0% found this document useful (0 votes)
20 views42 pages

Advanced Risk Management Strategies

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views42 pages

Advanced Risk Management Strategies

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd

Developments Advanced in

Risk Analysis and Risk Management

Lori Brown, Seton Hall University


Robert Roach, New York University
Jean Demchak, Marsh
Program Speakers:
Lori Brown
Director of Compliance
& Risk Management
Seton Hall University
South Orange, NJ

Jean Demchak
Managing Director
Global Education Leader
Marsh, Inc.
New York, NY

Robert F. Roach
Chief Compliance Officer
New York University
New York, NY
“It wasn’t the risk we knew about that
concerned us, but the risks we were
unaware of that worried us the most”

Chris McAlary, VP Finance,


Mount St Mary’s College
Program Overview

1. Trends in risk management and impact of ERM on


credit ratings.

2. Developing an Institutional ERM program.

3. Practical Risk Management tools for Compliance


and ERM programs
Risk: Upside and Downside

All organizations face internal and external


factors that make it uncertain whether and
when they will meet their objectives.

The effect of this uncertainty on achieving


objectives is called risk.
Risk Management in Application

Risk Management principles can be applied to any type of


risk, whatever its nature, whether having positive or
negative consequences.

Compliance Programs:
Use Risk Management principles to help identify,
assess, evaluate, and treat ethical and regulatory risks.

Enterprise Risk Management (ERM):


Is a coordinated program applied throughout the
life of an organization and to a wide range of activities,
including strategies and decisions, operations, processes,
functions, projects, and services.
Risk Assessment and Management Process
1. Organizational Context: What are your organization’s objectives, structure and
operations?

2. Risk Identification: What are the possible risk events your organization faces?

3. Risk Assessment:
o What is the likelihood of the risk event happening?
o What is the potential impact of the risk event?

4. Risk Evaluation: Having assessed the risks:


o What is your organizations “appetite” for risk?
o what are the most important risks to address?

5. Risk Treatment: What steps must be taken to mitigate the risks Identified?

6. Monitoring, Review and Corrective Action,


o Are internal controls working effectively to mitigate risk?
o Is there any corrective action needed?

7. Communication: Throughout the Organization


Simple Risk Assessment Diagram
Identified Risks

Conflicts of Interest
Medicare/Medicaid
Billing
Time and Effort
Reporting
Tax Exempt Bonds
Executive Compensation
Record Retention
Export Controls
EEO/AA Laws
Risk Evaluation

Having assessed the risks:

o What are the most important risks to address?

o What is your organizations “appetite” for risk?


Risk Response

• Avoidance
• Reduction/Mitigation (Internal Controls)

• Sharing (e.g. Insurance)

• Acceptance
o Crisis Management Plans
o Business Continuity Plans
o Other Operational Plans
Control Activities
•Organizational/Process Controls
o E.g. Separation of Duties

•Documentation
o Written Policies and Procedures Essential

•Training

•Audit Trails
o Final Results should be traceable back to originating transactions

•Security and Integrity


o Access Controls
Strategic Risk Management: Expectations and Opportunities
Areas where senior management’s expectations of risk
management have grown
Integrate with operations
Execute day-to-day RM activities
efficiently
Improve quantification/analysis

Understanding of non-insurable risks

Increase involvement in strategic planning


Lead ERM activities

Work with lower headcount


Serve on RM committee

Increase use of technology


Risk Manager
C-Suite Understanding of RM ROI
Finance
Source: Excellence in Risk Management VIII 25% 50%
Strategic Risk Management:
Expectations and Opportunities
Key performance indicators (KPIs)

Manage RM value through TCOR

Competitive procurement of risk transfer


Financial measures for retained/insured
exposures
Insurance budget management

Mitigate liabilities/support preparedness

Align RM objectives with company risk tolerance


Primary KPIs
RM alignment with company goals Secondary
KPIs
Build strategic risk awareness across
organization Tertiary KPIs

Deliver successful claim results

Compliance

Source: Excellence in Risk Management VIII


Strategic Risk Management: Expectations and
Opportunities
Effectiveness of risk committees
How effective are cross- How could your firm’s cross-functional risk
functional risk committees? committee become more effective?

Consider risks more


strategically
8%
30% Disseminate information
more widely

Increase visibility of senior


62%
management support

Use a wider range


of analytics
Very effective Engage senior
Somewhat effective management to
communicate support
Not effective
Source: Excellence in Risk Management VIII
Strategic Risk Management: Expectations and Opportunities
Primary focus areas for developing RM capabilities

53%
Strengthen ERM 56%
45%
52%
Training/education 52%
62%
35%
Technology upgrades 36%
41%
32%
Current employees 39%
42%
20%
Restructure insurance programs 19%
29%

Source: Excellence in Risk Management VIII 2011 2010 2009


Strategic Risk Management: Expectations and Opportunities
Barriers to senior management’s understanding
of the risk landscape

Siloed approaches to RM 42%

Lack of awareness of ERM concepts 39%

Organizational structure 34%

Inadequate RM representation at
31%
Board/C-suite level

Lack of relevant risk data 31%

Inadequate link to strategies 27%

Demonstrating value of ERM 27%

Source: Excellence in Risk Management VIII


Strategic Risk Management: Expectations and Opportunities
Top Ten Risks
Risk Managers
Rank C-suite Rank Finance Rank
` Company’s Top Risks (Readiness*) (Readiness*) (Readiness*)
1 Economic conditions 1 (30%) 1 (26%) 5 (31%)
2 Business disruption 2 (76%) 3 (58%) 1 (63%)
3 Reg. /Compliance 3 (60%) 5 (59%) 3 (62%)
4 Legal or reg. shifts 4 (44%) 2 (47%) 6 (53%)
5 Litigation or claims 6 (70%) 5 (63%) 9 (56%)
6 Tech. / systems failure 7 (63%) 11 (65%) 3 (60%)
7 Brand / reputation 5 (44%) 8 (51%) 12 (35%)
8 Data sec. / breach 9 (65%) 7 (60%) 8 (53%)
9 Physical resources 8 (80%) 20 (61%) 2 (73%)
10 Business continuity 10 (67%) 13 (64%) 17 (58%)
* Percent of respondents with management plan in place or recent review undertaken of the risk
Source: Excellence in Risk Management VIII
What is ERM
And Why Does it Matter to
Higher Education?
Definition of Enterprise Risk Management (ERM)
A structured, consistent, and continuous risk management process
applied across the entire organization that brings value by:
1. Proactively identifying, assessing, and prioritizing material
risks
2. Developing and deploying effective mitigation strategies

3. Aligning with strategic objectives and administrative


processes
4. Embedding key components into the organization’s culture:

1. Risk ownership, governance, and oversight

2. Reporting and communications

3. Leveraging technology and tools

5. S&P incorporating ERM reference into industry credit rating


reports
The Four Quadrants of Risk
Sample Enterprise Risk Issues in
Higher Education
Higher educ ation Enterprise risk inventory 1
Teaching and External
Students Faculty Alumni
Student Life Stakeholders
• Student satisfaction/preferences • Attract and retain faculty • Corporate/institutional alliances
• Inter-class relations • Tenure policies • Alumni relations • Community outreach
• Housing • Curricula/program design • Endowment • Endowment
• Athletics • Research & development • Donations • Donations
• Admissions policy • Intellectual property
• Recruitment • Fraudulent research
• Retention • Fraudulent credentials
• Greek life/Student life
• Student welfare Research & development programs Brand/reputation
• Student judiciary
Athletic rankings Academic rankings

 Employment  Faculty/tenure  Performance  Employee  Compensation  Workforce  Hiring and


Human Capital
practices succession planning incentives stress/ burnout  Unionization productivity retention

 Tuition rates/  Cost of capital/  Expansion capital  Pension fund  Risk financing  Litigation  Endowment
Finance tuition stability interest rate fluctuations  Claim reserve 
liability
 Conflict of interest  Employee fraud  Ethical decision-  Illegal acts  Management  Third party fraud  Unauthorized
Integrity making fraud acts

 Athletics  Field courses Faculty bookings  Regulatory  Failure to educate  Vendor alliances
Process  Business  Student activities Infrastructural renewal compliance  Licensing  Contract commitment
interruption and capacity
 Reputation/  Foreign expansion  Product and delivery  Corporate/  Planning  Resource
Strategy branding  Admissions policy model institutional  Intellectual allocation
 Marketing  Outsourcing alliances property  Technology transfer

Information  Access  Availability  Technological  Data integrity  e-Commerce  Infrastructure  Relevance


Technology  Privacy capacity  Internet security  Reliability

Environmental  Environmental  Visitors and contractors  Illness/injury to faculty,  Natural  Campus security  Special events  Student/faculty
Health/Safety compliance students or staff hazards travel

 Demographics  Competition  Economy  Social responsibility


External

This inventory does not capture the risks associated with a university medical center
1

Copyright © 2006 Mercer Oliver Wyman NYC-MOW171ERC-027 16


ERM Compliance Factors: Commentary
• Compliance and ethics oversight has traditionally been the
responsibility of an institution’s legal department

• Risk management procedures of institutions are under


increasing regulatory and private scrutiny

• There has been a shift from a defensive function focused on


policies, procedures and expenditures, to a strategic
function focused on optimizing resource allocation and
effectiveness

• Recent mandates and guidelines are fueling the momentum


ERM Compliance Factors: Current and
Emerging Standards and Guidelines

GUIDELINES & BEST PRACTICES:

• Committee of Sponsoring Organizations of the


Treadway Commission’s (COSO) ERM Framework

• Standard & Poor's (S&P) ERM Ratings Criteria for Non-


Financial Organizations

• ISO31000

EMERGING REGULATIONS & GUIDELINES:

• Accreditation requirements?
ERM Guidelines and Best Practices:
Overview of S&P’s ERM Ratings Criteria

Emerging Risk Strategic Risk


Culture Risk Controls
Preparation Management

 Organizational  Risk identification,  Environmental  Utilization of risk


structure measurement and scanning, management and
monitoring trending, stress return on risk in
 Risk management testing, strategic decision
staff roles and  Risk limit contingency making
accountability application and planning and other
enforcement pre-loss practices  Risk consideration
 Risk within capital
communication  Risk control  Expectation budgeting and
(internal and processes— planning for allocation,
external) policies, negative events performance
infrastructure, pre and post-loss measurement and
methodology (PIM) performance other
administrative
 Sector and firm- practices
specific risk
control criteria
ERM Guidelines and Best Practices: ISO 31000

6.3 Establishing the


context

6.4 Risk Assessment


• ISO 31000 Risk
6.4.2. Risk Management Standard
Identification follows the Australian /
6.2
6.6
Communicati
Monitoring New Zealand Standard
on & 6.4.3. Risk
analysis & Review
Consultation
• Released in late 2009
6.4.4 Risk
evaluation
• No current certification
6.5 Risk treatment
standard, but it may follow

Source: International Organization for


Standardization
ERM Compliance Factors:
Common Elements of ERM Frameworks
• They outline a process for ERM implementation that includes:

– Risk identification and assessment

– Risk prioritization

– Risk solution design and implementation

– Routine monitoring and reporting

– Communication

• They recognize that good risk management must be embedded into the
organization’s day to day activities

• They consider both the ‘upside’ and ‘downside’ of risk

• They are not one size fits all


How to Initiate an ERM
Program
Building Senior-Level Support

• Elements of an ERM Value Proposition:

– Optimal capital deployment

– Continued or improved rating agency confidence

– Effective critical event response

– Better decision making relative to risks assumed

– Enhanced stewardship and governance


Developing the Team/Structure
Risk
Board of Trustees Reports

President/Senior Leadership
Internal audit
Risk Management Committee
Risk
Reports
Finance/ Select
Ext Risk
Provost Legal/
HR Affairs Deans Mgr

?
RM
Compliance
Audit

ERM functional representation, risk management activity support and shared services
College College College
Dept A Dept B Dept C
A B C

Risk information and root data, issues management


Understanding Where You Want to Go…
Critical success factors
• Establish the right vision and realistic plan
• Obtain senior leadership buy-in and direction
• Align with mission and strategic objectives
• Attack silos at the onset
• Set objectives / performance / early warning indicators
• Stay focused on results
• Communicate vision and key outcomes
• Develop a sustainable process vs. a one-time a project
…Then Making It Happen

1 2 3
Assess the Envision the Implement
Current State Future State ERM

 Risk Identification,  Governance &  Implement Risk Solutions


Assessment & Accountability  ERM Integration with:
Prioritization  Reporting  Routine Processes
 Risk Mitigation &  Strategy  Strategic Plan
Controls
 Policies, Processes  Organizational
 Risk Management
& Procedures
Infrastructure Culture
 Technology &
Systems
 Culture
Keep in Mind ERM is a Journey - Not a
HIGH
Destination
Link to Strategy and Stakeholder Value

Value Creation &


Risk Optimization
• Embed risk management
into strategic planning
• Monitor risks with early
warning risk indicators
• Link risks to stakeholder
Risk Management value
Integration • Drive sustainable
• Implement a fully performance
integrated ERM structure
based on a framework
Enterprise Risk • Monitor & report on risks
Awareness through the enterprise
Risk Specialization • Adopt an ERM framework • Coordinate ERM activities
• Isolated and independent • Assign executive
risk management ownership of risk
activities, management
• Limited focus on the • Conduct routine risk
linkage between assessments
enterprise-wide risks and
strategies

LOW
Insurance & Compliance Core ERM Practices Risk-Reward Optimization

Risk Management Philosophy


A Few Practical Tools and
Deliverables
Sample Risk Map
Key risks
High
1. Intellectual Property
2. Greek Life
3 3. Pension Funding
1 4 - Illustration - 4. Succession Planning
5. Student Safety
2 5 14
6 6. Economy
9
7 7. Alumni Relations
8 11 13 15 8. Faculty Retention
12
Likelihood

10 17 9. Tuition Rate
Medium
10. Athletics
16 19
18 11. Research Compliance
12. Community Relations
13. Information Technology
14. Delivery Channel
15. Demographics
16. Operating Model
17. Research Grants
18. Endowment
Low
Performance
Very Low Low Moderate Major Catastrophic 19. Privacy
Impact
Tier one risks Tier two risks Tier three risks
Sample Questions for the Board of Trustees
Yes No Trustee Questions

Did we receive material which adequately distilled vast quantities of risk


information into prioritized, actionable summaries?

Were the risks associated with key departments presented in a comprehensive,


holistic manner?

Were any losses that occurred related to risks that have been identified? Are
the losses consistent in magnitude and frequency to the risk profile?

Did management tie revenues, losses, surprises and specific material events to
the presented risk profile?

Did management outline strategy altering scenarios? For example, could


multiple problems arise simultaneously or sequentially (the “perfect storm”)?

Was management forthcoming about any differences among senior leadership


regarding material strategic recommendations and decisions?

Were the assumptions underlying our strategy effectively challenged and tested
against changes in the external environment?
Sample Questions for the Board of Trustees, cont.
Yes No Trustee Questions

Did management outline the processes used to develop the data and
information that relates strategy with identified risk?

Do we have a common understanding of the types of triggers that bring an


issue to our attention?

Were we provided with an understanding of what capabilities are required to


address the institution’s risks? Were capability gaps identified?

Do we have a common understanding among management and the board


about the roles, responsibilities, and accountabilities relative to risk oversight?

Did we discuss the details of risk appetite with management?

Do we need a chief risk officer (CRO) or a similar resource?

Do we have the appropriate committee structure and reporting lines to ensure


we meet our risk oversight obligations?

Do we have sufficient personnel (including advisors) and financial resources in


place to enable us to fulfill risk engagement responsibilities?
Risk Identification

• Initial interview with Risk Owner


– What issues/areas of concern that keep them up at
night?
– What is the probability of occurrence, when taking into
account controls already in place?
– Risk owner impression of impact level.

• Create a basic risk register. Focus on high


probability and high impact risks.
Probability of
Occurrence
Person Affect On Other
Risk Owner Department Area of Concern Issues H = >70% Impact
Interviewed Departments
M = 30-70%
L = <30%
Arthur Anderson LLP v. United States

• US Supreme Court recognized the legitimacy of managing and


systematically disposing of records in accordance pursuant to a
records retention policy

• The Supreme Court held:

“Document retention policies,’ which are created in part to


keep certain information from getting into the hands of
others, including the Government, are common in
business. It is, of course, not wrongful for a manager to
instruct his employees to comply with a valid document
retention policy under ordinary circumstances.”*

*544 U.S. 696, 704 (2005)


Likelihood of Occurrence**
Indicative Frequency
Level Descriptor Description
(expected to occur)
Very Rare Heard of something like this Once every thirty years.
1 occuring elsewhere.
Unlikely Low likelihood of the event Once every three to ten
2 happening. The event does occur years.
somewhere from time to time.
Possible Medium likelihood of the event Once every three years.
happening. The event has
3 occurred at least once in your
career.
Likely The event has occurred several Once every year or less.
4 times or more in your career.
Almost certain High likelihood of the event More than once a year.
5 happening. The event has
occurred in the last six months.
**NOTE:
Please rate the likelihood of the event occuring AFTER taking into account
the adequacy of existing controls

Likelihood/Probability of Occurrence
Severity Level Probablity
>70% chance that the risk
HIGH
event will occur within the
H next year.
Between 30% and 70%
MEDIUM chance that the risk event
M will occur within the next
year.
<30% chance that the risk
LOW
event will occur within the
L next year.
Communication
• Each risk owner creates a project plan, including timelines
for mitigating that risk.
• The risk owner provides semi-annual progress updates on
risk mitigation projects.
• This information is provided to the Audit Committee of
the Board of Trustees.

1. General Project Information


Project Title:
Project Sponsor/Department:
Project Summary:
2. Project Update

Current Status List completed action items and project successes thus far.

Remaining Tasks List the remaining tasks/action items which are needed for the successful completion of the project.
“Meeting challenges gives rise
to opportunities.”
QUESTIONS

You might also like