SlideShare una empresa de Scribd logo
1 de 18
Building stronger risk management
cultures
Presented by:
Benjamin Kpodo
August, 2014
Confidentiality level on slide master
Version number on slide master12 November 2015
Option 1
2
Content
• What is risk culture?
• A case for a strong risk culture
• Elements of strong risk culture
• Practical steps to building a strong risk culture
• Conclusion
Confidentiality level on slide master
Version number on slide master
What is risk culture?
• The culture of an organization or a company may be
seen as the overall reflection of the attitude of every
component of management within the company. The
culture of an organisation determines how individuals
will behave in particular circumstances.
• Risk culture is an emerging terminology which
encapsulates a company’s risk appetite, tolerance and
risk management practices as demonstrated by its
employees.
• According to Erik Banks (2012); risk culture is
defined as an internal sensibility that reflects
knowledge of, and respect for risk.
12 November 20153
Confidentiality level on slide master
Version number on slide master
A case for a strong risk culture
Problems with risk culture are frequently found at the root
of organisational scandals and collapses.
The concept of risk culture has grown steadily since the
global financial crisis of 2008
“The absence of healthy risk management culture is the
cause of the organisational failures”*
Proposals that risk attracting box ticking conformity as
opposed to a much more important (though often much
more difficult) substantive behavioural change must be
avoided
“The development of a risk culture throughout the firm is
perhaps the most fundamental tool for effective risk
management”*.
EC 2010, IIF 2008
12 November 20154
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Tone from the top
Tone from the top refers to the ethical atmosphere that is
created in the workplace by the organization's
leadership. Whatever tone management sets will have a
trickle-down effect on employees of the company.
• Are the mission, vision and values clearly aligned and
communicated throughout the firm?
• Is the strategy appropriate given the risk appetite, and
does the risk appetite framework ensure that
decisions down through the organization are
consistent with risk appetite?
• Are risk outcomes articulated in strategy?
12 November 20155
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
• Can the board point to an example where risk
appetite considerations impacted strategic decision-
making?
• Does senior management lead by example?
• Is middle management displaying the right
behaviours?
• What process does the firm have to ensure the
message is consistent, well understood and accepted
throughout the firm?
• Is risk accurately factored into decision-making?
• Are limits consistent with risk appetite? Are limits at
the business unit level set to ensure risk appetite is
not exceeded?12 November 20156
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Accountability
It is the obligation to account for ones activities, accept
responsibility for them, and to disclose the results in a
transparent manner.
It is important to understand how various stakeholders
including employees and managers are held accountable
for their action.
Ownership of risk
• What is the expectations with respect to the
identification, assessment, monitoring and reporting
and response to, current and emerging risks across
the organisation?
12 November 20157
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Escalation process
• How are whistleblowers treated? Can you point to an
instance where an individual was promoted shortly
after he/she raised concerns about unacceptable risk
taking?
• Is the culture proactive? Do breaches in controls or
unacceptable behaviour have consequences?
• Are requests for increases to limits rubber stamped
by the board? How often are requests for limit
increases rejected?
12 November 20158
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Enforcement
• When was the last time an individual was disciplined
and compensation was cut as a result of
unacceptable risk taking?
12 November 20159
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Effective challenge
An effective risk culture will facilitate constructive
challenges in the line of business and in control
functions. This means that employees must be
empowered to challenge long held positions and new
decisions
Open to dissent
• Does the culture support risk transparency and
enable concerns to be voiced?
• Does the culture support constructive dissent? Can
you cite a time when an employee raised concerns
about risk taking? How did the company react?
12 November 201510
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Stature of risk management
• Does the CRO and the risk management function
share the same stature as the other departments of
the organisation
• Does the CRO and risk management function have
appropriate direct access to the board and senior
management
• Does the CRO have ex ante input to strategic
decisions? Are risk management and audit consulted
before new products are introduced?
• Does risk management have skills necessary to
understand all products and models?
12 November 201511
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Compensation
Inappropriate pay policy was one of the major
contributors to the failures in businesses that were
affected in the GFC of 2008.
Remuneration and performance
• How are compensation and risk-taking behaviours
linked?
• Is compensation based only on net income from a
given activity in a given financial year without
recourse to how that activity will affect the future
health of the organisation?
12 November 201512
Confidentiality level on slide master
Version number on slide master
Elements of strong risk culture
Compensation
Talent development and succession planning
• When was the last time a control function head was
promoted to run a business?
• Do business heads have control function experience?
12 November 201513
Confidentiality level on slide master
Version number on slide master
Practical steps to building a strong risk culture
Implementing the three lines defence
12 November 201514
Confidentiality level on slide master
Version number on slide master
Practical steps to building a strong risk culture
Adopting the BASELL III framework
12 November 201515
Confidentiality level on slide master
Version number on slide master
Practical steps to building a strong risk culture
Other steps
• Begin a dialogue on risk culture at management level
• Identify a team to lead the process
• Conduct a complete assessment of existing culture
• Develop a diagnostic report with a set of tangible
recommendations
• Determine what the desired risk culture should look like
• Design and implement an action plan based on the
recommendations to build the new risk culture
• Communicate changes and secure “buy in” from all
stakeholders
12 November 201516
Confidentiality level on slide master
Version number on slide master12 November 201517
Conclusion
• An effective or strong risk culture cannot be
developed without the support and involvement of
senior management.
• A strong risk culture should be focused on
optimizing well calculated and understood risk return
trade-offs within a comprehensive ERM strategy
aimed at consistent value creation for all
stakeholders.
• It is also important to note that developing an
effective risk culture is a journey, requiring several
resources and supported by consistent
communication, education and management.
Confidentiality level on slide master
Version number on slide master12 November 201518
Thank you!

Más contenido relacionado

La actualidad más candente

Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk Management
Andrew Smart
 
127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0
Rachael Phelan
 
ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
Jorge Vaz Girão , CISA, PMP, PMDPro I, ERMCP
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
Treasury Consulting LLP
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
Frackson Kathibula-Nyoni
 

La actualidad más candente (20)

Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk Management
 
Risk culture - IRM PROTIVITI
Risk culture - IRM PROTIVITIRisk culture - IRM PROTIVITI
Risk culture - IRM PROTIVITI
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0
 
ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
 
Introduction to Risk Management
Introduction to Risk ManagementIntroduction to Risk Management
Introduction to Risk Management
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Risk management
Risk managementRisk management
Risk management
 
Introduction To Risk Management Powerpoint Presentation Slides
Introduction To Risk Management Powerpoint Presentation SlidesIntroduction To Risk Management Powerpoint Presentation Slides
Introduction To Risk Management Powerpoint Presentation Slides
 
Risk Management Overview
Risk Management OverviewRisk Management Overview
Risk Management Overview
 
Risk management
Risk managementRisk management
Risk management
 
Integrating Risk Appetite With Strategy Feb 14 2011
Integrating Risk Appetite With Strategy   Feb 14 2011Integrating Risk Appetite With Strategy   Feb 14 2011
Integrating Risk Appetite With Strategy Feb 14 2011
 
Introduction to risk management
Introduction to risk managementIntroduction to risk management
Introduction to risk management
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
 
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
 

Destacado

Risk culture a5_web15_oct_2012
Risk culture a5_web15_oct_2012Risk culture a5_web15_oct_2012
Risk culture a5_web15_oct_2012
Kym Jaeger
 
Coffee Industry Analysis
Coffee Industry AnalysisCoffee Industry Analysis
Coffee Industry Analysis
Mairin O'Connor
 
Starbucks PowerPoint
Starbucks PowerPointStarbucks PowerPoint
Starbucks PowerPoint
jjhackn
 

Destacado (13)

Risk culture a5_web15_oct_2012
Risk culture a5_web15_oct_2012Risk culture a5_web15_oct_2012
Risk culture a5_web15_oct_2012
 
Starbuck’s innovation and turnaround success
Starbuck’s innovation and turnaround successStarbuck’s innovation and turnaround success
Starbuck’s innovation and turnaround success
 
Risk Management Enterprise and A Case Study on Starbucks
Risk Management Enterprise and A Case Study on StarbucksRisk Management Enterprise and A Case Study on Starbucks
Risk Management Enterprise and A Case Study on Starbucks
 
Starbucks corporation (indian coffee)
Starbucks corporation  (indian coffee) Starbucks corporation  (indian coffee)
Starbucks corporation (indian coffee)
 
What Does Good Risk Culture Actually Look Like?
What Does Good Risk Culture Actually Look Like?What Does Good Risk Culture Actually Look Like?
What Does Good Risk Culture Actually Look Like?
 
Brand Management Starbucks
Brand Management StarbucksBrand Management Starbucks
Brand Management Starbucks
 
Starbucks organisational culture
Starbucks organisational cultureStarbucks organisational culture
Starbucks organisational culture
 
Coffee Industry Analysis
Coffee Industry AnalysisCoffee Industry Analysis
Coffee Industry Analysis
 
Starbucks Key issues
Starbucks Key issuesStarbucks Key issues
Starbucks Key issues
 
Risk Management Framework
Risk Management FrameworkRisk Management Framework
Risk Management Framework
 
Risk management
Risk managementRisk management
Risk management
 
coffee shop market ppt
coffee shop market pptcoffee shop market ppt
coffee shop market ppt
 
Starbucks PowerPoint
Starbucks PowerPointStarbucks PowerPoint
Starbucks PowerPoint
 

Similar a Risk culture presentation

Five lines of assurance a new paradigm in internal audit & erm
Five lines of assurance a new paradigm in internal audit & ermFive lines of assurance a new paradigm in internal audit & erm
Five lines of assurance a new paradigm in internal audit & erm
Dr. Zar Rdj
 
Five Lines of Assurance A New ERM and IA Paradigm
Five Lines of Assurance  A New ERM and IA ParadigmFive Lines of Assurance  A New ERM and IA Paradigm
Five Lines of Assurance A New ERM and IA Paradigm
Tim Leech
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy Presentation
David Fernandes
 

Similar a Risk culture presentation (20)

Five lines of assurance a new paradigm in internal audit & erm
Five lines of assurance a new paradigm in internal audit & ermFive lines of assurance a new paradigm in internal audit & erm
Five lines of assurance a new paradigm in internal audit & erm
 
Five Lines of Assurance A New ERM and IA Paradigm
Five Lines of Assurance  A New ERM and IA ParadigmFive Lines of Assurance  A New ERM and IA Paradigm
Five Lines of Assurance A New ERM and IA Paradigm
 
#corpriskforum2016 - Vincent Tophoff
#corpriskforum2016 - Vincent Tophoff#corpriskforum2016 - Vincent Tophoff
#corpriskforum2016 - Vincent Tophoff
 
ISO 9001:2015 vs Enterprise Risk Management
ISO 9001:2015 vs Enterprise Risk ManagementISO 9001:2015 vs Enterprise Risk Management
ISO 9001:2015 vs Enterprise Risk Management
 
#corpriskforum2016 - Julia Graham
#corpriskforum2016 - Julia Graham#corpriskforum2016 - Julia Graham
#corpriskforum2016 - Julia Graham
 
10 Aspects of a Good Risk Appetite Implementation Process
10 Aspects of a Good Risk Appetite Implementation Process10 Aspects of a Good Risk Appetite Implementation Process
10 Aspects of a Good Risk Appetite Implementation Process
 
Module 2_Precaution & Avoidance of crises.pptx
Module 2_Precaution & Avoidance of crises.pptxModule 2_Precaution & Avoidance of crises.pptx
Module 2_Precaution & Avoidance of crises.pptx
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy Presentation
 
Critical risk and control frameworks - James Ritchie
Critical risk and control frameworks - James RitchieCritical risk and control frameworks - James Ritchie
Critical risk and control frameworks - James Ritchie
 
Module 15 - Risk Management.pptx
Module 15 - Risk Management.pptxModule 15 - Risk Management.pptx
Module 15 - Risk Management.pptx
 
Crisis Management Workshop Thailand 2012
Crisis Management Workshop Thailand 2012Crisis Management Workshop Thailand 2012
Crisis Management Workshop Thailand 2012
 
Assessing Your Supply Risk Maturity to Enhance Overall Performance
Assessing Your Supply Risk Maturity to Enhance Overall PerformanceAssessing Your Supply Risk Maturity to Enhance Overall Performance
Assessing Your Supply Risk Maturity to Enhance Overall Performance
 
Enterprise risk management presentation to APM SWWE branch
Enterprise risk management presentation to APM SWWE branchEnterprise risk management presentation to APM SWWE branch
Enterprise risk management presentation to APM SWWE branch
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
 
Why Quality is a Risky Business?
Why Quality is a Risky Business?Why Quality is a Risky Business?
Why Quality is a Risky Business?
 
Enterprise Risk Management 2014
Enterprise Risk Management 2014Enterprise Risk Management 2014
Enterprise Risk Management 2014
 
#Corpriskforum2016 - Tatiana Budishevskaya
#Corpriskforum2016 - Tatiana Budishevskaya#Corpriskforum2016 - Tatiana Budishevskaya
#Corpriskforum2016 - Tatiana Budishevskaya
 
FERMA presentation at Athens conference
FERMA presentation at Athens conferenceFERMA presentation at Athens conference
FERMA presentation at Athens conference
 
Aligning strategy decisions with risk appetite, presented by David Shearer, 1...
Aligning strategy decisions with risk appetite, presented by David Shearer, 1...Aligning strategy decisions with risk appetite, presented by David Shearer, 1...
Aligning strategy decisions with risk appetite, presented by David Shearer, 1...
 
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organizationPECB Webinar: ISO 31000 – Risk Management and how it can help an organization
PECB Webinar: ISO 31000 – Risk Management and how it can help an organization
 

Último

Beyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable developmentBeyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable development
Nimot Muili
 
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTECAbortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
Abortion pills in Riyadh +966572737505 get cytotec
 
The Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard BrownThe Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard Brown
SandaliGurusinghe2
 
internship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamrainternship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamra
AllTops
 

Último (14)

International Ocean Transportation p.pdf
International Ocean Transportation p.pdfInternational Ocean Transportation p.pdf
International Ocean Transportation p.pdf
 
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professionalW.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
 
Beyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable developmentBeyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable development
 
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTECAbortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
 
digital Human resource management presentation.pdf
digital Human resource management presentation.pdfdigital Human resource management presentation.pdf
digital Human resource management presentation.pdf
 
How Software Developers Destroy Business Value.pptx
How Software Developers Destroy Business Value.pptxHow Software Developers Destroy Business Value.pptx
How Software Developers Destroy Business Value.pptx
 
Gautam Buddh Nagar Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Gautam Buddh Nagar Call Girls 🥰 8617370543 Service Offer VIP Hot ModelGautam Buddh Nagar Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Gautam Buddh Nagar Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
The Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard BrownThe Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard Brown
 
Safety T fire missions army field Artillery
Safety T fire missions army field ArtillerySafety T fire missions army field Artillery
Safety T fire missions army field Artillery
 
Marketing Management 16th edition by Philip Kotler test bank.docx
Marketing Management 16th edition by Philip Kotler test bank.docxMarketing Management 16th edition by Philip Kotler test bank.docx
Marketing Management 16th edition by Philip Kotler test bank.docx
 
Persuasive and Communication is the art of negotiation.
Persuasive and Communication is the art of negotiation.Persuasive and Communication is the art of negotiation.
Persuasive and Communication is the art of negotiation.
 
Information Technology Project Management, Revised 7th edition test bank.docx
Information Technology Project Management, Revised 7th edition test bank.docxInformation Technology Project Management, Revised 7th edition test bank.docx
Information Technology Project Management, Revised 7th edition test bank.docx
 
Siliguri Escorts Service Girl ^ 9332606886, WhatsApp Anytime Siliguri
Siliguri Escorts Service Girl ^ 9332606886, WhatsApp Anytime SiliguriSiliguri Escorts Service Girl ^ 9332606886, WhatsApp Anytime Siliguri
Siliguri Escorts Service Girl ^ 9332606886, WhatsApp Anytime Siliguri
 
internship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamrainternship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamra
 

Risk culture presentation

  • 1. Building stronger risk management cultures Presented by: Benjamin Kpodo August, 2014
  • 2. Confidentiality level on slide master Version number on slide master12 November 2015 Option 1 2 Content • What is risk culture? • A case for a strong risk culture • Elements of strong risk culture • Practical steps to building a strong risk culture • Conclusion
  • 3. Confidentiality level on slide master Version number on slide master What is risk culture? • The culture of an organization or a company may be seen as the overall reflection of the attitude of every component of management within the company. The culture of an organisation determines how individuals will behave in particular circumstances. • Risk culture is an emerging terminology which encapsulates a company’s risk appetite, tolerance and risk management practices as demonstrated by its employees. • According to Erik Banks (2012); risk culture is defined as an internal sensibility that reflects knowledge of, and respect for risk. 12 November 20153
  • 4. Confidentiality level on slide master Version number on slide master A case for a strong risk culture Problems with risk culture are frequently found at the root of organisational scandals and collapses. The concept of risk culture has grown steadily since the global financial crisis of 2008 “The absence of healthy risk management culture is the cause of the organisational failures”* Proposals that risk attracting box ticking conformity as opposed to a much more important (though often much more difficult) substantive behavioural change must be avoided “The development of a risk culture throughout the firm is perhaps the most fundamental tool for effective risk management”*. EC 2010, IIF 2008 12 November 20154
  • 5. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Tone from the top Tone from the top refers to the ethical atmosphere that is created in the workplace by the organization's leadership. Whatever tone management sets will have a trickle-down effect on employees of the company. • Are the mission, vision and values clearly aligned and communicated throughout the firm? • Is the strategy appropriate given the risk appetite, and does the risk appetite framework ensure that decisions down through the organization are consistent with risk appetite? • Are risk outcomes articulated in strategy? 12 November 20155
  • 6. Confidentiality level on slide master Version number on slide master Elements of strong risk culture • Can the board point to an example where risk appetite considerations impacted strategic decision- making? • Does senior management lead by example? • Is middle management displaying the right behaviours? • What process does the firm have to ensure the message is consistent, well understood and accepted throughout the firm? • Is risk accurately factored into decision-making? • Are limits consistent with risk appetite? Are limits at the business unit level set to ensure risk appetite is not exceeded?12 November 20156
  • 7. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Accountability It is the obligation to account for ones activities, accept responsibility for them, and to disclose the results in a transparent manner. It is important to understand how various stakeholders including employees and managers are held accountable for their action. Ownership of risk • What is the expectations with respect to the identification, assessment, monitoring and reporting and response to, current and emerging risks across the organisation? 12 November 20157
  • 8. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Escalation process • How are whistleblowers treated? Can you point to an instance where an individual was promoted shortly after he/she raised concerns about unacceptable risk taking? • Is the culture proactive? Do breaches in controls or unacceptable behaviour have consequences? • Are requests for increases to limits rubber stamped by the board? How often are requests for limit increases rejected? 12 November 20158
  • 9. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Enforcement • When was the last time an individual was disciplined and compensation was cut as a result of unacceptable risk taking? 12 November 20159
  • 10. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Effective challenge An effective risk culture will facilitate constructive challenges in the line of business and in control functions. This means that employees must be empowered to challenge long held positions and new decisions Open to dissent • Does the culture support risk transparency and enable concerns to be voiced? • Does the culture support constructive dissent? Can you cite a time when an employee raised concerns about risk taking? How did the company react? 12 November 201510
  • 11. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Stature of risk management • Does the CRO and the risk management function share the same stature as the other departments of the organisation • Does the CRO and risk management function have appropriate direct access to the board and senior management • Does the CRO have ex ante input to strategic decisions? Are risk management and audit consulted before new products are introduced? • Does risk management have skills necessary to understand all products and models? 12 November 201511
  • 12. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Compensation Inappropriate pay policy was one of the major contributors to the failures in businesses that were affected in the GFC of 2008. Remuneration and performance • How are compensation and risk-taking behaviours linked? • Is compensation based only on net income from a given activity in a given financial year without recourse to how that activity will affect the future health of the organisation? 12 November 201512
  • 13. Confidentiality level on slide master Version number on slide master Elements of strong risk culture Compensation Talent development and succession planning • When was the last time a control function head was promoted to run a business? • Do business heads have control function experience? 12 November 201513
  • 14. Confidentiality level on slide master Version number on slide master Practical steps to building a strong risk culture Implementing the three lines defence 12 November 201514
  • 15. Confidentiality level on slide master Version number on slide master Practical steps to building a strong risk culture Adopting the BASELL III framework 12 November 201515
  • 16. Confidentiality level on slide master Version number on slide master Practical steps to building a strong risk culture Other steps • Begin a dialogue on risk culture at management level • Identify a team to lead the process • Conduct a complete assessment of existing culture • Develop a diagnostic report with a set of tangible recommendations • Determine what the desired risk culture should look like • Design and implement an action plan based on the recommendations to build the new risk culture • Communicate changes and secure “buy in” from all stakeholders 12 November 201516
  • 17. Confidentiality level on slide master Version number on slide master12 November 201517 Conclusion • An effective or strong risk culture cannot be developed without the support and involvement of senior management. • A strong risk culture should be focused on optimizing well calculated and understood risk return trade-offs within a comprehensive ERM strategy aimed at consistent value creation for all stakeholders. • It is also important to note that developing an effective risk culture is a journey, requiring several resources and supported by consistent communication, education and management.
  • 18. Confidentiality level on slide master Version number on slide master12 November 201518 Thank you!