SlideShare a Scribd company logo
Reporting to the Board on
Corporate Compliance: Informed
Decision Making
Hello!
I am John Jason
Canadian Compliance Group
john.jason@cancomgroup.com
The Board and Regulatory
Compliance
The Board and Regulatory Compliance
▪ Corporate statutes generally provide that it is the responsibility
of the board to supervise the management of the corporation
Leading Cases:
▪ In Re Caremark International Inc. Derivative Litigation
▪ Stone v. Ritter
▪ Directors must be reasonably informed concerning the
corporation
The Board and Regulatory Compliance
Directors must assure themselves that:
▪ Information and reporting systems exist
▪ These systems are reasonably designed to provide senior
management and the board with timely, accurate information
sufficient to allow them to reach informed judgments
concerning compliance with law
The Board and Regulatory Compliance
▪ The board must exercise a good faith judgment that the
corporation’s information and reporting system is adequate in
both concept and design
▪ Once these systems are implemented, the board must take
steps to monitor or oversee their operations
Basel Committee Corporate
Governance Guidance
Basel Committee Corporate Governance Guidance
The Board:
▪ Is responsible for overseeing the management of compliance risk
▪ Should establish a compliance function and approve the bank’s
policies and processes for identifying, assessing, monitoring and
reporting and advising on compliance risk
The Compliance Function:
▪ Should advise the board on the bank’s compliance with
applicable laws, rules and standards and keep them informed of
developments in the area
Basel Committee Corporate Governance Guidance
Goal of Risk Reporting
▪ Information should be communicated to the board in a timely,
accurate and understandable manner
▪ While the board should be sufficiently informed, reports should
avoid voluminous information that makes it difficult to identify
key issues
▪ Information should be prioritised and presented in a concise, fully
contextualised manner
Basel Committee Corporate Governance Guidance
Report to the Board
▪ Senior management should, with the assistance of the
compliance function, at least once a year, report to the board on
the management of compliance risk
▪ The report should be made in such a manner as to assist board
members to make an informed judgment on whether compliance
risk is being managed effectively
Basel Committee Corporate Governance Guidance
The head of compliance should report on a regular basis to senior
management on:
▪ The compliance risk assessment conducted during the period,
including any changes in the compliance risk profile
▪ Relevant measurements such as performance indicators
▪ Identified breaches and/or deficiencies
▪ Corrective measures recommended to address them and
corrective measures already taken
Oversight Functions
Oversight Functions
Role of Functions
▪ Provide independent and objective assessments to the
directors to allow them to fulfill their responsibilities
▪ Identify, measure, and report on the FRFI’s risks
▪ Assess the effectiveness of the FRFI’s risk management and
internal controls
▪ Determine whether the FRFI’s operations, results and risk
exposures are consistent with the FRFI’s risk appetite.
Oversight Functions
Heads of the Oversight Functions Should:
▪ Have sufficient stature and authority within the organization
▪ Be independent from operational management
▪ Have unfettered access and a direct reporting line to the
board or the appropriate board committee
Role of the Board
Board must regularly review and discuss:
▪ FRFI’s exposure to material regulatory compliance risk
▪ Significant RCM policies
▪ CCO reports and Internal Audit or other independent review
function reports, as appropriate
▪ Progress in implementing remedial actions taken with respect to
instances of material non-compliance or control weakness, and
▪ Effectiveness of compliance oversight
Responsibilities of the CCO
The CCO should be responsible for:
▪ Assessing the adequacy of, adherence to and effectiveness of
the FRFI’s day-to-day controls
▪ Providing an opinion to the board whether, based on the
independent monitoring and testing conducted, the RCM
controls are sufficiently robust to achieve compliance with the
applicable regulatory requirements enterprise-wide
▪ The opinion should be supported by sufficient pertinent
information that is verified or reasonably verifiable
What is the Basis for the Opinion?
Self-Assessments and Testing
Depending on available resources opinion can be based on:
▪ Self-assessments from accountable executives
(guided or ad hoc)
▪ Hands-on compliance testing
Is the Opinion Subjective or Objective?
Compliant Versus Effective Program
Even programs that incorporate a significant testing program can
result in subjective opinions.
▪ Why?
▪ Testing can never cover the universe of risks
Inputs Require Subjective Measurement
Program Effectiveness
▪ Although the equation is simple:
Inherent Risk – Control effectiveness = Residual Risk
▪ Assessing the components often requires a subjective
assessment
Example: Monitoring is a component of an effective control
How much monitoring is enough?
Is it Possible to Introduce
Objective Measurements?
Three Critical Areas
Three areas where measurement is essential:
▪ Risk Assessments
▪ Issue Classification
▪ KPIs and KRIs
Risk Assessments
▪ Identifies not only what are the biggest risks but why they are the
biggest
▪ Risk Assessments:
Provide a basis for resource decisions
▪ How many
▪ What kind
▪ Educate management and the board about the nature and level of
risk
What are the benefits
Input in many critical compliance steps
▪ Resourcing and allocation
▪ Control assessment
▪ Issue priority
▪ Reporting
▪ Monitoring
Developing a Measurement System
▪ What is the potential universe of data?
▪ Are the requirements straightforward or complex?
▪ Are the regulations stable or constantly changing?
▪ Are our products stable or do they constantly change?
▪ Do we control all of the processes or have they been outsourced?
Develop the Scorecard
Likelihood Scores
Complexity of Regulation
(High) Regulation imposes multiple requirements or detailed analysis
(Medium) Multiple requirements but the analysis is straightforward
(Low) Straightforward requirement
Complexity of Business
(High) Complex and involves the application of specialized skill
(Medium) Moderate degree of complexity and skill
(Low) Straightforward business not requiring advanced training or
skill
Impact Scores
Business objective subject to regulatory requirement
(High) Core objective
(Medium) Business unit objective
(Low) Local objective
Degree of impact on business objective
(High) Would prevent or materially alter achievement of objective
(Medium) May significantly delay or impact cost of achievement of objective
(Low) Nominal impact to timing or cost of achieving objective
Scoring Grid
RISK ASSESSMENT CHART
RISK SCORING
0 TO 4 TRIVIAL TO LOW RISK
5 TO 14 MODERATE TO MAJOR RISK
16 OR HIGHER HIGH TO SEVERE RISK
Benefits of Scorecard
▪ Risks identified on the basis of some empirical data
▪ Mix of objective and subjective data provides a more accurate
assessment
▪ Accumulation of several subjective elements reduces the impact
of judgment
Issue Reporting
▪ Tendency is to report issues as if they were all the same
magnitude
▪ Size the Compliance Gap
▪ Examples
Major Control Issue
Significant Control Issue
Minor Control Issue
▪ Incorporate inherent risk score
▪ Size of Gap + Inherent Risk Score = Issue Priority
KPIs
▪ Example: How are the 3 lines of defense functioning?
▪ Performance issue with framework as too many issues
identified by regulators
KRIs
▪ Example: New Initiatives
▪ Number of initiatives rated as high risk
▪ Indicates potential risk of non-compliance as number of new
initiatives may exceed ability to absorb
KRIs
▪ Example: Regulatory Change
▪ Number of New Regulations
▪ Indicates potential risk of non-compliance as amount of
regulatory change may exceed ability to absorb
KRIs
▪ Example: Compliance Monitoring/Audit
▪ Percent of High Risk Requirements Subject to Monitoring
▪ Indicates potential risk of non-compliance as monitoring
inadequate
What Do Boards Really Want to Know?
What they want to know:
▪ Is the organization in compliance?
What they should want to know:
▪ Why do you think the organization is in compliance?
Thanks!
Any questions?
john.jason@cancomgroup.com
Reporting to the Board on Corporate Compliance
Reporting to the Board on Corporate Compliance
Reporting to the Board on Corporate Compliance
Reporting to the Board on Corporate Compliance
Reporting to the Board on Corporate Compliance
Reporting to the Board on Corporate Compliance

More Related Content

What's hot

Corporate Compliance Overview
Corporate Compliance OverviewCorporate Compliance Overview
Corporate Compliance Overview
Sam Carr
 
Trade Life Cycle Presentation.pptx
Trade Life Cycle Presentation.pptxTrade Life Cycle Presentation.pptx
Trade Life Cycle Presentation.pptx
AnkitCapoor1
 
Kyc (know your customer)
Kyc (know your customer)Kyc (know your customer)
Kyc (know your customer)Kapil Rajput
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
Asad Hameed
 
Chapter 1 risk management
Chapter 1 risk managementChapter 1 risk management
Chapter 1 risk management
Rione Drevale
 
Treasury operations in_banks
Treasury operations in_banksTreasury operations in_banks
Treasury operations in_banksVaibhav Banjan
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management
Colleen Beck-Domanico
 
Types of Risks and its Management in Banking
Types of Risks and its Management in BankingTypes of Risks and its Management in Banking
Types of Risks and its Management in Banking
Mohit Chhabra
 
Bank analysis and rating using the CAMEL model
Bank analysis and rating using the CAMEL modelBank analysis and rating using the CAMEL model
Bank analysis and rating using the CAMEL modelRoger Aung
 
Risk management in banks
Risk management in banksRisk management in banks
Risk management in banks
eduCBA
 
Real Estate Investment Trust
Real Estate Investment TrustReal Estate Investment Trust
Real Estate Investment TrustHafizul Mukhlis
 
CORPORATE GOVERNANCE IN INDIA
CORPORATE GOVERNANCE IN INDIACORPORATE GOVERNANCE IN INDIA
CORPORATE GOVERNANCE IN INDIA
Sahil Nagpal
 
GST Presentation as on April 2017
GST Presentation as on April 2017GST Presentation as on April 2017
GST Presentation as on April 2017
Shakir Shaikh
 
ALM- an introduction
ALM- an  introductionALM- an  introduction
ALM- an introduction
Kumar Rakesh Chandra
 
Concept Of Risk Management PowerPoint presentation Slides
Concept Of Risk Management PowerPoint presentation SlidesConcept Of Risk Management PowerPoint presentation Slides
Concept Of Risk Management PowerPoint presentation Slides
SlideTeam
 
Tax Audit
Tax AuditTax Audit
Tax Audit
Harshit Arora
 
Risk Management in Banking Sectors.
Risk Management in Banking Sectors.Risk Management in Banking Sectors.
Risk Management in Banking Sectors.
Rupesh neupane
 
Credit Risk Management
Credit Risk ManagementCredit Risk Management
Credit Risk Management
Maryum Sarwar
 

What's hot (20)

Corporate Compliance Overview
Corporate Compliance OverviewCorporate Compliance Overview
Corporate Compliance Overview
 
Trade Life Cycle Presentation.pptx
Trade Life Cycle Presentation.pptxTrade Life Cycle Presentation.pptx
Trade Life Cycle Presentation.pptx
 
Kyc (know your customer)
Kyc (know your customer)Kyc (know your customer)
Kyc (know your customer)
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
 
Chapter 1 risk management
Chapter 1 risk managementChapter 1 risk management
Chapter 1 risk management
 
Treasury operations in_banks
Treasury operations in_banksTreasury operations in_banks
Treasury operations in_banks
 
Aml cft training programme
Aml cft training programmeAml cft training programme
Aml cft training programme
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management
 
Basel-2
Basel-2Basel-2
Basel-2
 
Types of Risks and its Management in Banking
Types of Risks and its Management in BankingTypes of Risks and its Management in Banking
Types of Risks and its Management in Banking
 
Bank analysis and rating using the CAMEL model
Bank analysis and rating using the CAMEL modelBank analysis and rating using the CAMEL model
Bank analysis and rating using the CAMEL model
 
Risk management in banks
Risk management in banksRisk management in banks
Risk management in banks
 
Real Estate Investment Trust
Real Estate Investment TrustReal Estate Investment Trust
Real Estate Investment Trust
 
CORPORATE GOVERNANCE IN INDIA
CORPORATE GOVERNANCE IN INDIACORPORATE GOVERNANCE IN INDIA
CORPORATE GOVERNANCE IN INDIA
 
GST Presentation as on April 2017
GST Presentation as on April 2017GST Presentation as on April 2017
GST Presentation as on April 2017
 
ALM- an introduction
ALM- an  introductionALM- an  introduction
ALM- an introduction
 
Concept Of Risk Management PowerPoint presentation Slides
Concept Of Risk Management PowerPoint presentation SlidesConcept Of Risk Management PowerPoint presentation Slides
Concept Of Risk Management PowerPoint presentation Slides
 
Tax Audit
Tax AuditTax Audit
Tax Audit
 
Risk Management in Banking Sectors.
Risk Management in Banking Sectors.Risk Management in Banking Sectors.
Risk Management in Banking Sectors.
 
Credit Risk Management
Credit Risk ManagementCredit Risk Management
Credit Risk Management
 

Similar to Reporting to the Board on Corporate Compliance

Risk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches WebinarRisk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches Webinar
Aviva Spectrum™
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinsteinAahil Malik
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinsteinRamaica Ona
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
Sukumar Reddy
 
UNCCInternalControls.pptx
UNCCInternalControls.pptxUNCCInternalControls.pptx
UNCCInternalControls.pptx
Aral20101
 
Upgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your OrganizationUpgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your Organization
International Federation of Accountants
 
Proactive Internal Auditing -- The Key to Improving Your Quality System
Proactive Internal Auditing -- The Key to Improving Your Quality SystemProactive Internal Auditing -- The Key to Improving Your Quality System
Proactive Internal Auditing -- The Key to Improving Your Quality System
SafetyChain Software
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Nimonik
 
Compliance Basics Presentation
Compliance Basics PresentationCompliance Basics Presentation
Compliance Basics Presentation
Compliagent
 
dt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformationdt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_TransformationMark Micallef
 
Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...
Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...
Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...
SAMTRAC International
 
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
International Federation of Accountants
 
Covering Your Bases McDonald
Covering Your Bases McDonaldCovering Your Bases McDonald
Covering Your Bases McDonald
EDR
 
Internal Audit Strategic Framework
Internal Audit Strategic FrameworkInternal Audit Strategic Framework
Internal Audit Strategic Framework
Jeremy Cheng
 
Risk review v diagnostic review
Risk review v diagnostic reviewRisk review v diagnostic review
Risk review v diagnostic review
AdamRice38
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
AstalapulosListestos
 

Similar to Reporting to the Board on Corporate Compliance (20)

The EISA Audit Presentation
The EISA Audit  PresentationThe EISA Audit  Presentation
The EISA Audit Presentation
 
Risk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches WebinarRisk Assessments Best Practice and Practical Approaches Webinar
Risk Assessments Best Practice and Practical Approaches Webinar
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
SFC Plan of engagement
SFC Plan of engagementSFC Plan of engagement
SFC Plan of engagement
 
UNCCInternalControls.pptx
UNCCInternalControls.pptxUNCCInternalControls.pptx
UNCCInternalControls.pptx
 
Upgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your OrganizationUpgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your Organization
 
2. Risk Management.pptx
2.  Risk Management.pptx2.  Risk Management.pptx
2. Risk Management.pptx
 
Proactive Internal Auditing -- The Key to Improving Your Quality System
Proactive Internal Auditing -- The Key to Improving Your Quality SystemProactive Internal Auditing -- The Key to Improving Your Quality System
Proactive Internal Auditing -- The Key to Improving Your Quality System
 
Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
 
Compliance Basics Presentation
Compliance Basics PresentationCompliance Basics Presentation
Compliance Basics Presentation
 
dt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformationdt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformation
 
2012-01-12 Audit Committees: Roles
2012-01-12 Audit Committees: Roles2012-01-12 Audit Committees: Roles
2012-01-12 Audit Committees: Roles
 
Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...
Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...
Oliver Laloux's The 'One Approach' - Integrating Risk Management, Governance ...
 
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
 
Covering Your Bases McDonald
Covering Your Bases McDonaldCovering Your Bases McDonald
Covering Your Bases McDonald
 
Internal Audit Strategic Framework
Internal Audit Strategic FrameworkInternal Audit Strategic Framework
Internal Audit Strategic Framework
 
Risk review v diagnostic review
Risk review v diagnostic reviewRisk review v diagnostic review
Risk review v diagnostic review
 
Enterprise risk management summary approach guide
Enterprise risk management summary approach guideEnterprise risk management summary approach guide
Enterprise risk management summary approach guide
 

More from Resolver Inc.

How to Prove the Value of Security Investments
How to Prove the Value of Security InvestmentsHow to Prove the Value of Security Investments
How to Prove the Value of Security Investments
Resolver Inc.
 
ERM Benchmarking Survey Results
ERM Benchmarking Survey ResultsERM Benchmarking Survey Results
ERM Benchmarking Survey Results
Resolver Inc.
 
Best Practices and ROI for Risk-based Vulnerability Management
Best Practices and ROI for Risk-based Vulnerability ManagementBest Practices and ROI for Risk-based Vulnerability Management
Best Practices and ROI for Risk-based Vulnerability Management
Resolver Inc.
 
Taking a Data-Driven Approach to Business Continuity
Taking a Data-Driven Approach to Business ContinuityTaking a Data-Driven Approach to Business Continuity
Taking a Data-Driven Approach to Business Continuity
Resolver Inc.
 
Terrorism in a Corporate Setting
Terrorism in a Corporate SettingTerrorism in a Corporate Setting
Terrorism in a Corporate Setting
Resolver Inc.
 
An Intro to Resolver's Compliance Application
An Intro to Resolver's Compliance ApplicationAn Intro to Resolver's Compliance Application
An Intro to Resolver's Compliance Application
Resolver Inc.
 
Information Security Best Practices: Keeping Your Company's Data Safe
Information Security Best Practices: Keeping Your Company's Data SafeInformation Security Best Practices: Keeping Your Company's Data Safe
Information Security Best Practices: Keeping Your Company's Data Safe
Resolver Inc.
 
Security Trends: From "Silos" to Integrated Risk Management
Security Trends: From "Silos" to Integrated Risk ManagementSecurity Trends: From "Silos" to Integrated Risk Management
Security Trends: From "Silos" to Integrated Risk Management
Resolver Inc.
 
Modelling your Business Processes with Resolver Core
Modelling your Business Processes with Resolver CoreModelling your Business Processes with Resolver Core
Modelling your Business Processes with Resolver Core
Resolver Inc.
 
How Resolver Uses Resolver
How Resolver Uses ResolverHow Resolver Uses Resolver
How Resolver Uses Resolver
Resolver Inc.
 
Scammed: Defend Against Social Engineering
Scammed: Defend Against Social EngineeringScammed: Defend Against Social Engineering
Scammed: Defend Against Social Engineering
Resolver Inc.
 
A Peek at adidas Group's Integrated Risk & Security Management Strategy
A Peek at adidas Group's Integrated Risk & Security Management StrategyA Peek at adidas Group's Integrated Risk & Security Management Strategy
A Peek at adidas Group's Integrated Risk & Security Management Strategy
Resolver Inc.
 
An Intro to Resolver's Resilience Application
An Intro to Resolver's Resilience ApplicationAn Intro to Resolver's Resilience Application
An Intro to Resolver's Resilience Application
Resolver Inc.
 
Data Driven Risk Assessment
Data Driven Risk AssessmentData Driven Risk Assessment
Data Driven Risk Assessment
Resolver Inc.
 
How to Achieve a Fully Integrated Approach to Business Resilience
How to Achieve a Fully Integrated Approach to Business ResilienceHow to Achieve a Fully Integrated Approach to Business Resilience
How to Achieve a Fully Integrated Approach to Business Resilience
Resolver Inc.
 
An Intro to Resolver's Risk Application
An Intro to Resolver's Risk ApplicationAn Intro to Resolver's Risk Application
An Intro to Resolver's Risk Application
Resolver Inc.
 
Keeping Your Data Clean
Keeping Your Data CleanKeeping Your Data Clean
Keeping Your Data Clean
Resolver Inc.
 
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Resolver Inc.
 
An Intro to Resolver's InfoSec Application (RiskVision)
An Intro to Resolver's InfoSec Application (RiskVision)An Intro to Resolver's InfoSec Application (RiskVision)
An Intro to Resolver's InfoSec Application (RiskVision)
Resolver Inc.
 
Leveraging Change Leadership to Find Success in your IRM Program
Leveraging Change Leadership to Find Success in your IRM ProgramLeveraging Change Leadership to Find Success in your IRM Program
Leveraging Change Leadership to Find Success in your IRM Program
Resolver Inc.
 

More from Resolver Inc. (20)

How to Prove the Value of Security Investments
How to Prove the Value of Security InvestmentsHow to Prove the Value of Security Investments
How to Prove the Value of Security Investments
 
ERM Benchmarking Survey Results
ERM Benchmarking Survey ResultsERM Benchmarking Survey Results
ERM Benchmarking Survey Results
 
Best Practices and ROI for Risk-based Vulnerability Management
Best Practices and ROI for Risk-based Vulnerability ManagementBest Practices and ROI for Risk-based Vulnerability Management
Best Practices and ROI for Risk-based Vulnerability Management
 
Taking a Data-Driven Approach to Business Continuity
Taking a Data-Driven Approach to Business ContinuityTaking a Data-Driven Approach to Business Continuity
Taking a Data-Driven Approach to Business Continuity
 
Terrorism in a Corporate Setting
Terrorism in a Corporate SettingTerrorism in a Corporate Setting
Terrorism in a Corporate Setting
 
An Intro to Resolver's Compliance Application
An Intro to Resolver's Compliance ApplicationAn Intro to Resolver's Compliance Application
An Intro to Resolver's Compliance Application
 
Information Security Best Practices: Keeping Your Company's Data Safe
Information Security Best Practices: Keeping Your Company's Data SafeInformation Security Best Practices: Keeping Your Company's Data Safe
Information Security Best Practices: Keeping Your Company's Data Safe
 
Security Trends: From "Silos" to Integrated Risk Management
Security Trends: From "Silos" to Integrated Risk ManagementSecurity Trends: From "Silos" to Integrated Risk Management
Security Trends: From "Silos" to Integrated Risk Management
 
Modelling your Business Processes with Resolver Core
Modelling your Business Processes with Resolver CoreModelling your Business Processes with Resolver Core
Modelling your Business Processes with Resolver Core
 
How Resolver Uses Resolver
How Resolver Uses ResolverHow Resolver Uses Resolver
How Resolver Uses Resolver
 
Scammed: Defend Against Social Engineering
Scammed: Defend Against Social EngineeringScammed: Defend Against Social Engineering
Scammed: Defend Against Social Engineering
 
A Peek at adidas Group's Integrated Risk & Security Management Strategy
A Peek at adidas Group's Integrated Risk & Security Management StrategyA Peek at adidas Group's Integrated Risk & Security Management Strategy
A Peek at adidas Group's Integrated Risk & Security Management Strategy
 
An Intro to Resolver's Resilience Application
An Intro to Resolver's Resilience ApplicationAn Intro to Resolver's Resilience Application
An Intro to Resolver's Resilience Application
 
Data Driven Risk Assessment
Data Driven Risk AssessmentData Driven Risk Assessment
Data Driven Risk Assessment
 
How to Achieve a Fully Integrated Approach to Business Resilience
How to Achieve a Fully Integrated Approach to Business ResilienceHow to Achieve a Fully Integrated Approach to Business Resilience
How to Achieve a Fully Integrated Approach to Business Resilience
 
An Intro to Resolver's Risk Application
An Intro to Resolver's Risk ApplicationAn Intro to Resolver's Risk Application
An Intro to Resolver's Risk Application
 
Keeping Your Data Clean
Keeping Your Data CleanKeeping Your Data Clean
Keeping Your Data Clean
 
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
 
An Intro to Resolver's InfoSec Application (RiskVision)
An Intro to Resolver's InfoSec Application (RiskVision)An Intro to Resolver's InfoSec Application (RiskVision)
An Intro to Resolver's InfoSec Application (RiskVision)
 
Leveraging Change Leadership to Find Success in your IRM Program
Leveraging Change Leadership to Find Success in your IRM ProgramLeveraging Change Leadership to Find Success in your IRM Program
Leveraging Change Leadership to Find Success in your IRM Program
 

Recently uploaded

Training- integrated management system (iso)
Training- integrated management system (iso)Training- integrated management system (iso)
Training- integrated management system (iso)
akaash13
 
Leadership Ethics and Change, Purpose to Impact Plan
Leadership Ethics and Change, Purpose to Impact PlanLeadership Ethics and Change, Purpose to Impact Plan
Leadership Ethics and Change, Purpose to Impact Plan
Muhammad Adil Jamil
 
TCS AI for Business Study – Key Findings
TCS AI for Business Study – Key FindingsTCS AI for Business Study – Key Findings
TCS AI for Business Study – Key Findings
Tata Consultancy Services
 
Case Analysis - The Sky is the Limit | Principles of Management
Case Analysis - The Sky is the Limit | Principles of ManagementCase Analysis - The Sky is the Limit | Principles of Management
Case Analysis - The Sky is the Limit | Principles of Management
A. F. M. Rubayat-Ul Jannat
 
Senior Project and Engineering Leader Jim Smith.pdf
Senior Project and Engineering Leader Jim Smith.pdfSenior Project and Engineering Leader Jim Smith.pdf
Senior Project and Engineering Leader Jim Smith.pdf
Jim Smith
 
一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证
一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证
一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证
gcljeuzdu
 
Founder-Game Director Workshop (Session 1)
Founder-Game Director  Workshop (Session 1)Founder-Game Director  Workshop (Session 1)
Founder-Game Director Workshop (Session 1)
Amir H. Fassihi
 
Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...
Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...
Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...
CIOWomenMagazine
 
W.H.Bender Quote 65 - The Team Member and Guest Experience
W.H.Bender Quote 65 - The Team Member and Guest ExperienceW.H.Bender Quote 65 - The Team Member and Guest Experience
W.H.Bender Quote 65 - The Team Member and Guest Experience
William (Bill) H. Bender, FCSI
 
SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....
SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....
SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....
juniourjohnstone
 

Recently uploaded (10)

Training- integrated management system (iso)
Training- integrated management system (iso)Training- integrated management system (iso)
Training- integrated management system (iso)
 
Leadership Ethics and Change, Purpose to Impact Plan
Leadership Ethics and Change, Purpose to Impact PlanLeadership Ethics and Change, Purpose to Impact Plan
Leadership Ethics and Change, Purpose to Impact Plan
 
TCS AI for Business Study – Key Findings
TCS AI for Business Study – Key FindingsTCS AI for Business Study – Key Findings
TCS AI for Business Study – Key Findings
 
Case Analysis - The Sky is the Limit | Principles of Management
Case Analysis - The Sky is the Limit | Principles of ManagementCase Analysis - The Sky is the Limit | Principles of Management
Case Analysis - The Sky is the Limit | Principles of Management
 
Senior Project and Engineering Leader Jim Smith.pdf
Senior Project and Engineering Leader Jim Smith.pdfSenior Project and Engineering Leader Jim Smith.pdf
Senior Project and Engineering Leader Jim Smith.pdf
 
一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证
一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证
一比一原版杜克大学毕业证(Duke毕业证)成绩单留信认证
 
Founder-Game Director Workshop (Session 1)
Founder-Game Director  Workshop (Session 1)Founder-Game Director  Workshop (Session 1)
Founder-Game Director Workshop (Session 1)
 
Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...
Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...
Oprah Winfrey: A Leader in Media, Philanthropy, and Empowerment | CIO Women M...
 
W.H.Bender Quote 65 - The Team Member and Guest Experience
W.H.Bender Quote 65 - The Team Member and Guest ExperienceW.H.Bender Quote 65 - The Team Member and Guest Experience
W.H.Bender Quote 65 - The Team Member and Guest Experience
 
SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....
SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....
SOCIO-ANTHROPOLOGY FACULTY OF NURSING.....
 

Reporting to the Board on Corporate Compliance

  • 1. Reporting to the Board on Corporate Compliance: Informed Decision Making
  • 2.
  • 3. Hello! I am John Jason Canadian Compliance Group john.jason@cancomgroup.com
  • 4. The Board and Regulatory Compliance
  • 5. The Board and Regulatory Compliance ▪ Corporate statutes generally provide that it is the responsibility of the board to supervise the management of the corporation Leading Cases: ▪ In Re Caremark International Inc. Derivative Litigation ▪ Stone v. Ritter ▪ Directors must be reasonably informed concerning the corporation
  • 6. The Board and Regulatory Compliance Directors must assure themselves that: ▪ Information and reporting systems exist ▪ These systems are reasonably designed to provide senior management and the board with timely, accurate information sufficient to allow them to reach informed judgments concerning compliance with law
  • 7. The Board and Regulatory Compliance ▪ The board must exercise a good faith judgment that the corporation’s information and reporting system is adequate in both concept and design ▪ Once these systems are implemented, the board must take steps to monitor or oversee their operations
  • 9. Basel Committee Corporate Governance Guidance The Board: ▪ Is responsible for overseeing the management of compliance risk ▪ Should establish a compliance function and approve the bank’s policies and processes for identifying, assessing, monitoring and reporting and advising on compliance risk The Compliance Function: ▪ Should advise the board on the bank’s compliance with applicable laws, rules and standards and keep them informed of developments in the area
  • 10. Basel Committee Corporate Governance Guidance Goal of Risk Reporting ▪ Information should be communicated to the board in a timely, accurate and understandable manner ▪ While the board should be sufficiently informed, reports should avoid voluminous information that makes it difficult to identify key issues ▪ Information should be prioritised and presented in a concise, fully contextualised manner
  • 11. Basel Committee Corporate Governance Guidance Report to the Board ▪ Senior management should, with the assistance of the compliance function, at least once a year, report to the board on the management of compliance risk ▪ The report should be made in such a manner as to assist board members to make an informed judgment on whether compliance risk is being managed effectively
  • 12. Basel Committee Corporate Governance Guidance The head of compliance should report on a regular basis to senior management on: ▪ The compliance risk assessment conducted during the period, including any changes in the compliance risk profile ▪ Relevant measurements such as performance indicators ▪ Identified breaches and/or deficiencies ▪ Corrective measures recommended to address them and corrective measures already taken
  • 14. Oversight Functions Role of Functions ▪ Provide independent and objective assessments to the directors to allow them to fulfill their responsibilities ▪ Identify, measure, and report on the FRFI’s risks ▪ Assess the effectiveness of the FRFI’s risk management and internal controls ▪ Determine whether the FRFI’s operations, results and risk exposures are consistent with the FRFI’s risk appetite.
  • 15. Oversight Functions Heads of the Oversight Functions Should: ▪ Have sufficient stature and authority within the organization ▪ Be independent from operational management ▪ Have unfettered access and a direct reporting line to the board or the appropriate board committee
  • 16. Role of the Board Board must regularly review and discuss: ▪ FRFI’s exposure to material regulatory compliance risk ▪ Significant RCM policies ▪ CCO reports and Internal Audit or other independent review function reports, as appropriate ▪ Progress in implementing remedial actions taken with respect to instances of material non-compliance or control weakness, and ▪ Effectiveness of compliance oversight
  • 17. Responsibilities of the CCO The CCO should be responsible for: ▪ Assessing the adequacy of, adherence to and effectiveness of the FRFI’s day-to-day controls ▪ Providing an opinion to the board whether, based on the independent monitoring and testing conducted, the RCM controls are sufficiently robust to achieve compliance with the applicable regulatory requirements enterprise-wide ▪ The opinion should be supported by sufficient pertinent information that is verified or reasonably verifiable
  • 18. What is the Basis for the Opinion? Self-Assessments and Testing Depending on available resources opinion can be based on: ▪ Self-assessments from accountable executives (guided or ad hoc) ▪ Hands-on compliance testing
  • 19. Is the Opinion Subjective or Objective? Compliant Versus Effective Program Even programs that incorporate a significant testing program can result in subjective opinions. ▪ Why? ▪ Testing can never cover the universe of risks
  • 20. Inputs Require Subjective Measurement Program Effectiveness ▪ Although the equation is simple: Inherent Risk – Control effectiveness = Residual Risk ▪ Assessing the components often requires a subjective assessment Example: Monitoring is a component of an effective control How much monitoring is enough?
  • 21. Is it Possible to Introduce Objective Measurements?
  • 22. Three Critical Areas Three areas where measurement is essential: ▪ Risk Assessments ▪ Issue Classification ▪ KPIs and KRIs
  • 23. Risk Assessments ▪ Identifies not only what are the biggest risks but why they are the biggest ▪ Risk Assessments: Provide a basis for resource decisions ▪ How many ▪ What kind ▪ Educate management and the board about the nature and level of risk
  • 24. What are the benefits Input in many critical compliance steps ▪ Resourcing and allocation ▪ Control assessment ▪ Issue priority ▪ Reporting ▪ Monitoring
  • 25. Developing a Measurement System ▪ What is the potential universe of data? ▪ Are the requirements straightforward or complex? ▪ Are the regulations stable or constantly changing? ▪ Are our products stable or do they constantly change? ▪ Do we control all of the processes or have they been outsourced?
  • 27. Likelihood Scores Complexity of Regulation (High) Regulation imposes multiple requirements or detailed analysis (Medium) Multiple requirements but the analysis is straightforward (Low) Straightforward requirement Complexity of Business (High) Complex and involves the application of specialized skill (Medium) Moderate degree of complexity and skill (Low) Straightforward business not requiring advanced training or skill
  • 28. Impact Scores Business objective subject to regulatory requirement (High) Core objective (Medium) Business unit objective (Low) Local objective Degree of impact on business objective (High) Would prevent or materially alter achievement of objective (Medium) May significantly delay or impact cost of achievement of objective (Low) Nominal impact to timing or cost of achieving objective
  • 29. Scoring Grid RISK ASSESSMENT CHART RISK SCORING 0 TO 4 TRIVIAL TO LOW RISK 5 TO 14 MODERATE TO MAJOR RISK 16 OR HIGHER HIGH TO SEVERE RISK
  • 30. Benefits of Scorecard ▪ Risks identified on the basis of some empirical data ▪ Mix of objective and subjective data provides a more accurate assessment ▪ Accumulation of several subjective elements reduces the impact of judgment
  • 31. Issue Reporting ▪ Tendency is to report issues as if they were all the same magnitude ▪ Size the Compliance Gap ▪ Examples Major Control Issue Significant Control Issue Minor Control Issue ▪ Incorporate inherent risk score ▪ Size of Gap + Inherent Risk Score = Issue Priority
  • 32. KPIs ▪ Example: How are the 3 lines of defense functioning? ▪ Performance issue with framework as too many issues identified by regulators
  • 33. KRIs ▪ Example: New Initiatives ▪ Number of initiatives rated as high risk ▪ Indicates potential risk of non-compliance as number of new initiatives may exceed ability to absorb
  • 34. KRIs ▪ Example: Regulatory Change ▪ Number of New Regulations ▪ Indicates potential risk of non-compliance as amount of regulatory change may exceed ability to absorb
  • 35. KRIs ▪ Example: Compliance Monitoring/Audit ▪ Percent of High Risk Requirements Subject to Monitoring ▪ Indicates potential risk of non-compliance as monitoring inadequate
  • 36. What Do Boards Really Want to Know? What they want to know: ▪ Is the organization in compliance? What they should want to know: ▪ Why do you think the organization is in compliance?