SlideShare una empresa de Scribd logo
1 de 32
Descargar para leer sin conexión
Embedding RCSA into Strategic Planning
and Business Strategy
Operatiivisten Riskien Hallinta, Helsinki, Finland
Andrew Smart, Ascendore
Post credit crunch, financial services firms are drowning
under a tsunami of regulatory change, cost and complexity
2
Run the Bank
£200bn
plus fines
492%
Annual increase
regulatory change
3
The cost & complexity
of operational risk &
compliance is too high
and there is a
“disproportionate risk
aversion creeping into
decision-making”
Chairman, HBSC, 2015
Accenture Risk Study, 2017
Boards and executives should be able to answer these
questions with confidence.
4
Are we in control?
Are we going to
deliver our strategy?
Are we operating
within appetite?
RCSA - an essential part of an integrated framework
Better Conversation
Better Decisions
Better Action-taking
Better Results
Risk & Control Self-
Assessment (RCSA) processes
and data should be an essential part of
an integrated Strategy & Risk
Management framework; an integral
part of enterprise management
reporting.
5
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
6
7
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
Compliance Enablers
Over the long-term, where are we going and
how will we get there?
Critical few things from the business model
that enable the delivery of the strategy
To deliver our long-term strategy what is the
focus over the next 12-24 months?
Where do we need to excel day-to-day
What are the ‘rules’ that define our operating
environment?
Risk Appetite defines the boundaries for
risk-takingStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
RISK THRESHOLDS
RISK EXPOSURES
Compliance Enablers
8
Manage threats & opportunities via the risk
taxonomyStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL RISK
COMPLIANCE RISK
Compliance Enablers
9
Managed at every level in the framework
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
StrategicRisk
Execution
Risk
Compliance
Risk
APPETITE
ALIGNMENT
ACCOUNTABILITY
ALIGNMENT
CASCADE
ASSESSMENT
MEASUREMENT
ACTION-TAKING
Operational
Risk
Compliance Enablers
10
The RACI framework is a proven approach to embedding accountability and
clarification of roles in decision-making. Supports the 3 Lines of Defence
InformResponsible(s)Accountable Consult
11
How do your operational and
regulatory enablers relate to
strategy?
Alignment mapping can identify gaps; areas
where your strategy is not supported or where
operational resources are been wasted.
Regulatory rules mapping provide assurance
that processes and initiatives are in place to
meet regulatory obligations and identify gaps;
where are the gaps or weaknesses in our
regulatory response landscape?
12
Key ControlsKey RisksObjectiveEntity
Processes
Initiatives
Technology
How does strategy & risk
cascade through the firm?
Board & Senior Management assurance is
enhanced by understanding the cascading of
objectives & risks through the firm.
Identify gaps in consolidated reporting by
linking objectives, risks and controls in ‘cascade
chains’ through the firm. Where does the chain
break?
13
Key Risk
(Strategic Risk)
Corporate
Division
Department
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Data points to inform your Risk Self-
Assessments
14
MAXIMUM
INHERENT
RESIDUAL
% $£€
IMPACT(S) LIKELIHOOD EXPOSURE
DRIVERS
use driver(s) as the basis for assessing impacts thus linking risk
back to strategy
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
KRIs
Losses / Near Misses
Expert Judgement
Scenarios & Models
Related KPIs & KCIs
Control Self Assessment
Data points to inform your Control
Self-Assessments
15
KCIs
Losses / Near Misses
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
Control Testing
Related KPIs & KRIs
DESIGN PERFORMANCE
CONTROL
EFFECTIVENESS
Three types of related
indicators to give a full picture
RAG is common practice
RAGAR is best practice
16
Key Performance Indicators (KPIs)
Used to define performance thresholds and
targets; and to monitor progress towards achieving
these targets.
Key Risk Indicators (KRIs)
Used to define risk thresholds and targets; to
monitor changes within the risk environment.
Key Control Indicators (KCIs)
Used to define control thresholds and targets; to
monitor changes within the controls environment.
BASELINE
LT 1
LT 2
UT2
UT 1
TARGET
T 2
T 1
Assessment and measurement
is not enough.
Action-taking is critical in
driving performance &
managing risk
Typically we think about two
types of actions
17
Improvement Actions
Audit Actions
Tools to bring it all together
18
Better
Action-
taking
Better
Decisions
Better
Results
Strategy
Map
Better
Conversations
Appetite
Alignment
Matrix
Risk
Appetite
Risk Map
Map Business Objectives & their
causal relationship to improve the
communication, monitoring and
management of strategic and
operational performance.
19
Define risk tolerances across the
framework reflecting the
materiality of the business unit.
Use Drivers to link RCSA back to
Strategy.
20
The Risk Map provides a visual
overview of the risk profile and
make it easy to identify potential
risk issues.
Four perspectives risk map is
aligned to the Strategy Map.
21
Starting with Strategic Drivers,
define Risk Appetite across the
framework, reflecting the
materiality and strategic intent of
the business unit.
22
The Appetite Alignment Matrix
visualise the alignment of risk-
taking to risk appetite showing
where the firm is aligned, over-
exposed and under-exposed.
23
Are we operating within appetite?
24
Appetite, Performance, Risk and Controls
Effectiveness should be assessed,
measured and aligned across the
organisational hierarchy and within the
taxonomy within the framework.
25
STRATEGY
typically strategy is cascaded top-down
DATA
typically data flows up the organization
EXECUTION
typically execution is driven from the middle
Corporate
Divisions
Departments
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL &
COMPLIANCE RISK
26
STRATEGY MAP
Are we on track to deliver the
strategy?
APPETITE ALIGNMENT MATRIX
Are we operating within
appetite?
RISK APPETITE
How much risk is acceptable?
RISK MAP
What level of risk are we taking?
Benefits of Improved
Strategic Execution
▪ A growth in shareholder value of 150%,
driven by a 180% growth in profits and a
120% growth in revenue
▪ A 50% improvement in customer
satisfaction
▪ A 50% improvement in key process
effectiveness
▪ A 25% improvement in employee
satisfaction, leading to a 50% reduction
in employee turnover
Benefits of an
Integrated approach
▪ Transformed our approach to risk and
regulatory compliance over 12-month
▪ Reduce the value of our operational
losses by 94%, the volume by 63% and
our economic capital provision by 23%”
▪ Eliminate 11 spreadsheet systems
▪ Enabled us to secure a 3% regulatory
capital release and reduce our cost of
capital significantly
27
Benefits of Enterprise
Risk Management
▪ Increasing the range of opportunities
▪ Identifying and managing risk entity-
wide
▪ Increasing positive outcomes and
advantage while reducing negative
surprises
▪ Reducing performance variability
▪ Improving resource deployment
▪ Enhancing enterprise resilience
Results based on 3 year performance of BSC Hall of Frame
winners
COSO ERM Framework, 2017 Example benefits reported by Ascendore customers
Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in
firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent"
or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
We believe that risk management and compliance must enable strategy
execution and value creation, not simply tick regulatory boxes.
28
“we have reduced our Pillar 2 capital by
81.2% while delivering a 94% reduction
in the value of errors and a 63%
reduction in the volume of errors”
Head of Enterprise Risk, Homeloan Management Limited
We provide Integrated GRC
(Governance, Risk and Compliance)
solutions to financial services firms
and their regulators built on familiar,
everyday office tools; SharePoint,
Office 365 & the Cloud.
COSO ERM Framework 2017 Risk-Based Performance
Management
29
What is Risk-Based Performance Management?
Enhance Shareholder value
Control Cost & Complexity
Drive Accountability
Align the firm
Risk-Based Performance
Management (RBPM) is an
strategic execution approach which
integrates business strategy, risk
appetite, performance management
and risk management.
30
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
31
Embedding RCSA into Strategic Planning
and Business Strategy?
Andrew Smart
Ascendore

Más contenido relacionado

La actualidad más candente

ORIGINATIONNEXT- Risk Assessment Model
ORIGINATIONNEXT- Risk Assessment ModelORIGINATIONNEXT- Risk Assessment Model
ORIGINATIONNEXT- Risk Assessment ModelCRMNEXT
 
CMLGroup - What is GRC?
CMLGroup - What is GRC?CMLGroup - What is GRC?
CMLGroup - What is GRC?CML Group
 
Presenting Metrics to the Executive Team
Presenting Metrics to the Executive TeamPresenting Metrics to the Executive Team
Presenting Metrics to the Executive TeamJohn D. Johnson
 
Business case for information security program
Business case for information security programBusiness case for information security program
Business case for information security programWilliam Godwin
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk managementMetricStream Inc
 
Success by integrating risk management in data governance
Success by integrating risk management in data governanceSuccess by integrating risk management in data governance
Success by integrating risk management in data governanceTejasvi Addagada, CBAP
 
Next generation-risk-management-solution
Next generation-risk-management-solutionNext generation-risk-management-solution
Next generation-risk-management-solutionMetricStream Inc
 
An industrial approach to risk and control self-assessments
An industrial approach to risk and control self-assessmentsAn industrial approach to risk and control self-assessments
An industrial approach to risk and control self-assessmentsGrant Thornton LLP
 
Introduction to Core Assessments
Introduction to Core AssessmentsIntroduction to Core Assessments
Introduction to Core AssessmentsResolver Inc.
 
Excel In Managing Spreadsheet Risk Presentation
Excel In Managing Spreadsheet Risk PresentationExcel In Managing Spreadsheet Risk Presentation
Excel In Managing Spreadsheet Risk Presentationgreghawes
 
K2 Healthcare Solutions Overview Map
K2 Healthcare Solutions Overview MapK2 Healthcare Solutions Overview Map
K2 Healthcare Solutions Overview MapGemma Adair
 
The Purpose of Holistic Risk Management
The Purpose of Holistic Risk ManagementThe Purpose of Holistic Risk Management
The Purpose of Holistic Risk ManagementCorporater
 
( Big ) Data Management - Governance - Global concepts in 5 slides
( Big ) Data Management - Governance - Global concepts in 5 slides( Big ) Data Management - Governance - Global concepts in 5 slides
( Big ) Data Management - Governance - Global concepts in 5 slidesNicolas Sarramagna
 
App Showcase: Internal Audit
App Showcase: Internal AuditApp Showcase: Internal Audit
App Showcase: Internal AuditResolver Inc.
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance BOC Group
 
The Use of Spreadsheets in Commodity Trading – 2015
The Use of Spreadsheets in Commodity Trading – 2015The Use of Spreadsheets in Commodity Trading – 2015
The Use of Spreadsheets in Commodity Trading – 2015CTRM Center
 
5 steps for better risk assessment
5 steps for better risk assessment5 steps for better risk assessment
5 steps for better risk assessmentDrMohammedFarid
 

La actualidad más candente (20)

ORIGINATIONNEXT- Risk Assessment Model
ORIGINATIONNEXT- Risk Assessment ModelORIGINATIONNEXT- Risk Assessment Model
ORIGINATIONNEXT- Risk Assessment Model
 
CMLGroup - What is GRC?
CMLGroup - What is GRC?CMLGroup - What is GRC?
CMLGroup - What is GRC?
 
Presenting Metrics to the Executive Team
Presenting Metrics to the Executive TeamPresenting Metrics to the Executive Team
Presenting Metrics to the Executive Team
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
 
Business case for information security program
Business case for information security programBusiness case for information security program
Business case for information security program
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk management
 
Success by integrating risk management in data governance
Success by integrating risk management in data governanceSuccess by integrating risk management in data governance
Success by integrating risk management in data governance
 
Next generation-risk-management-solution
Next generation-risk-management-solutionNext generation-risk-management-solution
Next generation-risk-management-solution
 
An industrial approach to risk and control self-assessments
An industrial approach to risk and control self-assessmentsAn industrial approach to risk and control self-assessments
An industrial approach to risk and control self-assessments
 
Introduction to Core Assessments
Introduction to Core AssessmentsIntroduction to Core Assessments
Introduction to Core Assessments
 
Excel In Managing Spreadsheet Risk Presentation
Excel In Managing Spreadsheet Risk PresentationExcel In Managing Spreadsheet Risk Presentation
Excel In Managing Spreadsheet Risk Presentation
 
K2 Healthcare Solutions Overview Map
K2 Healthcare Solutions Overview MapK2 Healthcare Solutions Overview Map
K2 Healthcare Solutions Overview Map
 
The Purpose of Holistic Risk Management
The Purpose of Holistic Risk ManagementThe Purpose of Holistic Risk Management
The Purpose of Holistic Risk Management
 
( Big ) Data Management - Governance - Global concepts in 5 slides
( Big ) Data Management - Governance - Global concepts in 5 slides( Big ) Data Management - Governance - Global concepts in 5 slides
( Big ) Data Management - Governance - Global concepts in 5 slides
 
App Showcase: Internal Audit
App Showcase: Internal AuditApp Showcase: Internal Audit
App Showcase: Internal Audit
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance
 
The Use of Spreadsheets in Commodity Trading – 2015
The Use of Spreadsheets in Commodity Trading – 2015The Use of Spreadsheets in Commodity Trading – 2015
The Use of Spreadsheets in Commodity Trading – 2015
 
5 steps for better risk assessment
5 steps for better risk assessment5 steps for better risk assessment
5 steps for better risk assessment
 
QuantAware
QuantAwareQuantAware
QuantAware
 

Similar a Embedding RCSA into Strategic Planning and Business Strategy

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxmadlynplamondon
 
Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Andrew Smart
 
Operational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningOperational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningEneni Oduwole
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Andrew Smart
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guideCenapSerdarolu
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guideAstalapulosListestos
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxmanjujayakumar2
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct RiskAndrew Smart
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerTanaMaeskm
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488Ashwin Kumar
 
StrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingStrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingNathan Ives
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Andrew Smart
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...PMI Indonesia Chapter
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk TransferCBIZ, Inc.
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementpeterObakozuwa
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityJeff B
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy PresentationDavid Fernandes
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__susanta subudhi
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__susanta subudhi
 

Similar a Embedding RCSA into Strategic Planning and Business Strategy (20)

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
 
Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.
 
Operational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningOperational Risk Management & Strategic Planning
Operational Risk Management & Strategic Planning
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptx
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
 
StrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingStrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance Mapping
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk Transfer
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and Sustainability
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy Presentation
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
HIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINALHIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINAL
 

Último

Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxMarkAnthonyAurellano
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607dollysharma2066
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Kirill Klimov
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchirictsugar
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfrichard876048
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africaictsugar
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfJos Voskuil
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
Investment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy CheruiyotInvestment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy Cheruiyotictsugar
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 

Último (20)

Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchir
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdf
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africa
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdf
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
Investment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy CheruiyotInvestment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy Cheruiyot
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 

Embedding RCSA into Strategic Planning and Business Strategy

  • 1. Embedding RCSA into Strategic Planning and Business Strategy Operatiivisten Riskien Hallinta, Helsinki, Finland Andrew Smart, Ascendore
  • 2. Post credit crunch, financial services firms are drowning under a tsunami of regulatory change, cost and complexity 2 Run the Bank £200bn plus fines 492% Annual increase regulatory change
  • 3. 3 The cost & complexity of operational risk & compliance is too high and there is a “disproportionate risk aversion creeping into decision-making” Chairman, HBSC, 2015 Accenture Risk Study, 2017
  • 4. Boards and executives should be able to answer these questions with confidence. 4 Are we in control? Are we going to deliver our strategy? Are we operating within appetite?
  • 5. RCSA - an essential part of an integrated framework Better Conversation Better Decisions Better Action-taking Better Results Risk & Control Self- Assessment (RCSA) processes and data should be an essential part of an integrated Strategy & Risk Management framework; an integral part of enterprise management reporting. 5
  • 6. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 6
  • 7. 7 Strategy Strategic Drivers Business Objectives Operational Enablers Compliance Enablers Over the long-term, where are we going and how will we get there? Critical few things from the business model that enable the delivery of the strategy To deliver our long-term strategy what is the focus over the next 12-24 months? Where do we need to excel day-to-day What are the ‘rules’ that define our operating environment?
  • 8. Risk Appetite defines the boundaries for risk-takingStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT RISK THRESHOLDS RISK EXPOSURES Compliance Enablers 8
  • 9. Manage threats & opportunities via the risk taxonomyStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT STRATEGIC RISK EXECUTION RISK OPERATIONAL RISK COMPLIANCE RISK Compliance Enablers 9
  • 10. Managed at every level in the framework Strategy Strategic Drivers Business Objectives Operational Enablers StrategicRisk Execution Risk Compliance Risk APPETITE ALIGNMENT ACCOUNTABILITY ALIGNMENT CASCADE ASSESSMENT MEASUREMENT ACTION-TAKING Operational Risk Compliance Enablers 10
  • 11. The RACI framework is a proven approach to embedding accountability and clarification of roles in decision-making. Supports the 3 Lines of Defence InformResponsible(s)Accountable Consult 11
  • 12. How do your operational and regulatory enablers relate to strategy? Alignment mapping can identify gaps; areas where your strategy is not supported or where operational resources are been wasted. Regulatory rules mapping provide assurance that processes and initiatives are in place to meet regulatory obligations and identify gaps; where are the gaps or weaknesses in our regulatory response landscape? 12 Key ControlsKey RisksObjectiveEntity Processes Initiatives Technology
  • 13. How does strategy & risk cascade through the firm? Board & Senior Management assurance is enhanced by understanding the cascading of objectives & risks through the firm. Identify gaps in consolidated reporting by linking objectives, risks and controls in ‘cascade chains’ through the firm. Where does the chain break? 13 Key Risk (Strategic Risk) Corporate Division Department Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk)
  • 14. Data points to inform your Risk Self- Assessments 14 MAXIMUM INHERENT RESIDUAL % $£€ IMPACT(S) LIKELIHOOD EXPOSURE DRIVERS use driver(s) as the basis for assessing impacts thus linking risk back to strategy ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. KRIs Losses / Near Misses Expert Judgement Scenarios & Models Related KPIs & KCIs Control Self Assessment
  • 15. Data points to inform your Control Self-Assessments 15 KCIs Losses / Near Misses ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. Control Testing Related KPIs & KRIs DESIGN PERFORMANCE CONTROL EFFECTIVENESS
  • 16. Three types of related indicators to give a full picture RAG is common practice RAGAR is best practice 16 Key Performance Indicators (KPIs) Used to define performance thresholds and targets; and to monitor progress towards achieving these targets. Key Risk Indicators (KRIs) Used to define risk thresholds and targets; to monitor changes within the risk environment. Key Control Indicators (KCIs) Used to define control thresholds and targets; to monitor changes within the controls environment. BASELINE LT 1 LT 2 UT2 UT 1 TARGET T 2 T 1
  • 17. Assessment and measurement is not enough. Action-taking is critical in driving performance & managing risk Typically we think about two types of actions 17 Improvement Actions Audit Actions
  • 18. Tools to bring it all together 18 Better Action- taking Better Decisions Better Results Strategy Map Better Conversations Appetite Alignment Matrix Risk Appetite Risk Map
  • 19. Map Business Objectives & their causal relationship to improve the communication, monitoring and management of strategic and operational performance. 19
  • 20. Define risk tolerances across the framework reflecting the materiality of the business unit. Use Drivers to link RCSA back to Strategy. 20
  • 21. The Risk Map provides a visual overview of the risk profile and make it easy to identify potential risk issues. Four perspectives risk map is aligned to the Strategy Map. 21
  • 22. Starting with Strategic Drivers, define Risk Appetite across the framework, reflecting the materiality and strategic intent of the business unit. 22
  • 23. The Appetite Alignment Matrix visualise the alignment of risk- taking to risk appetite showing where the firm is aligned, over- exposed and under-exposed. 23
  • 24. Are we operating within appetite? 24
  • 25. Appetite, Performance, Risk and Controls Effectiveness should be assessed, measured and aligned across the organisational hierarchy and within the taxonomy within the framework. 25 STRATEGY typically strategy is cascaded top-down DATA typically data flows up the organization EXECUTION typically execution is driven from the middle Corporate Divisions Departments STRATEGIC RISK EXECUTION RISK OPERATIONAL & COMPLIANCE RISK
  • 26. 26 STRATEGY MAP Are we on track to deliver the strategy? APPETITE ALIGNMENT MATRIX Are we operating within appetite? RISK APPETITE How much risk is acceptable? RISK MAP What level of risk are we taking?
  • 27. Benefits of Improved Strategic Execution ▪ A growth in shareholder value of 150%, driven by a 180% growth in profits and a 120% growth in revenue ▪ A 50% improvement in customer satisfaction ▪ A 50% improvement in key process effectiveness ▪ A 25% improvement in employee satisfaction, leading to a 50% reduction in employee turnover Benefits of an Integrated approach ▪ Transformed our approach to risk and regulatory compliance over 12-month ▪ Reduce the value of our operational losses by 94%, the volume by 63% and our economic capital provision by 23%” ▪ Eliminate 11 spreadsheet systems ▪ Enabled us to secure a 3% regulatory capital release and reduce our cost of capital significantly 27 Benefits of Enterprise Risk Management ▪ Increasing the range of opportunities ▪ Identifying and managing risk entity- wide ▪ Increasing positive outcomes and advantage while reducing negative surprises ▪ Reducing performance variability ▪ Improving resource deployment ▪ Enhancing enterprise resilience Results based on 3 year performance of BSC Hall of Frame winners COSO ERM Framework, 2017 Example benefits reported by Ascendore customers Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent" or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
  • 28. We believe that risk management and compliance must enable strategy execution and value creation, not simply tick regulatory boxes. 28 “we have reduced our Pillar 2 capital by 81.2% while delivering a 94% reduction in the value of errors and a 63% reduction in the volume of errors” Head of Enterprise Risk, Homeloan Management Limited We provide Integrated GRC (Governance, Risk and Compliance) solutions to financial services firms and their regulators built on familiar, everyday office tools; SharePoint, Office 365 & the Cloud.
  • 29. COSO ERM Framework 2017 Risk-Based Performance Management 29
  • 30. What is Risk-Based Performance Management? Enhance Shareholder value Control Cost & Complexity Drive Accountability Align the firm Risk-Based Performance Management (RBPM) is an strategic execution approach which integrates business strategy, risk appetite, performance management and risk management. 30
  • 31. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 31
  • 32. Embedding RCSA into Strategic Planning and Business Strategy? Andrew Smart Ascendore