Risk Governance Evolving beyond the traditional

Published  . 0 views
↓ Download
Risk Governance Evolving beyond the traditional
1 / 1
Risk Governance Evolving beyond the traditional - slide 1 of 26 Risk Governance Evolving beyond the traditional - slide 2 of 26 Risk Governance Evolving beyond the traditional - slide 3 of 26 Risk Governance Evolving beyond the traditional - slide 4 of 26 Risk Governance Evolving beyond the traditional - slide 5 of 26 Risk Governance Evolving beyond the traditional - slide 6 of 26 Risk Governance Evolving beyond the traditional - slide 7 of 26 Risk Governance Evolving beyond the traditional - slide 8 of 26 Risk Governance Evolving beyond the traditional - slide 9 of 26 Risk Governance Evolving beyond the traditional - slide 10 of 26 Risk Governance Evolving beyond the traditional - slide 11 of 26 Risk Governance Evolving beyond the traditional - slide 12 of 26 Risk Governance Evolving beyond the traditional - slide 13 of 26 Risk Governance Evolving beyond the traditional - slide 14 of 26 Risk Governance Evolving beyond the traditional - slide 15 of 26 Risk Governance Evolving beyond the traditional - slide 16 of 26 Risk Governance Evolving beyond the traditional - slide 17 of 26 Risk Governance Evolving beyond the traditional - slide 18 of 26 Risk Governance Evolving beyond the traditional - slide 19 of 26 Risk Governance Evolving beyond the traditional - slide 20 of 26 Risk Governance Evolving beyond the traditional - slide 21 of 26 Risk Governance Evolving beyond the traditional - slide 22 of 26 Risk Governance Evolving beyond the traditional - slide 23 of 26 Risk Governance Evolving beyond the traditional - slide 24 of 26 Risk Governance Evolving beyond the traditional - slide 25 of 26 Risk Governance Evolving beyond the traditional - slide 26 of 26
Description: Risk Governance Evolving beyond the traditional Three lines of defense model Implications for Internal Audit Leon Bloom Partner lebloomdeloitte.ca May, 2015 Agenda Emerging risk governance requirements Context and expectations

Related Topics

Download Presentation

"Risk Governance Evolving beyond the traditional" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Risk Governance Evolving beyond the traditional ‘Three lines of defense’ model – Implications for Internal Audit Leon Bloom
Partner
lebloom@deloitte.ca

May, 2015<br>
slide2. Agenda Emerging risk governance requirements – Context and expectations
Current practices in risk governance – Issues, challenges and shortcomings
Guiding principles – Roles, responsibilities and accountabilities
Guiding principles – Policies, processes and practices
Three lines of defense – Definition vs. effective application and the case for redesign
Aligning the risk governance model with the business model and risk and capital management processes
Structures for risk taking, risk oversight, risk assurance (Internal Audit) and board oversight
The business case for transition, challenges and benefits 2<br>
slide3. Among other things, regulators are giving emphasis to four high priority areas The inherent riskiness of the business model – Where and how are earnings generated and is there is an extreme or concentrated dependency on a particular source or sources and how is the associated risk(s) articulated and addressed/mitigated?
Tail risk – Has a competent process been established to identify tail risks and have the risks been objectively and realistically assessed vs. being underestimated?
Risk Governance – How well defined and embedded is the risk governance model? Is the assurance function (Internal Audit) being used as a management control or substitute for quality assurance and peer review practices by risk taking areas and the risk management function? Does the governance model in practice align with and support the principals of a sound risk management and control culture?
Operating culture – the degree of awareness, attitudes, and behaviors of an organization’s employees toward risk and how risk is managed within the organization. Risk culture is a key indicator of how widely an organization’s risk management policies and practices have been adopted. 3<br>
slide4. Risk governance requirements 4<br>
slide5. Emerging risk governance requirements The significantly changed environment resulting from the continuing global financial crisis has resulted in a ‘higher hurdle’ of regulatory requirements and Board expectations pertaining to the timeliness and quality of risk information, and robustness of risk management processes and practices. 5<br>
slide6. Risk governance – Challenges Governance observations
Roles, responsibilities and accountability are often unclear
Second and third line functions being used as management assurance and quality control functions
Communication paths are not defined
Committee structures, responsibilities and mandates lack clarity
Objectives and the target end state for ERM is unclear
Insufficient focus and time spent discussing risks across the organization
Monitoring fails to identify risk conditions and provide a competent understanding of exposure status
ERM programs are often not dynamic and fail to proactively identify and adapt to unexpected events ERM is a continuous activity that aggregates and integrates risk management activities in order to better optimize risk-adjusted returns 6<br>
slide7. Guiding principles – Roles and responsibilities The governance model should promote transparency of accountability, communication, decision making, and information flows
Decisions and accountability should reside with individuals, not committees, wherever possible
Business areas retain accountability for managing their own risks – That responsibility is not ‘transferred’ to the risk oversight function
All classes of risk should have clearly assigned responsible/accountable parties in the governance model (e.g., should not be purely focused on product risk)
Decisions should be made with appropriate consideration of the ‘enterprise’ impact - not just the impact of individual lines
Risk governance structure should clearly reflect the roles and interaction with pricing, underwriting, reserving, and other critical, interdependent functions
The structure should enable risks to be appropriately considered and factored in to broader business decisions
Should clearly articulate the requirements for independent assurance (e.g., Independent Audit) 7<br>
slide8. Guiding principles – Processes and policies Risk governance must be supported and enabled by explicit policies with transparent accountabilities and authorities
The governance processes should be as streamlined as possible, avoiding unnecessary levels of decision-making bureaucracy
Risks should ‘aggregate’ and integrate at the appropriate level of governance, including cross line, cross business unit, enterprise; the governance model should include ‘owners’ of the aggregated risk at each level within an aggregation hierarchy
Monitoring process must be clearly articulated in the governance model (including responsibilities, frequency, etc.)
Governance must be linked to a philosophy/vision/or governing objective at the top
Governance should enable making risk management processes proactive rather than reactive
The governance model should not be static – it should be re-evaluated every year to ensure appropriate evolution 8<br>
slide9. The evolution of the ‘lines of defense’ model 9<br>
slide10. Framework provides a design for the governance infrastructure and governance operating model. The top part of the framework depicts areas where responsibility of the board is typically heightened. A risk governance framework provides the foundation for oversight and establishing the necessary ‘checks and balances’ regarding risk taking A risk governance framework helps clarify oversight responsibilities by establishing a common foundation 10<br>
slide11. A focused assessment is needed to fully understand an organization’s current Risk Culture and to track progress of cultural change Measuring the risk and control culture 11<br>
slide12. Maturity Model Levels Risk practices maturity model 12<br>
slide13. Three lines of defense – Issues and challenges Enable Validation & assurance reporting Internal
Audit
Validation of controls
Objective review of risk management process
Assurance to senior executive management and Board on assertions of risk exposure Risk
Management
Policies, governance and information flow
Risk assessment methods
Measurement, aggregation rules and tools
Monitor risk exposure status and report to Board Assure Board of Directors & Senior Executive Management Report Assert Assertions on status of risk exposure Business Unit
Management
and Staff
Risk identification and assessments
Actions to exploit, reduce, transfer, or avoid risk
Provide assertions on risk exposure for each business unit or functional area within NFS 3rd line 2nd line 1st line 13<br>
slide14. Evolution of the three lines of defense Line of Business
(1st line of defense):
Day to day management & risk control Internal Audit
(3rd line of defense):
Independent assurance Risk
management framework Risk & Compliance
(2nd line of defense):
Risk policies, methodologies & oversight Regular risk model monitoring, peer or management compliance reviews of policies and controls, regular status reporting, monitors risk profile, effectiveness of controls & residual risk, monitors & ensures capital adequacy, ensures data accuracy, implements controls and reporting framework, reviews the impact of regulatory requirements to processes, policies and controls Completes regular risk model validation, annual reviews of policies and controls, addresses escalated risks, reviews and challenges risk appetite considering emerging risks and change risk profile, review policies regularly to ensure alignment with business strategy, ensures regulatory changes are developed and implemented in a timely manner Quality assurance review for internal controls, reviews compliance results, reviews overall approach to regulatory changes, peer review/periodic self assessment on the effectiveness of internal audit Executive Management: Reviews and updates risk appetite and strategy, processes, risk model and reporting framework The Board of Directors: Reviews and approves risk appetite, processes, risk model and reporting framework 14<br>
slide15. Risk taking structure Key Objectives & Responsibilities 15<br>
slide16. Risk oversight structure Board of Directors Overall accountability for the enterprise risk profile
Delegates responsibility and authority for risk management to Senior Management/Executive Management Committee
Approves overall risk appetite and the philosophy on risk taking Executive Management Committee Ultimately responsible for accepting the risks taken by the businesses within the context of the approved risk appetite and risk philosophy
Responsible for ensuring the effective management and control of risk by the business Enterprise Risk Management Committee Establishes risk management policy and recommends to the Executive Management Committee prior to submission to the Board for approval
Provides oversight of risk identification, assessment, mitigation and exposure status monitoring, supporting analysis, and risk issue escalation/resolution
Serves as a risk ‘clearing house’ and forum for the evaluation of enterprise risk issues
Monitors the exposure status of the enterprise risk profile and reports to Senior Management and the Board Individual Business ‘CRO’ or Risk Leads Responsible for ensuring that individual business unit or functional risk governance structures are effective in accordance with Board, Senior Management, and Enterprise Risk Management Committee mandates
‘Owns’ development and implementation of risk policy, processes and practices for individual business units or functional areas
Monitors exposure status of the risk profile of the business, and reports to the Enterprise Risk Management Committee Matrixed Risk Management Staff/Corp ERM Performs information aggregation, reporting, and analysis to support the risk governance structure Key Objectives & Responsibilities 16<br>
slide17. Risk assurance structure i.e. Internal Audit Board of Directors Overall accountability for the enterprise risk profile
Delegates responsibility for risk management to senior management i.e. to the Senior Executive Management Committee
Approves overall risk appetite, authority for risk taking and philosophy on risk taking
Reviews and challenges assertions by management on the exposure of the risk profile Audit and/or Risk Committee of the Board Reviews and approves governing policies and limits with respect to risk management and risk taking
Reviews and challenges assertions regarding the risk profile and its exposure status that are provided by management, the risk management function and internal audit
Engagement and oversight of independent auditors
Oversight of financial reporting activities
Oversight of Internal Audit function Internal Audit
and Compliance Periodic validation of control and compliance with laws , regulations and governing internal policies (Internal Audit)
Periodic validation of risk management processes (Internal Audit or external expert review(s)
Periodic assurance to senior executive management and Board on assertions regarding risk exposure (Internal Audit)
Identify and communicate regulatory compliance policies and expectations (Compliance) Key Objectives & Responsibilities 17<br>
slide18. How effective is an organization’s governance and how ethical and risk intelligent is its operating culture? Governance and culture 18<br>
slide19. Governance and culture – Organizational model characteristics 19<br>
slide20. Governance and culture – Communication and awareness characteristics 20<br>
slide21. Governance and culture – Reporting and monitoring characteristics 21<br>
slide22. Governance and culture – People characteristics 22<br>
slide23. Governance and culture – Training characteristics 23<br>
slide24. Governance and culture – Performance management characteristics 24<br>
slide25. Board level governance considerations Consideration Audit Committee
Assign risk management review to Audit Committee Centralization of risk management review and challenge in a Risk Committee or Audit and Risk Committee ) can promote effective risk oversight which can be achieved despite other significant committee responsibilities e.g., financial reporting
The Audit Committee’s existing responsibilities can provide solid foundation for comprehensive risk coverage All risk management oversight included among other duties legally required of the Audit Committee Entire Board
Make risk management review the purview of the entire Board rather than a separate committee Enterprise risk is an accountability for all Board members requiring them to be explicitly and directly focused on it vs. it being the focus of a Board sub-committee
Regular reports to the entire Board will be sufficient to provide overall ERM oversight
Full Board has capacity to comprehend and adequately deal with enterprise-wide risk issues Regular briefings at full Board meetings on the exposure status of the risk profile with periodic updates on specific significant risk related issues i.e. deeper dives Multiple Committees
Segment risk oversight by risk category across distinct Board sub-committees, with an aggregated and integrated view at the full Board level Separately focused committees are required to achieve adequate coverage of distinct types of risk e.g. a Credit Committee for credit risk
Audit Committee may already be overloaded with other responsibilities; potential overlap with Audit Committee will be minimal
Effective Board oversight of the risk profile and its exposure status can be achieved despite a ‘siloed’ Board structure Multiple Board committees will review different aspects of the overall risk profile Risk Committee
Establish Risk Committee of the Board Single Board committee dedicated to comprehensive risk oversight A Board Risk Committee will have sufficient capacity and technical depth to effectively oversee all categories and types of risk
It is important to ensure an integrated view of all risk categories and the overall risk profile at the Board committee level
Dedicated risk committee will evidence an explicit and strong commitment to risk management to external and internal stakeholders and interested parties
Risk related responsibilities currently resident in other Board committees could be merged into the Risk Committee of the Board It is critical to consider the most effective design of Board level oversight of risk, including the establishment of Board committees What you have to believe 25<br>
slide26. The business case for risk governance Risk governance should enable:
optimized use of capital and resources through their allocation to business areas which will achieve superior risk/reward results.
Improved understanding of interactions and interrelationships between risks.
improved risk adjusted returns.
clear accountability or ownership of risk.
reduced likelihood of unpleasant earnings surprises.
Anticipation risk thus minimizing the cost and effort in dealing with it.
Demonstration and evidencing of the “in control” status of significant risks.
Strengthened perceptions regarding governance and risk management by investors, supervisors, rating agencies and others. Risk governance is intended to help improve the odds in taking risk:
reducing surprises, optimizing risk and return, thus improving shareholder value 26<br>