effectively managing operational risk

24
NASDAQ – GOVERNANCE, RISK MANAGEMENT, COMPLIANCE

Upload: transcendent-group

Post on 03-Aug-2015

98 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Effectively managing operational risk

NASDAQ – GOVERNANCE, RISK

MANAGEMENT, COMPLIANCE

Page 2: Effectively managing operational risk

CONTENTS

Masdaq GRC Strategy 2

Brief Introduction Managing Risk Framework • Conduct Risk

How can technology help manage (Conduct) Risk Lessons Learned in Implementations Conclusion

Page 3: Effectively managing operational risk

WHO WE ARE

IGNITE YOUR AMBITION 3

Nasdaq –BWise is a global leader in Enterprise Governance, Risk Management and Compliance (GRC) software.

NASDAQ TICKER SYMBOL: NDAQ MEMBER OF S&P 500

OUR MISSION >

To provide end-to-end solutions supporting an organization’s ability to understand, track, measure, and manage key organizational risks

OUR VISION > To help companies to truly be in control by balancing performance with their financial and reputational risks, improving corporate accountability and operating efficiencies

Page 4: Effectively managing operational risk

NASDAQ-BWISE AT A GLANCE

4

The journey to success

NASDAQ lists

3400 COMPANIES

$6 TRILLION MARKET CAP

10,000 NASDAQ customers

Gartner and Forrester recognize BWise as GRC

leader since 2006

>1 million GRC professionals

use BWise daily

Page 5: Effectively managing operational risk

NASDAQ BWISE CUSTOMERS

5

Page 6: Effectively managing operational risk

WHAT IS CONDUCT RISK?

Page 7: Effectively managing operational risk

CONDUCT RISK

Stra

tegi

c R

isk

Rep

ort

ing

Ris

k

Co

mp

lian

ce R

isk

Op

erat

ion

al R

isk

Internal fraud

External fraud

Employment practices & Workplace safety

Clients, products & business practices

Damage to physical assets

Business disruption and failures

Execution, delivery & process management

Conduct Risk

Co

nd

uct

Ris

k

Page 8: Effectively managing operational risk

CONDUCT RISK

Stra

tegi

c R

isk

Rep

ort

ing

Ris

k

Co

mp

lian

ce R

isk

Op

erat

ion

al R

isk

Internal fraud

External fraud

Employment practices & Workplace safety

Clients, products & business practices

Damage to physical assets

Business disruption and failures

Execution, delivery & process management

Financial Risk Dimension

Reputational Risk Dimension

Conduct Risk Dimension

Page 9: Effectively managing operational risk

ALL AREAS OF THE BUSINESS, BUT TYPICALLY … (EXAMPLE FOR FINANCIAL SERVICES)

Client-facing processes • Sales & Marketing Processes • Asset Management and Investment Advice • Complaints Management • Front Office Processes Back-office processes • Product Approval • Remuneration & Incentives Program IT assets & processes • IT Assets and IT Processes involved in all of the above processes

Page 10: Effectively managing operational risk

NASDAQ GRC

BWise Master Roadmap 10

Page 11: Effectively managing operational risk

NASDAQ VIEW OF THE GRC INDUSTRY MAIN AREAS OF GRC

Nasdaq GRC Strategy 11

Board-related categories

Operational Risk categories

Compliance Categories

Legal Risk Categories

Physical Categories

Financial Risk Categories

Enterprise Risk Management

Audit Management

Corporate Governance

Corporate Social Responsibility

Operational Risk Management

Financial Assurance &

Control IT GRC

3rd Party Management

Anti-corruption & Fraud

Ethics & Integrity Privacy

Management

Crisis Management

Legal Matter Management

Geo-Political Risk

Management

Global Trade & International

Dealings

Employment/ Labor

Physical Security Management

Quality Management

Environmental, Health & Safety Management

Treasury Risk Management

Insurance & Claims

Management

Credit Risk Management

Market Risk Management

Financial Crime Risk

Management

Business Continuity

Management

Social Reputation Risk Management

Regulatory Compliance

Page 12: Effectively managing operational risk

ELEMENTS OF CONDUCT RISK MAIN AREAS OF GRC

Nasdaq GRC Strategy 12

Board-related categories

Operational Risk categories

Compliance Categories

Legal Risk Categories

Physical Categories

Financial Risk Categories

Enterprise Risk Management

Audit Management

Corporate Governance

Corporate Social Responsibility

Operational Risk Management

Financial Assurance &

Control IT GRC

3rd Party Management

Anti-corruption & Fraud

Ethics & Integrity Privacy

Management

Crisis Management

Legal Matter Management

Geo-Political Risk

Management

Global Trade & International

Dealings

Employment/ Labor

Physical Security Management

Quality Management

Environmental, Health & Safety Management

Treasury Risk Management

Insurance & Claims

Management

Credit Risk Management

Market Risk Management

Financial Crime Risk

Management

Business Continuity

Management

Social Reputation Risk Management

Regulatory Compliance

Page 13: Effectively managing operational risk

ELEMENTS OF CONDUCT RISK MAIN AREAS OF GRC

Nasdaq GRC Strategy 13

Board-related categories

Operational Risk categories

Compliance Categories

Legal Risk Categories

Physical Categories

Financial Risk Categories

Enterprise Risk Management

Audit Management

Corporate Governance

Corporate Social Responsibility

Operational Risk Management

Financial Assurance &

Control IT GRC

3rd Party Management

Anti-corruption & Fraud

Ethics & Integrity Privacy

Management

Crisis Management

Legal Matter Management

Geo-Political Risk

Management

Global Trade & International

Dealings

Employment/ Labor

Physical Security Management

Quality Management

Environmental, Health & Safety Management

Treasury Risk Management

Insurance & Claims

Management

Credit Risk Management

Financial Crime Risk

Management

Business Continuity

Management

Social Reputation Risk Management

Regulatory Compliance

Market Risk Management

Page 14: Effectively managing operational risk

HOW CAN TECHNOLOGY HELP TO MANAGE RISK?

Page 15: Effectively managing operational risk

OPRISK CYCLE

Risk Identification

RCSA

Loss & Incident Management

Action Management Risk Framework

Capital Calculation Risk Reporting

KRI Management

Page 16: Effectively managing operational risk

COMPLIANCE & POLICY MANAGEMENT CYCLE

Regulatory

Requirements

Risk-based Scoping

Policy Creation

Gap Analysis

Policy Dissemination Policy Attestation

Compliance

Assessment

Regulatory Alerts

Remediation & Risk

Acceptance Enterprise Reporting

Page 17: Effectively managing operational risk

Monitoring

INTERNAL CONTROL CYCLE

Page 18: Effectively managing operational risk

THE AUDIT CYCLE

Page 19: Effectively managing operational risk

INTEGRATION – SINGLE RISK LANGUAGE

Internal Control Internal Audit

Compliance Risk Management

Page 20: Effectively managing operational risk

IMPLEMENTATION APPROACH 3 variants

Page 21: Effectively managing operational risk

IMPLEMENTATION FORMATS

1. RDS

BWise Best Practice

working system

Gap Analysis

design document

Configuration

Go-Live system

2. Spiral

Business Design

design document

System Design

design document

Configuration

Go-Live system

3. BCOE

BWise Training

trained team

Design & Configure

working system

configuration

Go-Live system

Page 22: Effectively managing operational risk

WHY NASDAQ OMX BWISE

Page 23: Effectively managing operational risk

WHY NASDAQ BWISE

27

Company

Product

Services

Long term focus on GRC Industry Leader since the start of the GRC market GRC is an instrumental part of company strategy

100% configurable by client, 100% upgradable Scalable, secure, east-to-use modern platform 100% integrated GRC functions

Global implementation partnerships, Transcendent Global implementation teams and support Long-term customer relationships and references

Page 24: Effectively managing operational risk

28

THANK YOU