SlideShare ist ein Scribd-Unternehmen logo
1 von 32
Downloaden Sie, um offline zu lesen
Developing and Selling an
Enterprise Risk Management Approach
   Presented by:
   Dave Cunningham, Managing Director
   Baker Robbins & Company

   713-840-0510
   dcunningham@brco.com
Topics
Enterprise Risk Management

1.   Defined
2.   Trends and Issues
3.   Applied to Law Firms
4.   Technology
5.   Value
6.   Program Development
1. ERM Defined



ERM is a management approach focused on maximizing
  shareholder value and ensuring business continuity by
  creating a single view of internal and external risks and
  an executive-level strategy to deal with those risks.
Risk Management Categories
  Risk can be analyzed in these categories:


       Risk Types     Internal          External


    Strategic


     Economic


    Market


    Operational


     Technical
ERM Processes
Understanding Risk Management



       RM is about managing risks, not eliminating them.

Risks are both positive and negative, involving gains and losses.

  Risk management’s overall goal is building and maintaining
   stakeholder confidence: the key to organizational resilience.
2. ERM Trends and Issues

  Compliance Requirements
  Role of Chief Risk Officer
  European Influences (Data Protection, Ethical Walls, Anti-
  Cartel, Anti-Money Laundering, External Investments)
  Technology
     Dependency as business tool
     Risk management tool
  Convergence of Performance and Risk Management
3. ERM Applied to Law Firms


      “It doesn’t take a visionary to see that an
  enterprise view of risk is right for law firms. We
 are 20 years behind the big accounting firms. It’s
    just a matter of how fast we move forward.”

     - General Counsel of AmLaw 20 law firm
ERM Applied to Law Firms

 “Law firms should, in theory, be good in managing
  risks across the firm because the people we are
   dealing with are those who are most affected.”

 “We are coming off of a difficult loss cycle. Firm are
  now being much more active in managing risks.”

             - Managing Director of Aon
Areas of a Firm Addressing Risk (Example)
CONFLICTS & ETHICS                     LITIGATION & SUBPOENA                       INSURANCE
 Conflicts & Ethics and Securities      MATTERS
 Transaction Committees                 Litigation Attorneys                       Professional Indemnity
 Information Services and Records       Managing Attorney’s Office                  Professional Insurance Committee
 Department                             Outside Counsel                             Executive Group
 Outside Counsel                                                                    Finance Department

EMPLOYMENT &                           DATA PRIVACY, SECURITY                      Employment/Worker’s
 PERSONNEL MATTERS                      MATTERS                                     Compensation
 Professional Personnel and Admin HR    Finance Department                          Administrative HR
 Outside Counsel                        IT                                          Finance Department
                                        Professional Personnel and Admin HR
PARTNERSHIP ELECTIONS                                                              Other Insurance
 Policy Committee                      MARKETING & COMMUNICATIONS                   Finance Department
 Executive Group                       (Website, Branding, Copyright, Reviewing     Executive Group
 Finance Department                    Marketing Materials, etc.)
 IT                                       Marketing/Communications Department      FIRM MANUALS AND GUIDANCE
                                                                                    Executive Group (and delegates)
PARTNERSHIP ELECTIONS                  PROFESSIONAL DEVELOPMENT                     Applicable Practice Groups & Departments
                                        Professional Development Department
(Governance, Departures, Disputes)
                                        Professional Personnel
  Executive Group                                                                  INFORMATION RETENTION
  Policy Committee                                                                  IR Project Team
                                       VENDOR CONTRACTS
  Pension Committee                                                                 Steering Group
                                        Applicable Departments (IT, Finance, HR,
  Finance Department                    M/C, etc.)                                  Outside Consultants
  Professional Personnel                                                            All Practice Groups and Departments
  Outside Counsel                      AUDIT
                                        Audit Committee                            FIRM INVESTMENTS
                                        Finance Department                          Investment Committee
Risk Exposure

1. Clients
2. Employees
3. Operations

What keeps General Counsels awake at night?
4. ERM and Technology



             IT is not only a source of risk;
         it provides management with tools
            to implement a risk framework.
Technology: Source of Risk

  Continuity
  Integrity
  Accessibility
  Privacy
Technology: Mitigating Risks

  System Fault Tolerance
  Physical and Electronic Security
  Performance Modeling
  Intranet / Communications
Technology: Mitigating Risks
  Firm Business Processes
     Conflicts and Ethical Walls
     Billing
     Business intelligence and reporting
     Records (e-mail, paper and document) management
     Team-based folders and workspaces
     Knowledge management and expertise identification
     Client relationship management
     Enterprise resource planning
     Self-Service
     Litigation Support Management
Technology: Risk Management Tool (example)

Expected Loss                                          Unexpected Loss




  Internal
 Loss Data

                           Severity

  Enterprise                                             Panjer                           Required
Risk Assessor                                           Recursion                          Capital
                Mapping




                          Frequency
  External
   Data

                                  Adjust for Internal Control       1.   Damage to physical assets
                                                                    2.   Business disruption and system failures
                                                                    3.   Execution, delivery and process management
                                                                    4.   Employment practices and workplace safety
                                                                    5.   Clients, products and business practice
                                                                    6.   Internal fraud
                                                                    7.   External fraud
ERM Dashboard (example)
IT Management Dashboard (example)
5. ERM Business Impact


Gartner research shows that 60% of large enterprises without
   best practice risk management implemented consistently
   across the enterprise will significantly under-perform their
   peers.

Aon: Impact on insurable losses has not been measured.
   ERM helps you look better to the insurance company and
   establish a sense of awareness.
ERM Business Impact – IT Perspective


 Awareness of existing risks
 Mitigation of IT risks
 Necessary component of:
    Service level agreements
    Business continuity planning
    Project charters / business cases
 Reduction of surprises
 A seat with firm management on business issues
6. Program Development

  Two Tracks
     IT (Performance and) Risk Management
     Enterprise Risk Management
IT Performance and Risk Management

  IT Processes
  IT Service Levels
  IT Key Performance Indicators
  Roles and Responsibilities related to risk:
      Change and configuration management
      Quality assurance
      Data architecture and integrity
      Security and privacy
  Content management initiatives
ERM Program Development
Initial Steps
     Context
        Consider current actions and how they may or may not be
        aligned with desired culture of risk
        Establish a baseline


   Identify
        Identify existing risk-related responsibilities
        Identify existing gaps in risk management
        Decide roles and responsibilities
        Determine maturity of the existing situation
Maturity Assessment Model
Maturity Assessment: Risk Process Ratings
Maturity Assessment: Business Processes
Maturity Assessment: IT Processes (1 of 4)
Maturity Assessment: IT Processes (2 of 4)
ERM Standards and Influences
  ERM
     COSO ERM Framework
     AS NZS 4360: 2004
  Compliance
     Sarbanes-Oxley
     Basel II
     ISO
  Standards with risk aspects:
     IT Infrastructure Library (ITIL)
     Project Management Institute PMBOK
Risk Identification Example
       Risk Types         Internal   External


     Strategic


     Economic


     Market


     Operational

     Technical

      Continuity


      Access Management


      Integrity


      Privacy
Risk Prioritization
Conclusion
  Next Steps
     Review how risk is considered and managed in IT projects
     Have initial conversations in your firm about risks
     Determine your own role in enterprise risk
     Perform an assessment of risk areas and understand the
     implications



  Questions and Comments?

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (15)

Riskpro Business Risk Management
Riskpro Business Risk ManagementRiskpro Business Risk Management
Riskpro Business Risk Management
 
Riskpro Risk Alert: RBI regulates MFI
Riskpro Risk Alert: RBI regulates MFIRiskpro Risk Alert: RBI regulates MFI
Riskpro Risk Alert: RBI regulates MFI
 
Amper ERM Presentation to FEI
Amper ERM Presentation to FEIAmper ERM Presentation to FEI
Amper ERM Presentation to FEI
 
Risk Management Certification
Risk Management CertificationRisk Management Certification
Risk Management Certification
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
Riskpro construction industry 2013
Riskpro construction industry 2013Riskpro construction industry 2013
Riskpro construction industry 2013
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
Risk management for law firms chapter 1 ark 2009 by dave cunningham
Risk management for law firms   chapter 1 ark 2009 by dave cunninghamRisk management for law firms   chapter 1 ark 2009 by dave cunningham
Risk management for law firms chapter 1 ark 2009 by dave cunningham
 
PEO Risk Management Advisor 5/2011
PEO Risk Management Advisor 5/2011PEO Risk Management Advisor 5/2011
PEO Risk Management Advisor 5/2011
 
Riskpro healthcare industry 2013
Riskpro healthcare industry 2013Riskpro healthcare industry 2013
Riskpro healthcare industry 2013
 
Riskpro insurance advisory services 2013
Riskpro insurance advisory services 2013Riskpro insurance advisory services 2013
Riskpro insurance advisory services 2013
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
Riskpro construction industry 2013
Riskpro construction industry 2013Riskpro construction industry 2013
Riskpro construction industry 2013
 
Riskpro Construction Industry
Riskpro Construction IndustryRiskpro Construction Industry
Riskpro Construction Industry
 
Riskpro construction industry
Riskpro construction industryRiskpro construction industry
Riskpro construction industry
 

Ähnlich wie Developing an Enterprise Risk Management Approach

Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk ManagementManoj Jain
 
ERM Presentation
ERM PresentationERM Presentation
ERM PresentationH Contrex
 
Riskpro Introduction
Riskpro IntroductionRiskpro Introduction
Riskpro IntroductionManoj Jain
 

Ähnlich wie Developing an Enterprise Risk Management Approach (20)

Riskpro Security Audit
Riskpro Security AuditRiskpro Security Audit
Riskpro Security Audit
 
Riskpro Security Audit
Riskpro Security AuditRiskpro Security Audit
Riskpro Security Audit
 
Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk Management
 
Riskpro information risk management
Riskpro information risk managementRiskpro information risk management
Riskpro information risk management
 
Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk Management
 
Sap Risk Advisory Presentation
Sap Risk Advisory PresentationSap Risk Advisory Presentation
Sap Risk Advisory Presentation
 
Sap risk advisory presentation
Sap risk advisory presentationSap risk advisory presentation
Sap risk advisory presentation
 
Riskpro Information Risk Management
Riskpro Information Risk ManagementRiskpro Information Risk Management
Riskpro Information Risk Management
 
ERM Presentation
ERM PresentationERM Presentation
ERM Presentation
 
Riskpro information risk management 2013
Riskpro information risk management 2013Riskpro information risk management 2013
Riskpro information risk management 2013
 
Riskpro information risk management 2013
Riskpro information risk management 2013Riskpro information risk management 2013
Riskpro information risk management 2013
 
Bpo risk management 2013
Bpo risk management 2013Bpo risk management 2013
Bpo risk management 2013
 
Bpo risk management 2013
Bpo risk management 2013Bpo risk management 2013
Bpo risk management 2013
 
Riskpro Trainings Automotive Industry
Riskpro Trainings Automotive IndustryRiskpro Trainings Automotive Industry
Riskpro Trainings Automotive Industry
 
Riskpro Trainings Automotive Industry
Riskpro Trainings Automotive IndustryRiskpro Trainings Automotive Industry
Riskpro Trainings Automotive Industry
 
Riskpro Trainings Automotive Industry
Riskpro Trainings Automotive IndustryRiskpro Trainings Automotive Industry
Riskpro Trainings Automotive Industry
 
Risk Management Certification
Risk Management CertificationRisk Management Certification
Risk Management Certification
 
Riskpro Introduction
Riskpro IntroductionRiskpro Introduction
Riskpro Introduction
 
Bpo risk management 2013
Bpo risk management 2013Bpo risk management 2013
Bpo risk management 2013
 
Bpo Risk Management
Bpo Risk ManagementBpo Risk Management
Bpo Risk Management
 

Mehr von David Cunningham

The business of data analytics and business intelligence 15 nov 2016
The business of data analytics and business intelligence   15 nov 2016The business of data analytics and business intelligence   15 nov 2016
The business of data analytics and business intelligence 15 nov 2016David Cunningham
 
CLOC Legal Project Management and Simple RFPs
CLOC Legal Project Management and Simple RFPsCLOC Legal Project Management and Simple RFPs
CLOC Legal Project Management and Simple RFPsDavid Cunningham
 
Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015
Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015
Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015David Cunningham
 
ALA 2005 Outsourcing - Making a Decision that Fits by Dave Cunningham Apr 2005
ALA 2005 Outsourcing  - Making a Decision that Fits by Dave Cunningham Apr 2005ALA 2005 Outsourcing  - Making a Decision that Fits by Dave Cunningham Apr 2005
ALA 2005 Outsourcing - Making a Decision that Fits by Dave Cunningham Apr 2005David Cunningham
 
Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...
Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...
Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...David Cunningham
 
Establishing a framework for it governance by dave cunningham 2007
Establishing a framework for it governance by dave cunningham 2007Establishing a framework for it governance by dave cunningham 2007
Establishing a framework for it governance by dave cunningham 2007David Cunningham
 
Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...
Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...
Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...David Cunningham
 
Lit con 2009 collaborate to mitigate panel - facilitated by dave cunningham...
Lit con 2009   collaborate to mitigate panel - facilitated by dave cunningham...Lit con 2009   collaborate to mitigate panel - facilitated by dave cunningham...
Lit con 2009 collaborate to mitigate panel - facilitated by dave cunningham...David Cunningham
 
Ilta 2009 law firm risk management can it grow profitability - panel member...
Ilta 2009 law firm risk management   can it grow profitability - panel member...Ilta 2009 law firm risk management   can it grow profitability - panel member...
Ilta 2009 law firm risk management can it grow profitability - panel member...David Cunningham
 
Out with the old it in with the new by david cunningham - sep 2009
Out with the old it in with the new   by david cunningham - sep 2009Out with the old it in with the new   by david cunningham - sep 2009
Out with the old it in with the new by david cunningham - sep 2009David Cunningham
 
Managing partner retreat using technology to streamline the practice of law...
Managing partner retreat   using technology to streamline the practice of law...Managing partner retreat   using technology to streamline the practice of law...
Managing partner retreat using technology to streamline the practice of law...David Cunningham
 
Law journal news it is dead article; long live it controlling costs while g...
Law journal news   it is dead article; long live it controlling costs while g...Law journal news   it is dead article; long live it controlling costs while g...
Law journal news it is dead article; long live it controlling costs while g...David Cunningham
 
Risk management for law firms chapter 2 ark 2009 by meg block
Risk management for law firms   chapter 2 ark 2009 by meg blockRisk management for law firms   chapter 2 ark 2009 by meg block
Risk management for law firms chapter 2 ark 2009 by meg blockDavid Cunningham
 
Trends shaping the future of legal risk management by dave cunningham and m...
Trends shaping the future of legal risk management   by dave cunningham and m...Trends shaping the future of legal risk management   by dave cunningham and m...
Trends shaping the future of legal risk management by dave cunningham and m...David Cunningham
 
Ltn 2010 02 risk glossary by dave cunningham on page 23
Ltn 2010 02 risk glossary by dave cunningham on page 23Ltn 2010 02 risk glossary by dave cunningham on page 23
Ltn 2010 02 risk glossary by dave cunningham on page 23David Cunningham
 
Law firm information security overview focus on encryption by dave cunningh...
Law firm information security overview   focus on encryption by dave cunningh...Law firm information security overview   focus on encryption by dave cunningh...
Law firm information security overview focus on encryption by dave cunningh...David Cunningham
 
Hildebrandt baker robbins presentation for coo roundtable 2010 by dave cunn...
Hildebrandt baker robbins presentation for coo roundtable 2010   by dave cunn...Hildebrandt baker robbins presentation for coo roundtable 2010   by dave cunn...
Hildebrandt baker robbins presentation for coo roundtable 2010 by dave cunn...David Cunningham
 
Ala 2005 rfp best practices by dave cunningham apr 2005
Ala 2005 rfp best practices by dave cunningham   apr 2005Ala 2005 rfp best practices by dave cunningham   apr 2005
Ala 2005 rfp best practices by dave cunningham apr 2005David Cunningham
 
It sourcing threat or opportunity by dave cunningham- feb 2004
It sourcing   threat or opportunity by dave cunningham- feb 2004It sourcing   threat or opportunity by dave cunningham- feb 2004
It sourcing threat or opportunity by dave cunningham- feb 2004David Cunningham
 

Mehr von David Cunningham (20)

The business of data analytics and business intelligence 15 nov 2016
The business of data analytics and business intelligence   15 nov 2016The business of data analytics and business intelligence   15 nov 2016
The business of data analytics and business intelligence 15 nov 2016
 
50 Shades of Metrics
50 Shades of Metrics50 Shades of Metrics
50 Shades of Metrics
 
CLOC Legal Project Management and Simple RFPs
CLOC Legal Project Management and Simple RFPsCLOC Legal Project Management and Simple RFPs
CLOC Legal Project Management and Simple RFPs
 
Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015
Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015
Iltacon cio corporate legal operations consortium (cloc) metrics aug 2015
 
ALA 2005 Outsourcing - Making a Decision that Fits by Dave Cunningham Apr 2005
ALA 2005 Outsourcing  - Making a Decision that Fits by Dave Cunningham Apr 2005ALA 2005 Outsourcing  - Making a Decision that Fits by Dave Cunningham Apr 2005
ALA 2005 Outsourcing - Making a Decision that Fits by Dave Cunningham Apr 2005
 
Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...
Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...
Ilta 2005 - Evaluating Managed Services - Benchmarks and Case Studies by Dave...
 
Establishing a framework for it governance by dave cunningham 2007
Establishing a framework for it governance by dave cunningham 2007Establishing a framework for it governance by dave cunningham 2007
Establishing a framework for it governance by dave cunningham 2007
 
Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...
Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...
Ilta 2008 challenges in demonstrating it payoff presentation by dave cunningh...
 
Lit con 2009 collaborate to mitigate panel - facilitated by dave cunningham...
Lit con 2009   collaborate to mitigate panel - facilitated by dave cunningham...Lit con 2009   collaborate to mitigate panel - facilitated by dave cunningham...
Lit con 2009 collaborate to mitigate panel - facilitated by dave cunningham...
 
Ilta 2009 law firm risk management can it grow profitability - panel member...
Ilta 2009 law firm risk management   can it grow profitability - panel member...Ilta 2009 law firm risk management   can it grow profitability - panel member...
Ilta 2009 law firm risk management can it grow profitability - panel member...
 
Out with the old it in with the new by david cunningham - sep 2009
Out with the old it in with the new   by david cunningham - sep 2009Out with the old it in with the new   by david cunningham - sep 2009
Out with the old it in with the new by david cunningham - sep 2009
 
Managing partner retreat using technology to streamline the practice of law...
Managing partner retreat   using technology to streamline the practice of law...Managing partner retreat   using technology to streamline the practice of law...
Managing partner retreat using technology to streamline the practice of law...
 
Law journal news it is dead article; long live it controlling costs while g...
Law journal news   it is dead article; long live it controlling costs while g...Law journal news   it is dead article; long live it controlling costs while g...
Law journal news it is dead article; long live it controlling costs while g...
 
Risk management for law firms chapter 2 ark 2009 by meg block
Risk management for law firms   chapter 2 ark 2009 by meg blockRisk management for law firms   chapter 2 ark 2009 by meg block
Risk management for law firms chapter 2 ark 2009 by meg block
 
Trends shaping the future of legal risk management by dave cunningham and m...
Trends shaping the future of legal risk management   by dave cunningham and m...Trends shaping the future of legal risk management   by dave cunningham and m...
Trends shaping the future of legal risk management by dave cunningham and m...
 
Ltn 2010 02 risk glossary by dave cunningham on page 23
Ltn 2010 02 risk glossary by dave cunningham on page 23Ltn 2010 02 risk glossary by dave cunningham on page 23
Ltn 2010 02 risk glossary by dave cunningham on page 23
 
Law firm information security overview focus on encryption by dave cunningh...
Law firm information security overview   focus on encryption by dave cunningh...Law firm information security overview   focus on encryption by dave cunningh...
Law firm information security overview focus on encryption by dave cunningh...
 
Hildebrandt baker robbins presentation for coo roundtable 2010 by dave cunn...
Hildebrandt baker robbins presentation for coo roundtable 2010   by dave cunn...Hildebrandt baker robbins presentation for coo roundtable 2010   by dave cunn...
Hildebrandt baker robbins presentation for coo roundtable 2010 by dave cunn...
 
Ala 2005 rfp best practices by dave cunningham apr 2005
Ala 2005 rfp best practices by dave cunningham   apr 2005Ala 2005 rfp best practices by dave cunningham   apr 2005
Ala 2005 rfp best practices by dave cunningham apr 2005
 
It sourcing threat or opportunity by dave cunningham- feb 2004
It sourcing   threat or opportunity by dave cunningham- feb 2004It sourcing   threat or opportunity by dave cunningham- feb 2004
It sourcing threat or opportunity by dave cunningham- feb 2004
 

Kürzlich hochgeladen

EUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exportersEUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exportersPeter Horsten
 
WSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfWSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfJamesConcepcion7
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environmentelijahj01012
 
Darshan Hiranandani (Son of Niranjan Hiranandani).pdf
Darshan Hiranandani (Son of Niranjan Hiranandani).pdfDarshan Hiranandani (Son of Niranjan Hiranandani).pdf
Darshan Hiranandani (Son of Niranjan Hiranandani).pdfShashank Mehta
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckHajeJanKamps
 
Interoperability and ecosystems: Assembling the industrial metaverse
Interoperability and ecosystems:  Assembling the industrial metaverseInteroperability and ecosystems:  Assembling the industrial metaverse
Interoperability and ecosystems: Assembling the industrial metaverseSiemens
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...Operational Excellence Consulting
 
Customizable Contents Restoration Training
Customizable Contents Restoration TrainingCustomizable Contents Restoration Training
Customizable Contents Restoration TrainingCalvinarnold843
 
Technical Leaders - Working with the Management Team
Technical Leaders - Working with the Management TeamTechnical Leaders - Working with the Management Team
Technical Leaders - Working with the Management TeamArik Fletcher
 
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...ssuserf63bd7
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsIndiaMART InterMESH Limited
 
Excvation Safety for safety officers reference
Excvation Safety for safety officers referenceExcvation Safety for safety officers reference
Excvation Safety for safety officers referencessuser2c065e
 
20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdfChris Skinner
 
WSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdfWSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdfJamesConcepcion7
 
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxRakhi Bazaar
 
Introducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsIntroducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsKnowledgeSeed
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdfShaun Heinrichs
 
Psychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh JiPsychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh Jiastral oracle
 

Kürzlich hochgeladen (20)

EUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exportersEUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exporters
 
WSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfWSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdf
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environment
 
Darshan Hiranandani (Son of Niranjan Hiranandani).pdf
Darshan Hiranandani (Son of Niranjan Hiranandani).pdfDarshan Hiranandani (Son of Niranjan Hiranandani).pdf
Darshan Hiranandani (Son of Niranjan Hiranandani).pdf
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deck
 
Interoperability and ecosystems: Assembling the industrial metaverse
Interoperability and ecosystems:  Assembling the industrial metaverseInteroperability and ecosystems:  Assembling the industrial metaverse
Interoperability and ecosystems: Assembling the industrial metaverse
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors Data
 
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
The McKinsey 7S Framework: A Holistic Approach to Harmonizing All Parts of th...
 
Customizable Contents Restoration Training
Customizable Contents Restoration TrainingCustomizable Contents Restoration Training
Customizable Contents Restoration Training
 
Technical Leaders - Working with the Management Team
Technical Leaders - Working with the Management TeamTechnical Leaders - Working with the Management Team
Technical Leaders - Working with the Management Team
 
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
Intermediate Accounting, Volume 2, 13th Canadian Edition by Donald E. Kieso t...
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan Dynamics
 
Excvation Safety for safety officers reference
Excvation Safety for safety officers referenceExcvation Safety for safety officers reference
Excvation Safety for safety officers reference
 
20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf
 
WSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdfWSMM Technology February.March Newsletter_vF.pdf
WSMM Technology February.March Newsletter_vF.pdf
 
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
 
Introducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsIntroducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applications
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf
 
Psychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh JiPsychic Reading | Spiritual Guidance – Astro Ganesh Ji
Psychic Reading | Spiritual Guidance – Astro Ganesh Ji
 
Authentically Social - presented by Corey Perlman
Authentically Social - presented by Corey PerlmanAuthentically Social - presented by Corey Perlman
Authentically Social - presented by Corey Perlman
 

Developing an Enterprise Risk Management Approach

  • 1. Developing and Selling an Enterprise Risk Management Approach Presented by: Dave Cunningham, Managing Director Baker Robbins & Company 713-840-0510 dcunningham@brco.com
  • 2. Topics Enterprise Risk Management 1. Defined 2. Trends and Issues 3. Applied to Law Firms 4. Technology 5. Value 6. Program Development
  • 3. 1. ERM Defined ERM is a management approach focused on maximizing shareholder value and ensuring business continuity by creating a single view of internal and external risks and an executive-level strategy to deal with those risks.
  • 4. Risk Management Categories Risk can be analyzed in these categories: Risk Types Internal External Strategic Economic Market Operational Technical
  • 6. Understanding Risk Management RM is about managing risks, not eliminating them. Risks are both positive and negative, involving gains and losses. Risk management’s overall goal is building and maintaining stakeholder confidence: the key to organizational resilience.
  • 7. 2. ERM Trends and Issues Compliance Requirements Role of Chief Risk Officer European Influences (Data Protection, Ethical Walls, Anti- Cartel, Anti-Money Laundering, External Investments) Technology Dependency as business tool Risk management tool Convergence of Performance and Risk Management
  • 8. 3. ERM Applied to Law Firms “It doesn’t take a visionary to see that an enterprise view of risk is right for law firms. We are 20 years behind the big accounting firms. It’s just a matter of how fast we move forward.” - General Counsel of AmLaw 20 law firm
  • 9. ERM Applied to Law Firms “Law firms should, in theory, be good in managing risks across the firm because the people we are dealing with are those who are most affected.” “We are coming off of a difficult loss cycle. Firm are now being much more active in managing risks.” - Managing Director of Aon
  • 10. Areas of a Firm Addressing Risk (Example) CONFLICTS & ETHICS LITIGATION & SUBPOENA INSURANCE Conflicts & Ethics and Securities MATTERS Transaction Committees Litigation Attorneys Professional Indemnity Information Services and Records Managing Attorney’s Office Professional Insurance Committee Department Outside Counsel Executive Group Outside Counsel Finance Department EMPLOYMENT & DATA PRIVACY, SECURITY Employment/Worker’s PERSONNEL MATTERS MATTERS Compensation Professional Personnel and Admin HR Finance Department Administrative HR Outside Counsel IT Finance Department Professional Personnel and Admin HR PARTNERSHIP ELECTIONS Other Insurance Policy Committee MARKETING & COMMUNICATIONS Finance Department Executive Group (Website, Branding, Copyright, Reviewing Executive Group Finance Department Marketing Materials, etc.) IT Marketing/Communications Department FIRM MANUALS AND GUIDANCE Executive Group (and delegates) PARTNERSHIP ELECTIONS PROFESSIONAL DEVELOPMENT Applicable Practice Groups & Departments Professional Development Department (Governance, Departures, Disputes) Professional Personnel Executive Group INFORMATION RETENTION Policy Committee IR Project Team VENDOR CONTRACTS Pension Committee Steering Group Applicable Departments (IT, Finance, HR, Finance Department M/C, etc.) Outside Consultants Professional Personnel All Practice Groups and Departments Outside Counsel AUDIT Audit Committee FIRM INVESTMENTS Finance Department Investment Committee
  • 11. Risk Exposure 1. Clients 2. Employees 3. Operations What keeps General Counsels awake at night?
  • 12. 4. ERM and Technology IT is not only a source of risk; it provides management with tools to implement a risk framework.
  • 13. Technology: Source of Risk Continuity Integrity Accessibility Privacy
  • 14. Technology: Mitigating Risks System Fault Tolerance Physical and Electronic Security Performance Modeling Intranet / Communications
  • 15. Technology: Mitigating Risks Firm Business Processes Conflicts and Ethical Walls Billing Business intelligence and reporting Records (e-mail, paper and document) management Team-based folders and workspaces Knowledge management and expertise identification Client relationship management Enterprise resource planning Self-Service Litigation Support Management
  • 16. Technology: Risk Management Tool (example) Expected Loss Unexpected Loss Internal Loss Data Severity Enterprise Panjer Required Risk Assessor Recursion Capital Mapping Frequency External Data Adjust for Internal Control 1. Damage to physical assets 2. Business disruption and system failures 3. Execution, delivery and process management 4. Employment practices and workplace safety 5. Clients, products and business practice 6. Internal fraud 7. External fraud
  • 19. 5. ERM Business Impact Gartner research shows that 60% of large enterprises without best practice risk management implemented consistently across the enterprise will significantly under-perform their peers. Aon: Impact on insurable losses has not been measured. ERM helps you look better to the insurance company and establish a sense of awareness.
  • 20. ERM Business Impact – IT Perspective Awareness of existing risks Mitigation of IT risks Necessary component of: Service level agreements Business continuity planning Project charters / business cases Reduction of surprises A seat with firm management on business issues
  • 21. 6. Program Development Two Tracks IT (Performance and) Risk Management Enterprise Risk Management
  • 22. IT Performance and Risk Management IT Processes IT Service Levels IT Key Performance Indicators Roles and Responsibilities related to risk: Change and configuration management Quality assurance Data architecture and integrity Security and privacy Content management initiatives
  • 23. ERM Program Development Initial Steps Context Consider current actions and how they may or may not be aligned with desired culture of risk Establish a baseline Identify Identify existing risk-related responsibilities Identify existing gaps in risk management Decide roles and responsibilities Determine maturity of the existing situation
  • 25. Maturity Assessment: Risk Process Ratings
  • 27. Maturity Assessment: IT Processes (1 of 4)
  • 28. Maturity Assessment: IT Processes (2 of 4)
  • 29. ERM Standards and Influences ERM COSO ERM Framework AS NZS 4360: 2004 Compliance Sarbanes-Oxley Basel II ISO Standards with risk aspects: IT Infrastructure Library (ITIL) Project Management Institute PMBOK
  • 30. Risk Identification Example Risk Types Internal External Strategic Economic Market Operational Technical Continuity Access Management Integrity Privacy
  • 32. Conclusion Next Steps Review how risk is considered and managed in IT projects Have initial conversations in your firm about risks Determine your own role in enterprise risk Perform an assessment of risk areas and understand the implications Questions and Comments?