Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Risk Assessment – Getting It Right

Posted on April 16, 2009 by Doug Cornelius
Print Friendly, PDF & Email

pwc

PricewaterhouseCoopers LLP sponsored this webcast: Corporate leaders have long recognized that the pace of change continues to increase in velocity, thus challenging management’s execution of the business’ strategic and tactical plans. Enterprise Risk Management (ERM) is a management tool that can be effective in identifying and assessing the risks that come with change and allow management to respond to their organization’s changing risk profile in a timely fashion. The speakers were all from PricewaterhouseCoopers LLP:

  • Joseph C. Atkinson, Principal
  • Brian Brown, Partner
  • Peter Frank, Director
  • Catherine Jourdan, Director

These are my notes.

Why focus on risk? Changes in the marketplace and the world economy has given the perception that the world is a riskier place. That may or not be true. But people are more focused on risk. It seems that poor risk management had a role in the recent economic troubles. Joe advocates that risk assessment should be integrated into business processes.

Brian took over and focused on defining risk and risk management. “Risk assessment is a systematic process for identifying and evaluating the events that could affect the achievement of an organization’s objectives, both positively or negatively.”

Risk Assessment can be mandatory or voluntary. Anti-Money-Laundering, Basel II, and Sarbanes-Oxley compliance all require formalized risk assessment and focus on such processes as monitoring of client accounts, operational risk management, and internal control over financial reporting. Often it also voluntary, driven by business needs, to assess development opportunities, talent retention, operational efficiency and performance improvement.

There are three primary frameworks for risk management: COSO‘s ERM requirements, Federal Sentencing Guidelines, and OCEG’s Red Book.

Peter took over and focused on the challenges to an effective risk assessment. Common business challenges include:

  • Risk assessment is viewed only as an episodic initiative, a required report that needs to be updated
  • An inordinate amount of effort is invested in gathering data and information, and the volume is difficult to interpret and leverage in a meaningful way for executive leadership
  • The risk assessment is viewed as a conclusion of the process, rather than a starting point.
  • Risks are identified and risk mitigation practices are emphasized without meaningful understanding of impact, causing some risks to be over-controlled and stifling innovation
  • Risk assessment is viewed as an additional function or department, not as an integrated management capability to embed in day-to-day activities
  • Accountability for risk management and performance management resides in silos
  • Multiple risks assessments are performed, using different definitions and measurements of risks, creating confusion and making confident action impossible

Catherine moved on to the six essential steps to performing a risk assessment.

  1. Identify relevant business objectives
  2. Identify events that that could affect the achievement of objectives
  3. Determine risk tolerance
  4. Assess inherent likelihood and impact of risks
  5. Evaluate the portfolio of risks and determine risk responses
  6. Assess residual likelihood and impact of risks

Joe came back to conclude that “risk assessment discipline should be embedded in the organization’s regular business processes and yield valuable information to support decision-making to help systematically link risk, reward, and performance management.”

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • BlueSky Eagle and the Ghost Filing
  • Updates to the SEC Enforcement Manual
  • When Drug Lords Want Their Kids to Be Better Athletes
  • Insider Trading Before Bankruptcy
  • Relief for ’40 Act Funds
  • Artificial Intelligence Produced Materials are Not Protected by Privilege
  • FINRA Looks to Allow Projected Performance
  • California’s Fair Investment Practices by Venture Capital Companies
  • Compliance Bricks and Mortar for January 30
  • Interpreter Insider Trading

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.