ORCAS operational risk coassessor Operational Risk Management Audit

  • Slides: 20
Download presentation
ORCAS operational risk co-assessor Operational Risk Management & Audit Software for Financial Institutions www.

ORCAS operational risk co-assessor Operational Risk Management & Audit Software for Financial Institutions www. methodware. com

www. methodware. com Financial Clients Methodware tools encompass the experience of organisations around the

www. methodware. com Financial Clients Methodware tools encompass the experience of organisations around the world. Our risk management tools have been designed by risk managers, for risk managers. Below are a few examples of our financial sector clients; Ø Ø Ø Ø Central Banks Retail Banks Private Banks Mortgage Lenders Asset Managers Insurers Major PLCs About Methodware Ltd has been developing and distributing risk management and internal audit software solutions internationally since 1993. Methodware has its Head office in Wellington, New Zealand is extensively represented across the globe, with offices in Europe and North America. Methodware also has a network of partners selling and supporting its products in over 60 countries worldwide. The company’s mission is to improve the effectiveness of customers' assessment processes through the application of risk management and internal audit software tools. Methodware’s adaptable, powerful and user-friendly software solutions make assessment simple for organisations of all sizes and types, from small companies with a single risk manager, to large multi-national organisations with a group risk management function and international teams of auditors. The list of over 1000 clients using Methodware’s software encompasses the public sector, financial services, engineering and manufacturing, retail and telecommunications.

www. methodware. com Basel II - Principles of Sound Operational Risk Management* 10. Public

www. methodware. com Basel II - Principles of Sound Operational Risk Management* 10. Public disclosure of risk exposure & quality of management 9. Regular evalution of strategies, policies, procedures & practices 8. Ensure banks have an effective framework in place DISCLOSURE ROLE OF SUPERVISORS 7. Contingency & business continuity plans 6. Policies, processes & procedures to mitigate risks RISK MANAGEMENT Identification, measurement, monitoring & control 5. Monitor risk profiles & losses - KRIs 4. Identify & assess risks in: products, activities, processes, systems by CRSA, mapping & KRI’s etc. 3. Senior Mgmt responsible for implementing the framework 2. Framework subject to effective & comprehensive internal audit DEVELOP AN APPROPRIATE RISK MANAGEMENT ENVIRONMENT 1. Board sets strategy & framework plus oversight Basel Committee on Banking Supervision: Sound Practices for the Management and Supervision of Operational Risk (February 2003)

www. methodware. com Key Domains Operational Risk Business Unit / Line Management Group Risk’s

www. methodware. com Key Domains Operational Risk Business Unit / Line Management Group Risk’s view Methodology Business Unit’s / Internal Audit’s view Objectives/Processes Treatments Review Notes Risk Assessment Self-Assessment Co-Assessment Analytics Engine Internal Audit Resolver Ballot Control Effectiveness, Testing & Findings Indicators Risk Events Preventing Losses Analysis & Case Management Controls Test Plans Test Results

www. methodware. com ORCAS Home Window Model details can be built up for each

www. methodware. com ORCAS Home Window Model details can be built up for each model under review allowing for specific projects to be assessed as well as the total risk universe. ANZ: 4360 1999 defines absolute risk as consequence x likelihood and the user can define risk categories. Risk Event Impacts are also user definable.

www. methodware. com Business Entity Structure ORCAS allows users to decompose the business entity

www. methodware. com Business Entity Structure ORCAS allows users to decompose the business entity to unlimited levels of granularity. The level of decomposition required depends on the level of detail that is required in the assessment. This detail can also be built up over time as ORCAS allows risks to be defined at any level of the hierarchy.

www. methodware. com Risks Window Each risk identified has two key characteristics: “Consequence” (the

www. methodware. com Risks Window Each risk identified has two key characteristics: “Consequence” (the potential impact of the risk and its consequences should it occur) and “likelihood” (the probability that the risk and its consequences will occur). These variables are consistent with the ANZ Risk Management Standard 4360: 1999. A user definable assessment of these two variables combines to calculate the risk score.

www. methodware. com Risks Window Risks can be assessed at a Business Unit level

www. methodware. com Risks Window Risks can be assessed at a Business Unit level and also at a Corporate level. This allows buy in at all levels of management.

www. methodware. com Indicators Window Key Risk Indicators can be identified and linked to

www. methodware. com Indicators Window Key Risk Indicators can be identified and linked to one or many risks.

www. methodware. com Controls Window The Control screen captures the Control name, reference, description,

www. methodware. com Controls Window The Control screen captures the Control name, reference, description, test plans, test results, owner, category, status, effectiveness, adequacy and the annual cost of implementing it. Controls can also be attached to Risks, Risk Events, Review Notes and Action Plans.

www. methodware. com Multiple linking of objectives ORCAS supports many-to-many relationships between entities, risks,

www. methodware. com Multiple linking of objectives ORCAS supports many-to-many relationships between entities, risks, controls, action plans and risk events. E. g. Risks can be linked to more than one Entity.

www. methodware. com Action plans window Action Plans of Audit Findings and Treatments can

www. methodware. com Action plans window Action Plans of Audit Findings and Treatments can also be applied to risks or controls to further mitigate Risk Levels.

www. methodware. com Loss Events Window Monetary values can be allocated to both Actual

www. methodware. com Loss Events Window Monetary values can be allocated to both Actual and Potential impacts under user definable criteria. Risk Events can be classified to 3 levels and URL links can be made to web published data.

www. methodware. com Revue notes Window Once Risk, Control and Action Plan assessments have

www. methodware. com Revue notes Window Once Risk, Control and Action Plan assessments have been completed, Review Notes can be created to record items that need correction or clarification. Review notes can be linked to Entities, Risks, Controls, Risk Events and Action Plans.

www. methodware. com Graphing Capability ORCAS produces a number of bar charts so that

www. methodware. com Graphing Capability ORCAS produces a number of bar charts so that risk assessment scores (and control effectiveness) for each of the defined risks can be compared. The graphs are colour coded to show the extent to which controls are effective in mitigating risks. The key graphing output produced by ORCAS are the consequence and likelihood matrices (which can be modified to meet client requirements) that illustrate the movement from absolute, controlled to treated scores for each of the assessed risks.

www. methodware. com Absolute to controlled risk Risk matrices graphing The various matrices illustrate

www. methodware. com Absolute to controlled risk Risk matrices graphing The various matrices illustrate ORCAS provides how risks portrayal move graphical from absolute of your review to controlled to time their through real treated graphing. assessments.

www. methodware. com Graphing of Control effectiveness The effectiveness of controls assigned to risks

www. methodware. com Graphing of Control effectiveness The effectiveness of controls assigned to risks (which are grouped by entity) can be graphed.

www. methodware. com Graphing of Loss Events Actual and Potential Risk Events graphed according

www. methodware. com Graphing of Loss Events Actual and Potential Risk Events graphed according to monetary impact.

www. methodware. com ORCAS reporting The ORCAS reporting tool provides a wide range of

www. methodware. com ORCAS reporting The ORCAS reporting tool provides a wide range of high quality, focused reports at the touch of a button. A comprehensive selection of reports are available from the predefined list of batch reports. ORCAS will open either MS Word and MS Excel and generate a report. A selection of list reports is also available for user modification.

Contact Details For further information, or to arrange an online Webex demonstration of ORCAS

Contact Details For further information, or to arrange an online Webex demonstration of ORCAS contact: Martin Price General Manager - EMEA Phone +44 0207 816 6060 Email martin. price@methodware. com ORCAS operational risk co-assessor www. methodware. com