will identify which risks to remediate first and assign ownership responsibilities to key people within the organization to help create remediation strategies. Risk Combined RankingRisk Description Impact Probability Risk Rating 1. 4.29 4.86 20.85 2. 4.57 4.43 20.25 3. 4.43 4.57 20.25 4. 4.29 4.43 19.00 5. 4.43 4.29 19.00 6. 4.57 4 18.28 7. 4.43 4 17.72 8. 4.57 3.86 17.64 9. 4.14 4.14 17.14 10. 4.71 3.57 16.81 Reputational Risk Continuum 14

  15. Phase III: Risk Mitigation & Testing Identify/Confirm Risks Assess Design Test Operating Review Results with Mitigation Strategies Effectiveness of Risk Effectiveness of Risk ERM Steering for High/Medium Risk Mitigation Plans Mitigation Plans Committee Deliverables » Risk mitigation work plans » Testing results and observations document(s) 15

  16. Phase IV: Risk Monitoring & Tracking Ongoing Monitoring of Review Risk Results Ongoing Monitoring of Due Dates of Risk Quarterly with Steering Emerging Risks Mitigation Tasks Committee Phase II Review Deliverables » Updated risk matrix/register document » Quarterly risk results document 16

  17. Challenges » Demonstrating the benefit of ERM » Defining risk » Establishing ownership » Determining the appropriate approach » Identifying and quantifying risks 17

  18. Challenges » Prioritizing risks » Developing mitigation plans » Follow through of risk mitigation plans » Risk reporting » Keeping ERM alive 18

  19. Other » Risk mitigation plans can expose ERM previously unidentified risks and/or Outcomes opportunities ‒ Information technology ‒ Human resources ‒ Data and analytics 19

  20. Q&A

  21. THANK YOU

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend