Introduction to ERM
- Risk management unravelled
- Risk, risk management and Enterprise Risk
- Management (ERM) defined
- The corporate governance and regulatory context
- Lessons from the credit crunch
- Investor and stakeholder pressures
- Review of risk management standards and guidelines
- COSO ERM and the new British and ISO standards
- The core components of an ERM system
- The risk management process: key steps
- Risk language, risk registers and assessment methodology
- Defining, establishing and communicating risk appetite
- Roles and responsibilities for ERM
- The board and risk leadership
- Audit and risk committees
- Internal audit’s role in ERM
- Implications of the IIA’s position statements
- Internal audits and risk management’s respective roles
Promoting and Enhancing Enterprise Risk Management
- Determining what needs to be done
- Understanding risk management maturity and effectiveness
- Assessing the risk maturity of your business
- The implications for internal auditors and risk managers
- Articulating your risk management vision – and the steps to achieve it
- Identifying business risks
- Risk categorization
- Sample risk categories
- Risk identification: what works and what doesn't
- Getting at strategic risks
PESTLE Analysis & Assessing and Prioritizing Risks
- Handling threats and opportunities
- Articulating risks to elicit action
Improving risk identification
- Importance of inherent and residual risk
- Risk assessment methodologies for threats and opportunities
- Applying risk appetite
- Multiple risk appetites and risk appetite hierarchies
- Risk quantification
- Improving risk assessment
Responding to Risks
- Response options: the 4Ts (Tolerate, Treat, Transfer, Terminate)
- Establishing an appropriate response
- Black swans and risk resilience
- Ownership and action planning
- Enhancing risk responses
Monitoring, Reporting and Assurance
- The value of monitoring, reporting and assurance
- Who should do what?
- Assurance mapping: establishing the best source/type of assurance
- Clarifying reporting lines
- Reporting within the business
Sample Reporting Formats
- The latest developments in external risk disclosure
- Hints and hazards
- Common ERM weaknesses
- Top tips for successful ERM implementation
New and Emerging Risk Management Challenges
- Refreshing the business risk profile
- Governance, strategic and ethics risks
- Corporate responsibility and stakeholder risks
- Reputational risks
- Supply chain and outsourcing risks
- Project and program risks
- IT risk hotspots
The Business Case for ERM
- Exploring the benefits – does ERM deliver value?
- Gaining ‘buy in’ from non-believers
- Analysis of a disaster
Embedding Risk Management throughout the Organisation
- The importance of organizational culture
- Encouraging everyone to be their own risk manager
- Innovative use of Control Risk Self-assessment (CRSA)
- The power of risk workshops
Adapting Your Approach as Risk Management Matures
- Dealing with changing skills requirements
- Flexible interaction with other assurance providers
- Tools for assessing risk management capability and effectiveness
Sample Assessment Programs & Action Plan
- Towards best practice in ERM
- Modifying your relationship with management and the board/audit committee
- Measuring and reporting your own performance
- Optimizing and communicating your role