Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

The Corporate Risk Management Library

Posted on December 18, 2008April 16, 2009 by Doug Cornelius
Print Friendly, PDF & Email

Here are my notes from this webinar from Compliance Week, sponsored by CA, Inc.: Enhancing the Risk Profile of Your Organization: The Corporate Risk Management Library

Speakers:
Tom McHale, Vice President of Product Management, CA
Christopher Fox, Principal Consultant, Governance Compliance and Risk Group, CA

We are seeing a movement from executive autonomy to executive accountability and corporate secrecy to corporate transparency.

We are seeing an evolution in risk management. We need to identify the strategic risks. We also need to figure out how to get ourselves assured that we are addressing all risks. We are in a changing and diverse environment with government investments, stimulus packages, new regulations and new issues.

A “risk library” is comprehensive set of risks for specific categories, with a representation of the scope of risks for an organization, used by enterprise risk management processes. One key is to have an agreed upon classification (or taxonomy) across the organization.

In searching for a risk library where can you start? These are some references:

  • Federal Sentencing Guidelines
  • OCEG Redbook
  • COSO
  • Federal Reserve Guidance
  • CobIT 4.1
  • Federal Reserve URSIT
  • ISO 27002
  • EPA Legislations
  • Basel II
  • SEC  listing requirements
  • Australian Standard 4360

The requirements of a risk library should have a holistic view. Financial risk is only one dimension. You want to also include strategic and tactical risk.

They moved onto examples of a risk library structure.

They set level 1 as internal risk and external risk. Level 2 was broken down into governance, operations, technology, compliance, financial, reporting, environment, international, market and social trends. Then they showed a third level of risk below the level 2 risk of governance. then they show a level 4 of various market conditions  such as demographics, employment, labor relations and exchange rates.

Once you have the corporate risk management library, you decide which risks you can manage. After selecting those to manage you need to report on the risks, set up a compliance program, create policies and procedures, assess the risks and create an action program.

Share this:

  • Click to print (Opens in new window) Print
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on X (Opens in new window) X
  • Click to email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • Compliance Bricks and Mortar for January 9
  • “Small”: I Don’t Think You Know What That Means
  • CFTC is Saying Goodbye to Private Funds
  • New York’s LLC Transparency Act Will Remain Limited
  • SEC and CFTC With Only Republicans
  • Compliance Books from 2025
  • Happy New Year
  • The One That Can Drive You and Give You Investment Advice
  • The One with the Foreclosure and OFAC Sanctions
  • Can Precious Gem Buying Being Securities Fraud?

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.