SlideShare a Scribd company logo
1
Risk Management and the Company Secretary
Gerard Joyce & David Devereux
Dublin
2nd April 2019
Overview
• Introduction
• Company Secretary’s (expanding) Role
• Elements of a Risk Management Framework
• Role and Responsibilities of the Board
• Role of the Company Secretary
• Cyber Risk Example
• Fraud Risk Example
Brakes Allow a Car to go Fast
3
Why Do Risk Management?
Because:
• Objectives
• Focus
• Forward looking
• Process identifies opportunities
• Better / Informed decision making
• Improved performance
• Effective governance demands It
4
The Expanding Role of the CS
Note Taker
Advisor to the Board
Duties, Obligations, Effective Board Processes
Responsible for Corporate Governance
Compliance with law
Submit reports / filings, maintain registers
Communication
With management, other stakeholders
Risk Management System
An effective risk management system identifies and assesses risk,
decides on appropriate responses and then provides assurance
that the chosen responses are effective.(Code of Practice for the Governance of State
Bodies)
Governance, Risk and Compliance
reliably achieve objectives [GOVERNANCE],
while addressing uncertainty [RISK MANAGEMENT] and acting
with integrity [COMPLIANCE] (Michael Rasmussen)
Governance
Risk
Management
Compliance
Risk Management Framework
The Role and Responsibilities of the Board
Risk Oversight
– Set the Risk Appetite
– Approve risk management policy
– Demand a robust risk management process
– Ensure processes aligned with strategy / objectives
– Appoint one individual to drive / report
– Monitor the risk management system
– Make risk a periodic agenda item
– Review risk information including incidents
– Review effectiveness of controls
Risk Appetite – How Much is Too Much
Risk Capacity
is the maximum amount of risk which the organisation is technically
able to assume before breaching constraints determined by capital,
borrowing capacity, regulations, reputation and operational
environment.
Risk Management Capability
the ability to manage risk exposures within desired risk limits.
(Understanding, measurement, skills & knowledge, controls and
oversight, culture..)
10
The Role of the Company Secretary
• May be the effective Chief Risk Officer
• May be consultant at the beginning of the journey
• May be the go-between when the RO is bringing a report to the
Board
• May be the Compliance Officer and a contributor to the overall
Risk Profile report
The Role and Responsibilities of Management
• Advise Board on RM policy and processes
• Define how risk is to be managed
• Implement the risk management framework
• Communicate policy and process to all
• Identify, Analyse, Treat Risks
• Monitor performance
• Implement risk mitigation plan
• Report to the Board
Reporting – What Boards Should Know
• What is the overall risk profile?
• What are the Top 10 risks
• What is threatening the Objectives
• Are existing controls working / effective?
• Have there been any near misses / incidents?
• Where are the gaps?
• Confirmation of the overall compliance position
• What is being done to address the gaps?
• Key Risk Indicators (KRIs)
Risk Management Fundamentals 13
Key Risk Indicators
Exposure Indicators
Changes in the nature of the business environment
Interest rates, exchange rates, unemployment rate, financial results of key customers, outstanding debt
Stress Indicators
Significant rise in the use of resources (people / material)
Sick days, accidents, system downtime, customer complaints, order levels, helpdesk calls
Causal Indicators
Drivers of some key risks to the business
Time to fill vacant positions, training completed, equipment age
Failure Indicators
Poor performance and failing controls
Missed targets, fraud, complaints, audit findings, data breaches, policy breaches
14
Example Data Breach Risk
15
Employee - Intentional
Unauthorised Access
Employee - Unintentional
Data
Breach
IT Glitch
Policy
Procedures
Training & Education
Checks
Robust Contracts
Strong Access Control
Encryption
Due Diligence
Data Classification
Monitor Feedback
Measure Service
Monitor Network Traffic
Maintain Good Comms
Monitor Data Integrity
Monitor Press / SocMed
Response Plan
Privacy Impact
Notification Plan
Communications Plan
Collect Evidence
Review Controls
Document Action
Cyber Insurance
ICSA
RISK MANAGEMENT
David Devereux - Director, BDO Risk & Advisory Services
2nd April 2019
17
BDO RANGE OF SERVICES
The BDO Global Risk Advisory Services practice shares the knowledge and best
practices gained from years of experience operating across 162 countries and
territories.
• Risk Management Framework Implementation
• Board Effectiveness
• Internal Audit
• Controls Advisory and Assessment
• SOx
• Corruption, Financial Reporting & Fraud Investigations
• Fraud and Anti-Corruption Compliance
• Investigative Due Diligence
• Forensic Accounting and Technology Services
• Cyber Risk Management
THANK YOU
DAVID DEVEREUX | DIRECTOR, BDO RISK & ADVISORY SERVICES

More Related Content

What's hot

The ippf in 2017
The ippf in 2017The ippf in 2017
The ippf in 2017
Dr. Zar Rdj
 
COSO Internal Control - Integrated Framework
COSO Internal Control - Integrated FrameworkCOSO Internal Control - Integrated Framework
COSO Internal Control - Integrated Framework
Aziz Fataliyev, Internal Audit Practitioner
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management FrameworkTreasury Consulting LLP
 
Introduction to risk management
Introduction to risk managementIntroduction to risk management
Introduction to risk management
Kannan Subbiah
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
Asad Hameed
 
Risk management
Risk managementRisk management
Risk management
MECandPMV
 
Risk based internal auditing
 Risk based internal auditing Risk based internal auditing
Risk based internal auditing
Frederick Altum Pokoo-Aikins
 
The role of internal audit department
The role of internal audit departmentThe role of internal audit department
The role of internal audit department
Salih Islam
 
Financial Risk Management Strategies
Financial Risk Management StrategiesFinancial Risk Management Strategies
Financial Risk Management Strategies
Advantique Group Pte Ltd
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Managementarsqureshi
 
Risk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling TechniquesRisk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling Techniques
Manoj Agarwal
 
Risk Mitigation
Risk MitigationRisk Mitigation
Risk Mitigation
primeteacher32
 
The Role of Internal Audit
The Role of Internal AuditThe Role of Internal Audit
The Role of Internal Audit
ArmeniaFED
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity ManagementECC International
 
Improving effectiveness of internal auditing
Improving effectiveness of internal auditingImproving effectiveness of internal auditing
Improving effectiveness of internal auditing
PECB
 
Risk management concepts and learning
Risk management   concepts and learningRisk management   concepts and learning
Risk management concepts and learning
Vanita Ahuja
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk management
Andre Knipe
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Resolver Inc.
 
Risk management
Risk managementRisk management
Risk management
RajuPrasad33
 

What's hot (20)

The ippf in 2017
The ippf in 2017The ippf in 2017
The ippf in 2017
 
COSO Internal Control - Integrated Framework
COSO Internal Control - Integrated FrameworkCOSO Internal Control - Integrated Framework
COSO Internal Control - Integrated Framework
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
Introduction to risk management
Introduction to risk managementIntroduction to risk management
Introduction to risk management
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
 
Risk management
Risk managementRisk management
Risk management
 
Risk based internal auditing
 Risk based internal auditing Risk based internal auditing
Risk based internal auditing
 
The role of internal audit department
The role of internal audit departmentThe role of internal audit department
The role of internal audit department
 
Financial Risk Management Strategies
Financial Risk Management StrategiesFinancial Risk Management Strategies
Financial Risk Management Strategies
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
 
Risk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling TechniquesRisk Based Internal Audit and Sampling Techniques
Risk Based Internal Audit and Sampling Techniques
 
Risk Mitigation
Risk MitigationRisk Mitigation
Risk Mitigation
 
The Role of Internal Audit
The Role of Internal AuditThe Role of Internal Audit
The Role of Internal Audit
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Improving effectiveness of internal auditing
Improving effectiveness of internal auditingImproving effectiveness of internal auditing
Improving effectiveness of internal auditing
 
Risk management concepts and learning
Risk management   concepts and learningRisk management   concepts and learning
Risk management concepts and learning
 
Enterprise risk management
Enterprise risk managementEnterprise risk management
Enterprise risk management
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Risk management
Risk managementRisk management
Risk management
 
Internal audit
Internal auditInternal audit
Internal audit
 

Similar to Risk Management and the Company Secretary

C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
Aronson LLC
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinsteinAahil Malik
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinsteinRamaica Ona
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
Sukumar Reddy
 
Bcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementBcu msc cg week 4 risk management
Bcu msc cg week 4 risk management
Stephen Ong
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A JourneyDebashis Gupta
 
Risk assessment and compliance 151119
Risk assessment and compliance 151119Risk assessment and compliance 151119
Risk assessment and compliance 151119
KAYODE ADEBIYI
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
Nidhi Gupta
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013Nidhi Gupta
 
2016 - IQPC - Understanding and Assessing Corruption Risk
2016 - IQPC - Understanding and Assessing Corruption Risk2016 - IQPC - Understanding and Assessing Corruption Risk
2016 - IQPC - Understanding and Assessing Corruption RiskDr Darren O'Connell AGIA
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a Strategy
NICSA
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013Nidhi Gupta
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013Nidhi Gupta
 
Risk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and ImplementationRisk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and Implementation
Risk Management Institution of Australasia
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
Risk Management Institution of Australasia
 
FERMA presentation at Athens conference
FERMA presentation at Athens conferenceFERMA presentation at Athens conference
FERMA presentation at Athens conference
FERMA
 
FORUM 2013 Entreprise risk management: fact or fiction
FORUM 2013 Entreprise risk management: fact or fictionFORUM 2013 Entreprise risk management: fact or fiction
FORUM 2013 Entreprise risk management: fact or fictionFERMA
 

Similar to Risk Management and the Company Secretary (20)

C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
1 -corinne_berinstein
1  -corinne_berinstein1  -corinne_berinstein
1 -corinne_berinstein
 
Bcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementBcu msc cg week 4 risk management
Bcu msc cg week 4 risk management
 
Risk Management - A Journey
Risk Management - A JourneyRisk Management - A Journey
Risk Management - A Journey
 
Risk assessment and compliance 151119
Risk assessment and compliance 151119Risk assessment and compliance 151119
Risk assessment and compliance 151119
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
2016 - IQPC - Understanding and Assessing Corruption Risk
2016 - IQPC - Understanding and Assessing Corruption Risk2016 - IQPC - Understanding and Assessing Corruption Risk
2016 - IQPC - Understanding and Assessing Corruption Risk
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a Strategy
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
Risk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and ImplementationRisk Technology Strategy, Selection and Implementation
Risk Technology Strategy, Selection and Implementation
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
 
FERMA presentation at Athens conference
FERMA presentation at Athens conferenceFERMA presentation at Athens conference
FERMA presentation at Athens conference
 
FORUM 2013 Entreprise risk management: fact or fiction
FORUM 2013 Entreprise risk management: fact or fictionFORUM 2013 Entreprise risk management: fact or fiction
FORUM 2013 Entreprise risk management: fact or fiction
 

More from Institute of Chartered Secretaries and Administrators

Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Institute of Chartered Secretaries and Administrators
 
ICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slidesICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slides
Institute of Chartered Secretaries and Administrators
 
ICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slidesICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slides
Institute of Chartered Secretaries and Administrators
 
Board effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluationBoard effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluation
Institute of Chartered Secretaries and Administrators
 
ICSA qualifying programme update 2019
ICSA qualifying programme update 2019 ICSA qualifying programme update 2019
ICSA qualifying programme update 2019
Institute of Chartered Secretaries and Administrators
 
ICSA CPD - Cyber breaches
ICSA CPD -   Cyber breachesICSA CPD -   Cyber breaches
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
Institute of Chartered Secretaries and Administrators
 
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
Institute of Chartered Secretaries and Administrators
 
ICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight TechnologiesICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight Technologies
Institute of Chartered Secretaries and Administrators
 
ICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 MayICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 May
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region General Data Protection Regulation event, 10 October 2017
ICSA Irish Region General Data Protection Regulation event, 10 October 2017ICSA Irish Region General Data Protection Regulation event, 10 October 2017
ICSA Irish Region General Data Protection Regulation event, 10 October 2017
Institute of Chartered Secretaries and Administrators
 
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
Institute of Chartered Secretaries and Administrators
 
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Institute of Chartered Secretaries and Administrators
 
Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017
Institute of Chartered Secretaries and Administrators
 
Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017 Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017
Institute of Chartered Secretaries and Administrators
 

More from Institute of Chartered Secretaries and Administrators (20)

Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
Board effectiveness and performance beyond the annual evaluation_ICSA Dublin ...
 
ICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slidesICSA Jersey Conference 2019 - Updated presentation slides
ICSA Jersey Conference 2019 - Updated presentation slides
 
ICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slidesICSA Guernsey Conference 2019 - Updated presentation slides
ICSA Guernsey Conference 2019 - Updated presentation slides
 
Board effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluationBoard effectiveness and performance beyond the annual evaluation
Board effectiveness and performance beyond the annual evaluation
 
ICSA qualifying programme update 2019
ICSA qualifying programme update 2019 ICSA qualifying programme update 2019
ICSA qualifying programme update 2019
 
ICSA CPD - Cyber breaches
ICSA CPD -   Cyber breachesICSA CPD -   Cyber breaches
ICSA CPD - Cyber breaches
 
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
ICSA Competency Framework presentation for Guernsey branch - 26 February 2019
 
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
ICSA Ireland CPD_Senior Executive Accountability Regime_Deloitte 22Jan19
 
ICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight TechnologiesICSA Ireland CPD event - Essential Eight Technologies
ICSA Ireland CPD event - Essential Eight Technologies
 
ICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 MayICSA Ireland Conference 2018, 17 May
ICSA Ireland Conference 2018, 17 May
 
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
ICSA Irish Region Directors' Duties (Dublin) CPD event, 24 April 2018
 
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
ICSA Irish Region Directors' Duties (Cork) CPD event, 10 April 2018
 
ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018ICSA Irish Region Audit Committees CPD event, 6 March 2018
ICSA Irish Region Audit Committees CPD event, 6 March 2018
 
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
ICSA Irish Region Effective Minute Taking CPD event, 12 December 2017
 
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
ICSA Irish Region Effective Board Reporting CPD event, 5 December 2017
 
ICSA Irish Region General Data Protection Regulation event, 10 October 2017
ICSA Irish Region General Data Protection Regulation event, 10 October 2017ICSA Irish Region General Data Protection Regulation event, 10 October 2017
ICSA Irish Region General Data Protection Regulation event, 10 October 2017
 
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017ICSA Irish Region the Minuting of Meetings event, 12 September 2017
ICSA Irish Region the Minuting of Meetings event, 12 September 2017
 
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
Ireland Directors' Compliance Statement and Audit Committees event, 20 June 2017
 
Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017Yorkshire Branch Meeting 28 June 2017
Yorkshire Branch Meeting 28 June 2017
 
Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017 Guernsey Minute Taking event, 28 June 2017
Guernsey Minute Taking event, 28 June 2017
 

Recently uploaded

Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
Aurelien Domont, MBA
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Arihant Webtech Pvt. Ltd
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
RajPriye
 
Skye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto AirportSkye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto Airport
marketingjdass
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
ofm712785
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
zechu97
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
Workforce Group
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
BBPMedia1
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Avirahi City Dholera
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
Falcon Invoice Discounting
 
20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf
tjcomstrang
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
agatadrynko
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
creerey
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
BBPMedia1
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
Cynthia Clay
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Lviv Startup Club
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
Bojamma2
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
SynapseIndia
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
Sam H
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
KaiNexus
 

Recently uploaded (20)

Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
 
Skye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto AirportSkye Residences | Extended Stay Residences Near Toronto Airport
Skye Residences | Extended Stay Residences Near Toronto Airport
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
 
20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
 

Risk Management and the Company Secretary

  • 1. 1 Risk Management and the Company Secretary Gerard Joyce & David Devereux Dublin 2nd April 2019
  • 2. Overview • Introduction • Company Secretary’s (expanding) Role • Elements of a Risk Management Framework • Role and Responsibilities of the Board • Role of the Company Secretary • Cyber Risk Example • Fraud Risk Example
  • 3. Brakes Allow a Car to go Fast 3
  • 4. Why Do Risk Management? Because: • Objectives • Focus • Forward looking • Process identifies opportunities • Better / Informed decision making • Improved performance • Effective governance demands It 4
  • 5. The Expanding Role of the CS Note Taker Advisor to the Board Duties, Obligations, Effective Board Processes Responsible for Corporate Governance Compliance with law Submit reports / filings, maintain registers Communication With management, other stakeholders
  • 6. Risk Management System An effective risk management system identifies and assesses risk, decides on appropriate responses and then provides assurance that the chosen responses are effective.(Code of Practice for the Governance of State Bodies)
  • 7. Governance, Risk and Compliance reliably achieve objectives [GOVERNANCE], while addressing uncertainty [RISK MANAGEMENT] and acting with integrity [COMPLIANCE] (Michael Rasmussen) Governance Risk Management Compliance
  • 9. The Role and Responsibilities of the Board Risk Oversight – Set the Risk Appetite – Approve risk management policy – Demand a robust risk management process – Ensure processes aligned with strategy / objectives – Appoint one individual to drive / report – Monitor the risk management system – Make risk a periodic agenda item – Review risk information including incidents – Review effectiveness of controls
  • 10. Risk Appetite – How Much is Too Much Risk Capacity is the maximum amount of risk which the organisation is technically able to assume before breaching constraints determined by capital, borrowing capacity, regulations, reputation and operational environment. Risk Management Capability the ability to manage risk exposures within desired risk limits. (Understanding, measurement, skills & knowledge, controls and oversight, culture..) 10
  • 11. The Role of the Company Secretary • May be the effective Chief Risk Officer • May be consultant at the beginning of the journey • May be the go-between when the RO is bringing a report to the Board • May be the Compliance Officer and a contributor to the overall Risk Profile report
  • 12. The Role and Responsibilities of Management • Advise Board on RM policy and processes • Define how risk is to be managed • Implement the risk management framework • Communicate policy and process to all • Identify, Analyse, Treat Risks • Monitor performance • Implement risk mitigation plan • Report to the Board
  • 13. Reporting – What Boards Should Know • What is the overall risk profile? • What are the Top 10 risks • What is threatening the Objectives • Are existing controls working / effective? • Have there been any near misses / incidents? • Where are the gaps? • Confirmation of the overall compliance position • What is being done to address the gaps? • Key Risk Indicators (KRIs) Risk Management Fundamentals 13
  • 14. Key Risk Indicators Exposure Indicators Changes in the nature of the business environment Interest rates, exchange rates, unemployment rate, financial results of key customers, outstanding debt Stress Indicators Significant rise in the use of resources (people / material) Sick days, accidents, system downtime, customer complaints, order levels, helpdesk calls Causal Indicators Drivers of some key risks to the business Time to fill vacant positions, training completed, equipment age Failure Indicators Poor performance and failing controls Missed targets, fraud, complaints, audit findings, data breaches, policy breaches 14
  • 15. Example Data Breach Risk 15 Employee - Intentional Unauthorised Access Employee - Unintentional Data Breach IT Glitch Policy Procedures Training & Education Checks Robust Contracts Strong Access Control Encryption Due Diligence Data Classification Monitor Feedback Measure Service Monitor Network Traffic Maintain Good Comms Monitor Data Integrity Monitor Press / SocMed Response Plan Privacy Impact Notification Plan Communications Plan Collect Evidence Review Controls Document Action Cyber Insurance
  • 16. ICSA RISK MANAGEMENT David Devereux - Director, BDO Risk & Advisory Services 2nd April 2019
  • 17. 17 BDO RANGE OF SERVICES The BDO Global Risk Advisory Services practice shares the knowledge and best practices gained from years of experience operating across 162 countries and territories. • Risk Management Framework Implementation • Board Effectiveness • Internal Audit • Controls Advisory and Assessment • SOx • Corruption, Financial Reporting & Fraud Investigations • Fraud and Anti-Corruption Compliance • Investigative Due Diligence • Forensic Accounting and Technology Services • Cyber Risk Management
  • 18. THANK YOU DAVID DEVEREUX | DIRECTOR, BDO RISK & ADVISORY SERVICES