Washington Bankers Association Executive
Description: Washington Bankers Association Executive Development Program Audit and Compliance Risk Management: The Continuous Program Cycle Presenter: David McCrea U.S. Program Manager Global Regulatory Compliance Team Infosys Limited Investors
Related Topics
Download Presentation
"Washington Bankers Association Executive" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Washington Bankers Association
Executive Development Program
Audit and Compliance Risk Management:
The Continuous Program Cycle Presenter:
David McCrea
U.S. Program Manager
Global Regulatory Compliance Team
Infosys Limited<br>
slide2. Investors Government Media Environment Business Changes Community Legal Issues Competition Influences Assess
Risk Refine/Establish
Strategy, Goals & Objectives Refine/Establish
Control Environment Report Results Measure Performance Through Testing/ Monitoring of Control Environment Take Corrective Action Senior Management Business Compliance Board/Audit Assess
Risk Assess
Risk Assess
Risk Assess
Risk Risk Management Process Ownership<br>
slide3. The Continuous Program Cycle<br>
slide4. Setting Strategy and Structure Strategic Planning = the art and science of determining where an organization is going and how it’s going to get there.<br>
slide5. Setting Strategy and Structure What is management’s risk appetite?
Risk tolerant?
Risk averse?
Somewhere in between?<br>
slide6. Setting Strategy & Structure Vision Statement – aka – Mission Statement
A brief “big picture” description of your compliance program purpose and method.<br>
slide7. Setting Strategy and Structure Setting goals and objectives:
Goals are observable and measurable overall end results, and
Objectives are the steps to achieve specific results within a fixed time frame.
Compliance Department goals
Business Unit compliance goals
Company Goals<br>
slide8. Setting Strategy and Structure Defining a structure – roles and responsibilities
Compliance and Audit responsibility ultimately lies with the board of directors
Executive management needs to set the tone
Compliance/Risk Management provides the expertise and advice
The business units have responsibility to “do” risk management<br>
slide9. Setting Strategy and Structure Defining a structure
Compliance/Audit/Risk Management department configurations:
Solo;
Committee;
Numerous specialists;
Outsourcing;
Others?
(What about the centralized – decentralized continuum?)<br>
slide10. Setting Strategy and Structure Defining a structure - continued
Bank’s asset size;
Number of employees;
Number of branches and locations;
Product mix;
Services;
Other?
Risk Profile (coming soon…)<br>
slide11. Setting Strategy and Structure Defining Scope
What do you cover?
What do you NOT cover?
BSA?
Fair Lending?
CRA?
SOX / BASEL?
Info Sec?
Loan Review?
Other?
Ensure coverage for all out-of-scope functions.<br>
slide12. Assessing Risks Risk identification
Risk types
Risk ranking
Controls Effectiveness<br>
slide13. Risk Identification The detection and analysis of potential risks that may prevent the achievement of the bank’s objectives
What type of products and services does the bank offer?
What types of systems does the bank have in place and to what extent are processes automated?
What is your charter structure(s), who is/are your regulator(s)?
What regulations apply to the above?<br>
slide14. Forms of Assessment Risk assessments can take many different forms and have different purposes:
Product/Service specific (e.g., HELOCs, or e-banking)
Initial assessment of a new product or ongoing performance
Segmented by regulation (e.g., Reg. CC or Dodd-Frank).
May be required, such as AML/BSA or Identity Theft Prevention
Segmented by Business Line
Compliance Program (how is the program functioning)
Consumer Risk Assessment
Overall Compliance Performance (how is the company performing)<br>
slide15. Risk Types Inherent risk – the measure of risk before controls
Residual risk – the measure of risk after controls Or Inherent Risk + Controls = Residual Risk<br>
slide16. Assigning an Inherent Risk Rating Inherent compliance risk is risk that is basic natural and inseparable component or characteristic of a regulation. (Note: Inherent risk is risk before the consideration of controls.) These components could include the following risk sub-categories:
Financial
Litigation
Transaction
Reputation risks
Regulatory Environment<br>
slide17. Inherent Risk Ranking Exposure – the extent of potential damage
Likelihood – the probability that an actual event will occur, and/or that the resulting exposure from that event will take place<br>
slide18. Inherent Risk Ranking Making Sense of Multiple Views
Regulation
Consumer Risk
UDAAP Risk<br>
slide19. Risk Ranking Exposure (High) Significant or systemic
violations Severe regulatory criticism Cease and desist orders Memorandums
of Understanding Corrective actions with
large economic impact
and/or reputation damage Repeat Violations<br>
slide20. Risk Ranking Exposure (Moderate) Violations lead to some
regulatory criticism Some corrective actions with less
significant economic impact and/or less
significant reputation damage<br>
slide21. Risk Ranking Exposure (Low) Violations, if any, are not considered
significant or systemic. Minimal, if any, economic impact
and/or reputation risk.<br>
slide22. Risk Ranking Likelihood<br>
slide23. Inherent Risk Heat Map<br>
slide24. Inherent Risk Rating Using a Heat Map is not the only way to visualize Risk. Other possibilities:
-- Use numeric rating
-- Color Code
-- Other?
The Key is to know your audience.<br>
slide25. Inherent Risk Rating (sample 1)<br>
slide26. Assessing Risks Risk Controls Definition
Preventive Controls
Detective Controls
Assessing Control Effectiveness
Primary Controls
Secondary and other controls<br>
slide27. Control Activities Help ensure that directives are carried out. They can either be preventive or detective:
Preventive controls are generally applied at points where errors or irregularities could occur in the process
Detective controls discover errors during or after occurrence<br>
slide28. Preventive Controls Automated controls (e.g., system edit features for data entry control)
System processing controls (e.g., editing, balancing and internal control checks)
Written procedures and Training can be controls
Independent checks to determine if assigned responsibilities are completed and recorded amounts are accurate (e.g., account reconciliation, computer-programmed controls, management review of reports)
Approval and authorizations for transactions and activities<br>
slide29. Detective Controls Review of exception reports, reconciliations, SAR reports, and other ad hoc reports to detect erroneous or improper processing of transactions
Asset control activities, including periodic asset counts, comparison of physical counts to accounting records, investigation of discrepancies, establishment of physical safeguards, and maintenance of proper purchase authorizations<br>
slide30. Inventory the Preventive & Detective Controls Primary controls:
These represent the most effective of the controls deployed to this risk. Your control effectiveness rating is essentially the rating of this particular control.<br>
slide31. Inventory the Preventive & Detective Controls Secondary or additional controls:
Where they exist can include compensating controls that indirectly assist in achieving control objectives (such as third party review of transactions). They may also include policies and procedures referenced by the business in their risk self-assessment.<br>
slide32. Rating the Control Environment Evaluate overall risks (stratify your inherent vs. residual risks)
Establish level of confidence in control effectiveness ratings
Evaluate the “tone from the top”
Anticipate regulatory scrutiny<br>
slide33. Risk Ranking Control Strength<br>
slide34. Control Strength Example 1<br>
slide35. Control Strength Example 2<br>
slide36. Residual Risk Ratings Residual risk ratings should be based upon the inherent risk rating and the controls effectiveness rating for each regulation
A residual risk rating of high, moderate or low can be assigned. The basic formula is inherent risk + control effectiveness = residual risk<br>
slide37. Residual Risk Ratings Residual risk ratings can then be plotted on a matrix, or “heat map” as shown below:<br>
slide38. Risk Trend The direction of risk and probable change over the next 12 months.<br>
slide39. Implementing Your Risk Assessment Develop a methodology document:
State risk tolerance
Develop heat map scales
Discuss and socialize
Consider collaborating with other Risk Teams in your bank<br>
slide40. Implementing Your Risk Assessment Risk Assessment can be developed / segmented by:
Regulation
Business Unit / Department / Manager
Product / Services
If you discovered any gaps in controls, develop a mitigation plan<br>
slide41. Updating Your Risk Assessment Inherent Risk Ratings
Update at least annually
Document ratings
Controls / Residual Risk Ratings
Review outstanding issues regularly
Update quarterly<br>
slide42. Updating Your Risk Assessment To ensure your Risk Assessment stays current, you will also want to update it for:
New or Revised Products / Services
New / Amended Regulations<br>
Executive Development Program
Audit and Compliance Risk Management:
The Continuous Program Cycle Presenter:
David McCrea
U.S. Program Manager
Global Regulatory Compliance Team
Infosys Limited<br>
slide2. Investors Government Media Environment Business Changes Community Legal Issues Competition Influences Assess
Risk Refine/Establish
Strategy, Goals & Objectives Refine/Establish
Control Environment Report Results Measure Performance Through Testing/ Monitoring of Control Environment Take Corrective Action Senior Management Business Compliance Board/Audit Assess
Risk Assess
Risk Assess
Risk Assess
Risk Risk Management Process Ownership<br>
slide3. The Continuous Program Cycle<br>
slide4. Setting Strategy and Structure Strategic Planning = the art and science of determining where an organization is going and how it’s going to get there.<br>
slide5. Setting Strategy and Structure What is management’s risk appetite?
Risk tolerant?
Risk averse?
Somewhere in between?<br>
slide6. Setting Strategy & Structure Vision Statement – aka – Mission Statement
A brief “big picture” description of your compliance program purpose and method.<br>
slide7. Setting Strategy and Structure Setting goals and objectives:
Goals are observable and measurable overall end results, and
Objectives are the steps to achieve specific results within a fixed time frame.
Compliance Department goals
Business Unit compliance goals
Company Goals<br>
slide8. Setting Strategy and Structure Defining a structure – roles and responsibilities
Compliance and Audit responsibility ultimately lies with the board of directors
Executive management needs to set the tone
Compliance/Risk Management provides the expertise and advice
The business units have responsibility to “do” risk management<br>
slide9. Setting Strategy and Structure Defining a structure
Compliance/Audit/Risk Management department configurations:
Solo;
Committee;
Numerous specialists;
Outsourcing;
Others?
(What about the centralized – decentralized continuum?)<br>
slide10. Setting Strategy and Structure Defining a structure - continued
Bank’s asset size;
Number of employees;
Number of branches and locations;
Product mix;
Services;
Other?
Risk Profile (coming soon…)<br>
slide11. Setting Strategy and Structure Defining Scope
What do you cover?
What do you NOT cover?
BSA?
Fair Lending?
CRA?
SOX / BASEL?
Info Sec?
Loan Review?
Other?
Ensure coverage for all out-of-scope functions.<br>
slide12. Assessing Risks Risk identification
Risk types
Risk ranking
Controls Effectiveness<br>
slide13. Risk Identification The detection and analysis of potential risks that may prevent the achievement of the bank’s objectives
What type of products and services does the bank offer?
What types of systems does the bank have in place and to what extent are processes automated?
What is your charter structure(s), who is/are your regulator(s)?
What regulations apply to the above?<br>
slide14. Forms of Assessment Risk assessments can take many different forms and have different purposes:
Product/Service specific (e.g., HELOCs, or e-banking)
Initial assessment of a new product or ongoing performance
Segmented by regulation (e.g., Reg. CC or Dodd-Frank).
May be required, such as AML/BSA or Identity Theft Prevention
Segmented by Business Line
Compliance Program (how is the program functioning)
Consumer Risk Assessment
Overall Compliance Performance (how is the company performing)<br>
slide15. Risk Types Inherent risk – the measure of risk before controls
Residual risk – the measure of risk after controls Or Inherent Risk + Controls = Residual Risk<br>
slide16. Assigning an Inherent Risk Rating Inherent compliance risk is risk that is basic natural and inseparable component or characteristic of a regulation. (Note: Inherent risk is risk before the consideration of controls.) These components could include the following risk sub-categories:
Financial
Litigation
Transaction
Reputation risks
Regulatory Environment<br>
slide17. Inherent Risk Ranking Exposure – the extent of potential damage
Likelihood – the probability that an actual event will occur, and/or that the resulting exposure from that event will take place<br>
slide18. Inherent Risk Ranking Making Sense of Multiple Views
Regulation
Consumer Risk
UDAAP Risk<br>
slide19. Risk Ranking Exposure (High) Significant or systemic
violations Severe regulatory criticism Cease and desist orders Memorandums
of Understanding Corrective actions with
large economic impact
and/or reputation damage Repeat Violations<br>
slide20. Risk Ranking Exposure (Moderate) Violations lead to some
regulatory criticism Some corrective actions with less
significant economic impact and/or less
significant reputation damage<br>
slide21. Risk Ranking Exposure (Low) Violations, if any, are not considered
significant or systemic. Minimal, if any, economic impact
and/or reputation risk.<br>
slide22. Risk Ranking Likelihood<br>
slide23. Inherent Risk Heat Map<br>
slide24. Inherent Risk Rating Using a Heat Map is not the only way to visualize Risk. Other possibilities:
-- Use numeric rating
-- Color Code
-- Other?
The Key is to know your audience.<br>
slide25. Inherent Risk Rating (sample 1)<br>
slide26. Assessing Risks Risk Controls Definition
Preventive Controls
Detective Controls
Assessing Control Effectiveness
Primary Controls
Secondary and other controls<br>
slide27. Control Activities Help ensure that directives are carried out. They can either be preventive or detective:
Preventive controls are generally applied at points where errors or irregularities could occur in the process
Detective controls discover errors during or after occurrence<br>
slide28. Preventive Controls Automated controls (e.g., system edit features for data entry control)
System processing controls (e.g., editing, balancing and internal control checks)
Written procedures and Training can be controls
Independent checks to determine if assigned responsibilities are completed and recorded amounts are accurate (e.g., account reconciliation, computer-programmed controls, management review of reports)
Approval and authorizations for transactions and activities<br>
slide29. Detective Controls Review of exception reports, reconciliations, SAR reports, and other ad hoc reports to detect erroneous or improper processing of transactions
Asset control activities, including periodic asset counts, comparison of physical counts to accounting records, investigation of discrepancies, establishment of physical safeguards, and maintenance of proper purchase authorizations<br>
slide30. Inventory the Preventive & Detective Controls Primary controls:
These represent the most effective of the controls deployed to this risk. Your control effectiveness rating is essentially the rating of this particular control.<br>
slide31. Inventory the Preventive & Detective Controls Secondary or additional controls:
Where they exist can include compensating controls that indirectly assist in achieving control objectives (such as third party review of transactions). They may also include policies and procedures referenced by the business in their risk self-assessment.<br>
slide32. Rating the Control Environment Evaluate overall risks (stratify your inherent vs. residual risks)
Establish level of confidence in control effectiveness ratings
Evaluate the “tone from the top”
Anticipate regulatory scrutiny<br>
slide33. Risk Ranking Control Strength<br>
slide34. Control Strength Example 1<br>
slide35. Control Strength Example 2<br>
slide36. Residual Risk Ratings Residual risk ratings should be based upon the inherent risk rating and the controls effectiveness rating for each regulation
A residual risk rating of high, moderate or low can be assigned. The basic formula is inherent risk + control effectiveness = residual risk<br>
slide37. Residual Risk Ratings Residual risk ratings can then be plotted on a matrix, or “heat map” as shown below:<br>
slide38. Risk Trend The direction of risk and probable change over the next 12 months.<br>
slide39. Implementing Your Risk Assessment Develop a methodology document:
State risk tolerance
Develop heat map scales
Discuss and socialize
Consider collaborating with other Risk Teams in your bank<br>
slide40. Implementing Your Risk Assessment Risk Assessment can be developed / segmented by:
Regulation
Business Unit / Department / Manager
Product / Services
If you discovered any gaps in controls, develop a mitigation plan<br>
slide41. Updating Your Risk Assessment Inherent Risk Ratings
Update at least annually
Document ratings
Controls / Residual Risk Ratings
Review outstanding issues regularly
Update quarterly<br>
slide42. Updating Your Risk Assessment To ensure your Risk Assessment stays current, you will also want to update it for:
New or Revised Products / Services
New / Amended Regulations<br>