Tuesday, September 8, 2009

Corporate Boards Struggle With ERM

Corporate Board Member Magazine recently profiled the seven hot buttons for corporate boards today.  Not suprisingly, risk management was at the top of the list.  However, the article points out that many in the boardroom are having a difficult time not only addressing risk, but also understanding the best way to govern risk throughout the organization.  Here's an excerpt from the article.

The word risk has a broad range of meaning, and the term is bandied about in corporate America as much as healthcare is in Middle America. Yet, risk shouldn’t be a reduced to a buzzword or a single committee, but rather it should be considered as a managed process that is discussed yearlong. “Directors are asking, ‘What’s my job? How do I get my arms around risk, and what’s management doing to mitigate risk?’” Keith Higgins, partner, Ropes & Gray LLP, tells Corporate Board Member. “Directors have to talk to the CEO and get the CEO to put risk analysis on every agenda. All the math whizzes built great risk models and they were not maybe as predictive as people thought.”


Moreover, risk management should not be viewed in and of itself. Bernard C. Bailey, chairman, LaserCard Corp., a secure ID provider, and director on the boards of EF Johnson Technologies, Telos Corp., and Spectrum Control, doesn’t look at risk management as something you put into a separate box. “It permeates every function within the enterprise—legal, operational, financial, liquidity, marketplace, fraud,” he says, emphasizing that the risk conversation has to be expanded to the whole board.



As the gentlemen quoted in the article point out, effective enterprise risk management is not a simple or easy task.  It is a process that must be woven into the very culture and operation of the entire business - from the boardroom to the mailroom.


ERM challenge

Thursday, September 3, 2009

Implementing ERM: What Boards Must Consider

The Committee of Sponsoring Organizations of the Treadway Commission ("COSO") recently released a white paper discussing the role of the Board of Directors in an effective Enterprise Risk Management ("ERM") program.  It provides an overview of the key drivers for implementing ERM today and what Boards must consider during the implementation.  Here is what they suggest.
In the aftermath of the financial crisis, executives and their boards realize that ad hoc risk management is no longer tolerable and that current processes may be inadequate in today’s rapidly evolving business world. Boards, along with other parties, are under increased focus due to the widely-held perception that organizations encountered risks during the crisis for which they were not adequately prepared. Increasingly, boards and management teams are embracing the concept of enterprise risk management (ERM) to better connect their risk oversight with the creation and protection of stakeholder value.

While ERM is not a panacea for all the turmoil experienced in the markets in recent years, robust engagement by the board in enterprise risk oversight strengthens an organization’s resilience to significant risk exposures. ERM can help provide a path of greater awareness of the risks the organization faces and their inter-related nature, more proactive management of those risks, and more transparent decision making around risk/reward trade-offs, which can contribute toward greater likelihood of the achievement of objectives.

If your company is considering implementation of an ERM program or simply looking to enhance your current ERM program, Wheelhouse Advisors can help.  To learn more, visit www.WheelhouseAdvisors.com.

COSO

Wednesday, September 2, 2009

Enabling Cost-Effective ERM with GRC Software

Governance, Risk & Compliance ("GRC") software has become a hot topic in the world of risk management over the past several years.  Many business people often ask what is GRC software and what is its purpose?  GRC software is akin to Enterprise Resource Planning ("ERP") software in that it is intended to provide a single repository for disparate information in order to enable better analysis and decision making.  However, while ERP software is focused on integrating financial and operations management activities, GRC software is focused primarily on integrating risk management activities.  An article in the September 2009 issue of Insurance Networking News provides additional insight into the evolution of GRC software and its usefulness in the aftermath of the recent financial meltdown.

Much as the Greek goddess Athena emerged from the forehead of Zeus, the marketplace for governance, risk and compliance (GRC) software was birthed in an epic headache. The accounting scandals and subsequent bankruptcies of Enron and WorldCom prompted the creation of the Sarbanes-Oxley Act (SOX) and GRC software soon emerged to help companies comply with the regulations.


"If you look at the genesis of the GRC market, it was brought on by the passage of SOX in 2002," says Tom Eid, VP research, at Stamford, Conn.-based Gartner Inc. "The first GRC solutions emerged in 2004, and at that point the focus was really on the finance and audit function."


Five years and one credit crisis later, the risk management component of GRC seems poised for a similar boom. While no legislation has yet passed as a direct result of the financial services meltdown, few expect this to persist for too much longer. Bills intended to rewrite the regulation of financial services in general, and insurance in particular, are winding through both houses of Congress. Leaving aside the diverging opinions on the merits of the bills, a broad consensus exists that more regulations-and a larger emphasis on risk management by regulators-are inevitable.


"The administration continues to make the case that they need some sort of consolidated oversight over insurance and financial services at the federal level," says Gary Bhojwani, president & CEO of Minneapolis-based Allianz Life. "They are talking about true regulatory oversight, whether they get it is a whole other discussion." While the industry awaits development in Washington, rules propagated by standards bodies such as the Financial Accounting Standards Board are already being enacted, and rating agencies are putting a renewed emphasis on risk.



With so many different regulatory bodies and agencies placing new demands on businesses as well as the ever-increasing complexity of business transactions, the need to integrate risk management activities in a cost-effective manner is very real.  Wheelhouse Advisors is equipped to help companies build enterprise risk management programs and implement GRC software to enable the integration.  To learn more, visit www.WheelhouseAdvisors.com.


Cost-effective Solution

Tuesday, September 1, 2009

Did Calamity Jerome Commit a Crime?

According to a report in today's UK Guardian, the infamous rogue trader from Societe Generale will stand trial next year to face criminal charges associated with his bad bets.  Jerome Kerviel almost brought down one of the largest financial institutions in the world by conducting a series of trades that led to losses of over $7 billion.  He argues that his actions were not criminal because the bank knew about and encouraged his trading activity until the losses began to mount.  Here is what the Guardian reports about the ongoing investigations.

The independent investigations and the bank's own internal inquiries into the scandal have found that its managers and control systems failed to operate properly and ignored warnings. A report by PricewaterhouseCoopers blamed the "culture" at the trading desk, describing it as "overheated". France's central bank has fined SocGen €4m for "serious shortcomings" in its internal controls that led to the trading losses. Kerviel's legal team is trying to go further and prove that the bank knew what was actually happening.


Employed at the bank since 2000, Kerviel worked his way up from a desk that monitors traders to a job on the futures desk, where he invested the bank's money by making huge bets on the future direction of European stock exchange prices. He is accused of causing five times the financial damage inflicted by Nick Leeson, the rogue trader who sparked the collapse of Barings Bank in 1995 with losses of £800m.



At the very least, the bank lacked the controls necessary to prohibit unauthorized trading activity as well as limit authorized trading activity.  As financial institutions and the trading operations they support become more complex, opportunities for fraud and abuse will continue to increase.  Investments in controls and monitoring technology are crucial to prevent future calamities such as this.


Société Générale rogue trader to stand trial next year

Wednesday, August 26, 2009

Looming IFRS Risks Pose Significant Challenges

More and more companies are beginning to examine the potential impact of the imminent conversion from U.S. Generally Accepted Accounting Principles ("GAAP") to the International Financial Reporting Standards ("IFRS").  The big difference between the two sets of standards is the fact that GAAP is primarily "rules-based", while IFRS is "principles-based".  The nature of a more principles-based set of standards adds to the amount of interpretation and risk in financial reporting.   Here is what an article in September 2009 issue of the Journal of Accountancy recently noted on the emerging risks from IFRS implementation.
Conversion to IFRS will be far more than a technical accounting exercise. Implementing IFRS will impact many, if not all, aspects of your business operations. It may bring companywide changes that will spawn new risks. These include system changes, modifications to processes impacting employees’ day-to-day duties, and new accounting policies.

Companies will also need to evaluate the impact these differences may have on their accounting policies, as well as the underlying information technology systems that support the company’s financial reporting structure. Changes to policies and systems on this scale will invariably give rise to additional risks that your organization may need to monitor and control.

The move to IFRS represents a huge opportunity for global companies to streamline their financial reporting, while at the same time poses major risks in the quality of implementation across the organization.  Wheelhouse Advisors can help your company analyze the IFRS related risks and provide solid expertise to support a successful implementation. Visit www.WheelhouseAdvisors.com to learn more.

Looming IFRS Risks

Monday, August 24, 2009

Common Objectives of the Chief Risk Officer & Chief Audit Executive

John A. Wheeler of Wheelhouse Advisors delivered a presentation this week at the 2009 Institute of Internal Auditors Conference in San Diego, California.  His presentation focused on the common objectives of the Chief Risk Officer and the Chief Audit Executive in today's perilous global economy.  Key discussion topics included:

  1. Learning about the evolving role of the Chief Risk Officer (“CRO”) both before and during the current global economic crisis

  2. Developing an understanding of the complementary aspects of the CRO and Chief Audit Executive (“CAE”) roles, as well as the potential conflicts to avoid

  3. Discovering strategies and critical success factors for an effective CRO & CAE partnership


Given the increase in both complexity and interrelationships of risks across corporations, an effective relationship between these two executive roles and their organizations is vital.  Wheelhouse Advisors provides cost-effective solutions to enable strong relationships in support of robust ERM programs.  To learn more, visit www.WheelhouseAdvisors.com.

Wheelhouse Advisors LLC

Thursday, August 20, 2009

Looking to Satisfy Risk Management Demand

Companies are now beginning to shore up their risk management practices and are hiring more risk management professionals as a result.  An article in the New York Times this week discusses the increase in demand for risk management skills and how prominent business schools are preparing graduates for the field.
Among the hot areas now are positions related to minimizing risk, as firms try to mitigate the chances of another financial crisis. Risk in general is a relatively new focus, and the openings range from business, credit and operational risk to product and technology risk. “Risk is everywhere,” said Jeanne E. Branthover, head of the global financial services practice at Boyden Global Executive Search.

This year, the Stern School of Business at New York University started offering an executive master’s in risk management in partnership with the Amsterdam Institute of Finance. During the program, which lasts a year and costs 42,000 euros, or about $60,000, students meet 10 times for multi-day sessions and study subjects including risk metrics, credit risk and liquidity risk. The course covers about 75 percent of what one is required to know for the professional risk manager certification, said Ingo Walter, a professor of finance at Stern.

Stern also offers a less technical three-day executive education session on integrated risk management. Columbia Business School and the Kellogg School of Management at Northwestern University are among other institutions that offer similar programs, which range in cost from $3,750 to $10,000.

As more business school graduates with a foundation in risk management enter the corporate world, corporations will certainly benefit from having these skills proliferate throughout the organization.

business school