SlideShare a Scribd company logo
1 of 39
Establishing Key Risk Indicators for IT

July 31, 2012


 Maximo Neira Schliemann                         Ravi Mishra
 Founder & Partner at Beyond Economics &         Manager Product Marketing - IT GRC Solutions
 Former CIO Ros Casares Corporation in Spain &   MetricStream
 Member of the CIO office at Baxter

© 2012 MetricStream, Inc. All Rights Reserved.
Agenda


          • What are KRIs and how they differ from KPI and KCI?

          • Why is KRIs important to your IT?

          • Selecting the right set of KRIs for your IT organization

          • Leverage KRIs for effective IT Risk Management and improving

                business performance




© 2012 MetricStream, Inc. All Rights Reserved.
THE ENDLESS POSSIBILITIES
  OF REPUTATION, RISK &
  DESIGN IN BUSINESS.

  KRIs, KPIs & IT



Maximo Neira Schliemann
maxneira@beyondeconomics.es
@neiraschliemann
July 31st, 2012
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




Whether you love or hate them, it is hard to
dispute the popularity and mystique of fortune
cookies in their reputed ability to predict the
future…




                                                   “Your life will prosper only if you see and
                                                   acknowledge your faults, and work to reduce
                                                   them...”
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




What are KRIs?

How do they differ from KPIs?

Why are KRIs important for IT?

How to select the right KRIs?

How to leverage from KRIs?
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




“key risk indicators (KRIs) are
metrics or pieces of data serving
as ‘early warning indicators’ of
increased risk exposure in various
areas of the enterprise.”
                                              COSO, 2010




                                  Algorithmic & Heuristic
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




“Key Performance Indicators
(KPIs) are designed to provide a
high-level overview of the past
performance of the organization
and its major operating units,
often focused almost exclusively
on historical data.”
                                              COSO, 2010




Algorithmic
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




             KPIs                                          KRIs




                                                                           External
                                                                          GeoPolitical
                                                                  External
                                                                   Social
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT


                                                           Algorithmic
                                                                simple




                                                             COSO, 2010
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




“Not everything that can be counted
counts, and not everything that counts
can be counted.”
                        Albert Einstein




Heuristic & Inferred
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT


Reputation.
A Construct with more than 35 observable variables across 7
domains with proven impact on Performance.




    PERSONAL
    EXPERIENCE
    S
                                                                       SUPPORTING
                                                                       ATTITUDES




                                                           ATTITUDES
                                  FEELINGS
                        DOMAINS




    CORPORATE                                REPUTATION                             RESULTS
    ACTIONS


                                                                       PROSPECTS
                                                           6
    THIRD PARTY
    OPINION              7         4



  Heuristic & Inferred
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT


 Reputation.
 A Process with more than 35 observable variables across 7
 domains
 with Impact on Performance.




Products
                                                                        Purchase
Innovation



                                                            ATTITUDES
                                               Trust                    Recommend
                                    FEELINGS
                          DOMAINS




Workplace                                      Esteem                   Anti-crisis
Governance                                     Admiration                               RESULTS
                                                                        Word of Mouth
Citizenship                                    Reputation               Invest in
Leadership
                                                                        Work at
Performance
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT


Causal analysis and Constructs.
Can’t be directly observed, but it can be inferred.




       Cronbach Alfa
                                                           Source: Reputation Institute
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT


Reputation KRI and Market Value KPI have a causal
relationship.




                                                           Source: Reputation Institute.
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



 Developing effective KRIs is crucial to the
 success of any management program.
 First, as they assist in predicting potential adverse events, they are mostly
 useful, as noted above, in identifying key areas where additional controls or
 mitigation plans might be needed or to explore market opportunities.




                                                           “There is a prospect of a thrilling time
                                                           ahead for you.”
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




     A goal of developing an effective set of KRIs is to identify
     relevant metrics that provide useful insights about potential
     risks that have an impact on the achievement of the
     organization’s short & long term performance & goals.
     the selection and or design of effective KRIs starts with a firm grasp of organizational
     objectives and risk-related events - uncertainties that might affect the achievement of those
     objectives.



                                   regulatory compliance risks
                          fraud or corruption risks                      reputational risks

extended enterprise risks
        contract risks                                                                    competitor actions risks
                                                                                              geopolitical risks

talent related risks


                                                                                                  reporting risks



                                                     security risks
                       business interruption risks
                                             market dynamics risks
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




Linking Objectives to Strategies to KRI’s.
Mapping key risks to core strategic initiatives puts management in a
position to begin identifying the most critical metrics that can serve as
leading key risk indicators to help them oversee the execution of core or
strategic initiatives.




                           KPI
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




Opportunities for Proactive Strategic Risk Management.
This strategic use of KRIs increases the likelihood that objectives set by
management are achieved. Proactively monitoring relevant KRIs helps
minimize uncertainty and identify opportunities for strategy or operational
adjustments.
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




Why are KRIs important for IT?
How to select “right” KRIs for IT?
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




IT continues to emerge as a significant source of strategic risk.
 the selection and or design of effective KRIs starts with a firm grasp of organizational
 objectives and risk-related events - uncertainties that might affect the achievement of those
 objectives.




                                                                                                 source: Corporate Executive Board
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




                                                           are them linked?

                    Traditional IT Risk Areas




                                                                     *Illustrative
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




On top of the traditional IT risk areas, embedded within the enterprise
risk “heat map” lie an array of business risks that, upon further
consideration, reveal a significant IT component.


                  Emerging IT-related Risk Areas




                                                           *Illustrative
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



“By establishing the context, the organization articulates its objectives, defines the
external and internal parameters to be taken into account when managing risk, and sets
the scope and risk criteria for the remaining process.” (ISO 31000, p. 15)
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



   KRIs should be associated with corresponding KPIs measured as
   preceding events with causal relationship affecting desired outcomes.




Revenue
KPI




                   Reputation
                          KRI



                                           Data Privacy events
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



KRIs should be associated with corresponding KPIs measured as
preceding events with causal relationship affecting desired outcomes.



 IT Strategic Initiatives & Risks aligned with Company’s core Pillars, Initiatives & Goals




                                 Customer
                                Satisfaction
                                                                  Data
                               KPI                               Privacy



                               Operational
                               Excellence
                                                                Systems
                               KPI                             Availability


                                                                                             *Illustrative
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



Start with Credible & Discrete KRIs directly impacting business KPIs




 IT Strategic Initiatives aligned with Company’s core Pillars & Initiatives




                                                                              KPI
                                            KRI




                                                                                    *Illustrative. Source: Gartner
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



Real-world KRIs and KPIs mappings
                                                     KRIs     KPIs




                                                            *Illustrative. Source Gartner
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




How to leverage KRIs and
improve Business performance?
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



Business case example for a shipping company…
A cross-country shipping company with a fleet of 100 trucks.


                    KPI and KRI                                       Risk management
       KPI: On-time delivery has reputation,
       sales and customer service
       implications.
                                                               Changing oil every 3k mi raises costs
       KRI: Lorry breakdown rates have a
                                                               but does not significantly lower
       causal relationship with on-time
                                                               breakdown rates.
       delivery.
                                                               Changing oil every 10k mi lower costs
       KPI: Failure to change oil has a causal
                                                               but significantly raises breakdown rates.
       relationship and a negative impact with
       breakdowns.

       Control: Maintenance SLA with oil
       change every 5k mi.

Business outcomes:•           Alignment of risk-related activities to execution.
                  •           Risk visibility drives better business decisions with a KRI.




                                                                                                           *Illustrative
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



Risk adjusted KPIs improve decisions and increase business value.


     on-time delivery                                      oil change
     KPI                                                   KRI
     on-time delivery =
     orders delivered on-time /                            oil-change KRI = lorries w/o
     total orders received                                 oil change within last 5,000mi /
                                                           total fleet

     on-time delivery KPI =                                oil-change KRI =
     912/1,000 = 91%                                       75/100 = 75%

     KPI target = 90%


     Risk adjusted on-time delivery KPI = KPI – (4 * KRI)
                                      = 91% - 3% = 88%




                                                                                              *Illustrative
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



    The Risk Adjusted Value Model and the KRI Catalog
Business          Outcomes                                     Key Risk Indicators
aspect




                                                                                     *Illustrative. Source Gartner
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



The Risk Adjusted Value Model and the KRI Catalog
            KRI    Audit Exception Index
       Category    Compliance
       Business    Finance and Regulatory
         aspect
      Outcomes     Support Services
   Impacted KPI    Time to Market




KRI Description     Audit findings are a measure of Compliance failures. The Audit
                    Exception Index is a KRI that a company is accepting more risk than it
                    is addressing.
      KRI Metric    The Audit Exception Index measures the % of audit exceptions granted
                    over the total number of audit findings.
                    Audit Exception Index = Granted Exceptions / Total Audit Findings
   KRI Example      The ABC Co. granted 10 critical audit exceptions in the past 12mo.
                    During the same period, the total number of findings was 40.
                    Audit Exception Index = (10/40) = 25%
  Risk Adjusted     ABC Co. is in the heavily regulated pharma industry. Poor compliance
   KPI example      increases regulatory scrutiny, which increases new drug development
                    costs while delaying product launch.
                    RA New Product Index = New Product Index – (4 x Audit Exception
     Alternative    Index)
                    Compliance Program Maturity.
      Measures      Average days out of date for Critical Mandates.
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



        How to go about developing a Strategy-KRI-KPI mapping exercise?
        The “Vertical-Horizontal” analysis


                                     Security     I&O                  CIO                COO   CEO


dependency links
perspective analysis
         Core Competence Execution




                                                                   function critical
                                                                   perspective analysis
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



Three Takeaways



• Management Process need to consider Risk explicitly.

• Risk Adjusted KPIs improve business decisions and increases
  business value.

• A Risk Adjusted/Aware Value Model represents the activities
  and events that affect the expected or planned outcomes of
  your Co.
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT



Communicating & Engaging through KRIs
Organizing, monitoring, reviewing and communicating KRI progress and their
impact on KPIs can be greatly facilitated by having a centralized, automated
system for the company’s Risk Adjusted KPI program, with flexible, audience
oriented, reporting & dashboarding functionality.
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




Governance
Risk Management
and
Compliance
are
nuisances
without
an holistic strategy
and
proper tooling
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




IT GRC needs are often more complicated than those of their
enterprise colleagues.
With PCI, HIPAA, ISO certification, and privacy laws, IT Pros are typically looking for more
sophisticated control mapping, asset management, vulnerability and event data and product
integration functionality.


As we mentioned, KRIs can/need to be linked to multiple KPIs and
controls, across various enterprise key processes.
On top of the KRI-KPI linkage and its management complexity,
creating risk intelligence require embracing all risk related
information as policies, procedures, losses, incidents, source legal
and regulatory content, compliance control actions taken, auditing
, etc.
All this requires proper systems support to help risk owners and
senior management develop a common language and a clearer
vision of the future.

As of today, IT risk and compliance issues don’t usually get the executive visibility they deserve.
Although many firms may list one or two IT risks among their corporate top 10, most IT & Risk
heads struggle to get visibility with their corporate executives and boards.
(until there’s a breach, that is)
THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT




Even as concerns grow over mounting regulations, cyberwarfare, privacy,
reputation and fraud, it will be a proper KRI to KPI mapping and the existing large
and successful list of deployments and success stories, as much as anything
else, that will pave the way for your ITGRC program.

So buckle up, leverage from both of them and turn your IT into the domain expert
you Co. needs.



                                                           “The wise man expects to prepare for the
                                                           unexpected.”
THE ENDLESS POSSIBILITIES
  OF REPUTATION, RISK &
  DESIGN IN BUSINESS.

  KRIs, KPIs & IT



Maximo Neira Schliemann
maxneira@beyondeconomics.es
@neiraschliemann
July 31st, 2012

More Related Content

What's hot

Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksInternational Federation of Accountants
 
Enterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management ProcessEnterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management Processregio12
 
Operational risk management (orm)
Operational risk management (orm)Operational risk management (orm)
Operational risk management (orm)Bushra Angbeen
 
Integrating Risk Appetite With Strategy Feb 14 2011
Integrating Risk Appetite With Strategy   Feb 14 2011Integrating Risk Appetite With Strategy   Feb 14 2011
Integrating Risk Appetite With Strategy Feb 14 2011Andrew Smart
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkColleen Beck-Domanico
 
Risk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation SlidesRisk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation SlidesSlideTeam
 
Introduction To Risk Management Powerpoint Presentation Slides
Introduction To Risk Management Powerpoint Presentation SlidesIntroduction To Risk Management Powerpoint Presentation Slides
Introduction To Risk Management Powerpoint Presentation SlidesSlideTeam
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyNICSA
 
Legal Governance, Risk Management and Compliance
Legal Governance, Risk Management and ComplianceLegal Governance, Risk Management and Compliance
Legal Governance, Risk Management and ComplianceEffacts
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceResolver Inc.
 
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...Eric Campbell
 
The risk of risks: Reputation risk and resiliency Sept. 2014
The risk of risks: Reputation risk and resiliency Sept. 2014The risk of risks: Reputation risk and resiliency Sept. 2014
The risk of risks: Reputation risk and resiliency Sept. 2014Linda Locke Reputation Strategist
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & complianceHR Globe Consulting
 
127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0Rachael Phelan
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONFrackson Kathibula-Nyoni
 
Operational risk (by ms.sweta vijuraj)
Operational risk (by ms.sweta vijuraj)Operational risk (by ms.sweta vijuraj)
Operational risk (by ms.sweta vijuraj)Saras Singh
 
Introducing KRI model know your customers
Introducing KRI model   know your customersIntroducing KRI model   know your customers
Introducing KRI model know your customersBaby Sirota
 
operations risk management power point presentation.
operations risk management power point presentation.operations risk management power point presentation.
operations risk management power point presentation.Miyelani Shibambo
 

What's hot (20)

Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
 
Enterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management ProcessEnterprise Risk Management as a Core Management Process
Enterprise Risk Management as a Core Management Process
 
Operational risk management (orm)
Operational risk management (orm)Operational risk management (orm)
Operational risk management (orm)
 
Integrating Risk Appetite With Strategy Feb 14 2011
Integrating Risk Appetite With Strategy   Feb 14 2011Integrating Risk Appetite With Strategy   Feb 14 2011
Integrating Risk Appetite With Strategy Feb 14 2011
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Risk Management Framework
Risk Management FrameworkRisk Management Framework
Risk Management Framework
 
Risk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation SlidesRisk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation Slides
 
Introduction To Risk Management Powerpoint Presentation Slides
Introduction To Risk Management Powerpoint Presentation SlidesIntroduction To Risk Management Powerpoint Presentation Slides
Introduction To Risk Management Powerpoint Presentation Slides
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a Strategy
 
ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
 
Legal Governance, Risk Management and Compliance
Legal Governance, Risk Management and ComplianceLegal Governance, Risk Management and Compliance
Legal Governance, Risk Management and Compliance
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
Risk Appetite & Risk Tolerance: Improving their application from Abstract to ...
 
The risk of risks: Reputation risk and resiliency Sept. 2014
The risk of risks: Reputation risk and resiliency Sept. 2014The risk of risks: Reputation risk and resiliency Sept. 2014
The risk of risks: Reputation risk and resiliency Sept. 2014
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & compliance
 
127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0127017438_RMA_OperationalRiskAppetite_v1.0
127017438_RMA_OperationalRiskAppetite_v1.0
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
 
Operational risk (by ms.sweta vijuraj)
Operational risk (by ms.sweta vijuraj)Operational risk (by ms.sweta vijuraj)
Operational risk (by ms.sweta vijuraj)
 
Introducing KRI model know your customers
Introducing KRI model   know your customersIntroducing KRI model   know your customers
Introducing KRI model know your customers
 
operations risk management power point presentation.
operations risk management power point presentation.operations risk management power point presentation.
operations risk management power point presentation.
 

Similar to KRI (Key Risk Indicators) & IT

SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...SilverStormSolutions
 
Riskpro Introduction
Riskpro IntroductionRiskpro Introduction
Riskpro IntroductionManoj Jain
 
Riskpro Business Risk Management
Riskpro Business Risk ManagementRiskpro Business Risk Management
Riskpro Business Risk ManagementManoj Jain
 
Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk ManagementManoj Jain
 

Similar to KRI (Key Risk Indicators) & IT (20)

SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
SilverStorm "Credibility and Collaboration to achieve excellence in IT Govern...
 
Riskpro brief introduction
Riskpro brief introductionRiskpro brief introduction
Riskpro brief introduction
 
Riskpro construction industry
Riskpro construction industryRiskpro construction industry
Riskpro construction industry
 
Riskpro Introduction
Riskpro IntroductionRiskpro Introduction
Riskpro Introduction
 
Riskpro Construction Industry
Riskpro Construction IndustryRiskpro Construction Industry
Riskpro Construction Industry
 
Riskpro construction industry 2013
Riskpro construction industry 2013Riskpro construction industry 2013
Riskpro construction industry 2013
 
Riskpro construction industry 2013
Riskpro construction industry 2013Riskpro construction industry 2013
Riskpro construction industry 2013
 
Riskpro construction industry 2013
Riskpro construction industry 2013Riskpro construction industry 2013
Riskpro construction industry 2013
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
Reputation risk
Reputation riskReputation risk
Reputation risk
 
Riskpro Business Risk Management
Riskpro Business Risk ManagementRiskpro Business Risk Management
Riskpro Business Risk Management
 
Bi risk services 2013
Bi risk services 2013Bi risk services 2013
Bi risk services 2013
 
Bi risk services 2013
Bi risk services 2013Bi risk services 2013
Bi risk services 2013
 
Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk Management
 
Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk Management
 
Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk Management
 
Riskpro information risk management
Riskpro information risk managementRiskpro information risk management
Riskpro information risk management
 
People Risk Collateral
People Risk CollateralPeople Risk Collateral
People Risk Collateral
 
People Risk Collateral
People Risk CollateralPeople Risk Collateral
People Risk Collateral
 

More from Max Neira Schliemann

Your Global Yacht Club in 5min. BYDSEA.
Your Global Yacht Club in 5min. BYDSEA.Your Global Yacht Club in 5min. BYDSEA.
Your Global Yacht Club in 5min. BYDSEA.Max Neira Schliemann
 
Estética-Emociones-Sociedad MIE 5 2011
Estética-Emociones-Sociedad MIE 5 2011Estética-Emociones-Sociedad MIE 5 2011
Estética-Emociones-Sociedad MIE 5 2011Max Neira Schliemann
 
MetricStream GRC Solution Suite Brief
MetricStream GRC Solution Suite BriefMetricStream GRC Solution Suite Brief
MetricStream GRC Solution Suite BriefMax Neira Schliemann
 
Curso Inmersión en Sostenibilidad @ InterfaceFLOR
Curso Inmersión en Sostenibilidad @ InterfaceFLORCurso Inmersión en Sostenibilidad @ InterfaceFLOR
Curso Inmersión en Sostenibilidad @ InterfaceFLORMax Neira Schliemann
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveMax Neira Schliemann
 
Curso de Inmersión en Sostenibilidad
Curso de Inmersión en SostenibilidadCurso de Inmersión en Sostenibilidad
Curso de Inmersión en SostenibilidadMax Neira Schliemann
 
Estetica, Emociones y Estrategia 101
Estetica, Emociones y Estrategia 101Estetica, Emociones y Estrategia 101
Estetica, Emociones y Estrategia 101Max Neira Schliemann
 

More from Max Neira Schliemann (11)

Your Global Yacht Club in 5min. BYDSEA.
Your Global Yacht Club in 5min. BYDSEA.Your Global Yacht Club in 5min. BYDSEA.
Your Global Yacht Club in 5min. BYDSEA.
 
Estética-Emociones-Sociedad MIE 5 2011
Estética-Emociones-Sociedad MIE 5 2011Estética-Emociones-Sociedad MIE 5 2011
Estética-Emociones-Sociedad MIE 5 2011
 
Reputación y Ética. MIE V. 2011
Reputación y Ética. MIE V. 2011Reputación y Ética. MIE V. 2011
Reputación y Ética. MIE V. 2011
 
MetricStream GRC Solution Suite Brief
MetricStream GRC Solution Suite BriefMetricStream GRC Solution Suite Brief
MetricStream GRC Solution Suite Brief
 
Curso Inmersión en Sostenibilidad @ InterfaceFLOR
Curso Inmersión en Sostenibilidad @ InterfaceFLORCurso Inmersión en Sostenibilidad @ InterfaceFLOR
Curso Inmersión en Sostenibilidad @ InterfaceFLOR
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
 
Curso de Inmersión en Sostenibilidad
Curso de Inmersión en SostenibilidadCurso de Inmersión en Sostenibilidad
Curso de Inmersión en Sostenibilidad
 
Impacto de RRHH en la Reputacion
Impacto de RRHH en la ReputacionImpacto de RRHH en la Reputacion
Impacto de RRHH en la Reputacion
 
Estetica, Emociones y Estrategia 101
Estetica, Emociones y Estrategia 101Estetica, Emociones y Estrategia 101
Estetica, Emociones y Estrategia 101
 
Reputación, Etica y Negocios 101
Reputación, Etica y Negocios 101Reputación, Etica y Negocios 101
Reputación, Etica y Negocios 101
 
Escenarios Estrategicos 101
Escenarios Estrategicos 101Escenarios Estrategicos 101
Escenarios Estrategicos 101
 

Recently uploaded

Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...lizamodels9
 
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂EscortCall Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escortdlhescort
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...rajveerescorts2022
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceDamini Dixit
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon investment
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPanhandleOilandGas
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Sheetaleventcompany
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Sheetaleventcompany
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noidadlhescort
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Anamikakaur10
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceDamini Dixit
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...amitlee9823
 

Recently uploaded (20)

Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂EscortCall Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business Potential
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 

KRI (Key Risk Indicators) & IT

  • 1. Establishing Key Risk Indicators for IT July 31, 2012 Maximo Neira Schliemann Ravi Mishra Founder & Partner at Beyond Economics & Manager Product Marketing - IT GRC Solutions Former CIO Ros Casares Corporation in Spain & MetricStream Member of the CIO office at Baxter © 2012 MetricStream, Inc. All Rights Reserved.
  • 2. Agenda • What are KRIs and how they differ from KPI and KCI? • Why is KRIs important to your IT? • Selecting the right set of KRIs for your IT organization • Leverage KRIs for effective IT Risk Management and improving business performance © 2012 MetricStream, Inc. All Rights Reserved.
  • 3. THE ENDLESS POSSIBILITIES OF REPUTATION, RISK & DESIGN IN BUSINESS. KRIs, KPIs & IT Maximo Neira Schliemann maxneira@beyondeconomics.es @neiraschliemann July 31st, 2012
  • 4. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Whether you love or hate them, it is hard to dispute the popularity and mystique of fortune cookies in their reputed ability to predict the future… “Your life will prosper only if you see and acknowledge your faults, and work to reduce them...”
  • 5. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT What are KRIs? How do they differ from KPIs? Why are KRIs important for IT? How to select the right KRIs? How to leverage from KRIs?
  • 6. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT “key risk indicators (KRIs) are metrics or pieces of data serving as ‘early warning indicators’ of increased risk exposure in various areas of the enterprise.” COSO, 2010 Algorithmic & Heuristic
  • 7. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT “Key Performance Indicators (KPIs) are designed to provide a high-level overview of the past performance of the organization and its major operating units, often focused almost exclusively on historical data.” COSO, 2010 Algorithmic
  • 8. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT KPIs KRIs External GeoPolitical External Social
  • 9. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Algorithmic simple COSO, 2010
  • 10. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT “Not everything that can be counted counts, and not everything that counts can be counted.” Albert Einstein Heuristic & Inferred
  • 11. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Reputation. A Construct with more than 35 observable variables across 7 domains with proven impact on Performance. PERSONAL EXPERIENCE S SUPPORTING ATTITUDES ATTITUDES FEELINGS DOMAINS CORPORATE REPUTATION RESULTS ACTIONS PROSPECTS 6 THIRD PARTY OPINION 7 4 Heuristic & Inferred
  • 12. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Reputation. A Process with more than 35 observable variables across 7 domains with Impact on Performance. Products Purchase Innovation ATTITUDES Trust Recommend FEELINGS DOMAINS Workplace Esteem Anti-crisis Governance Admiration RESULTS Word of Mouth Citizenship Reputation Invest in Leadership Work at Performance
  • 13. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Causal analysis and Constructs. Can’t be directly observed, but it can be inferred. Cronbach Alfa Source: Reputation Institute
  • 14. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Reputation KRI and Market Value KPI have a causal relationship. Source: Reputation Institute.
  • 15. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Developing effective KRIs is crucial to the success of any management program. First, as they assist in predicting potential adverse events, they are mostly useful, as noted above, in identifying key areas where additional controls or mitigation plans might be needed or to explore market opportunities. “There is a prospect of a thrilling time ahead for you.”
  • 16. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT A goal of developing an effective set of KRIs is to identify relevant metrics that provide useful insights about potential risks that have an impact on the achievement of the organization’s short & long term performance & goals. the selection and or design of effective KRIs starts with a firm grasp of organizational objectives and risk-related events - uncertainties that might affect the achievement of those objectives. regulatory compliance risks fraud or corruption risks reputational risks extended enterprise risks contract risks competitor actions risks geopolitical risks talent related risks reporting risks security risks business interruption risks market dynamics risks
  • 17. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Linking Objectives to Strategies to KRI’s. Mapping key risks to core strategic initiatives puts management in a position to begin identifying the most critical metrics that can serve as leading key risk indicators to help them oversee the execution of core or strategic initiatives. KPI
  • 18. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Opportunities for Proactive Strategic Risk Management. This strategic use of KRIs increases the likelihood that objectives set by management are achieved. Proactively monitoring relevant KRIs helps minimize uncertainty and identify opportunities for strategy or operational adjustments.
  • 19. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Why are KRIs important for IT? How to select “right” KRIs for IT?
  • 20. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT IT continues to emerge as a significant source of strategic risk. the selection and or design of effective KRIs starts with a firm grasp of organizational objectives and risk-related events - uncertainties that might affect the achievement of those objectives. source: Corporate Executive Board
  • 21. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT are them linked? Traditional IT Risk Areas *Illustrative
  • 22. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT On top of the traditional IT risk areas, embedded within the enterprise risk “heat map” lie an array of business risks that, upon further consideration, reveal a significant IT component. Emerging IT-related Risk Areas *Illustrative
  • 23. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT “By establishing the context, the organization articulates its objectives, defines the external and internal parameters to be taken into account when managing risk, and sets the scope and risk criteria for the remaining process.” (ISO 31000, p. 15)
  • 24. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT KRIs should be associated with corresponding KPIs measured as preceding events with causal relationship affecting desired outcomes. Revenue KPI Reputation KRI Data Privacy events
  • 25. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT KRIs should be associated with corresponding KPIs measured as preceding events with causal relationship affecting desired outcomes. IT Strategic Initiatives & Risks aligned with Company’s core Pillars, Initiatives & Goals Customer Satisfaction Data KPI Privacy Operational Excellence Systems KPI Availability *Illustrative
  • 26. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Start with Credible & Discrete KRIs directly impacting business KPIs IT Strategic Initiatives aligned with Company’s core Pillars & Initiatives KPI KRI *Illustrative. Source: Gartner
  • 27. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Real-world KRIs and KPIs mappings KRIs KPIs *Illustrative. Source Gartner
  • 28. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT How to leverage KRIs and improve Business performance?
  • 29. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Business case example for a shipping company… A cross-country shipping company with a fleet of 100 trucks. KPI and KRI Risk management KPI: On-time delivery has reputation, sales and customer service implications. Changing oil every 3k mi raises costs KRI: Lorry breakdown rates have a but does not significantly lower causal relationship with on-time breakdown rates. delivery. Changing oil every 10k mi lower costs KPI: Failure to change oil has a causal but significantly raises breakdown rates. relationship and a negative impact with breakdowns. Control: Maintenance SLA with oil change every 5k mi. Business outcomes:• Alignment of risk-related activities to execution. • Risk visibility drives better business decisions with a KRI. *Illustrative
  • 30. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Risk adjusted KPIs improve decisions and increase business value. on-time delivery oil change KPI KRI on-time delivery = orders delivered on-time / oil-change KRI = lorries w/o total orders received oil change within last 5,000mi / total fleet on-time delivery KPI = oil-change KRI = 912/1,000 = 91% 75/100 = 75% KPI target = 90% Risk adjusted on-time delivery KPI = KPI – (4 * KRI) = 91% - 3% = 88% *Illustrative
  • 31. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT The Risk Adjusted Value Model and the KRI Catalog Business Outcomes Key Risk Indicators aspect *Illustrative. Source Gartner
  • 32. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT The Risk Adjusted Value Model and the KRI Catalog KRI Audit Exception Index Category Compliance Business Finance and Regulatory aspect Outcomes Support Services Impacted KPI Time to Market KRI Description Audit findings are a measure of Compliance failures. The Audit Exception Index is a KRI that a company is accepting more risk than it is addressing. KRI Metric The Audit Exception Index measures the % of audit exceptions granted over the total number of audit findings. Audit Exception Index = Granted Exceptions / Total Audit Findings KRI Example The ABC Co. granted 10 critical audit exceptions in the past 12mo. During the same period, the total number of findings was 40. Audit Exception Index = (10/40) = 25% Risk Adjusted ABC Co. is in the heavily regulated pharma industry. Poor compliance KPI example increases regulatory scrutiny, which increases new drug development costs while delaying product launch. RA New Product Index = New Product Index – (4 x Audit Exception Alternative Index) Compliance Program Maturity. Measures Average days out of date for Critical Mandates.
  • 33. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT How to go about developing a Strategy-KRI-KPI mapping exercise? The “Vertical-Horizontal” analysis Security I&O CIO COO CEO dependency links perspective analysis Core Competence Execution function critical perspective analysis
  • 34. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Three Takeaways • Management Process need to consider Risk explicitly. • Risk Adjusted KPIs improve business decisions and increases business value. • A Risk Adjusted/Aware Value Model represents the activities and events that affect the expected or planned outcomes of your Co.
  • 35. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Communicating & Engaging through KRIs Organizing, monitoring, reviewing and communicating KRI progress and their impact on KPIs can be greatly facilitated by having a centralized, automated system for the company’s Risk Adjusted KPI program, with flexible, audience oriented, reporting & dashboarding functionality.
  • 36. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Governance Risk Management and Compliance are nuisances without an holistic strategy and proper tooling
  • 37. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT IT GRC needs are often more complicated than those of their enterprise colleagues. With PCI, HIPAA, ISO certification, and privacy laws, IT Pros are typically looking for more sophisticated control mapping, asset management, vulnerability and event data and product integration functionality. As we mentioned, KRIs can/need to be linked to multiple KPIs and controls, across various enterprise key processes. On top of the KRI-KPI linkage and its management complexity, creating risk intelligence require embracing all risk related information as policies, procedures, losses, incidents, source legal and regulatory content, compliance control actions taken, auditing , etc. All this requires proper systems support to help risk owners and senior management develop a common language and a clearer vision of the future. As of today, IT risk and compliance issues don’t usually get the executive visibility they deserve. Although many firms may list one or two IT risks among their corporate top 10, most IT & Risk heads struggle to get visibility with their corporate executives and boards. (until there’s a breach, that is)
  • 38. THE ENDLESS POSSIBILITIES OF RISK IN BUSINESS. KRIs & IT Even as concerns grow over mounting regulations, cyberwarfare, privacy, reputation and fraud, it will be a proper KRI to KPI mapping and the existing large and successful list of deployments and success stories, as much as anything else, that will pave the way for your ITGRC program. So buckle up, leverage from both of them and turn your IT into the domain expert you Co. needs. “The wise man expects to prepare for the unexpected.”
  • 39. THE ENDLESS POSSIBILITIES OF REPUTATION, RISK & DESIGN IN BUSINESS. KRIs, KPIs & IT Maximo Neira Schliemann maxneira@beyondeconomics.es @neiraschliemann July 31st, 2012