SlideShare a Scribd company logo
1 of 32
Download to read offline
Embedding RCSA into Strategic Planning
and Business Strategy
Operatiivisten Riskien Hallinta, Helsinki, Finland
Andrew Smart, Ascendore
Post credit crunch, financial services firms are drowning
under a tsunami of regulatory change, cost and complexity
2
Run the Bank
£200bn
plus fines
492%
Annual increase
regulatory change
3
The cost & complexity
of operational risk &
compliance is too high
and there is a
“disproportionate risk
aversion creeping into
decision-making”
Chairman, HBSC, 2015
Accenture Risk Study, 2017
Boards and executives should be able to answer these
questions with confidence.
4
Are we in control?
Are we going to
deliver our strategy?
Are we operating
within appetite?
RCSA - an essential part of an integrated framework
Better Conversation
Better Decisions
Better Action-taking
Better Results
Risk & Control Self-
Assessment (RCSA) processes
and data should be an essential part of
an integrated Strategy & Risk
Management framework; an integral
part of enterprise management
reporting.
5
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
6
7
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
Compliance Enablers
Over the long-term, where are we going and
how will we get there?
Critical few things from the business model
that enable the delivery of the strategy
To deliver our long-term strategy what is the
focus over the next 12-24 months?
Where do we need to excel day-to-day
What are the ‘rules’ that define our operating
environment?
Risk Appetite defines the boundaries for
risk-takingStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
RISK THRESHOLDS
RISK EXPOSURES
Compliance Enablers
8
Manage threats & opportunities via the risk
taxonomyStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL RISK
COMPLIANCE RISK
Compliance Enablers
9
Managed at every level in the framework
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
StrategicRisk
Execution
Risk
Compliance
Risk
APPETITE
ALIGNMENT
ACCOUNTABILITY
ALIGNMENT
CASCADE
ASSESSMENT
MEASUREMENT
ACTION-TAKING
Operational
Risk
Compliance Enablers
10
The RACI framework is a proven approach to embedding accountability and
clarification of roles in decision-making. Supports the 3 Lines of Defence
InformResponsible(s)Accountable Consult
11
How do your operational and
regulatory enablers relate to
strategy?
Alignment mapping can identify gaps; areas
where your strategy is not supported or where
operational resources are been wasted.
Regulatory rules mapping provide assurance
that processes and initiatives are in place to
meet regulatory obligations and identify gaps;
where are the gaps or weaknesses in our
regulatory response landscape?
12
Key ControlsKey RisksObjectiveEntity
Processes
Initiatives
Technology
How does strategy & risk
cascade through the firm?
Board & Senior Management assurance is
enhanced by understanding the cascading of
objectives & risks through the firm.
Identify gaps in consolidated reporting by
linking objectives, risks and controls in ‘cascade
chains’ through the firm. Where does the chain
break?
13
Key Risk
(Strategic Risk)
Corporate
Division
Department
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Data points to inform your Risk Self-
Assessments
14
MAXIMUM
INHERENT
RESIDUAL
% $£€
IMPACT(S) LIKELIHOOD EXPOSURE
DRIVERS
use driver(s) as the basis for assessing impacts thus linking risk
back to strategy
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
KRIs
Losses / Near Misses
Expert Judgement
Scenarios & Models
Related KPIs & KCIs
Control Self Assessment
Data points to inform your Control
Self-Assessments
15
KCIs
Losses / Near Misses
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
Control Testing
Related KPIs & KRIs
DESIGN PERFORMANCE
CONTROL
EFFECTIVENESS
Three types of related
indicators to give a full picture
RAG is common practice
RAGAR is best practice
16
Key Performance Indicators (KPIs)
Used to define performance thresholds and
targets; and to monitor progress towards achieving
these targets.
Key Risk Indicators (KRIs)
Used to define risk thresholds and targets; to
monitor changes within the risk environment.
Key Control Indicators (KCIs)
Used to define control thresholds and targets; to
monitor changes within the controls environment.
BASELINE
LT 1
LT 2
UT2
UT 1
TARGET
T 2
T 1
Assessment and measurement
is not enough.
Action-taking is critical in
driving performance &
managing risk
Typically we think about two
types of actions
17
Improvement Actions
Audit Actions
Tools to bring it all together
18
Better
Action-
taking
Better
Decisions
Better
Results
Strategy
Map
Better
Conversations
Appetite
Alignment
Matrix
Risk
Appetite
Risk Map
Map Business Objectives & their
causal relationship to improve the
communication, monitoring and
management of strategic and
operational performance.
19
Define risk tolerances across the
framework reflecting the
materiality of the business unit.
Use Drivers to link RCSA back to
Strategy.
20
The Risk Map provides a visual
overview of the risk profile and
make it easy to identify potential
risk issues.
Four perspectives risk map is
aligned to the Strategy Map.
21
Starting with Strategic Drivers,
define Risk Appetite across the
framework, reflecting the
materiality and strategic intent of
the business unit.
22
The Appetite Alignment Matrix
visualise the alignment of risk-
taking to risk appetite showing
where the firm is aligned, over-
exposed and under-exposed.
23
Are we operating within appetite?
24
Appetite, Performance, Risk and Controls
Effectiveness should be assessed,
measured and aligned across the
organisational hierarchy and within the
taxonomy within the framework.
25
STRATEGY
typically strategy is cascaded top-down
DATA
typically data flows up the organization
EXECUTION
typically execution is driven from the middle
Corporate
Divisions
Departments
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL &
COMPLIANCE RISK
26
STRATEGY MAP
Are we on track to deliver the
strategy?
APPETITE ALIGNMENT MATRIX
Are we operating within
appetite?
RISK APPETITE
How much risk is acceptable?
RISK MAP
What level of risk are we taking?
Benefits of Improved
Strategic Execution
▪ A growth in shareholder value of 150%,
driven by a 180% growth in profits and a
120% growth in revenue
▪ A 50% improvement in customer
satisfaction
▪ A 50% improvement in key process
effectiveness
▪ A 25% improvement in employee
satisfaction, leading to a 50% reduction
in employee turnover
Benefits of an
Integrated approach
▪ Transformed our approach to risk and
regulatory compliance over 12-month
▪ Reduce the value of our operational
losses by 94%, the volume by 63% and
our economic capital provision by 23%”
▪ Eliminate 11 spreadsheet systems
▪ Enabled us to secure a 3% regulatory
capital release and reduce our cost of
capital significantly
27
Benefits of Enterprise
Risk Management
▪ Increasing the range of opportunities
▪ Identifying and managing risk entity-
wide
▪ Increasing positive outcomes and
advantage while reducing negative
surprises
▪ Reducing performance variability
▪ Improving resource deployment
▪ Enhancing enterprise resilience
Results based on 3 year performance of BSC Hall of Frame
winners
COSO ERM Framework, 2017 Example benefits reported by Ascendore customers
Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in
firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent"
or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
We believe that risk management and compliance must enable strategy
execution and value creation, not simply tick regulatory boxes.
28
“we have reduced our Pillar 2 capital by
81.2% while delivering a 94% reduction
in the value of errors and a 63%
reduction in the volume of errors”
Head of Enterprise Risk, Homeloan Management Limited
We provide Integrated GRC
(Governance, Risk and Compliance)
solutions to financial services firms
and their regulators built on familiar,
everyday office tools; SharePoint,
Office 365 & the Cloud.
COSO ERM Framework 2017 Risk-Based Performance
Management
29
What is Risk-Based Performance Management?
Enhance Shareholder value
Control Cost & Complexity
Drive Accountability
Align the firm
Risk-Based Performance
Management (RBPM) is an
strategic execution approach which
integrates business strategy, risk
appetite, performance management
and risk management.
30
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
31
Embedding RCSA into Strategic Planning
and Business Strategy?
Andrew Smart
Ascendore

More Related Content

What's hot

Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceResolver Inc.
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk ManagementAsad Hameed
 
Risk Management ERM Presentation
Risk Management ERM PresentationRisk Management ERM Presentation
Risk Management ERM Presentationalygale
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityJeff B
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONFrackson Kathibula-Nyoni
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Diane Christina
 
Operational risk management and measurement
Operational risk management and measurementOperational risk management and measurement
Operational risk management and measurementRahmat Mulyana
 
Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk ManagementAndrew Smart
 
Risk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling TechniquesRisk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling TechniquesManoj Agarwal
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management FrameworkTreasury Consulting LLP
 
Operational Risk Management under BASEL era
Operational Risk Management under BASEL eraOperational Risk Management under BASEL era
Operational Risk Management under BASEL eraTreat Risk
 
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...Eric Campbell
 
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksInternational Federation of Accountants
 
Risk Management Lifecycle PowerPoint Presentation Slides
Risk Management Lifecycle PowerPoint Presentation Slides Risk Management Lifecycle PowerPoint Presentation Slides
Risk Management Lifecycle PowerPoint Presentation Slides SlideTeam
 

What's hot (20)

Key risk indicators shareslide
Key risk indicators shareslideKey risk indicators shareslide
Key risk indicators shareslide
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
 
Risk Management ERM Presentation
Risk Management ERM PresentationRisk Management ERM Presentation
Risk Management ERM Presentation
 
Risk appetite
Risk appetite Risk appetite
Risk appetite
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and Sustainability
 
Coso erm
Coso ermCoso erm
Coso erm
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
Operational risk management and measurement
Operational risk management and measurementOperational risk management and measurement
Operational risk management and measurement
 
Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk Management
 
Risk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling TechniquesRisk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling Techniques
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
Operational Risk Management under BASEL era
Operational Risk Management under BASEL eraOperational Risk Management under BASEL era
Operational Risk Management under BASEL era
 
Coso erm
Coso ermCoso erm
Coso erm
 
KRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & ITKRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & IT
 
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
 
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
 
Risk Management Lifecycle PowerPoint Presentation Slides
Risk Management Lifecycle PowerPoint Presentation Slides Risk Management Lifecycle PowerPoint Presentation Slides
Risk Management Lifecycle PowerPoint Presentation Slides
 

Similar to Embedding RCSA into Strategic Planning and Business Strategy

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxmadlynplamondon
 
Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Andrew Smart
 
Operational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningOperational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningEneni Oduwole
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Andrew Smart
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guideCenapSerdarolu
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guideAstalapulosListestos
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxmanjujayakumar2
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct RiskAndrew Smart
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerTanaMaeskm
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488Ashwin Kumar
 
StrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingStrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingNathan Ives
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...PMI Indonesia Chapter
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk TransferCBIZ, Inc.
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementpeterObakozuwa
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy PresentationDavid Fernandes
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__susanta subudhi
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__susanta subudhi
 
Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Andrew Smart
 

Similar to Embedding RCSA into Strategic Planning and Business Strategy (20)

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
 
Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.
 
Operational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningOperational Risk Management & Strategic Planning
Operational Risk Management & Strategic Planning
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptx
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
 
StrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingStrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance Mapping
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk Transfer
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy Presentation
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
HIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINALHIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINAL
 
Governance-design
Governance-designGovernance-design
Governance-design
 
Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Strategically+Speaking+October+2015
Strategically+Speaking+October+2015
 

More from Andrew Smart

FMM&A15-StratexSystems
FMM&A15-StratexSystemsFMM&A15-StratexSystems
FMM&A15-StratexSystemsAndrew Smart
 
StratexSystems_270115
StratexSystems_270115StratexSystems_270115
StratexSystems_270115Andrew Smart
 
Cyber Risk Management
Cyber Risk Management Cyber Risk Management
Cyber Risk Management Andrew Smart
 
Managing Information Risk in Financial Services
Managing Information Risk in Financial Services Managing Information Risk in Financial Services
Managing Information Risk in Financial Services Andrew Smart
 
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk ManagementStrategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk ManagementAndrew Smart
 
Making Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As UsualMaking Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As UsualAndrew Smart
 
Governance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational RiskGovernance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational RiskAndrew Smart
 
StratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro VideoStratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro VideoAndrew Smart
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct RiskAndrew Smart
 
Middle east insurance market
Middle east insurance marketMiddle east insurance market
Middle east insurance marketAndrew Smart
 
Amnded stratexpoint screens1
Amnded stratexpoint screens1Amnded stratexpoint screens1
Amnded stratexpoint screens1Andrew Smart
 
HML Risk Transformation
HML Risk TransformationHML Risk Transformation
HML Risk TransformationAndrew Smart
 
Greater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperGreater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperAndrew Smart
 
Manigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy ProcessManigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy ProcessAndrew Smart
 
Manigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureManigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureAndrew Smart
 

More from Andrew Smart (15)

FMM&A15-StratexSystems
FMM&A15-StratexSystemsFMM&A15-StratexSystems
FMM&A15-StratexSystems
 
StratexSystems_270115
StratexSystems_270115StratexSystems_270115
StratexSystems_270115
 
Cyber Risk Management
Cyber Risk Management Cyber Risk Management
Cyber Risk Management
 
Managing Information Risk in Financial Services
Managing Information Risk in Financial Services Managing Information Risk in Financial Services
Managing Information Risk in Financial Services
 
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk ManagementStrategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
 
Making Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As UsualMaking Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As Usual
 
Governance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational RiskGovernance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational Risk
 
StratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro VideoStratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro Video
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
 
Middle east insurance market
Middle east insurance marketMiddle east insurance market
Middle east insurance market
 
Amnded stratexpoint screens1
Amnded stratexpoint screens1Amnded stratexpoint screens1
Amnded stratexpoint screens1
 
HML Risk Transformation
HML Risk TransformationHML Risk Transformation
HML Risk Transformation
 
Greater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperGreater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service Whitepaper
 
Manigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy ProcessManigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy Process
 
Manigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureManigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And Exposure
 

Recently uploaded

Unveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic ExperiencesUnveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic ExperiencesDoe Paoro
 
digital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingdigital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingrajputmeenakshi733
 
Entrepreneurship lessons in Philippines
Entrepreneurship lessons in  PhilippinesEntrepreneurship lessons in  Philippines
Entrepreneurship lessons in PhilippinesDavidSamuel525586
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...Operational Excellence Consulting
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckHajeJanKamps
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024Adnet Communications
 
Healthcare Feb. & Mar. Healthcare Newsletter
Healthcare Feb. & Mar. Healthcare NewsletterHealthcare Feb. & Mar. Healthcare Newsletter
Healthcare Feb. & Mar. Healthcare NewsletterJamesConcepcion7
 
Introducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsIntroducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsKnowledgeSeed
 
Planetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in LifePlanetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in LifeBhavana Pujan Kendra
 
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfGUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfDanny Diep To
 
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxRakhi Bazaar
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Americas Got Grants
 
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryEffective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryWhittensFineJewelry1
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsIndiaMART InterMESH Limited
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxmbikashkanyari
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environmentelijahj01012
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
Driving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon HarmerDriving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon HarmerAggregage
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...ssuserf63bd7
 

Recently uploaded (20)

Unveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic ExperiencesUnveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic Experiences
 
digital marketing , introduction of digital marketing
digital marketing , introduction of digital marketingdigital marketing , introduction of digital marketing
digital marketing , introduction of digital marketing
 
Entrepreneurship lessons in Philippines
Entrepreneurship lessons in  PhilippinesEntrepreneurship lessons in  Philippines
Entrepreneurship lessons in Philippines
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deck
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024
 
Healthcare Feb. & Mar. Healthcare Newsletter
Healthcare Feb. & Mar. Healthcare NewsletterHealthcare Feb. & Mar. Healthcare Newsletter
Healthcare Feb. & Mar. Healthcare Newsletter
 
Introducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsIntroducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applications
 
Planetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in LifePlanetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in Life
 
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfGUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
 
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptxThe Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
 
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...
 
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryEffective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan Dynamics
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environment
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors Data
 
Driving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon HarmerDriving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon Harmer
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
 

Embedding RCSA into Strategic Planning and Business Strategy

  • 1. Embedding RCSA into Strategic Planning and Business Strategy Operatiivisten Riskien Hallinta, Helsinki, Finland Andrew Smart, Ascendore
  • 2. Post credit crunch, financial services firms are drowning under a tsunami of regulatory change, cost and complexity 2 Run the Bank £200bn plus fines 492% Annual increase regulatory change
  • 3. 3 The cost & complexity of operational risk & compliance is too high and there is a “disproportionate risk aversion creeping into decision-making” Chairman, HBSC, 2015 Accenture Risk Study, 2017
  • 4. Boards and executives should be able to answer these questions with confidence. 4 Are we in control? Are we going to deliver our strategy? Are we operating within appetite?
  • 5. RCSA - an essential part of an integrated framework Better Conversation Better Decisions Better Action-taking Better Results Risk & Control Self- Assessment (RCSA) processes and data should be an essential part of an integrated Strategy & Risk Management framework; an integral part of enterprise management reporting. 5
  • 6. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 6
  • 7. 7 Strategy Strategic Drivers Business Objectives Operational Enablers Compliance Enablers Over the long-term, where are we going and how will we get there? Critical few things from the business model that enable the delivery of the strategy To deliver our long-term strategy what is the focus over the next 12-24 months? Where do we need to excel day-to-day What are the ‘rules’ that define our operating environment?
  • 8. Risk Appetite defines the boundaries for risk-takingStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT RISK THRESHOLDS RISK EXPOSURES Compliance Enablers 8
  • 9. Manage threats & opportunities via the risk taxonomyStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT STRATEGIC RISK EXECUTION RISK OPERATIONAL RISK COMPLIANCE RISK Compliance Enablers 9
  • 10. Managed at every level in the framework Strategy Strategic Drivers Business Objectives Operational Enablers StrategicRisk Execution Risk Compliance Risk APPETITE ALIGNMENT ACCOUNTABILITY ALIGNMENT CASCADE ASSESSMENT MEASUREMENT ACTION-TAKING Operational Risk Compliance Enablers 10
  • 11. The RACI framework is a proven approach to embedding accountability and clarification of roles in decision-making. Supports the 3 Lines of Defence InformResponsible(s)Accountable Consult 11
  • 12. How do your operational and regulatory enablers relate to strategy? Alignment mapping can identify gaps; areas where your strategy is not supported or where operational resources are been wasted. Regulatory rules mapping provide assurance that processes and initiatives are in place to meet regulatory obligations and identify gaps; where are the gaps or weaknesses in our regulatory response landscape? 12 Key ControlsKey RisksObjectiveEntity Processes Initiatives Technology
  • 13. How does strategy & risk cascade through the firm? Board & Senior Management assurance is enhanced by understanding the cascading of objectives & risks through the firm. Identify gaps in consolidated reporting by linking objectives, risks and controls in ‘cascade chains’ through the firm. Where does the chain break? 13 Key Risk (Strategic Risk) Corporate Division Department Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk)
  • 14. Data points to inform your Risk Self- Assessments 14 MAXIMUM INHERENT RESIDUAL % $£€ IMPACT(S) LIKELIHOOD EXPOSURE DRIVERS use driver(s) as the basis for assessing impacts thus linking risk back to strategy ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. KRIs Losses / Near Misses Expert Judgement Scenarios & Models Related KPIs & KCIs Control Self Assessment
  • 15. Data points to inform your Control Self-Assessments 15 KCIs Losses / Near Misses ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. Control Testing Related KPIs & KRIs DESIGN PERFORMANCE CONTROL EFFECTIVENESS
  • 16. Three types of related indicators to give a full picture RAG is common practice RAGAR is best practice 16 Key Performance Indicators (KPIs) Used to define performance thresholds and targets; and to monitor progress towards achieving these targets. Key Risk Indicators (KRIs) Used to define risk thresholds and targets; to monitor changes within the risk environment. Key Control Indicators (KCIs) Used to define control thresholds and targets; to monitor changes within the controls environment. BASELINE LT 1 LT 2 UT2 UT 1 TARGET T 2 T 1
  • 17. Assessment and measurement is not enough. Action-taking is critical in driving performance & managing risk Typically we think about two types of actions 17 Improvement Actions Audit Actions
  • 18. Tools to bring it all together 18 Better Action- taking Better Decisions Better Results Strategy Map Better Conversations Appetite Alignment Matrix Risk Appetite Risk Map
  • 19. Map Business Objectives & their causal relationship to improve the communication, monitoring and management of strategic and operational performance. 19
  • 20. Define risk tolerances across the framework reflecting the materiality of the business unit. Use Drivers to link RCSA back to Strategy. 20
  • 21. The Risk Map provides a visual overview of the risk profile and make it easy to identify potential risk issues. Four perspectives risk map is aligned to the Strategy Map. 21
  • 22. Starting with Strategic Drivers, define Risk Appetite across the framework, reflecting the materiality and strategic intent of the business unit. 22
  • 23. The Appetite Alignment Matrix visualise the alignment of risk- taking to risk appetite showing where the firm is aligned, over- exposed and under-exposed. 23
  • 24. Are we operating within appetite? 24
  • 25. Appetite, Performance, Risk and Controls Effectiveness should be assessed, measured and aligned across the organisational hierarchy and within the taxonomy within the framework. 25 STRATEGY typically strategy is cascaded top-down DATA typically data flows up the organization EXECUTION typically execution is driven from the middle Corporate Divisions Departments STRATEGIC RISK EXECUTION RISK OPERATIONAL & COMPLIANCE RISK
  • 26. 26 STRATEGY MAP Are we on track to deliver the strategy? APPETITE ALIGNMENT MATRIX Are we operating within appetite? RISK APPETITE How much risk is acceptable? RISK MAP What level of risk are we taking?
  • 27. Benefits of Improved Strategic Execution ▪ A growth in shareholder value of 150%, driven by a 180% growth in profits and a 120% growth in revenue ▪ A 50% improvement in customer satisfaction ▪ A 50% improvement in key process effectiveness ▪ A 25% improvement in employee satisfaction, leading to a 50% reduction in employee turnover Benefits of an Integrated approach ▪ Transformed our approach to risk and regulatory compliance over 12-month ▪ Reduce the value of our operational losses by 94%, the volume by 63% and our economic capital provision by 23%” ▪ Eliminate 11 spreadsheet systems ▪ Enabled us to secure a 3% regulatory capital release and reduce our cost of capital significantly 27 Benefits of Enterprise Risk Management ▪ Increasing the range of opportunities ▪ Identifying and managing risk entity- wide ▪ Increasing positive outcomes and advantage while reducing negative surprises ▪ Reducing performance variability ▪ Improving resource deployment ▪ Enhancing enterprise resilience Results based on 3 year performance of BSC Hall of Frame winners COSO ERM Framework, 2017 Example benefits reported by Ascendore customers Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent" or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
  • 28. We believe that risk management and compliance must enable strategy execution and value creation, not simply tick regulatory boxes. 28 “we have reduced our Pillar 2 capital by 81.2% while delivering a 94% reduction in the value of errors and a 63% reduction in the volume of errors” Head of Enterprise Risk, Homeloan Management Limited We provide Integrated GRC (Governance, Risk and Compliance) solutions to financial services firms and their regulators built on familiar, everyday office tools; SharePoint, Office 365 & the Cloud.
  • 29. COSO ERM Framework 2017 Risk-Based Performance Management 29
  • 30. What is Risk-Based Performance Management? Enhance Shareholder value Control Cost & Complexity Drive Accountability Align the firm Risk-Based Performance Management (RBPM) is an strategic execution approach which integrates business strategy, risk appetite, performance management and risk management. 30
  • 31. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 31
  • 32. Embedding RCSA into Strategic Planning and Business Strategy? Andrew Smart Ascendore