enterprise risk management - fis...

29
Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist Managing Director, Enterprise Risk Management National Practice FIS RISC Solutions

Upload: others

Post on 12-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Enterprise Risk ManagementEffective Risk Monitoring and Reporting

May 2017

Eric Holmquist

Managing Director, Enterprise Risk Management National Practice

FIS™ RISC Solutions

Page 2: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

What are We Going to Discuss?

2

CHALLENGES1

RISK MONITORING 2

KRI DESIGN3

RISK REPORTING4

REPORT DESIGN CONSIDERATIONS5

FINAL THOUGHTS6

QUESTIONS AND ANSWERS7

Page 3: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Common Challenges

3

So many moving parts

Risk often defy quantification

Hard to establish what “matters”

Presenting information

Availability of good data (quality & quantity)

Assessed globally but managed locally

Danger of “artificial precision”

Getting the right people on board

Page 4: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

4

Page 5: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

5

Risk Monitoring

and Measuring

Page 6: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

6

“KRI’s are the most

important tool in the

Risk Manager’s bag

because…"

Page 7: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

7

Key Risk Indicators (KRIs)

Page 8: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

8

Key Risk Indicators (KRIs) continued…

Page 9: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

What KRIs Are Not

9

A CRYSTAL BALL DESIGNED TO PREDICT THE FUTURE

1AN INDICATION OF THE PRESENCE OF A RISK

2A FORM OF AUTOPILOT

3INHERENTLY FORWARD LOOKING

5ONE SIZE FITS ALL

4

Page 10: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

What KRIs “Are”

10

PROCESS EQUIVALENT OF A SMOKE DETECTOR

1A MEANS OF TRACKING THE “SUBTLE”

2AN INDICATION THAT SOMETHING “MAY” NOT BE RIGHT

3CRITICAL TO EFFECTIVE RISK MANAGEMENT

5USEFUL ONLY WHEN INTERPRETED

4

Page 11: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Ten Effective KRI Attributes

11

Should be agreed upon

Are measurable

Correlated to a tangible risk

Documented exceedingly well

Give insight into the subtle

Clearly defined tolerance levels

Points of accountability

Integrated with assessments

Focused

Dynamic

Page 12: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

How to define KRIs

12

• Build into documenting processes

• Clearly define green, yellow and red (risk limits)

• Never expect the KRI to interpret risk

• Goal is a leading indicator, not root cause

• Don’t start enterprise-wide

• Build validation into audit program

• Incorporate selectively into dashboards

• One good one is better than 1,000 ignored

• USE COMMON SENSE!!!

Page 13: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

13

Risk Reporting

Page 14: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

14

Page 15: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

15

1. Set expectations early and often

Page 16: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

16

1. Set expectations early and often

2. Results must be culturally acceptable

Page 17: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

17

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

Page 18: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

18

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

Page 19: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

19

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

Page 20: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

20

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

6. Accuracy goes straight to credibility

Page 21: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

21

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

6. Accuracy goes straight to credibility

7. Don’t assume a certain response

Page 22: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

22

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

6. Accuracy goes straight to credibility

7. Don’t assume a certain response

8. Focus on what’s important

Page 23: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

23

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

6. Accuracy goes straight to credibility

7. Don’t assume a certain response

8. Focus on what’s important

9. Simple or complex, neither are good or bad

Page 24: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

24

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

6. Accuracy goes straight to credibility

7. Don’t assume a certain response

8. Focus on what’s important

9. Simple or complex, neither are good or bad

10. Find ways to translate data into risk

Page 25: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

25

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

6. Accuracy goes straight to credibility

7. Don’t assume a certain response

8. Focus on what’s important

9. Simple or complex, neither are good or bad

10. Find ways to translate data into risk

11. All data has context

Page 26: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Twelve Design Considerations

26

1. Set expectations early and often

2. Results must be culturally acceptable

3. Reports should create dialog

4. Data should inform not confuse

5. Know your audience

6. Accuracy goes straight to credibility

7. Don’t assume a certain response

8. Focus on what’s important

9. Simple or complex, neither are good or bad

10. Find ways to translate data into risk

11. All data has context

12. The 3 most important things to communicate:1. What is our risk level?

2. Why do we believe that?

3. Where are we headed?

Page 27: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

27

Risk Reporting

Inherent RiskMitigating

ControlsResidual Risk Direction of the Risk

Credit High Satisfactory Moderate Stable

Interest Rate High Satisfactory Low Stable

Liquidity High Satisfactory Low Stable

Operational High Satisfactory Moderate Stable

Compliance High Satisfactory Moderate Stable

Financial High Satisfactory ModerateStable

IT High Satisfactory Moderate Stable

Strategic High Satisfactory Moderate Increasing

Mortgage (Georgia) High Satisfactory Moderate Stable

Risk Summary High Satisfactory Moderate Stable

Page 28: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Risk Reporting Final Thoughts

28

Something is

better than

nothing01

03

02

04

Differentiate

between smoke

and rubble

Something +1

isn’t always

better

Numbers tell a

story, pictures

leave an

impression

05Crunched

numbers are

still just

numbers06

In the end,

creativity

wins

Page 29: Enterprise Risk Management - FIS Globalempower1.fisglobal.com/rs/650-KGE-239/images/1505...Enterprise Risk Management Effective Risk Monitoring and Reporting May 2017 Eric Holmquist

Eric [email protected]

215.208.8775