SlideShare ist ein Scribd-Unternehmen logo
1 von 29
HCCA Board Audit Committee Compliance
Conference
February 27 – 28, 2017
Presented by:
Kimberly Lansford, RN, BSN, MHL, CHC®
Shannon Sumner, CPA, CHC®
ASSESSING THE EFFECTIVENESS OF ERM
Enterprise Risk Management
Prepared for Health Care Compliance Association Page 1
SPEAKERS
Kimberly A. Lansford
RN, BSN, MHL, CHC ®
Chief Compliance Officer
PennState Health
Shannon Sumner
CPA, CHC ®
Principal/Shareholder
Pershing Yoakley & Associates, P.C.
ssumner@pyapc.com
PERSHING YOAKLEY & ASSOCIATES, P.C.
800.270.9629 | www.pyapc.com
Prepared for Health Care Compliance Association Page 2
What Is Enterprise Risk Management (ERM)?
 A process that engages all in the practice of identifying, managing,
monitoring, and communicating risks across an organization
 Main objective is to help management and the board understand and
manage those events most likely to impact the organization’s
strategic objectives
 Its aim is to function in a proactive and efficient manner and as a key
enabler of the organization’s strategic objectives
 It seeks to orchestrate the harmonization, synchronization, and
rationalization of areas managing risks by moving beyond
organizational barriers to open transparent communications across
disciplines
Prepared for Health Care Compliance Association Page 3
Definitions
 Risk Culture: "The values, beliefs, knowledge, attitudes and
understanding about risk shared by a group of people with a common
purpose, in particular the employees of an organization" (Institute of
Risk Management)
 Risk Appetite: Relates to the amount of risk that an organization is
willing to seek or accept in the pursuit of its long-term objectives
Source: The Institute of Risk Management https://www.theirm.org/
Prepared for Health Care Compliance Association Page 4
ERM Provides a Process that Allows the Organization to:
 Present governance and management with a comprehensive picture
of interdependent risks across the entire enterprise
 Break down the department silos that tend to exist in assessing risk
 Create cross-functional teams evaluating risk using a common
framework
 Communicate information about risks in a consistent manner
Prepared for Health Care Compliance Association Page 5
Traditional Healthcare RM vs. ERM
Traditional Risk Management
 Reactive, incident-based, clinically focused
program
 May use different processes, controls,
metrics, language, and frameworks for
discussing risks and risk mitigation strategies
 Considers impact of risks to specific
departments or issues in isolation
 Focus on adverse events most likely to
impact operations and finances
 Examines risks individually, with limited
communication between disciplines to
consider the impact of their actions on other
parts of the organization
 Defines risks in terms of the probability that
adverse events will occur and result in
financial losses
 Tendency to be a bottom-up approach
Enterprise Risk Management
 Proactive, holistic, multi-disciplinary approach
focused on anticipating and managing both
internal and external risks
 Provides a common framework, processes,
metrics, and language for discussing risks
and risk mitigation strategies
 Considers impact of risks across the
organization
 Focus on events most likely to impact
strategic objectives
 Emphasis on synergistic relationship among
and between risks that span across the
organization
 Recognizes that risk does not solely mean
something negative has or could occur –
something good not happening as a result of
not acting is also a risk
 Top-down and bottom-up approach
Prepared for Health Care Compliance Association Page 6
ERM Benefits
 Helps identify and understand key risks impacting achievement of
strategies and objectives
 Invites broad participation and perspectives of senior leaders and
governance
 Helps avoid a “functional silo” approach that often fails to consider the
interconnective nature of risks across large, complex organizations
 Provides a common framework for discussing risks and risk
management or “treatment” strategies
 Assists in establishing accountabilities for risk management activities
 Integrates risk planning with strategic and tactical planning
 Over time, more effective and cost-efficient management of risks
increases enterprise value
Prepared for Health Care Compliance Association Page 7
Why Is an ERM Approach Important?
 The United States Federal Sentencing Guidelines are clear that
standards and procedures should provide sufficient and effective
controls that take into account the highest risk areas, given an
organization’s business
 The Office of Inspector General (OIG) recommends a risk-based
approach in its guidance, and recent Corporate Integrity Agreement
templates require a provider’s compliance program to include a
comprehensive risk assessment and internal review process
 The OIG is clear that a comprehensive risk assessment cannot be
pursued by the Compliance Department alone, and involvement from key
business leaders (including legal) is critical to the effectiveness of the risk
assessment process
Prepared for Health Care Compliance Association Page 8
Why Is an ERM approach important? (cont.)
 All major rating agencies include ERM in their evaluation of credit
ratings
 Critical component of financial and insurance
industry evaluations
 Healthcare auditing entities, such as those that
have oversight for HIPAA, may inquire into the
process when auditing areas that require a
risk-based approach (e.g., information security)
Prepared for Health Care Compliance Association Page 9
Why Is the Compliance Department Well Situated
to Facilitate an ERM Approach?
 An ERM approach engages all workforce members in the practice of
identifying, managing, monitoring, and communicating risks across
the organization
 We are already doing this with regard to our compliance risks in our
compliance programs
Prepared for Health Care Compliance Association Page 10
Components of a Successful ERM Approach
Step One: Know the Business Climate
 Understand which business factors have the
ability to impact operations or cause potential
compliance concerns
 Benchmark both inside and outside the
organization, and possibly even outside the
healthcare industry
Prepared for Health Care Compliance Association Page 11
Components of a Successful ERM Approach (cont.)
Step Two: Understand and Prioritize Risks and
Opportunities
 Ensure colleagues understand how to identify and report risks and
opportunities
 Two key activities:
 Deploy a comprehensive Education and Awareness program
 Perform an Enterprise Risk Assessment, with focused reviews of an
organization’s most significant risks, on an ongoing basis
 Leverage existing strategies used by colleagues to report events,
such as those utilized in Privacy, Information Security, Insurance/Risk
Management, Compliance, Clinical/Nursing, and other departments
Prepared for Health Care Compliance Association Page 12
Step Three: Manage the Identified Risks and Opportunities
 Create a centralized process or have a collaborative process to
analyze and manage risk and opportunity information
 Some common risk management (“treatment”) techniques:
 Avoidance (eliminate, withdraw from, or not become involved)
 Reduction (optimize – mitigate)
 Sharing (transfer – outsource or insure)
 Retention (accept and budget)
Components of a Successful ERM Approach (cont.)
Prepared for Health Care Compliance Association Page 13
Step Four: Reporting and Metrics
 Reports and metrics can be used by operations, budgeting, strategy,
audit, compliance, and many other departments for strategy and
decision-making, where the consideration of risk can influence the
outcome
 Dashboards, risk monitoring reports,
qualitative, and quantitative analysis
can be used to measure the effectiveness
of risk treatment activities and to understand
any implications for an organization’s overall
business strategy
Components of a Successful ERM Approach (cont.)
Prepared for Health Care Compliance Association Page 14
Step Five: Risk “Alert” Culture and Risk Control
 A risk alert culture is the intrinsic understanding and assessment of
risk embedded in day-to-day operations. It fosters the integration of
enterprise risk principles throughout every layer of the organization
 Risk Controls are measures to limit vulnerabilities and manage risks
to an acceptable level
 A risk alert culture and risk control are created by:
 Adhering to policies and procedures, laws, and regulations
 Educating and holding colleagues accountable for evaluating risk
holistically in strategic initiatives
 Creating and utilizing a common language
 Effectively using preemptive risk concepts within business units
Components of a Successful ERM Approach (cont.)
Prepared for Health Care Compliance Association Page 15
ERM Is Everyone’s Responsibility…
• ERM engages everyone at the organization in the management of
those risks for which they are responsible
• Risk ownership does not reside in a single department
• The compliance department can easily
facilitate an ERM approach to managing
risks across the organization
Prepared for Health Care Compliance Association Page 16
ERM Is a Journey…It Is Not a Destination!
Prepared for Health Care Compliance Association Page 17
Board Accountability for Risk
 Greater Scrutiny from OIG and DOJ
 Recent CIA Risk Assessment Requirements
 Three Lines of Defense Theory
 Quality of Risk Assessment Process
 Ongoing Risk Assessment Process
 Connecting the Dots
Prepared for Health Care Compliance Association Page 18
Greater Scrutiny Emerges
Prepared for Health Care Compliance Association Page 19
DOJ Hires Compliance Expert
Source: http://www.corpcounsel.com/id=1202737784530/Report-Justice-Dept-Names-Chen-to-Controversial-Compliance-Counsel-Post?slreturn=20150923095150
“…the person will be assessing the
company’s claims about their compliance
program – i.e., if a company seeks to
claim that it deserves credit for
implementing a state of the art
compliance program, which is a metric
under the Sentencing Guidelines for a
break on a fine. The counsel will help
subject that to a rigorous analysis,
something that a federal prosecutor does
not have a lot of expertise in carrying out.”
Prepared for Health Care Compliance Association Page 20
Risk-Specific CIA Requirements
Source: https://oig.hhs.gov/fraud/cia/agreements/Dignity_Health_10302014.pdf
 Risk Assessment and Internal Review Process
“The risk assessment and internal review process shall include: (1) a process
for identifying and prioritizing potential risks; (2) developing an assessment
plan to evaluate and respond to potential risks, including internal auditing
and monitoring of the potential risk areas; (3) developing action plans to
remediate potential risks; and (4) tracking results to assess the effectiveness
of the risk assessment and internal review process, including any
remediation efforts that ABC pursues.”
Prepared for Health Care Compliance Association Page 21
Three Lines of Defense
Source: Institute of Internal Auditors: The Three Lines of Defense in Effective Risk Management and Control
Prepared for Health Care Compliance Association Page 22
Quality of Risk Assessment Process
 Risk Assessment Inputs – Questions to Ask
 Is the risk universe inclusive of all significant processes/entities/joint
ventures/outsourced service providers?
 What is the competency of staff performing the risk assessment?
 What risk-ranking criteria and weight factors are used?
 Have risks to the achievement of strategic objectives been included?
 What is the involvement of other “assurance providers”
(e.g., internal audit, legal, compliance, IT, quality, risk management, etc.)?
 Who is the Executive Sponsor (e.g., “Tone at the Top”)?
Prepared for Health Care Compliance Association Page 23
Quality of Risk Assessment Process (cont.)
 Risk Ranking Example
RISK FACTOR DESCRIPTION/EXAMPLES WEIGHT
Internal Control History
Control environment, risk management process, effectiveness
of Internal Controls
25%
Change
Systems, processes, personnel/turnover, new services, laws
and regulations
20%
Factors External to Process
Industry forces, market forces, national politics, community
needs, degree of exposure to adversity,
governance/management concern
15%
Customer Service (Internal
& External)
Degree of customer service provided, impact on operations,
effect on reputation
15%
Complexity
Multiple systems required, date of technology in use, equipment
and expertise required
15%
Materiality & Resources
Extent that the size of the unit could affect potential loss to the
organization, adequacy of available resources for associated
process
10%
Prepared for Health Care Compliance Association Page 24
Quality of Risk Assessment Process (cont.)
 Risk Assessment Outputs – Questions to Ask
 Does the prioritization of risks align with risk appetite?
 What is the coverage of risks not able to be audited/monitored?
 Has management accountability been established?
 Are there any significant risks not included?
 Is the resulting work plan risk focused vs. department focused (e.g., risk doesn’t
reside in silos)?
 Centralized governance oversight and reporting?
Prepared for Health Care Compliance Association Page 25
Ongoing Risk Assessment
 Risk-Trending/Red Flags
 Central themes in internal audit/external audit/compliance reports
 Monitor work plan additions/subtractions
 Monitor deferrals or cancellations (risk is still there!)
 Monitor completeness throughout the year
 Error percentages consistently high (>5%)
 Action plans consistently past due
Prepared for Health Care Compliance Association Page 26
Ongoing Risk Assessment (cont.)
 Places Where Risks Hide
 Outsourced service providers
 Significant turnover/new management
 New and/or complex service lines
 People, Process, Technology
 Lack of ongoing training/education in
high-risk areas
 Drivers for incentive compensation
 Lack of contract monitoring (e.g.,
physicians, outsourced areas)
?
?
?
Prepared for Health Care Compliance Association Page 27
Connect the Dots
 Control Environment “Dashboard”
 Management Letter Comments
 Turnover in Key Management Positions
 External Audit Findings
 Internal Audit Findings
 Audit Follow-up Completion (High Risks)
Prepared for Health Care Compliance Association Page 28
THANK YOU!
Kimberly A. Lansford
RN, BSN, MHL, CHC ®
Chief Compliance Officer
PennState Health
Shannon Sumner
CPA, CHC ®
Principal/Shareholder
Pershing Yoakley & Associates, P.C.
ssumner@pyapc.com
PERSHING YOAKLEY & ASSOCIATES, P.C.
800.270.9629 | www.pyapc.com

Weitere ähnliche Inhalte

Was ist angesagt?

Risk Management Fundamentals
Risk Management FundamentalsRisk Management Fundamentals
Risk Management Fundamentals
mikaelastafrace
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
arsqureshi
 
Operational Risk Management - A Gateway to managing the risk profile of your...
Operational Risk Management -  A Gateway to managing the risk profile of your...Operational Risk Management -  A Gateway to managing the risk profile of your...
Operational Risk Management - A Gateway to managing the risk profile of your...
Eneni Oduwole
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
Frackson Kathibula-Nyoni
 

Was ist angesagt? (20)

Risk Management
Risk ManagementRisk Management
Risk Management
 
The importance of risk management in business
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in business
 
Chapter 4: Governance and Risk Management
Chapter 4: Governance and Risk ManagementChapter 4: Governance and Risk Management
Chapter 4: Governance and Risk Management
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
Risk Management Fundamentals
Risk Management FundamentalsRisk Management Fundamentals
Risk Management Fundamentals
 
ERM Presentation
ERM PresentationERM Presentation
ERM Presentation
 
Operational Risk Management
Operational Risk ManagementOperational Risk Management
Operational Risk Management
 
Organizational Risk Management
Organizational Risk Management Organizational Risk Management
Organizational Risk Management
 
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Risk Management Framework
Risk Management FrameworkRisk Management Framework
Risk Management Framework
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
RisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNT
RisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNTRisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNT
RisK, RiSk MaNaGeMeNt & EnterPRise RisK ManaGemeNT
 
Risk management
Risk managementRisk management
Risk management
 
Risk management
Risk management Risk management
Risk management
 
Risk Management module PowerPoint Presentation Slides
Risk Management module PowerPoint Presentation SlidesRisk Management module PowerPoint Presentation Slides
Risk Management module PowerPoint Presentation Slides
 
Operational Risk Management - A Gateway to managing the risk profile of your...
Operational Risk Management -  A Gateway to managing the risk profile of your...Operational Risk Management -  A Gateway to managing the risk profile of your...
Operational Risk Management - A Gateway to managing the risk profile of your...
 
Enterprise Risk Management
Enterprise Risk Management Enterprise Risk Management
Enterprise Risk Management
 
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATIONOPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
OPERATIONAL RISK MANAGEMENT FRAMEWORK PRESENTATION
 

Andere mochten auch

Career pathways: Who Will Hire Me?
Career pathways: Who Will Hire Me?Career pathways: Who Will Hire Me?
Career pathways: Who Will Hire Me?
s302067
 
a Career as an Actuary
a Career as an Actuarya Career as an Actuary
a Career as an Actuary
guest5393d
 

Andere mochten auch (20)

Risk-Based Contracting: Background, Assessment, and Implementation
Risk-Based Contracting: Background, Assessment, and ImplementationRisk-Based Contracting: Background, Assessment, and Implementation
Risk-Based Contracting: Background, Assessment, and Implementation
 
What's CMS Up To These Days
What's CMS Up To These DaysWhat's CMS Up To These Days
What's CMS Up To These Days
 
Exploring Methodologies and Discount Rates in Valuing Intangible Assets
Exploring Methodologies and Discount Rates in Valuing Intangible AssetsExploring Methodologies and Discount Rates in Valuing Intangible Assets
Exploring Methodologies and Discount Rates in Valuing Intangible Assets
 
The Vicissitudes of Valuing Value--Legal and Valuation Issues Associated with...
The Vicissitudes of Valuing Value--Legal and Valuation Issues Associated with...The Vicissitudes of Valuing Value--Legal and Valuation Issues Associated with...
The Vicissitudes of Valuing Value--Legal and Valuation Issues Associated with...
 
Using the Relief from Royalty Method to Value Trade Names
Using the Relief from Royalty Method to Value Trade NamesUsing the Relief from Royalty Method to Value Trade Names
Using the Relief from Royalty Method to Value Trade Names
 
Transforming the Business of Oncology Through Science and Technology
Transforming the Business of Oncology Through Science and TechnologyTransforming the Business of Oncology Through Science and Technology
Transforming the Business of Oncology Through Science and Technology
 
Office of Civil Rights HIPAA Audits Preparing Your Clients and Yourself
Office of Civil Rights HIPAA Audits Preparing Your Clients and YourselfOffice of Civil Rights HIPAA Audits Preparing Your Clients and Yourself
Office of Civil Rights HIPAA Audits Preparing Your Clients and Yourself
 
Surviving the Healthcare World of Risk Adjustment
Surviving the Healthcare World of Risk AdjustmentSurviving the Healthcare World of Risk Adjustment
Surviving the Healthcare World of Risk Adjustment
 
Transitioning Within a New Market
Transitioning Within a New MarketTransitioning Within a New Market
Transitioning Within a New Market
 
Compliance Is One of the Best Ways to Market Your Business
Compliance Is One of the Best Ways to Market Your BusinessCompliance Is One of the Best Ways to Market Your Business
Compliance Is One of the Best Ways to Market Your Business
 
Enterprise Risk Management Framework
Enterprise Risk Management FrameworkEnterprise Risk Management Framework
Enterprise Risk Management Framework
 
What are actuaries good for?
What are actuaries good for?What are actuaries good for?
What are actuaries good for?
 
What Is Actuaries Job?
What Is Actuaries Job? What Is Actuaries Job?
What Is Actuaries Job?
 
Analytics for actuaries cia
Analytics for actuaries ciaAnalytics for actuaries cia
Analytics for actuaries cia
 
Career pathways: Who Will Hire Me?
Career pathways: Who Will Hire Me?Career pathways: Who Will Hire Me?
Career pathways: Who Will Hire Me?
 
A career as an actuary
A career as an actuaryA career as an actuary
A career as an actuary
 
a Career as an Actuary
a Career as an Actuarya Career as an Actuary
a Career as an Actuary
 
Tesis 2
Tesis 2Tesis 2
Tesis 2
 
Slide computao quântica
Slide computao quânticaSlide computao quântica
Slide computao quântica
 
夏休み自由研究(2015年) 後編
夏休み自由研究(2015年) 後編夏休み自由研究(2015年) 後編
夏休み自由研究(2015年) 後編
 

Ähnlich wie Enterprise Risk Management

Coso Erm(2)
Coso Erm(2)Coso Erm(2)
Coso Erm(2)
deeptica
 
Financial Management Of Head Starts.1.Qa
Financial Management Of Head Starts.1.QaFinancial Management Of Head Starts.1.Qa
Financial Management Of Head Starts.1.Qa
Reginald Walker
 
ERM Evolving From Risk Assessment to Strategic RiskManageme.docx
ERM Evolving From Risk Assessment to Strategic RiskManageme.docxERM Evolving From Risk Assessment to Strategic RiskManageme.docx
ERM Evolving From Risk Assessment to Strategic RiskManageme.docx
russelldayna
 
WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)
WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)
WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)
Keith Darcy
 
Write a 3-4 page risk management policy and procedure for a health c.docx
Write a 3-4 page risk management policy and procedure for a health c.docxWrite a 3-4 page risk management policy and procedure for a health c.docx
Write a 3-4 page risk management policy and procedure for a health c.docx
owenhall46084
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
peterObakozuwa
 
STRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_Newsletter
STRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_NewsletterSTRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_Newsletter
STRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_Newsletter
Dion K Hamilton
 

Ähnlich wie Enterprise Risk Management (20)

Coso Erm(2)
Coso Erm(2)Coso Erm(2)
Coso Erm(2)
 
Risk management
Risk managementRisk management
Risk management
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_en
 
Managing Organizational Risk: The Mighty Triad of Compliance, Internal Audit,...
Managing Organizational Risk: The Mighty Triad of Compliance, Internal Audit,...Managing Organizational Risk: The Mighty Triad of Compliance, Internal Audit,...
Managing Organizational Risk: The Mighty Triad of Compliance, Internal Audit,...
 
A to Z of Risk Management
A to Z of Risk ManagementA to Z of Risk Management
A to Z of Risk Management
 
Financial Management Of Head Starts.1.Qa
Financial Management Of Head Starts.1.QaFinancial Management Of Head Starts.1.Qa
Financial Management Of Head Starts.1.Qa
 
Operations
OperationsOperations
Operations
 
ERM Evolving From Risk Assessment to Strategic RiskManageme.docx
ERM Evolving From Risk Assessment to Strategic RiskManageme.docxERM Evolving From Risk Assessment to Strategic RiskManageme.docx
ERM Evolving From Risk Assessment to Strategic RiskManageme.docx
 
WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)
WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)
WSJ-Compliance Risks What You Don’t Contain Can Hurt You - Deloitte Risk (1)
 
7 Key Elements Of An Enterprise Risk Management Program
7 Key Elements Of An Enterprise Risk Management Program7 Key Elements Of An Enterprise Risk Management Program
7 Key Elements Of An Enterprise Risk Management Program
 
Risk Courseware Complete courses for Financier
Risk Courseware Complete courses for FinancierRisk Courseware Complete courses for Financier
Risk Courseware Complete courses for Financier
 
Risk_Courseware.ppt
Risk_Courseware.pptRisk_Courseware.ppt
Risk_Courseware.ppt
 
Write a 3-4 page risk management policy and procedure for a health c.docx
Write a 3-4 page risk management policy and procedure for a health c.docxWrite a 3-4 page risk management policy and procedure for a health c.docx
Write a 3-4 page risk management policy and procedure for a health c.docx
 
Risck intelligence in the energy and resources industry
Risck intelligence in the energy and resources industry Risck intelligence in the energy and resources industry
Risck intelligence in the energy and resources industry
 
The IRM India- A Risk Management Standard
The IRM India- A Risk Management StandardThe IRM India- A Risk Management Standard
The IRM India- A Risk Management Standard
 
Audit, control and enterprise wide risk management
Audit, control and enterprise wide risk managementAudit, control and enterprise wide risk management
Audit, control and enterprise wide risk management
 
STRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_Newsletter
STRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_NewsletterSTRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_Newsletter
STRATEGIC RISK ADVISORY SOLUTIONS_Risk Management_Newsletter
 
Qpr 8 Risk Management And Compliance Solution
Qpr 8 Risk Management And Compliance SolutionQpr 8 Risk Management And Compliance Solution
Qpr 8 Risk Management And Compliance Solution
 
My report_donald.docx
My report_donald.docxMy report_donald.docx
My report_donald.docx
 
Southmead Hospital Presentation
Southmead Hospital PresentationSouthmead Hospital Presentation
Southmead Hospital Presentation
 

Mehr von PYA, P.C.

Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...
Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...
Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...
PYA, P.C.
 

Mehr von PYA, P.C. (20)

“CARES Act Provider Relief Fund: Opportunities, Compliance, and Reporting”
“CARES Act Provider Relief Fund: Opportunities, Compliance, and Reporting”“CARES Act Provider Relief Fund: Opportunities, Compliance, and Reporting”
“CARES Act Provider Relief Fund: Opportunities, Compliance, and Reporting”
 
PYA Presented on 2021 E/M Changes and a CARES Act Update During GHA Complianc...
PYA Presented on 2021 E/M Changes and a CARES Act Update During GHA Complianc...PYA Presented on 2021 E/M Changes and a CARES Act Update During GHA Complianc...
PYA Presented on 2021 E/M Changes and a CARES Act Update During GHA Complianc...
 
Webinar: “Trick or Treat? October 22nd Revisions to Provider Relief Fund Repo...
Webinar: “Trick or Treat? October 22nd Revisions to Provider Relief Fund Repo...Webinar: “Trick or Treat? October 22nd Revisions to Provider Relief Fund Repo...
Webinar: “Trick or Treat? October 22nd Revisions to Provider Relief Fund Repo...
 
“Regulatory Compliance Enforcement Update: Getting Results from the Guidance”
“Regulatory Compliance Enforcement Update: Getting Results from the Guidance” “Regulatory Compliance Enforcement Update: Getting Results from the Guidance”
“Regulatory Compliance Enforcement Update: Getting Results from the Guidance”
 
“Federal Legislative and Regulatory Update,” Webinar at DFWHC
 “Federal Legislative and Regulatory Update,” Webinar at DFWHC “Federal Legislative and Regulatory Update,” Webinar at DFWHC
“Federal Legislative and Regulatory Update,” Webinar at DFWHC
 
On-Demand Webinar: Compliance With New Provider Relief Funds Reporting Requir...
On-Demand Webinar: Compliance With New Provider Relief Funds Reporting Requir...On-Demand Webinar: Compliance With New Provider Relief Funds Reporting Requir...
On-Demand Webinar: Compliance With New Provider Relief Funds Reporting Requir...
 
Webinar: “While You Were Sleeping…Proposed Rule Positioned to Significantly I...
Webinar: “While You Were Sleeping…Proposed Rule Positioned to Significantly I...Webinar: “While You Were Sleeping…Proposed Rule Positioned to Significantly I...
Webinar: “While You Were Sleeping…Proposed Rule Positioned to Significantly I...
 
Webinar: “Cybersecurity During COVID-19: A Look Behind the Scenes
Webinar: “Cybersecurity During COVID-19: A Look Behind the ScenesWebinar: “Cybersecurity During COVID-19: A Look Behind the Scenes
Webinar: “Cybersecurity During COVID-19: A Look Behind the Scenes
 
Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...
Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...
Webinar: CMS Pricing Transparency — Final Rule Requirements, Compliance Chall...
 
Federal Regulatory Update
Federal Regulatory UpdateFederal Regulatory Update
Federal Regulatory Update
 
Webinar: Post-Pandemic Provider Realignment — Navigating An Uncertain Market
Webinar: Post-Pandemic Provider Realignment — Navigating An Uncertain MarketWebinar: Post-Pandemic Provider Realignment — Navigating An Uncertain Market
Webinar: Post-Pandemic Provider Realignment — Navigating An Uncertain Market
 
07 24-20 pya webinar covid physician compensation
07 24-20 pya webinar covid physician compensation07 24-20 pya webinar covid physician compensation
07 24-20 pya webinar covid physician compensation
 
Engaging Your Board In the COVID-19 Era
Engaging Your Board In the COVID-19 EraEngaging Your Board In the COVID-19 Era
Engaging Your Board In the COVID-19 Era
 
Webinar: Free Money with Strings Attached – Cares Act Considerations for Fron...
Webinar: Free Money with Strings Attached – Cares Act Considerations for Fron...Webinar: Free Money with Strings Attached – Cares Act Considerations for Fron...
Webinar: Free Money with Strings Attached – Cares Act Considerations for Fron...
 
Webinar: “Got a Payroll? Don’t Leave Money on the Table”
Webinar: “Got a Payroll? Don’t Leave Money on the Table”Webinar: “Got a Payroll? Don’t Leave Money on the Table”
Webinar: “Got a Payroll? Don’t Leave Money on the Table”
 
Webinar: So You Have a PPP Loan. Now What?
Webinar: So You Have a PPP Loan. Now What?Webinar: So You Have a PPP Loan. Now What?
Webinar: So You Have a PPP Loan. Now What?
 
Webinar: “Making It Work—Physician Compensation During the COVID-19 Pandemic”
Webinar: “Making It Work—Physician Compensation During the COVID-19 Pandemic”Webinar: “Making It Work—Physician Compensation During the COVID-19 Pandemic”
Webinar: “Making It Work—Physician Compensation During the COVID-19 Pandemic”
 
Webinar: “Provider Relief Fund Payments – What We Know, What We Don’t Know, W...
Webinar: “Provider Relief Fund Payments – What We Know, What We Don’t Know, W...Webinar: “Provider Relief Fund Payments – What We Know, What We Don’t Know, W...
Webinar: “Provider Relief Fund Payments – What We Know, What We Don’t Know, W...
 
Webinar: “Hospitals, Capital, and Cashflow Under COVID-19”
Webinar: “Hospitals, Capital, and Cashflow Under COVID-19”Webinar: “Hospitals, Capital, and Cashflow Under COVID-19”
Webinar: “Hospitals, Capital, and Cashflow Under COVID-19”
 
PYA Webinar: “Additional Expansion of Medicare Telehealth Coverage During COV...
PYA Webinar: “Additional Expansion of Medicare Telehealth Coverage During COV...PYA Webinar: “Additional Expansion of Medicare Telehealth Coverage During COV...
PYA Webinar: “Additional Expansion of Medicare Telehealth Coverage During COV...
 

Kürzlich hochgeladen

palanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
palanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetpalanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
palanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetbhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
jabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
jabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetjabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
jabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
9316020077📞Goa Call Girls Numbers, Call Girls Whatsapp Numbers Goa
9316020077📞Goa  Call Girls  Numbers, Call Girls  Whatsapp Numbers Goa9316020077📞Goa  Call Girls  Numbers, Call Girls  Whatsapp Numbers Goa
9316020077📞Goa Call Girls Numbers, Call Girls Whatsapp Numbers Goa
russian goa call girl and escorts service
 
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in LahoreBest Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Deny Daniel
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
Bhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Bhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetBhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Bhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetnagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
kochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
kochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetkochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
kochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetSambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024
Sheetaleventcompany
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
russian goa call girl and escorts service
 
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetErnakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Chandigarh
 
dhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetdhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Call Girls Service
 
Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...
Sheetaleventcompany
 

Kürzlich hochgeladen (20)

palanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
palanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetpalanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
palanpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510
 
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetbhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
jabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
jabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetjabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
jabalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
 
9316020077📞Goa Call Girls Numbers, Call Girls Whatsapp Numbers Goa
9316020077📞Goa  Call Girls  Numbers, Call Girls  Whatsapp Numbers Goa9316020077📞Goa  Call Girls  Numbers, Call Girls  Whatsapp Numbers Goa
9316020077📞Goa Call Girls Numbers, Call Girls Whatsapp Numbers Goa
 
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in LahoreBest Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
Best Lahore Escorts 😮‍💨03250114445 || VIP escorts in Lahore
 
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetOzhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ozhukarai Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Bhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Bhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetBhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Bhagalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetnagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
kochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
kochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetkochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
kochi Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetSambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024Top 20 Famous Indian Female Pornstars Name List 2024
Top 20 Famous Indian Female Pornstars Name List 2024
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
 
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetErnakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Ernakulam Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
dhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetdhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
dhanbad Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
Independent Call Girls Hyderabad 💋 9352988975 💋 Genuine WhatsApp Number for R...
 
Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9xxxx00000} ❤️VVIP POOJA Call Girls in Bangalor...
 

Enterprise Risk Management

  • 1. HCCA Board Audit Committee Compliance Conference February 27 – 28, 2017 Presented by: Kimberly Lansford, RN, BSN, MHL, CHC® Shannon Sumner, CPA, CHC® ASSESSING THE EFFECTIVENESS OF ERM Enterprise Risk Management
  • 2. Prepared for Health Care Compliance Association Page 1 SPEAKERS Kimberly A. Lansford RN, BSN, MHL, CHC ® Chief Compliance Officer PennState Health Shannon Sumner CPA, CHC ® Principal/Shareholder Pershing Yoakley & Associates, P.C. ssumner@pyapc.com PERSHING YOAKLEY & ASSOCIATES, P.C. 800.270.9629 | www.pyapc.com
  • 3. Prepared for Health Care Compliance Association Page 2 What Is Enterprise Risk Management (ERM)?  A process that engages all in the practice of identifying, managing, monitoring, and communicating risks across an organization  Main objective is to help management and the board understand and manage those events most likely to impact the organization’s strategic objectives  Its aim is to function in a proactive and efficient manner and as a key enabler of the organization’s strategic objectives  It seeks to orchestrate the harmonization, synchronization, and rationalization of areas managing risks by moving beyond organizational barriers to open transparent communications across disciplines
  • 4. Prepared for Health Care Compliance Association Page 3 Definitions  Risk Culture: "The values, beliefs, knowledge, attitudes and understanding about risk shared by a group of people with a common purpose, in particular the employees of an organization" (Institute of Risk Management)  Risk Appetite: Relates to the amount of risk that an organization is willing to seek or accept in the pursuit of its long-term objectives Source: The Institute of Risk Management https://www.theirm.org/
  • 5. Prepared for Health Care Compliance Association Page 4 ERM Provides a Process that Allows the Organization to:  Present governance and management with a comprehensive picture of interdependent risks across the entire enterprise  Break down the department silos that tend to exist in assessing risk  Create cross-functional teams evaluating risk using a common framework  Communicate information about risks in a consistent manner
  • 6. Prepared for Health Care Compliance Association Page 5 Traditional Healthcare RM vs. ERM Traditional Risk Management  Reactive, incident-based, clinically focused program  May use different processes, controls, metrics, language, and frameworks for discussing risks and risk mitigation strategies  Considers impact of risks to specific departments or issues in isolation  Focus on adverse events most likely to impact operations and finances  Examines risks individually, with limited communication between disciplines to consider the impact of their actions on other parts of the organization  Defines risks in terms of the probability that adverse events will occur and result in financial losses  Tendency to be a bottom-up approach Enterprise Risk Management  Proactive, holistic, multi-disciplinary approach focused on anticipating and managing both internal and external risks  Provides a common framework, processes, metrics, and language for discussing risks and risk mitigation strategies  Considers impact of risks across the organization  Focus on events most likely to impact strategic objectives  Emphasis on synergistic relationship among and between risks that span across the organization  Recognizes that risk does not solely mean something negative has or could occur – something good not happening as a result of not acting is also a risk  Top-down and bottom-up approach
  • 7. Prepared for Health Care Compliance Association Page 6 ERM Benefits  Helps identify and understand key risks impacting achievement of strategies and objectives  Invites broad participation and perspectives of senior leaders and governance  Helps avoid a “functional silo” approach that often fails to consider the interconnective nature of risks across large, complex organizations  Provides a common framework for discussing risks and risk management or “treatment” strategies  Assists in establishing accountabilities for risk management activities  Integrates risk planning with strategic and tactical planning  Over time, more effective and cost-efficient management of risks increases enterprise value
  • 8. Prepared for Health Care Compliance Association Page 7 Why Is an ERM Approach Important?  The United States Federal Sentencing Guidelines are clear that standards and procedures should provide sufficient and effective controls that take into account the highest risk areas, given an organization’s business  The Office of Inspector General (OIG) recommends a risk-based approach in its guidance, and recent Corporate Integrity Agreement templates require a provider’s compliance program to include a comprehensive risk assessment and internal review process  The OIG is clear that a comprehensive risk assessment cannot be pursued by the Compliance Department alone, and involvement from key business leaders (including legal) is critical to the effectiveness of the risk assessment process
  • 9. Prepared for Health Care Compliance Association Page 8 Why Is an ERM approach important? (cont.)  All major rating agencies include ERM in their evaluation of credit ratings  Critical component of financial and insurance industry evaluations  Healthcare auditing entities, such as those that have oversight for HIPAA, may inquire into the process when auditing areas that require a risk-based approach (e.g., information security)
  • 10. Prepared for Health Care Compliance Association Page 9 Why Is the Compliance Department Well Situated to Facilitate an ERM Approach?  An ERM approach engages all workforce members in the practice of identifying, managing, monitoring, and communicating risks across the organization  We are already doing this with regard to our compliance risks in our compliance programs
  • 11. Prepared for Health Care Compliance Association Page 10 Components of a Successful ERM Approach Step One: Know the Business Climate  Understand which business factors have the ability to impact operations or cause potential compliance concerns  Benchmark both inside and outside the organization, and possibly even outside the healthcare industry
  • 12. Prepared for Health Care Compliance Association Page 11 Components of a Successful ERM Approach (cont.) Step Two: Understand and Prioritize Risks and Opportunities  Ensure colleagues understand how to identify and report risks and opportunities  Two key activities:  Deploy a comprehensive Education and Awareness program  Perform an Enterprise Risk Assessment, with focused reviews of an organization’s most significant risks, on an ongoing basis  Leverage existing strategies used by colleagues to report events, such as those utilized in Privacy, Information Security, Insurance/Risk Management, Compliance, Clinical/Nursing, and other departments
  • 13. Prepared for Health Care Compliance Association Page 12 Step Three: Manage the Identified Risks and Opportunities  Create a centralized process or have a collaborative process to analyze and manage risk and opportunity information  Some common risk management (“treatment”) techniques:  Avoidance (eliminate, withdraw from, or not become involved)  Reduction (optimize – mitigate)  Sharing (transfer – outsource or insure)  Retention (accept and budget) Components of a Successful ERM Approach (cont.)
  • 14. Prepared for Health Care Compliance Association Page 13 Step Four: Reporting and Metrics  Reports and metrics can be used by operations, budgeting, strategy, audit, compliance, and many other departments for strategy and decision-making, where the consideration of risk can influence the outcome  Dashboards, risk monitoring reports, qualitative, and quantitative analysis can be used to measure the effectiveness of risk treatment activities and to understand any implications for an organization’s overall business strategy Components of a Successful ERM Approach (cont.)
  • 15. Prepared for Health Care Compliance Association Page 14 Step Five: Risk “Alert” Culture and Risk Control  A risk alert culture is the intrinsic understanding and assessment of risk embedded in day-to-day operations. It fosters the integration of enterprise risk principles throughout every layer of the organization  Risk Controls are measures to limit vulnerabilities and manage risks to an acceptable level  A risk alert culture and risk control are created by:  Adhering to policies and procedures, laws, and regulations  Educating and holding colleagues accountable for evaluating risk holistically in strategic initiatives  Creating and utilizing a common language  Effectively using preemptive risk concepts within business units Components of a Successful ERM Approach (cont.)
  • 16. Prepared for Health Care Compliance Association Page 15 ERM Is Everyone’s Responsibility… • ERM engages everyone at the organization in the management of those risks for which they are responsible • Risk ownership does not reside in a single department • The compliance department can easily facilitate an ERM approach to managing risks across the organization
  • 17. Prepared for Health Care Compliance Association Page 16 ERM Is a Journey…It Is Not a Destination!
  • 18. Prepared for Health Care Compliance Association Page 17 Board Accountability for Risk  Greater Scrutiny from OIG and DOJ  Recent CIA Risk Assessment Requirements  Three Lines of Defense Theory  Quality of Risk Assessment Process  Ongoing Risk Assessment Process  Connecting the Dots
  • 19. Prepared for Health Care Compliance Association Page 18 Greater Scrutiny Emerges
  • 20. Prepared for Health Care Compliance Association Page 19 DOJ Hires Compliance Expert Source: http://www.corpcounsel.com/id=1202737784530/Report-Justice-Dept-Names-Chen-to-Controversial-Compliance-Counsel-Post?slreturn=20150923095150 “…the person will be assessing the company’s claims about their compliance program – i.e., if a company seeks to claim that it deserves credit for implementing a state of the art compliance program, which is a metric under the Sentencing Guidelines for a break on a fine. The counsel will help subject that to a rigorous analysis, something that a federal prosecutor does not have a lot of expertise in carrying out.”
  • 21. Prepared for Health Care Compliance Association Page 20 Risk-Specific CIA Requirements Source: https://oig.hhs.gov/fraud/cia/agreements/Dignity_Health_10302014.pdf  Risk Assessment and Internal Review Process “The risk assessment and internal review process shall include: (1) a process for identifying and prioritizing potential risks; (2) developing an assessment plan to evaluate and respond to potential risks, including internal auditing and monitoring of the potential risk areas; (3) developing action plans to remediate potential risks; and (4) tracking results to assess the effectiveness of the risk assessment and internal review process, including any remediation efforts that ABC pursues.”
  • 22. Prepared for Health Care Compliance Association Page 21 Three Lines of Defense Source: Institute of Internal Auditors: The Three Lines of Defense in Effective Risk Management and Control
  • 23. Prepared for Health Care Compliance Association Page 22 Quality of Risk Assessment Process  Risk Assessment Inputs – Questions to Ask  Is the risk universe inclusive of all significant processes/entities/joint ventures/outsourced service providers?  What is the competency of staff performing the risk assessment?  What risk-ranking criteria and weight factors are used?  Have risks to the achievement of strategic objectives been included?  What is the involvement of other “assurance providers” (e.g., internal audit, legal, compliance, IT, quality, risk management, etc.)?  Who is the Executive Sponsor (e.g., “Tone at the Top”)?
  • 24. Prepared for Health Care Compliance Association Page 23 Quality of Risk Assessment Process (cont.)  Risk Ranking Example RISK FACTOR DESCRIPTION/EXAMPLES WEIGHT Internal Control History Control environment, risk management process, effectiveness of Internal Controls 25% Change Systems, processes, personnel/turnover, new services, laws and regulations 20% Factors External to Process Industry forces, market forces, national politics, community needs, degree of exposure to adversity, governance/management concern 15% Customer Service (Internal & External) Degree of customer service provided, impact on operations, effect on reputation 15% Complexity Multiple systems required, date of technology in use, equipment and expertise required 15% Materiality & Resources Extent that the size of the unit could affect potential loss to the organization, adequacy of available resources for associated process 10%
  • 25. Prepared for Health Care Compliance Association Page 24 Quality of Risk Assessment Process (cont.)  Risk Assessment Outputs – Questions to Ask  Does the prioritization of risks align with risk appetite?  What is the coverage of risks not able to be audited/monitored?  Has management accountability been established?  Are there any significant risks not included?  Is the resulting work plan risk focused vs. department focused (e.g., risk doesn’t reside in silos)?  Centralized governance oversight and reporting?
  • 26. Prepared for Health Care Compliance Association Page 25 Ongoing Risk Assessment  Risk-Trending/Red Flags  Central themes in internal audit/external audit/compliance reports  Monitor work plan additions/subtractions  Monitor deferrals or cancellations (risk is still there!)  Monitor completeness throughout the year  Error percentages consistently high (>5%)  Action plans consistently past due
  • 27. Prepared for Health Care Compliance Association Page 26 Ongoing Risk Assessment (cont.)  Places Where Risks Hide  Outsourced service providers  Significant turnover/new management  New and/or complex service lines  People, Process, Technology  Lack of ongoing training/education in high-risk areas  Drivers for incentive compensation  Lack of contract monitoring (e.g., physicians, outsourced areas) ? ? ?
  • 28. Prepared for Health Care Compliance Association Page 27 Connect the Dots  Control Environment “Dashboard”  Management Letter Comments  Turnover in Key Management Positions  External Audit Findings  Internal Audit Findings  Audit Follow-up Completion (High Risks)
  • 29. Prepared for Health Care Compliance Association Page 28 THANK YOU! Kimberly A. Lansford RN, BSN, MHL, CHC ® Chief Compliance Officer PennState Health Shannon Sumner CPA, CHC ® Principal/Shareholder Pershing Yoakley & Associates, P.C. ssumner@pyapc.com PERSHING YOAKLEY & ASSOCIATES, P.C. 800.270.9629 | www.pyapc.com