- They are not satisfied that their oversight of various IT risks is effective, or that the company's strategic planning process deals effectively with the pace of technology change and innovation.
- The one person they would most like to hear from more frequently is the CIO.
- They want to spend more time with the CRO and mid-level management/business-unit leaders; and few are satisfied that they hear dissenting views about the company's risks and control environment, or rate their company's crisis response plan as "robust and ready to go."
- The audit committee is devoting significant agenda time to legal/regulatory compliance risk, with the Foreign Corrupt Practices Act (FCPA), UK Bribery Act, and impact of the SEC's whistleblower "bounty" program of particular concern.
Wednesday, October 12, 2011
IT Risk Tops List of Concerns for Board Members
Monday, May 16, 2011
Wheelhouse Announces New Strategic Alliance
Wheelhouse, a professional services firm specializing in Enterprise Risk Management & Control will be Xactium’s first US-based partner, operating in Atlanta, Georgia.
John A Wheeler, founder and Managing Principal of Wheelhouse Advisors brings over twenty years of strategic, operations and risk management professional to the firm. Prior to founding his company, John served as a Senior Vice President within the Corporate Risk Management division at a major U.S financial services company.
Dr. Andy Evans, Managing Director of Xactium, said: “This is a great opportunity for collaboration and signals the widening interest in our Force.com GRC Suite. Working with Wheelhouse will enable us to extend our reach to American markets and reinforce our position as a leading cloud risk solution provider. ”
John added: “We recognise the power of Xactium’s cloud-based solutions to provide clients with a complete, robust solution in a time frame they want. We look forward to extending our level of customer support with our new implementation services.”
The partnership follows a period of growth from Xactium, whose customer numbers have more than doubled in the last year. The potential for a future Xactium North America division will also be considered.
About Xactium: Xactium is a leading cloud-computing software company specialising in Governance, Risk and Compliance (GRC) solutions. Xactium helps customers efficiently and effectively access and manage risk and compliance activities without the need for complex, expensive risk software. Recent significant business wins include insurance brokers Jardine Lloyd Thompson; insurance and reinsurance group, RiverStone Europe; and Scottish water retailer, Business Stream.
About Wheelhouse Advisors: Founded in 2007, Wheelhouse Advisors serves corporate clients across the United States with the implementation and continuous improvement of their Enterprise Risk Management (“ERM”) programs. Their service offerings include: Bespoke Enterprise Risk Assessment, Independent Risk & Control Program Analysis, Financial Process Compliance; and Governance, Risk & Compliance Automation.
Thursday, May 12, 2011
The Path to ERM Success
As a result, 55% of the respondents expect to integrate risk management deeper into and across operations and 54% of respondents expect to perform day-to-day risk management activities more efficiently. To meet these expectations, organizations will need to improve the way they gather and report risk data through more cost-effective technology. The survey report supports this notion through the following observation. “It’s worth noting to risk managers that their counterparts in the C-suite were the most likely to view technology upgrades as a focus area. This should help pave the way for technology that can ease the time spent on mundane tasks and open the door to developing the deeper integration of risk management with other departments.”
Source: Risk & Insurance Management Society, Excellence in Risk Management VIII
Thursday, April 28, 2011
How to Strengthen Your IT Risk Management Program
A recent survey by Carnegie Mellon University’s CyLab highlights ten key steps to building a stronger ERM program with a focus on IT Risk. The CyLab 2010 survey is based on results received from 66 respondents at the board or senior executive level from Fortune 1000 companies. Twenty-seven percent of the respondents were board chairmen; 3 percent were outside directors; 47 percent were inside directors; and 50 percent were senior executives but not a board member. Forty-five percent of the participants were from critical infrastructure companies.
The survey revealed that governance of enterprise security is lacking in most corporations, with gaps in critical areas. If boards and senior management take the following ten actions, they can significantly improve their organizations’ security posture and reduce risk:
1. Establish a board risk committee separate from the audit committee and assign it responsibility for enterprise risks, including IT risks. Recruit directors with risk and IT governance expertise.
2. Ensure that privacy and security roles within the organization are separated and responsibilities are appropriately assigned. The CIO, CISO/CSO, and CPO should report independently to senior management.
3. Evaluate the existing organizational structure and establish a cross-organizational team that is required to meet at least monthly to coordinate and communicate on privacy and security issues. This team should include senior management from human resources, public relations, legal, and procurement, as well as the CFO, the CIO, CISO/CSO (or CRO), the CPO, and business line executives.
4. Review existing top-level policies to create a culture of security and respect for privacy. Organizations can enhance their reputation by valuing cyber security and the protection of privacy and viewing these as corporate social responsibilities.
5. Review the components of the organization’s security program and ensure that it comports with best practices and standards and includes incident response, disaster recovery, and breach response plans.
6. Establish privacy and security requirements for vendors based on key aspects of the organization’s security program, including annual audits or security reviews.
7. Conduct an annual audit of the organization’s enterprise security program, to be reviewed by the audit committee.
8. Conduct an annual review of the enterprise security program and the effectiveness of controls, to be reviewed by the board risk committee, and ensure that identified gaps or weaknesses are addressed.
9. Require regular reports from senior management on privacy and security risks and review annual budgets for IT risk management.
10. Conduct annual privacy compliance audits and review incident response and security breach notification plans.
These steps should be integrated into a holistic enterprise risk management approach to provide an effective and seamless program that is fully embraced at all levels within the organization. Doing so will not only raise a company’s risk mindfulness level, but also secure positive returns for key investors and stakeholders for years to come.
Wednesday, April 20, 2011
Cloud Security Concerns Are Diminishing
As cloud vendors mature, Web-based delivery of applications, storage and infrastructure is getting more secure and trustworthy. That doesn’t mean that the risks are gone—they’ve just migrated to a more difficult-to-manage form. Today, big-name cloud providers like Salesforce.com offer top-notch security, auditability and compliance. Even Google provides a compliant e-mail hosting solution for regulated industries such as healthcare and finance.
In fact, clouds can offer a security advantage over traditional software, since cloud providers specialize in making their application as secure as possible, spreading the costs of that effort among many customers. On their own, companies might not be able to afford the same level of security.
Coupled with the benefits of little or no maintenance as well as the minimal initial investment, the fact that cloud-based software is highly secure makes the business case for moving to the cloud a no-brainer for businesses looking for efficient and effective software solutions.
Tuesday, February 1, 2011
Risk Won't Wait
A unique convergence of circumstances makes this the perfect time to bring IT and business units together under the flag of a risk-oriented approach to security. Economic stress and cutthroat competition on a global scale mean every dollar you spend on security had better matter. Executives are increasingly being held personally accountable, and unified risk management as a discipline is finally reaching maturity.
Plus, the money is there. Thirty-five percent of the 563 respondents to our InformationWeek Analytics IT Risk Management Survey say their companies' IT risk management programs will get more funding in 2011 than they did last year. Very few will see cuts.
Don't be left behind. With leaps in technology occurring in a matter of months rather than years, no company can afford to delay their improvements in risk management.
Monday, November 29, 2010
Information Technology is a Core ERM Building Block
The Dodd-Frank legislation establishes the Office of Financial Reform (OFR), a new department within the U.S. Department of the Treasury that is tasked with gathering and reporting to lawmakers information regarding potential risks and threats within the nation's financial industry. To accomplish this, the OFR's director can use his or her subpoena power to gather data from any financial institution.
Simply, says Michael Atkin, director of the Enterprise Data Management Council, a nonprofit trade association focused on managing and leveraging data, the regulation gives banks' corporate leadership a new opportunity to examine the growing problem of managing skyrocketing amounts of data and finally to budget appropriately to meet the challenge. "It kicked the practice of data management into high gear," Atkin says. "We're now set up for addressing the data dilemma that we have because we finally have a reason that is not subject to the whim of a business case. It is a regulatory requirement."
The OFR director, who has not yet been appointed, will make his or her report to Congress in 2012, adds Atkin. But that initial report, he notes, likely will be more on the state of the industry than a detailed analysis of its data, giving financial institutions a window of several years to prepare for potential requirements. "The implications from an infrastructure perspective are about getting the core building blocks of risk management in place," Atkin relates.
Now is the time, as Atkin says, to get your "core building blocks of risk management in place". Wheelhouse Advisors can help. Visit www.WheelhouseAdvisors.com to learn more.
Thursday, October 21, 2010
Fear of Innovation is a Huge Risk
1) The mobile phone is the new branch. Twenty-five percent of consumers have ditched their wireline phone and gone completely wireless. This of course puts increased pressure on banks to invest in mobile banking and payments. Yet except for remote check capture via mobile phones from banks like USAA, real innovation remains elusive. Most of the industry innovations are being driven not by banks, but by specialist companies like mFoundry, ClariMail, Monitise, Mocapay, PayPal, Bling and Obopay. This while bankers complain that their major tech suppliers, including First Data, Fidelity, Fiserv and Jack Henry, are just not moving fast enough to meet their needs.
2) Social Networking is a dangerous tool for customer interaction but necessary. Banks get that social networking are here to stay. And many believe it has the potential to be something other than a digital version of a call center. But social networking is not a controlled environment and that scares bankers. It should. Sites like Twitter and Facebook provide a podium for every whack job to speak his or her mind. The benefactors of the uncertainties that retail banks have about how to use and measure social media effectiveness are likely IBM, SAS, SAP and Microsoft and could provide a watershed year for a slew of nimble-footed specialist firms who are building business to consumer (B2C) enterprise grade measurement and engagement tools.
3) Cloud Computing: the outlook remains cloudy. Instinctively it would seem that cloud computing technology would be a critical weapon to break down the line of business silos that exist in retail banks. This seems especially true given consumer demands to have an experience they value, on their terms, on the bank interaction channel of choice — online, mobile, ATM or branch, irrespective of the type of business a consumer wants to transact with the bank. Consumers value convenience and they want to define what convenience looks like. But banks seem crippled to navigate the abyss of implementation schemes, cost sharing, regulatory compliance, security and customer ownership issues.
Fear of innovation is a very real risk that many companies face in today's uncertain environment. The value of innovation is at its maximum during times of complexity and chaos. Those companies that work to escape the fear and embrace innovation will be the ultimate winners, while those that do not will suffer a painful fate.
Thursday, August 19, 2010
The Risks of Cloud Computing
It all starts with what the company is looking to achieve through cloud computing and whether the investment is worth the risk. For example, will the application hosted in the cloud be customer facing and subject to strict regulatory standards? If so, then the risk assessment should include the probability and impact of events such as a data breach or unplanned downtime.
Once the risk assessment has been completed and the investment decision has been made, then a comprehensive due diligence exercise should be conducted. Some vendors may suggest simply relying on their SAS 70 report from their external auditing firm rather than performing a due diligence exercise. While SAS 70 reports are useful, they are not specific to the relationship between the two companies. It is imperative that the following areas are examined in relation to a company’s current information security policies and overall operating expectations.
- Organizational and Human Resource Security
- Access Control
- Asset Management
- Physical and Environmental Security
- Operations and Change Management
- Disaster Recovery and Business Continuity
- Privacy
- Regulatory Compliance
Like any other partnership or outsourcing agreement, the time to address potential risks and issues with cloud computing is at the very beginning of the relationship. By doing so, both the company and the vendor will benefit from the opportunity to understand each other’s expectations. It will also serve as the foundation for a successful cloud computing solution.
If your company would like to learn more about performing a cloud computing risk assessment and due diligence exercise, email us at NavigateSuccessfully@WheelhouseAdvisors.com.
Tuesday, January 26, 2010
CFOs and CIOs Find Common Ground
If one trait of CIOs could be changed, the executive said bluntly, they would develop more appreciation for prudent risk-taking. "They're always coming up with these very capital-intensive programs that are essentially faith-based initiatives. The projects are not well supported with metrics, the numbers don't work, but they want to run off and take the risk." Similarly, one CFO at the table, who also asked not to be named, chimed in: "Stop saying that it's going to produce 2,000% ROI. Nobody believes you." The first executive did allow, though, that there are two sides to the issue. Finance leaders, he acknowledged, often lose sight of the fact that "we have to have some vision, too." Rather than being just numbers-driven, CFOs have to find room for belief in innovation and "understand the power of a better idea."
To be truly successful, the two executives must find common ground. Wheelhouse Advisors provides practical solutions to bridge the gap between CFOs and CIOs leading to stronger business results. To learn more, visit www.WheelhouseAdvisors.com.
Tuesday, December 15, 2009
Maximize Your GRC Technology Investment
1. Greater process efficiency -- Compliance requirements continue to swell, and the risk landscape is getting more complex. Above all else, customers cited process automation as the core value of their GRC platform implementations. Workflow management capabilities help keep everyone on task, and centralized content management and reporting reduce the need to jump back and forth between different systems. In addition, ongoing improvements in automated controls and control-testing functionality generate even greater efficiency gains. The manager of corporate compliance for a large pharmaceutical company told Forrester: "Managing all GRC initiatives in one platform saves time, resources and money. The ability to build a solid foundation for our compliance program in a relatively short time frame allows us to focus on the acute compliance issues facing our industry."
2. Convergence of GRC efforts -- As well as increasing efficiency, converging the various efforts relevant to governance, risk and compliance fosters cooperation between business functions and improves overall GRC insight. Comparing exposure across different categories of risk or using risk assessments to generate audit scopes are just two examples of GRC convergence benefits. An operational risk management director for a large financial services company said that one of the biggest benefits of implementing a GRC platform was the ability to "integrate the risk disciplines, including internal audit, ORM [operational risk management], SOX and compliance."
3. Consistency of processes and methodologies -- Getting different functions to work with each other is one thing, but getting them to use the same processes and methodologies is much harder. GRC platforms allow organizations to create standard templates for documenting and assessing risks, controls, incidents and other elements of GRC. Consistency also leads to convergence and efficiency and is often an initial driver for the development of a GRC program. The director of risk and compliance for a top high-tech company succinctly explained to Forrester that one of the most important values of GRC technology was the creation of a "consistent way to manage compliance, operational and ERM [enterprise risk management] projects." Pay close attention to this aspect of GRC value. As risk and compliance become more complex, consistency will quickly become a necessity.
Wheelhouse Advisors can help your company identify the right technology solution and implement a program that will maximize the benefit of your technology investment. Visit www.WheelhouseAdvisors.com to learn more.
Wednesday, December 9, 2009
The Role of IT and Risk Management in the Financial Crisis
No industry spends more on information technology than financial services: about $500 billion globally, more than a fifth of the total (see chart below). Many of the world’s computers, networking and storage systems live in the huge data centres run by banks. “Banks are essentially technology firms,” says Hugo Banziger, chief risk officer at Deutsche Bank. Yet most in the industry agree that its woeful IT systems have, in Mr Banziger’s words, “exacerbated the crisis”. The industry spent billions on being able to trade faster and make more money, but not nearly enough on creating the necessary transparency. “Banks had lots of tools to create leverage, but not many to manage risk,” says Roger Portnoy of Daylight Venture Partners, a venture-capital firm that invests in risk-management start-ups.
Wheelhouse Advisors provides solutions to financial services companies looking to strengthen their risk management practices with better information technology tools. Together with our strategic partners, Wheelhouse Advisors can deliver cost-effective solutions that can be easily implemented within a complex environment. Visit www.WheelhouseAdvisors.com, to learn more about our services and our strategic partners.
Wednesday, October 21, 2009
IT Organizations Adjust to "New Normal"
- Cost and Funding Management: IT organizations will increasingly be forced to develop cost profiles, including the business value of solutions, to support investment decisions. This will not be an easy or pleasant task, and has been a requirement that has dogged IT organizations for years.
- Sourcing and Platform Strategies: As new options become available to achieve an IT or business objective, IT organizations will have more room to experiment, innovate, and change, but will also have to justify their choices more conclusively.
- Equipment Leasing and Software Financing: Commercial organizations will return to IT leasing and financing as a means of bolstering their access to IT resources.
- Life Cycle Management: IT organizations have already extended the planned deployment of many major systems, but they still need to develop the tools and management processes to quantify the underlying cost implications of these longer asset lifecycle models.
- IT Financial Management Tools: As IT platforms and business processes increasingly move toward a mix of in-house and third-party provision, the need for IT financial management software, tools, and best practices to better enable IT organization operational decision-making will become apparent.
Does your IT organization have the necessary tools and supporting business practices to operate in this new environment? If not, Wheelhouse Advisors can help. Visit www.WheelhouseAdvisors.com to learn more.
Tuesday, October 20, 2009
Building Trust to Support Growth in 2010
Risk management is about accepting that IT organizations cannot protect the company from everything, so they will have to make conscious decisions about what they will do to protect themselves, and what they will not do. They must learn to balance risk and performance. People need IT organizations to share information, so that they can trust them. IT leaders should accommodate letting outside information in, and sharing inside information appropriately. CIOs shouldn`t think they can shut down the two-way flow of information because they can`t stop it.
Gartner analysts said that the quality of data underpinning metrics such as measuring business productivity, profits, value, and efficiency of services delivered is inadequate. This stems from siloed and inconsistent business data, and from an over reliance on spreadsheets. Even where there have been investments in business intelligence, it`s not giving the business what it needs. The challenge for IT leaders is getting the information that everyone can believe in, and that everyone in the organization will trust. "IT leaders need robust information architectures and governance, coupled with data quality and integration capabilities to create an enterprise view across these silos," said Nigel Rayner, research vice president at Gartner. "You will need to rationalize and link performance measures across the business in an enterprise metrics framework. When the data is consistent, and everyone believes it, then you have built trust."
Wheelhouse Advisors recently partnered with Apptio, the leading provider of IT Financial Management solutions, to help companies achieve a balanced risk and performance management approach. Apptio’s on-demand IT Financial Management solutions provide greater visibility into the cost, utilization and operations of IT products and services so that businesses can identify ways to reduce IT costs, make better IT decisions and provide the business with a true Bill of IT. World class companies such as Blue Cross Blue Shield of Kansas, BNP Paribas, EMD Chemical and Starbucks use Apptio’s IT cost analysis capabilities to reduce cost and achieve greater visibility into their IT costs and cost drivers. For more information, please visit www.apptio.com.
Monday, October 12, 2009
A Risk & Financial Management Balancing Act
Let's face it, we are entering an era of tighter statutory requirements and rapidly changing regulations. But focusing solely on statute requirements can lead to a disjointed strategy that is neither comprehensive nor aligned with business goals. While compliance mandates are often used to drive security investments, compliance by itself does not ensure a company's security posture.
Instead, businesses must look beyond their technology and compliance needs and understand the challenges of ensuring their company's security posture. Achieving this level of transparency requires the right mix of innovation, talent and technology underscored by a strategy that addresses risk at the broadest level. This is where relationships with business partners and vendors can play a valuable role. By joining forces with industry-leading third-party providers, companies gain access to new thinking and innovation to address key needs and challenges. With the right strategy and technology partnerships, businesses can drive a consistent and global set of security practices focused on risk reduction and information security.
Wheelhouse Advisors is uniquely positioned to help companies address their risk and security challenges while meeting the financial demands of the businesses they support. To learn more, email us at NavigateSuccessfully@WheelhouseAdvisors.com or visit our website at www.WheelhouseAdvisors.com.
Monday, July 13, 2009
Weak Links in Risk Management Programs
Weaknesses in the infrastructure often limited banks to identifying and aggregating exposures across the bank. A fragmented risk architecture dispersed over a multitude of systems made the reconciliation of the relevant data a time-consuming exercise, which was at best semi-automated, but more often a manual process. This led to banks needing far too long to aggregate their exposures and other relevant accounting and risk figures on a firmwide level. In the bankruptcy case of Lehman Brothers, for example, it was reported that it took some banks more than three weeks to determine their overall exposure to Lehman.
An inflexible risk environment within the banks rendered them incapable of reacting to sudden changes driven by external and internal circumstances—for example, the ability to perform ad hoc stress tests to assess the impact of new stress scenarios designed to address a rapidly changing environment.
In short, the interlinkage among risk types was not captured. The recent crisis has exposed the strong dependency among credit risk, market liquidity and funding liquidity pressures. Banks need to move away from silo-based risk management to achieve a more integrated and connected way of managing risk.
An integrated approach is not only required, it is also the most cost-effective solution in times like these. Wheelhouse Advisors provides services to help companies build an integrated risk management program. Visit www.WheelhouseAdvisors.com to learn more.
Tuesday, April 28, 2009
The IT Risk Paradox
Standard risk-management strategies are too outmoded to help companies contain catastrophic IT-linked risks. These strategies tend to assume that the risks are well understood and that the possibility of extreme events is tiny. As a result, organizations typically concentrate on ensuring that they have good policies and procedures for managing known risks and are using high-quality processes for creating and operating IT. But this old-fashioned focus can prevent firms from seeing new risks.
How do you identify events that, by definition, are hard to anticipate? Start by instilling from the top down an organizational culture that encourages employees to take ownership of risks and weigh their potential rewards and hazards. This means modeling risks and analyzing their business impact and, even more important, making the process integral both to corporate risk management systems and to every stage of IT system development. The culture must encourage employees to bring concerns about risk forward early, particularly when IT is being applied in new ways.
Developing the proper organizational culture is critical not only for managing IT risks, but for all risks. Wheelhouse Advisors can help your company develop the frameworks and methodologies to create the optimal risk management culture. Visit www.WheelhouseAdvisors.com to learn more.
Tuesday, February 17, 2009
Get Ahead of the Risk Curve
Dana Wiklund, a research director in the risk management practice at Financial Insights, a unit of International Data Group Inc., said banks are willing to spend in a few key areas, including this kind of risk analysis. "Risk is an area of investment this year," he said. "This is an area where, if banks haven't done their homework up till now, this is going to be a priority for them." Shareholders, boards and examiners are asking tough questions about how executives are analyzing risk and how they are implementing the necessary fixes, he added. "They have to make the investment."
Is your company prepared to make the necessary investments in order to get ahead of the risk curve? If so, then contact Wheelhouse Advisors to learn how you can implement the necessary enhancements in the most efficient and cost-effective way.
Tuesday, December 16, 2008
Beyond the Models
"Although selecting the right modeling tools for risk management is essential, one further mistake companies commonly make doesn’t have anything to do with tools. It is essential to ensure that corporate culture avoids the typical silo approach to running a business. As we continue to follow news on the economy, it becomes clear that companies that conduct risk management in business silos expose their firms to unnecessary and avoidable risks. Tying true enterprise-wide risk management to business performance management, along with implementation of the right tools, is the only way for companies to ensure long-term success."
Having an appropriate risk framework and governance structure is critical to creating a strong culture focused on effectively managing risks. Wheelhouse Advisors can provide cost-effective solutions to help companies break-down the silos and implement successful enterprise risk managemement programs. Visit www.WheelhouseAdvisors.com to learn more.
Monday, December 15, 2008
Keys to Success
- Define what ERM or GRC means to your organization.
- Survey your organization's regulatory and compliance landscape.
- Determine the most logical entry point and develop a phased approach.
- Establish a clear business case, considering both short-term and long-term value.
- Determine how success will be measured.
Interestingly, the author of the article is a representative of one of the major GRC technology vendors. While some vendors may want companies to rush to a purchase decision, this author agrees it is critical for companies to gain this perspective prior to evaluating solutions. He states,
"With these steps complete, you will be in a much stronger position to qualify vendors and solutions and to determine the best fit for your organization, based on a well-defined project scope and equally well-defined business requirements and associated benefits."
Wheelhouse Advisors can provide an independent viewpoint and work with your company to achieve the keys to success. Visit www.WheelhouseAdvisors.com to learn more.