SlideShare a Scribd company logo
Embedding RCSA into Strategic Planning
and Business Strategy
Operatiivisten Riskien Hallinta, Helsinki, Finland
Andrew Smart, Ascendore
Post credit crunch, financial services firms are drowning
under a tsunami of regulatory change, cost and complexity
2
Run the Bank
£200bn
plus fines
492%
Annual increase
regulatory change
3
The cost & complexity
of operational risk &
compliance is too high
and there is a
“disproportionate risk
aversion creeping into
decision-making”
Chairman, HBSC, 2015
Accenture Risk Study, 2017
Boards and executives should be able to answer these
questions with confidence.
4
Are we in control?
Are we going to
deliver our strategy?
Are we operating
within appetite?
RCSA - an essential part of an integrated framework
Better Conversation
Better Decisions
Better Action-taking
Better Results
Risk & Control Self-
Assessment (RCSA) processes
and data should be an essential part of
an integrated Strategy & Risk
Management framework; an integral
part of enterprise management
reporting.
5
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
6
7
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
Compliance Enablers
Over the long-term, where are we going and
how will we get there?
Critical few things from the business model
that enable the delivery of the strategy
To deliver our long-term strategy what is the
focus over the next 12-24 months?
Where do we need to excel day-to-day
What are the ‘rules’ that define our operating
environment?
Risk Appetite defines the boundaries for
risk-takingStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
RISK THRESHOLDS
RISK EXPOSURES
Compliance Enablers
8
Manage threats & opportunities via the risk
taxonomyStrategy
Strategic Drivers
Business Objectives
Operational Enablers
APPETITE
ALIGNMENT
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL RISK
COMPLIANCE RISK
Compliance Enablers
9
Managed at every level in the framework
Strategy
Strategic Drivers
Business Objectives
Operational Enablers
StrategicRisk
Execution
Risk
Compliance
Risk
APPETITE
ALIGNMENT
ACCOUNTABILITY
ALIGNMENT
CASCADE
ASSESSMENT
MEASUREMENT
ACTION-TAKING
Operational
Risk
Compliance Enablers
10
The RACI framework is a proven approach to embedding accountability and
clarification of roles in decision-making. Supports the 3 Lines of Defence
InformResponsible(s)Accountable Consult
11
How do your operational and
regulatory enablers relate to
strategy?
Alignment mapping can identify gaps; areas
where your strategy is not supported or where
operational resources are been wasted.
Regulatory rules mapping provide assurance
that processes and initiatives are in place to
meet regulatory obligations and identify gaps;
where are the gaps or weaknesses in our
regulatory response landscape?
12
Key ControlsKey RisksObjectiveEntity
Processes
Initiatives
Technology
How does strategy & risk
cascade through the firm?
Board & Senior Management assurance is
enhanced by understanding the cascading of
objectives & risks through the firm.
Identify gaps in consolidated reporting by
linking objectives, risks and controls in ‘cascade
chains’ through the firm. Where does the chain
break?
13
Key Risk
(Strategic Risk)
Corporate
Division
Department
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Key Risk
(Strategic Risk)
Key Risk
(Operational Risk)
Data points to inform your Risk Self-
Assessments
14
MAXIMUM
INHERENT
RESIDUAL
% $£€
IMPACT(S) LIKELIHOOD EXPOSURE
DRIVERS
use driver(s) as the basis for assessing impacts thus linking risk
back to strategy
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
KRIs
Losses / Near Misses
Expert Judgement
Scenarios & Models
Related KPIs & KCIs
Control Self Assessment
Data points to inform your Control
Self-Assessments
15
KCIs
Losses / Near Misses
ASSESSMENT FREQUENCY
assess risks on a pre-determined frequency (daily, weekly,
monthly, quarterly, annually) and/or on an event driven basis.
Control Testing
Related KPIs & KRIs
DESIGN PERFORMANCE
CONTROL
EFFECTIVENESS
Three types of related
indicators to give a full picture
RAG is common practice
RAGAR is best practice
16
Key Performance Indicators (KPIs)
Used to define performance thresholds and
targets; and to monitor progress towards achieving
these targets.
Key Risk Indicators (KRIs)
Used to define risk thresholds and targets; to
monitor changes within the risk environment.
Key Control Indicators (KCIs)
Used to define control thresholds and targets; to
monitor changes within the controls environment.
BASELINE
LT 1
LT 2
UT2
UT 1
TARGET
T 2
T 1
Assessment and measurement
is not enough.
Action-taking is critical in
driving performance &
managing risk
Typically we think about two
types of actions
17
Improvement Actions
Audit Actions
Tools to bring it all together
18
Better
Action-
taking
Better
Decisions
Better
Results
Strategy
Map
Better
Conversations
Appetite
Alignment
Matrix
Risk
Appetite
Risk Map
Map Business Objectives & their
causal relationship to improve the
communication, monitoring and
management of strategic and
operational performance.
19
Define risk tolerances across the
framework reflecting the
materiality of the business unit.
Use Drivers to link RCSA back to
Strategy.
20
The Risk Map provides a visual
overview of the risk profile and
make it easy to identify potential
risk issues.
Four perspectives risk map is
aligned to the Strategy Map.
21
Starting with Strategic Drivers,
define Risk Appetite across the
framework, reflecting the
materiality and strategic intent of
the business unit.
22
The Appetite Alignment Matrix
visualise the alignment of risk-
taking to risk appetite showing
where the firm is aligned, over-
exposed and under-exposed.
23
Are we operating within appetite?
24
Appetite, Performance, Risk and Controls
Effectiveness should be assessed,
measured and aligned across the
organisational hierarchy and within the
taxonomy within the framework.
25
STRATEGY
typically strategy is cascaded top-down
DATA
typically data flows up the organization
EXECUTION
typically execution is driven from the middle
Corporate
Divisions
Departments
STRATEGIC RISK
EXECUTION RISK
OPERATIONAL &
COMPLIANCE RISK
26
STRATEGY MAP
Are we on track to deliver the
strategy?
APPETITE ALIGNMENT MATRIX
Are we operating within
appetite?
RISK APPETITE
How much risk is acceptable?
RISK MAP
What level of risk are we taking?
Benefits of Improved
Strategic Execution
▪ A growth in shareholder value of 150%,
driven by a 180% growth in profits and a
120% growth in revenue
▪ A 50% improvement in customer
satisfaction
▪ A 50% improvement in key process
effectiveness
▪ A 25% improvement in employee
satisfaction, leading to a 50% reduction
in employee turnover
Benefits of an
Integrated approach
▪ Transformed our approach to risk and
regulatory compliance over 12-month
▪ Reduce the value of our operational
losses by 94%, the volume by 63% and
our economic capital provision by 23%”
▪ Eliminate 11 spreadsheet systems
▪ Enabled us to secure a 3% regulatory
capital release and reduce our cost of
capital significantly
27
Benefits of Enterprise
Risk Management
▪ Increasing the range of opportunities
▪ Identifying and managing risk entity-
wide
▪ Increasing positive outcomes and
advantage while reducing negative
surprises
▪ Reducing performance variability
▪ Improving resource deployment
▪ Enhancing enterprise resilience
Results based on 3 year performance of BSC Hall of Frame
winners
COSO ERM Framework, 2017 Example benefits reported by Ascendore customers
Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in
firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent"
or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
We believe that risk management and compliance must enable strategy
execution and value creation, not simply tick regulatory boxes.
28
“we have reduced our Pillar 2 capital by
81.2% while delivering a 94% reduction
in the value of errors and a 63%
reduction in the volume of errors”
Head of Enterprise Risk, Homeloan Management Limited
We provide Integrated GRC
(Governance, Risk and Compliance)
solutions to financial services firms
and their regulators built on familiar,
everyday office tools; SharePoint,
Office 365 & the Cloud.
COSO ERM Framework 2017 Risk-Based Performance
Management
29
What is Risk-Based Performance Management?
Enhance Shareholder value
Control Cost & Complexity
Drive Accountability
Align the firm
Risk-Based Performance
Management (RBPM) is an
strategic execution approach which
integrates business strategy, risk
appetite, performance management
and risk management.
30
Integrated Strategy & Risk Management Framework
APPETITE
ALIGNMENT
APPETITESTRATEGY PERFORMANCE RISK
31
Embedding RCSA into Strategic Planning
and Business Strategy?
Andrew Smart
Ascendore

More Related Content

What's hot

Risk and Control Self Assessment - IRM India Affiliate
Risk and Control Self  Assessment - IRM India AffiliateRisk and Control Self  Assessment - IRM India Affiliate
Risk and Control Self Assessment - IRM India Affiliate
IRM India Affiliate
 
Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk Management
Andrew Smart
 
Awareness iso 22301 danang suryo
Awareness iso 22301 danang suryoAwareness iso 22301 danang suryo
Awareness iso 22301 danang suryo
Danang suryo Wardhono
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
Croydon Consulting, LLC
 
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
International Federation of Accountants
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite
Andrew Smart
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONFrackson Kathibula-Nyoni
 
Risk Appetite
Risk AppetiteRisk Appetite
Risk Appetite
Towers Perrin
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
Diane Christina
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
Colleen Beck-Domanico
 
A Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk ManagementA Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk Management
Turlough Guerin GAICD FGIA
 
Risk Overview & Risk management
Risk Overview & Risk managementRisk Overview & Risk management
Risk Overview & Risk management
Subhendu Datta
 
GRC Fundamentals
GRC FundamentalsGRC Fundamentals
GRC Fundamentals
3Sixty Insights
 
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...Susan Young
 
Strategic Risk: Linking Risk Management & Strategy Management processes
Strategic Risk: Linking Risk Management & Strategy Management processesStrategic Risk: Linking Risk Management & Strategy Management processes
Strategic Risk: Linking Risk Management & Strategy Management processes
GlobalStrategyTribe
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Resolver Inc.
 
Risk Management
Risk ManagementRisk Management
Risk Management
Stefan Csosz
 
Enterprise Risk Management (ERM) Framework 2020
Enterprise Risk Management (ERM) Framework 2020 Enterprise Risk Management (ERM) Framework 2020
Enterprise Risk Management (ERM) Framework 2020
Richard Swartzbaugh
 
Enterprise Risk Management PowerPoint Presentation Slides
Enterprise Risk Management PowerPoint Presentation Slides Enterprise Risk Management PowerPoint Presentation Slides
Enterprise Risk Management PowerPoint Presentation Slides
SlideTeam
 

What's hot (20)

Risk Appetite
Risk AppetiteRisk Appetite
Risk Appetite
 
Risk and Control Self Assessment - IRM India Affiliate
Risk and Control Self  Assessment - IRM India AffiliateRisk and Control Self  Assessment - IRM India Affiliate
Risk and Control Self Assessment - IRM India Affiliate
 
Integrating Strategy and Risk Management
Integrating Strategy and Risk ManagementIntegrating Strategy and Risk Management
Integrating Strategy and Risk Management
 
Awareness iso 22301 danang suryo
Awareness iso 22301 danang suryoAwareness iso 22301 danang suryo
Awareness iso 22301 danang suryo
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
 
Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite Shaping Your Culture via Risk Appetite
Shaping Your Culture via Risk Appetite
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
 
Risk Appetite
Risk AppetiteRisk Appetite
Risk Appetite
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
A Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk ManagementA Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk Management
 
Risk Overview & Risk management
Risk Overview & Risk managementRisk Overview & Risk management
Risk Overview & Risk management
 
GRC Fundamentals
GRC FundamentalsGRC Fundamentals
GRC Fundamentals
 
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
 
Strategic Risk: Linking Risk Management & Strategy Management processes
Strategic Risk: Linking Risk Management & Strategy Management processesStrategic Risk: Linking Risk Management & Strategy Management processes
Strategic Risk: Linking Risk Management & Strategy Management processes
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
Enterprise Risk Management (ERM) Framework 2020
Enterprise Risk Management (ERM) Framework 2020 Enterprise Risk Management (ERM) Framework 2020
Enterprise Risk Management (ERM) Framework 2020
 
Enterprise Risk Management PowerPoint Presentation Slides
Enterprise Risk Management PowerPoint Presentation Slides Enterprise Risk Management PowerPoint Presentation Slides
Enterprise Risk Management PowerPoint Presentation Slides
 

Similar to Embedding RCSA into Strategic Planning and Business Strategy

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
madlynplamondon
 
Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.
Andrew Smart
 
Operational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningOperational Risk Management & Strategic Planning
Operational Risk Management & Strategic Planning
Eneni Oduwole
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
AstalapulosListestos
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
CenapSerdarolu
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptx
manjujayakumar2
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
Andrew Smart
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
TanaMaeskm
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
Ashwin Kumar
 
StrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingStrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance Mapping
Nathan Ives
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
PMI Indonesia Chapter
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk Transfer
CBIZ, Inc.
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
peterObakozuwa
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and Sustainability
Jeff B
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy PresentationDavid Fernandes
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__susanta subudhi
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__susanta subudhi
 
Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Andrew Smart
 

Similar to Embedding RCSA into Strategic Planning and Business Strategy (20)

DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docxDISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
DISUSSION-1RE Chapter 15 Embedding ERM into Strategic Planning.docx
 
Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.Having trouble with your enterprise risk management strategy? Map it.
Having trouble with your enterprise risk management strategy? Map it.
 
Operational Risk Management & Strategic Planning
Operational Risk Management & Strategic PlanningOperational Risk Management & Strategic Planning
Operational Risk Management & Strategic Planning
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 
Introduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptxIntroduction to Risk Management and Sources of Risk.pptx
Introduction to Risk Management and Sources of Risk.pptx
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
 
Enterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and PerEnterprise Risk Management Integrating with Strategy and Per
Enterprise Risk Management Integrating with Strategy and Per
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
 
StrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance MappingStrategyDriven Risk Assurance Mapping
StrategyDriven Risk Assurance Mapping
 
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...SymEx 2015 - Turning Risks Into Results, A Wider Perspective  to Understand P...
SymEx 2015 - Turning Risks Into Results, A Wider Perspective to Understand P...
 
Risk Management and Risk Transfer
Risk Management and Risk TransferRisk Management and Risk Transfer
Risk Management and Risk Transfer
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and Sustainability
 
Super Strategies 2014 Risk Strategy Presentation
Super Strategies 2014  Risk Strategy PresentationSuper Strategies 2014  Risk Strategy Presentation
Super Strategies 2014 Risk Strategy Presentation
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
GRC_Strategic_Agenda__The_Value_Proposition_of_Goverance,_Risk,_and_Compliance__
 
HIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINALHIRimsISO311KandERMFINAL
HIRimsISO311KandERMFINAL
 
Governance-design
Governance-designGovernance-design
Governance-design
 
Strategically+Speaking+October+2015
Strategically+Speaking+October+2015Strategically+Speaking+October+2015
Strategically+Speaking+October+2015
 

More from Andrew Smart

FMM&A15-StratexSystems
FMM&A15-StratexSystemsFMM&A15-StratexSystems
FMM&A15-StratexSystemsAndrew Smart
 
StratexSystems_270115
StratexSystems_270115StratexSystems_270115
StratexSystems_270115Andrew Smart
 
Cyber Risk Management
Cyber Risk Management Cyber Risk Management
Cyber Risk Management
Andrew Smart
 
Managing Information Risk in Financial Services
Managing Information Risk in Financial Services Managing Information Risk in Financial Services
Managing Information Risk in Financial Services
Andrew Smart
 
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk ManagementStrategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
Andrew Smart
 
Making Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As UsualMaking Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As Usual
Andrew Smart
 
StratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro VideoStratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro Video
Andrew Smart
 
Managing with KPI's and KRI's
Managing with KPI's and KRI's Managing with KPI's and KRI's
Managing with KPI's and KRI's
Andrew Smart
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
Andrew Smart
 
Middle east insurance market
Middle east insurance marketMiddle east insurance market
Middle east insurance marketAndrew Smart
 
Amnded stratexpoint screens1
Amnded stratexpoint screens1Amnded stratexpoint screens1
Amnded stratexpoint screens1Andrew Smart
 
HML Risk Transformation
HML Risk TransformationHML Risk Transformation
HML Risk Transformation
Andrew Smart
 
Greater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperGreater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperAndrew Smart
 
Manigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy ProcessManigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy Process
Andrew Smart
 
Manigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureManigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And Exposure
Andrew Smart
 

More from Andrew Smart (15)

FMM&A15-StratexSystems
FMM&A15-StratexSystemsFMM&A15-StratexSystems
FMM&A15-StratexSystems
 
StratexSystems_270115
StratexSystems_270115StratexSystems_270115
StratexSystems_270115
 
Cyber Risk Management
Cyber Risk Management Cyber Risk Management
Cyber Risk Management
 
Managing Information Risk in Financial Services
Managing Information Risk in Financial Services Managing Information Risk in Financial Services
Managing Information Risk in Financial Services
 
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk ManagementStrategic Planning Society Webinar- Integrating Strategy and Risk Management
Strategic Planning Society Webinar- Integrating Strategy and Risk Management
 
Making Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As UsualMaking Conduct Risk [Good] Business As Usual
Making Conduct Risk [Good] Business As Usual
 
StratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro VideoStratexPoint Risk Management Solution Intro Video
StratexPoint Risk Management Solution Intro Video
 
Managing with KPI's and KRI's
Managing with KPI's and KRI's Managing with KPI's and KRI's
Managing with KPI's and KRI's
 
Enabling Effective Conduct Risk
Enabling Effective Conduct RiskEnabling Effective Conduct Risk
Enabling Effective Conduct Risk
 
Middle east insurance market
Middle east insurance marketMiddle east insurance market
Middle east insurance market
 
Amnded stratexpoint screens1
Amnded stratexpoint screens1Amnded stratexpoint screens1
Amnded stratexpoint screens1
 
HML Risk Transformation
HML Risk TransformationHML Risk Transformation
HML Risk Transformation
 
Greater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service WhitepaperGreater Manchester Fire and Rescue Service Whitepaper
Greater Manchester Fire and Rescue Service Whitepaper
 
Manigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy ProcessManigent Embedding Risk Appetite Within The Strategy Process
Manigent Embedding Risk Appetite Within The Strategy Process
 
Manigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And ExposureManigent Aligning Risk Appetite And Exposure
Manigent Aligning Risk Appetite And Exposure
 

Recently uploaded

The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
Bojamma2
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
fisherameliaisabella
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
Operational Excellence Consulting
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
Workforce Group
 
LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024
Lital Barkan
 
April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
NathanBaughman3
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
Nicola Wreford-Howard
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
Sam H
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
Falcon Invoice Discounting
 
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptxCADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
fakeloginn69
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
awaisafdar
 
Skye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto AirportSkye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto Airport
marketingjdass
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
tanyjahb
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
zechu97
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
BBPMedia1
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
dylandmeas
 
20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf
tjcomstrang
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
Ben Wann
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Avirahi City Dholera
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
BBPMedia1
 

Recently uploaded (20)

The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
 
LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024
 
April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
 
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptxCADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
 
Skye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto AirportSkye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto Airport
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
 
20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
 

Embedding RCSA into Strategic Planning and Business Strategy

  • 1. Embedding RCSA into Strategic Planning and Business Strategy Operatiivisten Riskien Hallinta, Helsinki, Finland Andrew Smart, Ascendore
  • 2. Post credit crunch, financial services firms are drowning under a tsunami of regulatory change, cost and complexity 2 Run the Bank £200bn plus fines 492% Annual increase regulatory change
  • 3. 3 The cost & complexity of operational risk & compliance is too high and there is a “disproportionate risk aversion creeping into decision-making” Chairman, HBSC, 2015 Accenture Risk Study, 2017
  • 4. Boards and executives should be able to answer these questions with confidence. 4 Are we in control? Are we going to deliver our strategy? Are we operating within appetite?
  • 5. RCSA - an essential part of an integrated framework Better Conversation Better Decisions Better Action-taking Better Results Risk & Control Self- Assessment (RCSA) processes and data should be an essential part of an integrated Strategy & Risk Management framework; an integral part of enterprise management reporting. 5
  • 6. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 6
  • 7. 7 Strategy Strategic Drivers Business Objectives Operational Enablers Compliance Enablers Over the long-term, where are we going and how will we get there? Critical few things from the business model that enable the delivery of the strategy To deliver our long-term strategy what is the focus over the next 12-24 months? Where do we need to excel day-to-day What are the ‘rules’ that define our operating environment?
  • 8. Risk Appetite defines the boundaries for risk-takingStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT RISK THRESHOLDS RISK EXPOSURES Compliance Enablers 8
  • 9. Manage threats & opportunities via the risk taxonomyStrategy Strategic Drivers Business Objectives Operational Enablers APPETITE ALIGNMENT STRATEGIC RISK EXECUTION RISK OPERATIONAL RISK COMPLIANCE RISK Compliance Enablers 9
  • 10. Managed at every level in the framework Strategy Strategic Drivers Business Objectives Operational Enablers StrategicRisk Execution Risk Compliance Risk APPETITE ALIGNMENT ACCOUNTABILITY ALIGNMENT CASCADE ASSESSMENT MEASUREMENT ACTION-TAKING Operational Risk Compliance Enablers 10
  • 11. The RACI framework is a proven approach to embedding accountability and clarification of roles in decision-making. Supports the 3 Lines of Defence InformResponsible(s)Accountable Consult 11
  • 12. How do your operational and regulatory enablers relate to strategy? Alignment mapping can identify gaps; areas where your strategy is not supported or where operational resources are been wasted. Regulatory rules mapping provide assurance that processes and initiatives are in place to meet regulatory obligations and identify gaps; where are the gaps or weaknesses in our regulatory response landscape? 12 Key ControlsKey RisksObjectiveEntity Processes Initiatives Technology
  • 13. How does strategy & risk cascade through the firm? Board & Senior Management assurance is enhanced by understanding the cascading of objectives & risks through the firm. Identify gaps in consolidated reporting by linking objectives, risks and controls in ‘cascade chains’ through the firm. Where does the chain break? 13 Key Risk (Strategic Risk) Corporate Division Department Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk) Key Risk (Strategic Risk) Key Risk (Operational Risk)
  • 14. Data points to inform your Risk Self- Assessments 14 MAXIMUM INHERENT RESIDUAL % $£€ IMPACT(S) LIKELIHOOD EXPOSURE DRIVERS use driver(s) as the basis for assessing impacts thus linking risk back to strategy ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. KRIs Losses / Near Misses Expert Judgement Scenarios & Models Related KPIs & KCIs Control Self Assessment
  • 15. Data points to inform your Control Self-Assessments 15 KCIs Losses / Near Misses ASSESSMENT FREQUENCY assess risks on a pre-determined frequency (daily, weekly, monthly, quarterly, annually) and/or on an event driven basis. Control Testing Related KPIs & KRIs DESIGN PERFORMANCE CONTROL EFFECTIVENESS
  • 16. Three types of related indicators to give a full picture RAG is common practice RAGAR is best practice 16 Key Performance Indicators (KPIs) Used to define performance thresholds and targets; and to monitor progress towards achieving these targets. Key Risk Indicators (KRIs) Used to define risk thresholds and targets; to monitor changes within the risk environment. Key Control Indicators (KCIs) Used to define control thresholds and targets; to monitor changes within the controls environment. BASELINE LT 1 LT 2 UT2 UT 1 TARGET T 2 T 1
  • 17. Assessment and measurement is not enough. Action-taking is critical in driving performance & managing risk Typically we think about two types of actions 17 Improvement Actions Audit Actions
  • 18. Tools to bring it all together 18 Better Action- taking Better Decisions Better Results Strategy Map Better Conversations Appetite Alignment Matrix Risk Appetite Risk Map
  • 19. Map Business Objectives & their causal relationship to improve the communication, monitoring and management of strategic and operational performance. 19
  • 20. Define risk tolerances across the framework reflecting the materiality of the business unit. Use Drivers to link RCSA back to Strategy. 20
  • 21. The Risk Map provides a visual overview of the risk profile and make it easy to identify potential risk issues. Four perspectives risk map is aligned to the Strategy Map. 21
  • 22. Starting with Strategic Drivers, define Risk Appetite across the framework, reflecting the materiality and strategic intent of the business unit. 22
  • 23. The Appetite Alignment Matrix visualise the alignment of risk- taking to risk appetite showing where the firm is aligned, over- exposed and under-exposed. 23
  • 24. Are we operating within appetite? 24
  • 25. Appetite, Performance, Risk and Controls Effectiveness should be assessed, measured and aligned across the organisational hierarchy and within the taxonomy within the framework. 25 STRATEGY typically strategy is cascaded top-down DATA typically data flows up the organization EXECUTION typically execution is driven from the middle Corporate Divisions Departments STRATEGIC RISK EXECUTION RISK OPERATIONAL & COMPLIANCE RISK
  • 26. 26 STRATEGY MAP Are we on track to deliver the strategy? APPETITE ALIGNMENT MATRIX Are we operating within appetite? RISK APPETITE How much risk is acceptable? RISK MAP What level of risk are we taking?
  • 27. Benefits of Improved Strategic Execution ▪ A growth in shareholder value of 150%, driven by a 180% growth in profits and a 120% growth in revenue ▪ A 50% improvement in customer satisfaction ▪ A 50% improvement in key process effectiveness ▪ A 25% improvement in employee satisfaction, leading to a 50% reduction in employee turnover Benefits of an Integrated approach ▪ Transformed our approach to risk and regulatory compliance over 12-month ▪ Reduce the value of our operational losses by 94%, the volume by 63% and our economic capital provision by 23%” ▪ Eliminate 11 spreadsheet systems ▪ Enabled us to secure a 3% regulatory capital release and reduce our cost of capital significantly 27 Benefits of Enterprise Risk Management ▪ Increasing the range of opportunities ▪ Identifying and managing risk entity- wide ▪ Increasing positive outcomes and advantage while reducing negative surprises ▪ Reducing performance variability ▪ Improving resource deployment ▪ Enhancing enterprise resilience Results based on 3 year performance of BSC Hall of Frame winners COSO ERM Framework, 2017 Example benefits reported by Ascendore customers Study of 275 insurance companies showed those implementing an ERM program over an 11 year period enjoyed a 20% premium in firm value compared to those that didn't. Standard & Poor's "ERM opinion" rating program reported firm rated as having an "excellent" or "strong" ERM program reported a stronger positive change in equity prices and lower stock volatility than peers.
  • 28. We believe that risk management and compliance must enable strategy execution and value creation, not simply tick regulatory boxes. 28 “we have reduced our Pillar 2 capital by 81.2% while delivering a 94% reduction in the value of errors and a 63% reduction in the volume of errors” Head of Enterprise Risk, Homeloan Management Limited We provide Integrated GRC (Governance, Risk and Compliance) solutions to financial services firms and their regulators built on familiar, everyday office tools; SharePoint, Office 365 & the Cloud.
  • 29. COSO ERM Framework 2017 Risk-Based Performance Management 29
  • 30. What is Risk-Based Performance Management? Enhance Shareholder value Control Cost & Complexity Drive Accountability Align the firm Risk-Based Performance Management (RBPM) is an strategic execution approach which integrates business strategy, risk appetite, performance management and risk management. 30
  • 31. Integrated Strategy & Risk Management Framework APPETITE ALIGNMENT APPETITESTRATEGY PERFORMANCE RISK 31
  • 32. Embedding RCSA into Strategic Planning and Business Strategy? Andrew Smart Ascendore