Transformating It Risk Management
Transformating It Risk Management
of IT Risk
Management
[Link]
The transformation of IT Risk Management
• Case studies
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
Redefining the role of IT Risk Management
in a changing world
Organizations are facing increasing demand
to realign their IT Risk Management (ITRM)
framework to meet constantly changing
regulatory standards. An effective ITRM
framework poses many challenges, including
maintaining a cost-effective process design
and meeting the efficiency demands of
company management, while balancing the
need to intervene and enabling innovation and
the flow of business. This is forcing leading
organizations to redefine and transform their
traditional ITRM model.
Although cost factors are a challenge for
organizations in deriving value from an ITRM
function, integrated ITRM operating models
can significantly help to improve business
decision making and accountability for IT risk.
An effective ITRM function can also assist in
establishing a risk-aware culture and methods
of working and collaborating to take appropriate
action, strengthening the first line of defense
within the organization.
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
1 The transformation of IT Risk Management
The role of IT in an organization has transformed over recent A holistic view and discussion on ITRM helps management
years and is no longer seen as just supporting the business. to identify, manage and optimize risks—not just mitigate
IT also allows organizations to differentiate themselves and their risks—turning IT risks into advantages and aligning
provides many organizations a competitive advantage. This management’s risk appetite with a desired return.
results in IT being a strategic enabler instead of a cost center.
ITRM should define a comprehensive view of IT risks;
As a result, the view on managing IT risk within an organization
continuously refresh the inventory of IT risks; help create
has also evolved. Because IT risk covers many aspects of the
strategies to prevent, mitigate, or accept these risks;
organization, it is assumed that the functions of internal audit,
and monitor risks against defined tolerances. Through
business operations, and/or technology operations will be able
fit-for-purpose design, skills, and competencies, and
to identify, monitor, and address these risks. However, that is
automation platforms, the ITRM function provides
not the case, and often, if these functions are performing an
management an opportunity to proactively manage risk and
element of IT risk management, the efforts are not coordinated,
transform its ITRM needs into a capability that plays to the
consistent, or consolidated for an enterprise view.
broader enterprise strategy and the critical issues that
The ITRM function within an organization operates as a distinct, organizations face.
but integrated, function within IT. It supports the enterprise
Aligning the ITRM function with the other risk oversight
as a whole addressing the strategic objectives, mission, and
functions such as internal audit, enterprise risk management,
business model of the organization. An ITRM function manages
and compliance, as well as with regulatory mandates, is an
the firm’s risk posture and appetite for IT risk and security
important element in more effectively ensuring that risks
by determining the key IT threats that an organization faces
are optimized.
and leading a proactive response to combat these threats.
An effective ITRM function ensures a robust and effective
engagement with regulatory bodies to determine compliance
priorities for each jurisdiction. Furthermore, as an enterprise
business issue, ITRM requires an organization to build
capabilities that must be embedded and managed across a
matrixed organization through a sustainable process to provide
transparency and accountability.
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
The transformation of IT Risk Management 2
Understanding the complexity of the business environment numerous forces, whether external such as regulatory,
and changes from within the organization are some of geopolitical, or market-driven, or internal such as new
the key drivers in understanding key areas of risk in an products, acquisitions, or IT implementations.
organization. These factors are in turn being driven by
A coordinated approach to ITRM enables information flow and a measuring and reporting; it is about optimizing the resources
clear understanding of the risk domains within IT. Organizations dedicated to ITRM on a business impact-prioritized basis,
need to assess for risk and develop risk optimization strategies leveraging a defined process, using lessons from history, and
by defining and delivering broad risk optimization programs. applying as appropriate across the landscape of enterprise
They also need to establish a measurement program to report IT risks.
holistically on the IT risk posture. But this is not just about
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
3 The transformation of IT Risk Management
• Alignment of IT risk control framework with business strategy • More rigorous regulations
• IT portfolio prioritization • Regulatory uncertainty
• Risk posture and key program updates • Rising costs for compliance
• Risk assessment rationalization and enterprise alignment
Cloud
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
The transformation of IT Risk Management 4
KPMG member firms assist organizations in transforming capabilities to monitor the ITRM function’s effectiveness
their ITRM across the entire continuum. Whether working by defining KRIs for managing risks such as number of risks
with organizations that want to establish an ITRM function within each risk area, and number of risks mitigated, number
or organizations that are looking to enhance their current of risks by ongoing mitigation effectiveness; determining
risk management function, our services help organizations appropriate collection and reporting methods; and developing
transform ITRM by proactively building integrated capabilities tools for reporting on essential measurements for managing
to identify and manage strategic, regulatory, and emerging risks. KPMG can help design and launch an ITRM function,
technology risks and helping design methods to reduce the recommend and implement ITRM function improvements, and
associated operational costs through sustainable, repeatable, support the monitoring of ongoing ITRM performance through
and insightful processes. “health check” exercises. Our professionals and methods
can help transform how companies view and manage IT risk
For either mature or early-stage ITRM functions, we consider
through wide-ranging ITRM design and improvement based
monitoring to be essential in terms of compliance and
upon industry-wide practices and trends.
operations. Organizations need to consider implementing
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
5 The transformation of IT Risk Management
Case studies
CASE STUDY 1
Client challenge The client needed assistance in implementing a formal ITRM framework and strategy that would align
with its corporate risk management framework. More specifically, the client needed assistance in
addressing the corporate risk management requirements, supporting regulatory and other compliance
concerns, strengthening and reviewing their current ITRM processes, and improving IT risk reports to
management.
Benefits to client • A methodology that has resulted in cost savings for the client while also maintaining a high level of quality
• Support from an onshore KPMG team with local industry and subject-matter knowledge
• A holistic process for assessing the client’s controls and aligning the ITRM function with the client’s
overall risk management framework
CASE STUDY 2
Client challenge The client needed a solution that would reduce the cost associated with monitoring compliance and
assessing the effectiveness of its IT controls—without compromising the quality of the controls.
KPMG response KPMG developed an onshore/offshore delivery model for monitoring compliance and assessing the
effectiveness of the client’s IT controls. Local KPMG staff provided an onshore presence, working with
the client to understand the controls and the client’s requirements and needs. Offshore resources
were provided by KPMG’s Global Services team. Together, the two KPMG teams were able to deliver
a cost-effective methodology without compromising the quality of the client’s IT controls.
Benefits to client • A solution that has resulted in cost savings for the client, while also maintaining a high level of quality
• Support from an onshore KPMG team with local industry and subject-matter knowledge
• A tested process for assessing the client’s controls and providing reporting to the client
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
The transformation of IT Risk Management 6
CASE STUDY 3
Global multinational oil and gas company looking to identify and manage business critical infrastructure
Client challenge The client needed to define, and maintain a process that would identify and categorize risks related to
business critical infrastructure components.
KPMG response KPMG developed a wide-ranging process for identifying, defining, and maintaining business critical
infrastructure services. Local KPMG staff then provided a single point of contact to communicate and
train the client in understanding the risks associated with business critical services, business critical
attributes/definitions, and controls specific to each. In addition, business impact assessments were
performed as part of the ongoing management of these assets on an annual basis.
Benefits to client • A methodology that has resulted in proper risk identification of business critical services
• Support from an onshore KPMG team with local industry and subject-matter knowledge
• A robust process for assessing the client’s business critical assets and the proper maintenance and
management of these assets
CASE STUDY 4
Client challenge The client had developed an ITRM strategy. However, assistance was needed in developing an IT
risk and controls framework that could be implemented as part of the corporate ITRM framework.
Additionally, the client needed help in capturing and defining IT risks and controls while also monitoring
and reporting compliance to management.
KPMG response KPMG assisted the client by developing a risk and controls framework that could capture and monitor
IT risks. The focus of the engagement was to develop the framework of IT controls and IT risks
including the key activities that should be in place to attest to the effectiveness of the IT controls in
place. This also included developing metrics (KRIs) that could be used to monitor the effectiveness
of the implemented IT controls within the applications at the client, as well as be used for reporting
to management.
Benefits to client • An ITRM framework that is aligned to the client’s ITRM strategy and industry practice
• The identification of IT risks and the development of IT controls that align with standard practices, as
well as used for other assessments with the potential for future cost savings
• KPMG professionals who have industry experience and provide insight into how ITRM frameworks
and controls have been implemented and monitored at similar organizations
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
7 The transformation of IT Risk Management
CASE STUDY 5
Global oil and gas company looking for control focused input into process design
Client challenge The client needed to ensure control designs were being validated and to allow control best practices to
be built into the design of its new configuration management and asset management processes.
KPMG response KPMG participated directly in the project design workshops and provided industry leading control
recommendations to the client in the integration of its configuration and asset management systems.
KPMG also included a risk-based objective review of the overall project governance, with an assessment
on key project risks and recommended actions.
Benefits to client • Client was able to evaluate its control design for its configuration and asset management
process areas
• Identified areas of improvement during the design phase around control procedures which were
easier to change before the implementation phase
• Support from an onshore KPMG team with local industry and subject-matter knowledge
CASE STUDY 6
Client challenge The client had recently redeveloped its ITRM function so it could be adopted by all regions globally.
The client needed assistance in rolling out and performing the IT risk assessments. However,
upcoming compliance requirements in one of the local regions meant that risks for a significant
number of applications distributed globally needed to be analyzed and addressed in a very short
period of time.
KPMG response KPMG assisted with IT risk assessments across applications that were subject to local regulatory
requirements. Upon completion of the assessments, KPMG helped the client to better understand
the IT risks that were identified and determine whether sufficient controls were in place to mitigate
these risks.
Benefits to client • Objective evaluation of IT risk assessments for the identified applications
• A KPMG team, including member firms of KPMG International advised on a global approach toward
the assessment and provided regional/local regulatory knowledge along with experience with
financial services
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
The transformation of IT Risk Management 8
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member
firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved. NDPPS 155175
Contact us
David DiCristofaro
Partner
212-872-3382
ddicristofaro@[Link]
Phillip J. Lageschulte
Partner
312-665-5380
pjlageschulte@[Link]
Vivek Mehta
Director
212-872-6548
vivekmehta@[Link]
Joshua Galvan
Managing Director
713-319-2082
jgalvan@[Link]
[Link]
The information contained herein is of a general nature and is not intended to address the circumstances of any particular individual or
entity. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as
of the date it is received or that it will continue to be accurate in the future. No one should act upon such information without appropriate
professional advice after a thorough examination of the particular situation.
© 2013 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms
firms affiliated
affiliated with KPMG
with KPMG
International
International
Cooperative
Cooperative
(“KPMG
(“KPMG
International”),
International”),
a Swiss
a Swiss
[Link].
All rights
All rights
reserved.
reserved.
The KPMG
Printed
name,
in thelogo
U.S.A.
and
The KPMG
“cutting through
name,complexity”
logo and “cutting
are registered
through complexity”
trademarks or
are
trademarks
registeredoftrademarks
KPMG International.
or trademarksNDPPSof KPMG
155175
International. NDPPS 155175