1
Flexibility of WRM and The Power of WRM
Bob Adderley
Flexibility of WRM and The Power of WRM Bob Adderley 1 Risk - - PowerPoint PPT Presentation
Flexibility of WRM and The Power of WRM Bob Adderley 1 Risk Management (GRCA) are the starting point but you can add on many other things including: Internal Audit Business Continuity Management Incident Management Policy
1
Bob Adderley
2
3
4
.
5
6
7
8
9
10
disruption, and building capacity to: – Stabilise any disruptive effects as soon as possible – Continue or quickly resume operations that are most critical to the
– Expedite a return to normal operations and a full recovery
integrated with ERM practices.
11
Determine business activity / processes to be analysed Process Review
Prepare inventory list of controls / determine significance of disruption
Determine the case for risk treatment Record and review contingency plan. Add / Update Risk linked to Processes Business Impact Analysis Add / Update Risk & Control with impact of disruption Add / Update Risk Treatment Contingency Plan
12
13
14
15
16
17
18
– Loss Events reporting for Operational Risk Management in Financial Institutions – Incident Reporting for healthcare organizations – Occupational health and safety accident reporting – Fraud / Irregularities reporting
20
21
22
24
25
Incidents, including those with Financial Impact
26
27
developed to meet the following high-level process.
Policy Creation Policy Approval Policy Attestation
Policy Creation Policy Version Policy Authoring Policy Review Policy Approval Policy Publish Policy Testing Policy Attestation
28
29
if required). Note the Status of the policy as it moves through the workflow
30
31
32
an exemption if required.
33
34
35
36
37
38
39
UNITED KINGDOM UNITED STATES CANADA DUBAI AUSTRALIA NEW ZEALAND
40
MS SQL Server Reporting Services (SSRS)
allows for integration with SSRS using both a Reporting Component that can be added to the Dashboard views, and a reporting menu command on Dashboard Lists
compatible with SSRS) External Reporting Interface (vERI)
extraction purposes
used to create reports in other external reporting tools such as Crystal Reports, Business Objects or Cognos
43
44
45
46
47
48
Vendor Management Examples
BCP items, etc…
49
Criticality and Spend
50
Vendor Details
51
Issues/Concerns/Criticality tied to Vendors/Systems
52
Contract Renewal Dates
53
54
Vendor Questionnaire Overview
58
UNITED KINGDOM UNITED STATES CANADA DUBAI AUSTRALIA NEW ZEALAND
59
60
– User friendly interfaces: easy to use, fewer errors, reduced training time – Standardize approach: ensure consistent workflow across the enterprise – Engage experts in directly managing the components of GRC – Centralized, timely data: ease of monitoring, updating, reporting – Flexible dashboards: analyze information in new ways – Eliminate redundancy and duplicate effort – Reduce overhead of chasing and collating data
61
– Best approach is to treat this like a standard project – Begin with Requirements Analysis – Expand focus to what we’d like to be able to do, Not limit ourselves to what we are currently doing with ERA – Engage the Subject Matter Experts throughout – Including groups that aren’t going to use immediately – Document all objectives and requirements: – Immediate short term – Medium term – Long term – Phased approach is best - Don’t boil the Ocean
62
63
Bob’s Winter Igloo Home
64
UNITED KINGDOM UNITED STATES CANADA DUBAI AUSTRALIA NEW ZEALAND
65
employees
direct access for external auditors.
1740 users to 2, 4 or 8 hour sessions depending on roles.
bitmaps of testing calendars
66
improvements and extensions
67
Officers updating items.
Complaints Management.
68
– Wasted low value work chasing, correcting data
– WRM to improve quality
– WRM to standardize
– Centralize the data – reduce delays
69
categories and processes
improvements, directives from Leadership Committees.
tasks.
70