Advanced Risk Management Strategies
Advanced Risk Management Strategies
Jean Demchak
Managing Director
Global Education Leader
Marsh, Inc.
New York, NY
Robert F. Roach
Chief Compliance Officer
New York University
New York, NY
“It wasn’t the risk we knew about that
concerned us, but the risks we were
unaware of that worried us the most”
Compliance Programs:
Use Risk Management principles to help identify,
assess, evaluate, and treat ethical and regulatory risks.
2. Risk Identification: What are the possible risk events your organization faces?
3. Risk Assessment:
o What is the likelihood of the risk event happening?
o What is the potential impact of the risk event?
5. Risk Treatment: What steps must be taken to mitigate the risks Identified?
Conflicts of Interest
Medicare/Medicaid
Billing
Time and Effort
Reporting
Tax Exempt Bonds
Executive Compensation
Record Retention
Export Controls
EEO/AA Laws
Risk Evaluation
• Avoidance
• Reduction/Mitigation (Internal Controls)
• Acceptance
o Crisis Management Plans
o Business Continuity Plans
o Other Operational Plans
Control Activities
•Organizational/Process Controls
o E.g. Separation of Duties
•Documentation
o Written Policies and Procedures Essential
•Training
•Audit Trails
o Final Results should be traceable back to originating transactions
Compliance
53%
Strengthen ERM 56%
45%
52%
Training/education 52%
62%
35%
Technology upgrades 36%
41%
32%
Current employees 39%
42%
20%
Restructure insurance programs 19%
29%
Inadequate RM representation at
31%
Board/C-suite level
Tuition rates/ Cost of capital/ Expansion capital Pension fund Risk financing Litigation Endowment
Finance tuition stability interest rate fluctuations Claim reserve
liability
Conflict of interest Employee fraud Ethical decision- Illegal acts Management Third party fraud Unauthorized
Integrity making fraud acts
Athletics Field courses Faculty bookings Regulatory Failure to educate Vendor alliances
Process Business Student activities Infrastructural renewal compliance Licensing Contract commitment
interruption and capacity
Reputation/ Foreign expansion Product and delivery Corporate/ Planning Resource
Strategy branding Admissions policy model institutional Intellectual allocation
Marketing Outsourcing alliances property Technology transfer
Environmental Environmental Visitors and contractors Illness/injury to faculty, Natural Campus security Special events Student/faculty
Health/Safety compliance students or staff hazards travel
This inventory does not capture the risks associated with a university medical center
1
• ISO31000
• Accreditation requirements?
ERM Guidelines and Best Practices:
Overview of S&P’s ERM Ratings Criteria
– Risk prioritization
– Communication
• They recognize that good risk management must be embedded into the
organization’s day to day activities
President/Senior Leadership
Internal audit
Risk Management Committee
Risk
Reports
Finance/ Select
Ext Risk
Provost Legal/
HR Affairs Deans Mgr
?
RM
Compliance
Audit
ERM functional representation, risk management activity support and shared services
College College College
Dept A Dept B Dept C
A B C
1 2 3
Assess the Envision the Implement
Current State Future State ERM
LOW
Insurance & Compliance Core ERM Practices Risk-Reward Optimization
10 17 9. Tuition Rate
Medium
10. Athletics
16 19
18 11. Research Compliance
12. Community Relations
13. Information Technology
14. Delivery Channel
15. Demographics
16. Operating Model
17. Research Grants
18. Endowment
Low
Performance
Very Low Low Moderate Major Catastrophic 19. Privacy
Impact
Tier one risks Tier two risks Tier three risks
Sample Questions for the Board of Trustees
Yes No Trustee Questions
Were any losses that occurred related to risks that have been identified? Are
the losses consistent in magnitude and frequency to the risk profile?
Did management tie revenues, losses, surprises and specific material events to
the presented risk profile?
Were the assumptions underlying our strategy effectively challenged and tested
against changes in the external environment?
Sample Questions for the Board of Trustees, cont.
Yes No Trustee Questions
Did management outline the processes used to develop the data and
information that relates strategy with identified risk?
Likelihood/Probability of Occurrence
Severity Level Probablity
>70% chance that the risk
HIGH
event will occur within the
H next year.
Between 30% and 70%
MEDIUM chance that the risk event
M will occur within the next
year.
<30% chance that the risk
LOW
event will occur within the
L next year.
Communication
• Each risk owner creates a project plan, including timelines
for mitigating that risk.
• The risk owner provides semi-annual progress updates on
risk mitigation projects.
• This information is provided to the Audit Committee of
the Board of Trustees.
Current Status List completed action items and project successes thus far.
Remaining Tasks List the remaining tasks/action items which are needed for the successful completion of the project.
“Meeting challenges gives rise
to opportunities.”
QUESTIONS