ERM: What’s New & What’s Next
Institute of Internal Auditors Webinar
February 19, 2009

Presented by:
John A. Wheeler, Managing Principal, Wheelhouse Advisors LLC
Kenneth K. Yoo, Senior Vice President – Enterprise Risk Management,
Federal Home Loan Bank of Atlanta



                                                         www.theiia.org/Training
Discussion Topics

       • Key risks facing companies operating both inside and
         outside the United States

       • Developing an Enterprise Risk Management Framework &
         Approach

       • Evolution of a Risk & Controls Program

       • Enterprise Risk Management in the era of increased
         regulatory and shareholder scrutiny


                                                     www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                     │1
Changing Risk Environment




                                             www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                             │2
Changing Risk Environment
       In 2008 & 2009, the risk landscape has shifted dramatically

                                             Fannie and Freddie
                                              Likely to Plunge,
                                              Searing Investors




                                                                  www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                  │3
Developing an ERM Framework


            What is “ERM”?
            “… a process, effected by an entity's board of directors,
              management and other personnel, applied in strategy
              setting and across the enterprise, designed to identify
              potential events that may affect the entity, and manage
              risks to be within its risk appetite, to provide reasonable
              assurance regarding the achievement of entity objectives.”


            Source: COSO Enterprise Risk Management – Integrated Framework - 2004.




                                                                                     www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                                     │4
Developing an ERM Framework

       • ERM is a process that encompasses the following key
         activities
                 – Identifies potential events that may arise out of and/or impact a
                   company’s strategic objectives
                 – Assesses the severity and likelihood of risk events
                 – Determines risk response
                          • Evaluates in relation to risk tolerances
                          • Determines approach – Avoid, Accept, Reduce, Share
                          • Specifies mitigation plan
                 – Manages risk within the enterprise’s risk appetite
                 – Takes a portfolio view of risk at the top
                 – Monitors performance continuously


                                                                             www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                             │5
Developing an ERM Framework
                          “Old School” Approach                   “New School” Approach
         Risk perceived as individual hazards that may    Understand risks in context of business
          negatively impact a given area                    strategies and objectives
         Ad hoc focus on risks with greatest emphasis     Disciplined and forward looking focus on
          on recent events                                  critical risks
         Managing risks is senior management’s            Managing risk is everyone’s responsibility
          responsibility
         Minimize and/or eliminate risk                   Manage risk within tolerance levels and
                                                            capitalize on opportunities
         No risk owners                                   Well defined accountability for risks

         No formal risk reporting or monitoring at the    Risk reporting emanating from existing
          entity level                                      channels to the top
         Highly decentralized                             Portfolio management




                                                                                   www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                                   │6
Risk Assessment vs. ERM
          • Risk Assessment
                    –      Point-in-time snapshot
                    –      Often internal audit driven
                    –      Identifies where to focus current attention
                    –      Great for planning, but not the full solution


          • ERM
                    – Continuous risk monitoring and identification
                    – Real-time assessment using indicators as well as evaluation of new
                      strategic initiatives
                    – Balanced focus on opportunities and impacts
                    – Built-in ownership of risks at the right level – embedded in the
                      business

                                                                           www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                           │7
Benefits of ERM
         ERM provides the ability for a company to:
                   –      Understand and define risk appetite as it relates to strategy
                   –      Link growth, risk and return
                   –      Optimize risk response decisions
                   –      Minimize operational losses and surprises
                   –      Rationalize capital resources
                   –      Strengthen credit ratings
                   –      Improve efficiency by integrating responses to multiple risks
                   –      Seize opportunities to capitalize on rewards from taking
                          intelligent risks




                                                                            www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                            │8
Evolution of a Risk & Controls Program

       • Sarbanes-Oxley (“SOX”) Section 404 as a starting point

       • Innovation and integration leading to greater efficiency
         and effectiveness

       • Barriers to overcome

       • Required changes in approach




                                                       www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                       │9
SOX as a starting point
       • Similar disciplined approach with primary focus on risks
         first, processes second and controls third
       • Streamlining business processes
                 – Eliminating duplicative activities
                 – Process improvement, eliminate outdated procedures
                 – Enhancing data integrity for critical decision-making
       • Enhancing, automating and integrating data flow
                 – Focus on data analytics and mining opportunities to strengthen
                   controls
                 – Providing more transparent and seamless communication across
                   the business
                 – Viewing the process end-to-end to understand control gaps


                                                                    www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                │10
Evolution of Risk & Control Programs

                      Developing                    Implementing               Improving                 Integrating



            • Highly reactive to              • Individual control     • Alignment of control    • Seamless and proactive
              individual regulatory             programs in various      programs to increase      risk & control program
              mandates                          phases of                efficiency and reduce
                                                implementation           administrative burden   • Risk governance &
            • Immature risk                     and/or refinement                                  oversight structure fully
              governance &                                             • More focused risk         embedded in business
              oversight structure             • Evolving risk            governance &              governance structure
                                                governance &             oversight structure       (i.e. from strategy
            • Informal risk related             oversight structure                                through execution)
              infrastructure                                           • Identification and
                                              • More formal risk         implementation of       • Risk infrastructure
                                                related                  best practices across     automated and fully
                                                infrastructure at        business units            integrated across
                                                corporate and                                      enterprise
                                                business unit levels




                                         Evolving                                          Mature

                                                                                                     www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                                                     │11
Barriers to Overcome
        Attitudes / Culture
        •       People are “burned-out” by SOX
        •       Seen as interfering with “real work”
        •       Lack of alignment with performance measurements – little incentive to
                participate
        •       Budget constraints are increasing leaving few resources to commit
        •       View that one-time training is the answer
        •       Wavering support from executive management and board


        Infrastructure
        •       No shared language
        •       Over reliance on support functions
        •       Little or no linkage between risks, process and controls
        •       Enabling technology is non-existent or fragmented at best

                                                                            www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                        │12
Barriers to Overcome




                                             www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                         │13
Internal Audit’s ERM Barriers to Overcome

                                                Internal Audit ERM Competency Map


                       Enterprise Risk Assessment          30%                      53%                        17%




                     Fraud prevention / detection        26%                      55%                         19%




                 Use of technology and analytics         26%                     52%                         22%




                                             Improvement Opportunity   Somewhat Competent      Very Competent




                                                                                 Source: Ernst & Young 2008 Global Internal Audit Survey



                                                                                                                www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                                                                 │14
Internal Audit’s Role in ERM




                                             Source: The Institute of Internal Auditors


                                                           www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                │15
ERM Program Sustainability

              Has your company reached a                       What makes your ERM program
             sustaining ERM maturity level?                           sustainable?

                                                       Senior management endorses the
                                                                                                      84%
                                                        organization’s risk management
                                             Yes                    efforts
                                             29%
                                                          Management is part of the risk             74%
                                                             management program

                      No                               Risk management efforts are part
                                                                                                   66%
                     71%                               of the organization’s management
                                                                process and tools

                                                                                             22%
                                                                                  Other


                                                                                           0% 20% 40% 60% 80% 100%




                                                   Source: 2008 ERM Benchmarking Survey - The Institute of Internal Auditors



                                                                                             www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                                                     │16
Changes Required
   • Clear and consistent support from executive management
   • High-level, multi-disciplinary, dedicated core team
   • Strong business case on how ERM will enhance
             – Business decision-making
             – Achievement of corporate and business unit strategic objectives
             – Identification of opportunities as well as potential impacts
   • Building ERM into business processes – efficiently and without
     undue administrative burden
   • Well defined roles and responsibilities for risk leading to improved
     accountability – build into incentives and performance
     management
   • Long-term commitment to the effort, linked to strategic planning


                                                                     www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                 │17
Changes Required




                                             www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                         │18
Increased Scrutiny
         • Legal / Regulatory
                   –      SEC
                   –      Department of Justice
                   –      Stock Exchanges
                   –      Securities Fraud Plaintiff Attorneys
                   –      Sarbanes-Oxley Act – Sections 302 & 404
                   –      Foreign Corrupt Practices Act
                   –      Industry specific regulations (Privacy, Anti-money laundering,
                          Risk-based capital requirements, etc.)
         • Shareholders & Stakeholders
                   –      Outsourcing / Third-party resources
                   –      Credit rating agencies
                   –      Institutional Investors
                   –      Personal liability for Board Members


                                                                                 www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                             │19
Critical Success Factors
        1. Organizational Culture
                   –     Governance (Board & Executive
                         Management)
                                                                  Continuous
                   –     Roles and Responsibilities               Monitoring
                   –     Incentive Programs
        2. Infrastructure
                                                                  Integration
                   –     Simple, consistent and well
                         understood risk framework
                   –     Effective controls at the appropriate
                                                                 Infrastructure
                         stages of the process
        3. Integration
                   –     Portfolio view
                   –     Mind the control gaps                   Organizational
                   –     Focused effort with optimal use of         Culture
                         resources
        4. Continuous Monitoring
                   –     Current risk levels vs. risk appetite
                   –     Effectiveness of control performance

                                                                       www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                                   │20
For more information about service offerings, please visit:
                        www.WheelhouseAdvisors.com
                               Or email us at:
               NavigateSuccessfully@WheelhouseAdvisors.com




                                                         www.theiia.org/Training

© Copyright 2009 - Wheelhouse Advisors LLC                                     │21

More Related Content

PDF
Shared Services for Finance & Accounting - Wheelhouse Advisors 7.15.08
PDF
Common Objectives of the CRO and the CAE
PDF
Leadership and Risk Management report
PPTX
CFO Risk Intelligence - Harvey Christophers
PPTX
Julia graham@bdm2014
PDF
#corpriskforum2016 - Julia Graham
PPTX
Common failures of risk management
PPT
Leading risk culture change webinar
Shared Services for Finance & Accounting - Wheelhouse Advisors 7.15.08
Common Objectives of the CRO and the CAE
Leadership and Risk Management report
CFO Risk Intelligence - Harvey Christophers
Julia graham@bdm2014
#corpriskforum2016 - Julia Graham
Common failures of risk management
Leading risk culture change webinar

What's hot (19)

PDF
CFO Summit XVI - Wheelhouse Advisors LLC
PDF
Introductory Considerations for Enterprise Security Risk Management Programs
PDF
Enterprise Risk Management Workshop (Singapore 2006)
PPTX
ERM Overview for Credit Unions
DOCX
Enterprise risk management
PDF
IT Risk Management - the right posture
PDF
Delivering stronger business security and resilience
PDF
51_operational_risk
PPTX
2014.03.20 BDM Transport Insurance Seminar presentation
PDF
Risk Treatment Standard-ASB
PDF
ERM: DIFFERENCES BETWEEN SECTORS
PDF
Discover Risk Culture with Mohammad Fheili
PPTX
Five Lines of Assurance A New ERM and IA Paradigm
PDF
Risk Offering Summary
PPT
ORM Operational Risks Management
PDF
Navigating the edge of risk
PDF
Risk 2012 Walenta 120926 sanitized
PDF
Final Aerice Newsflash 9 Dec2011
PDF
Risk culture - IRM PROTIVITI
CFO Summit XVI - Wheelhouse Advisors LLC
Introductory Considerations for Enterprise Security Risk Management Programs
Enterprise Risk Management Workshop (Singapore 2006)
ERM Overview for Credit Unions
Enterprise risk management
IT Risk Management - the right posture
Delivering stronger business security and resilience
51_operational_risk
2014.03.20 BDM Transport Insurance Seminar presentation
Risk Treatment Standard-ASB
ERM: DIFFERENCES BETWEEN SECTORS
Discover Risk Culture with Mohammad Fheili
Five Lines of Assurance A New ERM and IA Paradigm
Risk Offering Summary
ORM Operational Risks Management
Navigating the edge of risk
Risk 2012 Walenta 120926 sanitized
Final Aerice Newsflash 9 Dec2011
Risk culture - IRM PROTIVITI
Ad

Viewers also liked (20)

PPTX
Open source technology
PPTX
Cloud computing and emerging technology
PDF
Digitization and EPR
PPTX
Reverse charge mechanism
PPT
PPT
Tech Audit overview
PPTX
Forensic Auditing
PDF
Company Profile
PPTX
Internal Audit with Data Analytics
PPTX
7 Habits of Highly Effective Enterprise Risk Managers
PDF
Use Of Techniques And Technology In Internal Audit
PDF
Riskpro iso 31000 services 2013
PDF
How technology continues to revolutionize auditing tmuc 2011
PDF
An Anatomy of a Digital Audit (Digital Marketing Audit)
PDF
ERM-Enterprise Risk Management
PDF
Data Audit Approach To Developing An Enterprise Data Strategy
PDF
How to Build an Enterprise Risk Management Framework
PPTX
6. audit techniques
PPTX
Basic Internal Auditing Presentation
PDF
10 Hyper Disruptive Business Models
Open source technology
Cloud computing and emerging technology
Digitization and EPR
Reverse charge mechanism
Tech Audit overview
Forensic Auditing
Company Profile
Internal Audit with Data Analytics
7 Habits of Highly Effective Enterprise Risk Managers
Use Of Techniques And Technology In Internal Audit
Riskpro iso 31000 services 2013
How technology continues to revolutionize auditing tmuc 2011
An Anatomy of a Digital Audit (Digital Marketing Audit)
ERM-Enterprise Risk Management
Data Audit Approach To Developing An Enterprise Data Strategy
How to Build an Enterprise Risk Management Framework
6. audit techniques
Basic Internal Auditing Presentation
10 Hyper Disruptive Business Models
Ad

Similar to ERM: What's New & What's Next (20)

PPT
Coso erm frmwrk
PDF
SAP Inside Track 2012 enterprise risk management newman v fx
PDF
Risk Health Check
PDF
Enterprise tools and_techniques
PDF
Amper ERM Presentation to FEI
PDF
Integrating Enterprise Risk Management (ERM) with Organizational Strategy
PPT
COSO ERM Framework
PDF
PDF
FERMA Survey Part 1 - The Maturity of Risk Management in Europe
PDF
Riskpro Trainings Automotive Industry
PDF
Riskpro Trainings Automotive Industry
PDF
Riskpro Trainings Automotive Industry
PDF
Riskpro Trainings Telecom Industry
PDF
Riskpro Trainings Telecom Industry
PDF
Risk pro trainings brochure 2013
Coso erm frmwrk
SAP Inside Track 2012 enterprise risk management newman v fx
Risk Health Check
Enterprise tools and_techniques
Amper ERM Presentation to FEI
Integrating Enterprise Risk Management (ERM) with Organizational Strategy
COSO ERM Framework
FERMA Survey Part 1 - The Maturity of Risk Management in Europe
Riskpro Trainings Automotive Industry
Riskpro Trainings Automotive Industry
Riskpro Trainings Automotive Industry
Riskpro Trainings Telecom Industry
Riskpro Trainings Telecom Industry
Risk pro trainings brochure 2013

Recently uploaded (20)

PDF
Statistics for Management and Economics Keller 10th Edition by Gerald Keller ...
DOCX
Final. 150 minutes exercise agrumentative Essay
PDF
DTC TRADIND CLUB MAKE YOUR TRADING BETTER
PDF
How to join illuminati agent in Uganda Kampala call 0782561496/0756664682
PDF
Best Accounting Outsourcing Companies in The USA
PDF
Pension Trustee Training (1).pdf From Salih Shah
PDF
HCWM AND HAI FOR BHCM STUDENTS(1).Pdf and ptts
PPTX
PROFITS AND GAINS OF BUSINESS OR PROFESSION 2024.pptx
PPTX
Grp C.ppt presentation.pptx for Economics
PDF
Management Accounting Information for Decision-Making and Strategy Execution ...
PPTX
lesson in englishhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
PPT
CompanionAsset_9780128146378_Chapter04.ppt
PDF
Pitch Deck.pdf .pdf all about finance in
PDF
THE EFFECT OF FOREIGN AID ON ECONOMIC GROWTH IN ETHIOPIA
PPTX
2. RBI.pptx202029291023i38039013i92292992
PDF
2018_Simulating Hedge Fund Strategies Generalising Fund Performance Presentat...
PPTX
INDIAN FINANCIAL SYSTEM (Financial institutions, Financial Markets & Services)
PDF
Buy Verified Stripe Accounts for Sale - Secure and.pdf
PPTX
28 - relative valuation lecture economicsnotes
Statistics for Management and Economics Keller 10th Edition by Gerald Keller ...
Final. 150 minutes exercise agrumentative Essay
DTC TRADIND CLUB MAKE YOUR TRADING BETTER
How to join illuminati agent in Uganda Kampala call 0782561496/0756664682
Best Accounting Outsourcing Companies in The USA
Pension Trustee Training (1).pdf From Salih Shah
HCWM AND HAI FOR BHCM STUDENTS(1).Pdf and ptts
PROFITS AND GAINS OF BUSINESS OR PROFESSION 2024.pptx
Grp C.ppt presentation.pptx for Economics
Management Accounting Information for Decision-Making and Strategy Execution ...
lesson in englishhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
CompanionAsset_9780128146378_Chapter04.ppt
Pitch Deck.pdf .pdf all about finance in
THE EFFECT OF FOREIGN AID ON ECONOMIC GROWTH IN ETHIOPIA
2. RBI.pptx202029291023i38039013i92292992
2018_Simulating Hedge Fund Strategies Generalising Fund Performance Presentat...
INDIAN FINANCIAL SYSTEM (Financial institutions, Financial Markets & Services)
Buy Verified Stripe Accounts for Sale - Secure and.pdf
28 - relative valuation lecture economicsnotes

ERM: What's New & What's Next

  • 1. ERM: What’s New & What’s Next Institute of Internal Auditors Webinar February 19, 2009 Presented by: John A. Wheeler, Managing Principal, Wheelhouse Advisors LLC Kenneth K. Yoo, Senior Vice President – Enterprise Risk Management, Federal Home Loan Bank of Atlanta www.theiia.org/Training
  • 2. Discussion Topics • Key risks facing companies operating both inside and outside the United States • Developing an Enterprise Risk Management Framework & Approach • Evolution of a Risk & Controls Program • Enterprise Risk Management in the era of increased regulatory and shareholder scrutiny www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │1
  • 3. Changing Risk Environment www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │2
  • 4. Changing Risk Environment In 2008 & 2009, the risk landscape has shifted dramatically Fannie and Freddie Likely to Plunge, Searing Investors www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │3
  • 5. Developing an ERM Framework What is “ERM”? “… a process, effected by an entity's board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.” Source: COSO Enterprise Risk Management – Integrated Framework - 2004. www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │4
  • 6. Developing an ERM Framework • ERM is a process that encompasses the following key activities – Identifies potential events that may arise out of and/or impact a company’s strategic objectives – Assesses the severity and likelihood of risk events – Determines risk response • Evaluates in relation to risk tolerances • Determines approach – Avoid, Accept, Reduce, Share • Specifies mitigation plan – Manages risk within the enterprise’s risk appetite – Takes a portfolio view of risk at the top – Monitors performance continuously www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │5
  • 7. Developing an ERM Framework “Old School” Approach “New School” Approach  Risk perceived as individual hazards that may  Understand risks in context of business negatively impact a given area strategies and objectives  Ad hoc focus on risks with greatest emphasis  Disciplined and forward looking focus on on recent events critical risks  Managing risks is senior management’s  Managing risk is everyone’s responsibility responsibility  Minimize and/or eliminate risk  Manage risk within tolerance levels and capitalize on opportunities  No risk owners  Well defined accountability for risks  No formal risk reporting or monitoring at the  Risk reporting emanating from existing entity level channels to the top  Highly decentralized  Portfolio management www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │6
  • 8. Risk Assessment vs. ERM • Risk Assessment – Point-in-time snapshot – Often internal audit driven – Identifies where to focus current attention – Great for planning, but not the full solution • ERM – Continuous risk monitoring and identification – Real-time assessment using indicators as well as evaluation of new strategic initiatives – Balanced focus on opportunities and impacts – Built-in ownership of risks at the right level – embedded in the business www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │7
  • 9. Benefits of ERM ERM provides the ability for a company to: – Understand and define risk appetite as it relates to strategy – Link growth, risk and return – Optimize risk response decisions – Minimize operational losses and surprises – Rationalize capital resources – Strengthen credit ratings – Improve efficiency by integrating responses to multiple risks – Seize opportunities to capitalize on rewards from taking intelligent risks www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │8
  • 10. Evolution of a Risk & Controls Program • Sarbanes-Oxley (“SOX”) Section 404 as a starting point • Innovation and integration leading to greater efficiency and effectiveness • Barriers to overcome • Required changes in approach www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │9
  • 11. SOX as a starting point • Similar disciplined approach with primary focus on risks first, processes second and controls third • Streamlining business processes – Eliminating duplicative activities – Process improvement, eliminate outdated procedures – Enhancing data integrity for critical decision-making • Enhancing, automating and integrating data flow – Focus on data analytics and mining opportunities to strengthen controls – Providing more transparent and seamless communication across the business – Viewing the process end-to-end to understand control gaps www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │10
  • 12. Evolution of Risk & Control Programs Developing Implementing Improving Integrating • Highly reactive to • Individual control • Alignment of control • Seamless and proactive individual regulatory programs in various programs to increase risk & control program mandates phases of efficiency and reduce implementation administrative burden • Risk governance & • Immature risk and/or refinement oversight structure fully governance & • More focused risk embedded in business oversight structure • Evolving risk governance & governance structure governance & oversight structure (i.e. from strategy • Informal risk related oversight structure through execution) infrastructure • Identification and • More formal risk implementation of • Risk infrastructure related best practices across automated and fully infrastructure at business units integrated across corporate and enterprise business unit levels Evolving Mature www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │11
  • 13. Barriers to Overcome Attitudes / Culture • People are “burned-out” by SOX • Seen as interfering with “real work” • Lack of alignment with performance measurements – little incentive to participate • Budget constraints are increasing leaving few resources to commit • View that one-time training is the answer • Wavering support from executive management and board Infrastructure • No shared language • Over reliance on support functions • Little or no linkage between risks, process and controls • Enabling technology is non-existent or fragmented at best www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │12
  • 14. Barriers to Overcome www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │13
  • 15. Internal Audit’s ERM Barriers to Overcome Internal Audit ERM Competency Map Enterprise Risk Assessment 30% 53% 17% Fraud prevention / detection 26% 55% 19% Use of technology and analytics 26% 52% 22% Improvement Opportunity Somewhat Competent Very Competent Source: Ernst & Young 2008 Global Internal Audit Survey www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │14
  • 16. Internal Audit’s Role in ERM Source: The Institute of Internal Auditors www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │15
  • 17. ERM Program Sustainability Has your company reached a What makes your ERM program sustaining ERM maturity level? sustainable? Senior management endorses the 84% organization’s risk management Yes efforts 29% Management is part of the risk 74% management program No Risk management efforts are part 66% 71% of the organization’s management process and tools 22% Other 0% 20% 40% 60% 80% 100% Source: 2008 ERM Benchmarking Survey - The Institute of Internal Auditors www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │16
  • 18. Changes Required • Clear and consistent support from executive management • High-level, multi-disciplinary, dedicated core team • Strong business case on how ERM will enhance – Business decision-making – Achievement of corporate and business unit strategic objectives – Identification of opportunities as well as potential impacts • Building ERM into business processes – efficiently and without undue administrative burden • Well defined roles and responsibilities for risk leading to improved accountability – build into incentives and performance management • Long-term commitment to the effort, linked to strategic planning www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │17
  • 19. Changes Required www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │18
  • 20. Increased Scrutiny • Legal / Regulatory – SEC – Department of Justice – Stock Exchanges – Securities Fraud Plaintiff Attorneys – Sarbanes-Oxley Act – Sections 302 & 404 – Foreign Corrupt Practices Act – Industry specific regulations (Privacy, Anti-money laundering, Risk-based capital requirements, etc.) • Shareholders & Stakeholders – Outsourcing / Third-party resources – Credit rating agencies – Institutional Investors – Personal liability for Board Members www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │19
  • 21. Critical Success Factors 1. Organizational Culture – Governance (Board & Executive Management) Continuous – Roles and Responsibilities Monitoring – Incentive Programs 2. Infrastructure Integration – Simple, consistent and well understood risk framework – Effective controls at the appropriate Infrastructure stages of the process 3. Integration – Portfolio view – Mind the control gaps Organizational – Focused effort with optimal use of Culture resources 4. Continuous Monitoring – Current risk levels vs. risk appetite – Effectiveness of control performance www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │20
  • 22. For more information about service offerings, please visit: www.WheelhouseAdvisors.com Or email us at: NavigateSuccessfully@WheelhouseAdvisors.com www.theiia.org/Training © Copyright 2009 - Wheelhouse Advisors LLC │21