Risk Management: Getting Too Strong
CIOREVIEW >> Data Security >> NEWS

at Zions Bancorporation

Peggy Hammond, CISA, CDPSE, MOL, Risk Management Executive

Risk Management: Getting Too Strong

Peggy Hammond, CISA, CDPSE, MOL, Risk Management Executive

Risk management professionals continue to work to strengthen operational practices but often fall short.  Opportunities to leverage the broader organization and lighten the governance load are missed, often resulting in less effective results and more expensive oversight.  Less mature practices are often reactive and based solely on feedback from third parties or internal risk or audit functions. 

Various risk management maturity models have been developed that speak to a five-tier measurement system and offer criteria organizations can leverage to strengthen risk management.  The Committee of Sponsoring Organizations (COSO), the National Institute of Standards and Technology (NIST), and the Control Objectives for Information Technology (COBIT) – developed by the Information Systems Audit and Control Association (ISACA), all speak to continuous improvement; metrics; and automation as key to strong, optimized, and integrated risk management.

  
​Adjusting
from manual processing and workarounds to automated controls and workflow will
boost an organization’s risk management effectiveness and reduce costs.
   
Continuous Improvement

Many organizations have implemented agile practices to enhance business practices in an incremental and more timely fashion.  Those same practices can be applied to risk management.  Management can shift from annual risk and control assessments to assessments that align with the planned business changes. 

As a part of continuous improvement, management-identified (often noted as self-identified) initiativesand opportunities identified by those who are somewhat removed from the day-to-day practices provide a balance for the organization to enhance controls.  The independent perspective provides for a diversity of thought and complements management's ongoing activities.  Timely implementation of the recognized opportunities supports a culture of responsiveness to change and encourages innovation.

Metrics

A key component to strengthening risk management includes the use of metrics to support risk assessments, management decisions, and operational performance.  Understanding the data created and stored by the organization is critical to metrics development and management.  Inventories of key risk indicators (KRIs) and key performance indicators (KPIs) can be developed to assist management with understanding the effectiveness of their practices. Boundaries to assist management with meeting established risk appetites and tolerance for errors can be included, thereby triggering key discussions for reducing breached conditions.  Those metrics can be trended, normalized, and tweaked over time as the business needs change.

 

Automation

Adjusting from manual processing and workarounds to automated controls and workflow will boost an organization’s risk management effectiveness and reduce costs.  Automation can assist with preventing an undesirable event from occurring, as well as detecting problems in a timely manner, which enables quicker resolution.  Tools that log user and operational events will assist organizations with analytics and decision-making.  Retiring manual processes and workarounds will reduce errors and lower costs for control validations where required.

Conclusion

Organizations with the ability to implement and sustain continuous improvement practices, metrics programs to include KRIs and KPIs, and leveraging automation will develop a culture that integrates risk management into day-to-day activities.  The integration provides for the timely identification and remediation of significant risks.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.