Operational Risk Management

Operational Risk Management Aligning your organisation to harness risk April 30, 2015 Mark Dinning GRC Solutions Consultant © Copyright 2014 EMC Corp...
Author: Shanon Holt
5 downloads 0 Views 1MB Size
Operational Risk Management Aligning your organisation to harness risk

April 30, 2015 Mark Dinning GRC Solutions Consultant © Copyright 2014 EMC Corporation. All rights reserved.

1

Session Abstract In this session you will learn: • Challenges to effective Operational Risk Management today • The basic elements of an effective ORM programme • Keys to successfully creating and implementing an ORM programme © Copyright 2014 EMC Corporation. All rights reserved.

2

Defining Operational Risk The risk of direct or indirect loss resulting from:  Human factors  Inadequate or failed internal processes  Inadequate or failed systems  External events

© Copyright 2014 EMC Corporation. All rights reserved.

3

Three Lines of Defence

Board/Audit Committee Senior Management 3rd Line of Defence

• Business

• Risk Mgmt • Compliance • Security

• Internal Audit

Owns and Manages

© Copyright 2014 EMC Corporation. All rights reserved.

Assesses and Aggregates

Independent Review

Regulators

2nd Line of Defence

External Audit

1st Line of Defence

4

Today’s ORM Challenge Global, Technology and Organisational factors have created significant incremental risk management challenges for organisations. Velocity of Risk

© Copyright 2014 EMC Corporation. All rights reserved.

Multiple Views of Risk

Incomplete Picture

5

Managing the Operational Risk Process

RSA Archer

© Copyright 2014 EMC Corporation. All rights reserved.

Identifying where Assessing Managinginherent risk Monitoring the Making consistent the risk via and residual treatment to risk via arises KRIs risk and Intelligence decisions about incidents, losses, via RCSA and reduce to KCIs to risk remain risk treatment Driven ORM audits, and scenario analysis within tolerable within risk with accountability assessments capabilities allowances appetite

6

Intelligence Driven Operational Risk

Your approach should change the organisation’s focus from reacting to surprises to proactive management based on risk intelligence Risk Visibility Visibility + Analysis =

Priority

Priority + Action =

Results

Results + Metrics =

Progress

Analysis

Action

Metrics © Copyright 2014 EMC Corporation. All rights reserved.

7

Extending ORM

Board External Audit

Enterprise Risk Management LOB Executives

CXO

Audit

Operational Risk Management

Manage inherited risks

Third Party Management

Manage regulatory obligations

Regulatory Compliance

Protect against disruptions

Resiliency

Protect business assets

Security

CISO

Third Line of Defence

Business Operations

RSA Archer

© Copyright 2014 EMC Corporation. All rights reserved.

8

The Keys to a Successful Programme Minimise implementation risk Foster culture of adoption Reduce time to incremental value

© Copyright 2014 EMC Corporation. All rights reserved.

9

Minimise Implementation Risk • Expertise in technology, business process and organisation • Quick Wins • Hosting

© Copyright 2014 EMC Corporation. All rights reserved.

10

Foster Culture of Adoption Across the 1st line of Defence • Provide Value • Usability • Training

© Copyright 2014 EMC Corporation. All rights reserved.

11

Reduce Time to Incremental Value

• Strategy Roadmap • Focussed Solutions • RSA Archer GRC Community

© Copyright 2014 EMC Corporation. All rights reserved.

12

Gartner Magic Quadrant for ORM

Source: Gartner Magic Quadrant for Operational Risk Management John A. Wheeler, Paul E. Proctor 15 December 2014

Source: Gartner (December 2014) This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from EMC. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

© Copyright 2014 EMC Corporation. All rights reserved.

13

EMC, RSA, the EMC logo and the RSA logo are trademarks of EMC Corporation in the U.S. and other countries.

Suggest Documents