SlideShare una empresa de Scribd logo
1 de 32
Descargar para leer sin conexión
Embedding RCSA into Strategic Planning
and Business Strategy
Operatiivisten Riskien Hallinta, Helsinki, Finland
Andrew Smart, Ascendore
Post credit crunch, financial services firms are drowning
under a tsunami of regulatory change, cost and complexity
2
Run the Bank
£200bn
plus fines
492%
Annual increase
regulatory change
3
The cost & complexity
of operational risk &
compliance is too high
and there is a
“disproportionate risk
aversion creeping into
decision-making”
Chairman, HBSC, 2015
Accenture Risk Study, 2017
Boards and executives should be able to answer these
questions with confidence.
4
Are we in control?
Are we going to
deliver our strategy?
Are we operating
within appetite?
RCSA - an essential part of an integrated framework
Better Conversation
Better Decisions
Better Action-taking
Better Results
Risk & Control Self-
Assessment (RCSA) processes
and data should be an essential part of
an integrated Strategy & Risk
Management framework; an integral
part of enterprise management
reporting.
5
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
6
7
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
Compliance Enablers
Over the long-term, where are we going and
how will we get there?
Critical few things from the business model
that enable the delivery of the strategy
To deliver our long-term strategy what is the
focus over the next 12-24 months?
Where do we need to excel day-to-day
What are the ‘rules’ that define our operating
environment?
Risk Appetite defines the boundaries for
risk-takingStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
RISK THRESHOLDS
RISK EXPOSURES
Compliance Enablers
8
Manage threats & opportunities via the risk
taxonomyStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL RISK
COMPLIANCE RISK
Compliance Enablers
9
Managed at every level in the framework
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
StrategicRisk
Execution
Risk
Compliance
Risk
APPETITE
ALIGNMENT
ACCOUNTABILITY
ALIGNMENT
CASCADE
ASSESSMENT
MEASUREMENT
ACTION-TAKING
Operational
Risk
Compliance Enablers
10
The RACI framework is a proven approach to embedding accountability and
clarification of roles in decision-making. Supports the 3 Lines of Defence
InformResponsible(s)Accountable Consult
11
How do your operational and
regulatory enablers relate to
strategy?
Alignment mapping can identify gaps; areas
where your strategy is not supported or where
operational resources are been wasted.
Regulatory rules mapping provide assurance
that processes and initiatives are in place to
meet regulatory obligations and identify gaps;
where are the gaps or weaknesses in our
regulatory response landscape?
12
Key ControlsKey RisksObjectiveEntity
Processes
Initiatives
Technology
How does strategy & risk
cascade through the firm?
Board & Senior Management assurance is
enhanced by understanding the cascading of
objectives & risks through the firm.
Identify gaps in consolidated reporting by
linking objectives, risks and controls in ‘cascade
chains’ through the firm. Where does the chain
break?
13
Key Risk
(Strategic Risk)
Corporate
Division
Department
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Data points to inform your Risk Self-
Assessments
14
MAXIMUM
INHERENT
RESIDUAL
% $£€
IMPACT(S) LIKELIHOOD EXPOSURE
DRIVERS
use driver(s) as the basis for assessing impacts thus linking risk
back to strategy
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
KRIs
Losses / Near Misses
Expert Judgement
Scenarios & Models
Related KPIs & KCIs
Control Self Assessment
Data points to inform your Control
Self-Assessments
15
KCIs
Losses / Near Misses
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
Control Testing
Related KPIs & KRIs
DESIGN PERFORMANCE
CONTROL
EFFECTIVENESS
Three types of related
indicators to give a full picture
RAG is common practice
RAGAR is best practice
16
Key Performance Indicators (KPIs)
Used to define performance thresholds and
targets; and to monitor progress towards achieving
these targets.
Key Risk Indicators (KRIs)
Used to define risk thresholds and targets; to
monitor changes within the risk environment.
Key Control Indicators (KCIs)
Used to define control thresholds and targets; to
monitor changes within the controls environment.
BASELINE
LT 1
LT 2
UT2
UT 1
TARGET
T 2
T 1
Assessment and measurement
is not enough.
Action-taking is critical in
driving performance &
managing risk
Typically we think about two
types of actions
17
Improvement Actions
Audit Actions
Tools to bring it all together
18
Better
Action-
taking
Better
Decisions
Better
Results
Strategy
Map
Better
Conversations
Appetite
Alignment
Matrix
Risk
Appetite
Risk Map
Map Business Objectives & their
causal relationship to improve the
communication, monitoring and
management of strategic and
operational performance.
19
Define risk tolerances across the
framework reflecting the
materiality of the business unit.
Use Drivers to link RCSA back to
Strategy.
20
The Risk Map provides a visual
overview of the risk profile and
make it easy to identify potential
risk issues.
Four perspectives risk map is
aligned to the Strategy Map.
21
Starting with Strategic Drivers,
define Risk Appetite across the
framework, reflecting the
materiality and strategic intent of
the business unit.
22
The Appetite Alignment Matrix
visualise the alignment of risk-
taking to risk appetite showing
where the firm is aligned, over-
exposed and under-exposed.
23
Are we operating within appetite?
24
Appetite, Performance, Risk and Controls
Effectiveness should be assessed,
measured and aligned across the
organisational hierarchy and within the
taxonomy within the framework.
25
STRATEGY
typically strategy is cascaded top-down
DATA
typically data flows up the organization
EXECUTION
typically execution is driven from the middle
Corporate
Divisions
Departments
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL &
COMPLIANCE RISK
26
STRATEGY MAP
Are we on track to deliver the
strategy?
APPETITE ALIGNMENT MATRIX
Are we operating within
appetite?
RISK APPETITE
How much risk is acceptable?
RISK MAP
What level of risk are we taking?
Benefits of Improved
Strategic Execution
▪ A growth in shareholder value of 150%,
driven by a 180% growth in profits and a
120% growth in revenue
▪ A 50% improvement in customer
satisfaction
▪ A 50% improvement in key process
effectiveness
▪ A 25% improvement in employee
satisfaction, leading to a 50% reduction
in employee turnover
Benefits of an
Integrated approach
▪ Transformed our approach to risk and
regulatory compliance over 12-month
▪ Reduce the value of our operational
losses by 94%, the volume by 63% and
our economic capital provision by 23%”
▪ Eliminate 11 spreadsheet systems
▪ Enabled us to secure a 3% regulatory
capital release and reduce our cost of
capital significantly
27
Benefits of Enterprise
Risk Management
▪ Increasing the range of opportunities
▪ Identifying and managing risk entity-
wide
▪ Increasing positive outcomes and
advantage while reducing negative
surprises
▪ Reducing performance variability
▪ Improving resource deployment
▪ Enhancing enterprise resilience
Results based on 3 year performance of BSC Hall of Frame
winners
COSO ERM Framework, 2017 Example benefits reported by Ascendore customers
Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in
firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent"
or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
We believe that risk management and compliance must enable strategy
execution and value creation, not simply tick regulatory boxes.
28
“we have reduced our Pillar 2 capital by
81.2% while delivering a 94% reduction
in the value of errors and a 63%
reduction in the volume of errors”
Head of Enterprise Risk, Homeloan Management Limited
We provide Integrated GRC
(Governance, Risk and Compliance)
solutions to financial services firms
and their regulators built on familiar,
everyday office tools; SharePoint,
Office 365 & the Cloud.
COSO ERM Framework 2017 Risk-Based Performance
Management
29
What is Risk-Based Performance Management?
Enhance Shareholder value
Control Cost & Complexity
Drive Accountability
Align the firm
Risk-Based Performance
Management (RBPM) is an
strategic execution approach which
integrates business strategy, risk
appetite, performance management
and risk management.
30
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
31
Embedding RCSA into Strategic Planning
and Business Strategy?
Andrew Smart
Ascendore

Más contenido relacionado

La actualidad más candente

ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
Jorge Vaz Girão , CISA, PMP, PMDPro I, ERMCP
 
Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk Management
Andrew Smart
 
Risk Management ERM Presentation
Risk Management ERM PresentationRisk Management ERM Presentation
Risk Management ERM Presentation
alygale
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
Treasury Consulting LLP
 
Operation Risk Management in Banking Sector
Operation Risk Management in Banking SectorOperation Risk Management in Banking Sector
Operation Risk Management in Banking Sector
Sanjay Kumbhar
 
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
Susan Young
 
operations risk management power point presentation.
operations risk management power point presentation.operations risk management power point presentation.
operations risk management power point presentation.
Miyelani Shibambo
 
Risk & Risk Management
Risk & Risk ManagementRisk & Risk Management
Risk & Risk Management
ansula
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & compliance
HR Globe Consulting
 

La actualidad más candente (20)

ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
 
KRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & ITKRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & IT
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Governance risk and compliance
Governance risk and complianceGovernance risk and compliance
Governance risk and compliance
 
Risk and Control Self Assessment - IRM India Affiliate
Risk and Control Self  Assessment - IRM India AffiliateRisk and Control Self  Assessment - IRM India Affiliate
Risk and Control Self Assessment - IRM India Affiliate
 
Operational risk management and measurement
Operational risk management and measurementOperational risk management and measurement
Operational risk management and measurement
 
Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk Management
 
Risk Management ERM Presentation
Risk Management ERM PresentationRisk Management ERM Presentation
Risk Management ERM Presentation
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
Operation Risk Management in Banking Sector
Operation Risk Management in Banking SectorOperation Risk Management in Banking Sector
Operation Risk Management in Banking Sector
 
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
 
Operational Risk for Bank
Operational Risk for BankOperational Risk for Bank
Operational Risk for Bank
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Operational Risk Management Under Basel II & Basel III
Operational Risk Management Under Basel II & Basel IIIOperational Risk Management Under Basel II & Basel III
Operational Risk Management Under Basel II & Basel III
 
operations risk management power point presentation.
operations risk management power point presentation.operations risk management power point presentation.
operations risk management power point presentation.
 
Strategic Risk Management as a CFO: Getting Risk Management Right
Strategic Risk Management as a CFO: Getting Risk Management RightStrategic Risk Management as a CFO: Getting Risk Management Right
Strategic Risk Management as a CFO: Getting Risk Management Right
 
Risk & Risk Management
Risk & Risk ManagementRisk & Risk Management
Risk & Risk Management
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & compliance
 
Risk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling TechniquesRisk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling Techniques
 

Similar a Embedding RCSA into Strategic Planning and Business Strategy

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
madlynplamondon
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptx
manjujayakumar2
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
Andrew Smart
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
TanaMaeskm
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
Ashwin Kumar
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
PMI Indonesia Chapter
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
peterObakozuwa
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy Presentation
David Fernandes
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
susanta subudhi
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
susanta subudhi
 

Similar a Embedding RCSA into Strategic Planning and Business Strategy (20)

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
 
Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.
 
Operational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningOperational Risk Management & Strategic Planning
Operational Risk Management & Strategic Planning
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptx
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
 
StrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingStrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance Mapping
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk Transfer
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and Sustainability
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy Presentation
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
HIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINALHIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINAL
 

Más de Andrew Smart

FMM&A15-StratexSystems
FMM&A15-StratexSystemsFMM&A15-StratexSystems
FMM&A15-StratexSystems
Andrew Smart
 
Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Strategically+Speaking+October+2015
Strategically+Speaking+October+2015
Andrew Smart
 
StratexSystems_270115
StratexSystems_270115StratexSystems_270115
StratexSystems_270115
Andrew Smart
 
Managing with KPI's and KRI's
Managing with KPI's and KRI's Managing with KPI's and KRI's
Managing with KPI's and KRI's
Andrew Smart
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
Andrew Smart
 
Middle east insurance market
Middle east insurance marketMiddle east insurance market
Middle east insurance market
Andrew Smart
 
Amnded stratexpoint screens1
Amnded stratexpoint screens1Amnded stratexpoint screens1
Amnded stratexpoint screens1
Andrew Smart
 
Greater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperGreater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service Whitepaper
Andrew Smart
 

Más de Andrew Smart (16)

FMM&A15-StratexSystems
FMM&A15-StratexSystemsFMM&A15-StratexSystems
FMM&A15-StratexSystems
 
Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Strategically+Speaking+October+2015
Strategically+Speaking+October+2015
 
StratexSystems_270115
StratexSystems_270115StratexSystems_270115
StratexSystems_270115
 
Cyber Risk Management
Cyber Risk Management Cyber Risk Management
Cyber Risk Management
 
Managing Information Risk in Financial Services
Managing Information Risk in Financial Services Managing Information Risk in Financial Services
Managing Information Risk in Financial Services
 
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk ManagementStrategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
 
Making Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As UsualMaking Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As Usual
 
StratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro VideoStratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro Video
 
Managing with KPI's and KRI's
Managing with KPI's and KRI's Managing with KPI's and KRI's
Managing with KPI's and KRI's
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
 
Middle east insurance market
Middle east insurance marketMiddle east insurance market
Middle east insurance market
 
Amnded stratexpoint screens1
Amnded stratexpoint screens1Amnded stratexpoint screens1
Amnded stratexpoint screens1
 
HML Risk Transformation
HML Risk TransformationHML Risk Transformation
HML Risk Transformation
 
Greater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperGreater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service Whitepaper
 
Manigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy ProcessManigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy Process
 
Manigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureManigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And Exposure
 

Último

Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
lizamodels9
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
amitlee9823
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
daisycvs
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
lizamodels9
 
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂EscortCall Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
dlhescort
 

Último (20)

Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂EscortCall Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 

Embedding RCSA into Strategic Planning and Business Strategy

  • 1. Embedding RCSA into Strategic Planning and Business Strategy Operatiivisten Riskien Hallinta, Helsinki, Finland Andrew Smart, Ascendore
  • 2. Post credit crunch, financial services firms are drowning under a tsunami of regulatory change, cost and complexity 2 Run the Bank £200bn plus fines 492% Annual increase regulatory change
  • 3. 3 The cost & complexity of operational risk & compliance is too high and there is a “disproportionate risk aversion creeping into decision-making” Chairman, HBSC, 2015 Accenture Risk Study, 2017
  • 4. Boards and executives should be able to answer these questions with confidence. 4 Are we in control? Are we going to deliver our strategy? Are we operating within appetite?
  • 5. RCSA - an essential part of an integrated framework Better Conversation Better Decisions Better Action-taking Better Results Risk & Control Self- Assessment (RCSA) processes and data should be an essential part of an integrated Strategy & Risk Management framework; an integral part of enterprise management reporting. 5
  • 6. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 6
  • 7. 7 Strategy Strategic Drivers Business Objectives Operational Enablers Compliance Enablers Over the long-term, where are we going and how will we get there? Critical few things from the business model that enable the delivery of the strategy To deliver our long-term strategy what is the focus over the next 12-24 months? Where do we need to excel day-to-day What are the ‘rules’ that define our operating environment?
  • 8. Risk Appetite defines the boundaries for risk-takingStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT RISK THRESHOLDS RISK EXPOSURES Compliance Enablers 8
  • 9. Manage threats & opportunities via the risk taxonomyStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT STRATEGIC RISK EXECUTION RISK OPERATIONAL RISK COMPLIANCE RISK Compliance Enablers 9
  • 10. Managed at every level in the framework Strategy Strategic Drivers Business Objectives Operational Enablers StrategicRisk Execution Risk Compliance Risk APPETITE ALIGNMENT ACCOUNTABILITY ALIGNMENT CASCADE ASSESSMENT MEASUREMENT ACTION-TAKING Operational Risk Compliance Enablers 10
  • 11. The RACI framework is a proven approach to embedding accountability and clarification of roles in decision-making. Supports the 3 Lines of Defence InformResponsible(s)Accountable Consult 11
  • 12. How do your operational and regulatory enablers relate to strategy? Alignment mapping can identify gaps; areas where your strategy is not supported or where operational resources are been wasted. Regulatory rules mapping provide assurance that processes and initiatives are in place to meet regulatory obligations and identify gaps; where are the gaps or weaknesses in our regulatory response landscape? 12 Key ControlsKey RisksObjectiveEntity Processes Initiatives Technology
  • 13. How does strategy & risk cascade through the firm? Board & Senior Management assurance is enhanced by understanding the cascading of objectives & risks through the firm. Identify gaps in consolidated reporting by linking objectives, risks and controls in ‘cascade chains’ through the firm. Where does the chain break? 13 Key Risk (Strategic Risk) Corporate Division Department Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk)
  • 14. Data points to inform your Risk Self- Assessments 14 MAXIMUM INHERENT RESIDUAL % $£€ IMPACT(S) LIKELIHOOD EXPOSURE DRIVERS use driver(s) as the basis for assessing impacts thus linking risk back to strategy ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. KRIs Losses / Near Misses Expert Judgement Scenarios & Models Related KPIs & KCIs Control Self Assessment
  • 15. Data points to inform your Control Self-Assessments 15 KCIs Losses / Near Misses ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. Control Testing Related KPIs & KRIs DESIGN PERFORMANCE CONTROL EFFECTIVENESS
  • 16. Three types of related indicators to give a full picture RAG is common practice RAGAR is best practice 16 Key Performance Indicators (KPIs) Used to define performance thresholds and targets; and to monitor progress towards achieving these targets. Key Risk Indicators (KRIs) Used to define risk thresholds and targets; to monitor changes within the risk environment. Key Control Indicators (KCIs) Used to define control thresholds and targets; to monitor changes within the controls environment. BASELINE LT 1 LT 2 UT2 UT 1 TARGET T 2 T 1
  • 17. Assessment and measurement is not enough. Action-taking is critical in driving performance & managing risk Typically we think about two types of actions 17 Improvement Actions Audit Actions
  • 18. Tools to bring it all together 18 Better Action- taking Better Decisions Better Results Strategy Map Better Conversations Appetite Alignment Matrix Risk Appetite Risk Map
  • 19. Map Business Objectives & their causal relationship to improve the communication, monitoring and management of strategic and operational performance. 19
  • 20. Define risk tolerances across the framework reflecting the materiality of the business unit. Use Drivers to link RCSA back to Strategy. 20
  • 21. The Risk Map provides a visual overview of the risk profile and make it easy to identify potential risk issues. Four perspectives risk map is aligned to the Strategy Map. 21
  • 22. Starting with Strategic Drivers, define Risk Appetite across the framework, reflecting the materiality and strategic intent of the business unit. 22
  • 23. The Appetite Alignment Matrix visualise the alignment of risk- taking to risk appetite showing where the firm is aligned, over- exposed and under-exposed. 23
  • 24. Are we operating within appetite? 24
  • 25. Appetite, Performance, Risk and Controls Effectiveness should be assessed, measured and aligned across the organisational hierarchy and within the taxonomy within the framework. 25 STRATEGY typically strategy is cascaded top-down DATA typically data flows up the organization EXECUTION typically execution is driven from the middle Corporate Divisions Departments STRATEGIC RISK EXECUTION RISK OPERATIONAL & COMPLIANCE RISK
  • 26. 26 STRATEGY MAP Are we on track to deliver the strategy? APPETITE ALIGNMENT MATRIX Are we operating within appetite? RISK APPETITE How much risk is acceptable? RISK MAP What level of risk are we taking?
  • 27. Benefits of Improved Strategic Execution ▪ A growth in shareholder value of 150%, driven by a 180% growth in profits and a 120% growth in revenue ▪ A 50% improvement in customer satisfaction ▪ A 50% improvement in key process effectiveness ▪ A 25% improvement in employee satisfaction, leading to a 50% reduction in employee turnover Benefits of an Integrated approach ▪ Transformed our approach to risk and regulatory compliance over 12-month ▪ Reduce the value of our operational losses by 94%, the volume by 63% and our economic capital provision by 23%” ▪ Eliminate 11 spreadsheet systems ▪ Enabled us to secure a 3% regulatory capital release and reduce our cost of capital significantly 27 Benefits of Enterprise Risk Management ▪ Increasing the range of opportunities ▪ Identifying and managing risk entity- wide ▪ Increasing positive outcomes and advantage while reducing negative surprises ▪ Reducing performance variability ▪ Improving resource deployment ▪ Enhancing enterprise resilience Results based on 3 year performance of BSC Hall of Frame winners COSO ERM Framework, 2017 Example benefits reported by Ascendore customers Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent" or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
  • 28. We believe that risk management and compliance must enable strategy execution and value creation, not simply tick regulatory boxes. 28 “we have reduced our Pillar 2 capital by 81.2% while delivering a 94% reduction in the value of errors and a 63% reduction in the volume of errors” Head of Enterprise Risk, Homeloan Management Limited We provide Integrated GRC (Governance, Risk and Compliance) solutions to financial services firms and their regulators built on familiar, everyday office tools; SharePoint, Office 365 & the Cloud.
  • 29. COSO ERM Framework 2017 Risk-Based Performance Management 29
  • 30. What is Risk-Based Performance Management? Enhance Shareholder value Control Cost & Complexity Drive Accountability Align the firm Risk-Based Performance Management (RBPM) is an strategic execution approach which integrates business strategy, risk appetite, performance management and risk management. 30
  • 31. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 31
  • 32. Embedding RCSA into Strategic Planning and Business Strategy? Andrew Smart Ascendore