Managing IT risks and compliance are major concerns for many organizations, including those in public accounting, business and industry, consulting, and government/ not-for-profit. Organizations that do not understand, or have not considered, the risks associated with information technology are generally not prepared to mitigate such risks. As a result they are ill-prepared to face the pressures that accompany increased vulnerability within the IT environment.
Our clients, especially those in Financial service, Telecommunications, Healthcare, and Government are feeling even greater regulatory and risk management pressures than ever before as issues surrounding IT risks and compliance seem to exponentially increase from year to year. The Regulatory and Risk Management Indicator highlights the concerns that several organizations have with risk management and the obstacles they face in managing those risks effectively.
Categories of Risk
The term “Risk Management” is often used by different groups of professionals to describe rather different, yet related, functions. Risk management might be best thought of as having three different iterations: operational risk management, financial risk management, and enterprise risk management.
- Operational Risk Management is the management of the risks that arise from the day to day functions of an organization. Many of these risks are legal, physical, and/or insurable in their nature. Compliance has a role to play in operational risk management by helping to prevent behaviors that can result in loss, such as worker injury or legal liabilities.
- Financial Risk Management focuses on portfolio risk—how the organizations’ financial decisions do or do not expose it to larger financial loss. Financial risk management and operational risk management are often considered separate, but related, disciplines. Compliance has a role to play in financial risk management by helping to prevent excessive risk-taking on the part of portfolio managers.
- Enterprise Risk Management is the process by which an organization integrates risk management policies and procedures across all aspects of an organization, with one of the aims being to embed a risk management-oriented culture at all levels, from mundane daily operations to strategic board decisions. Compliance has a role to play in ERM in that there are compliance aspects to any portion of an organization, and harmonizing that creates an enterprisewide solution that easily syncs with ERM in philosophy and execution.
- ISO 31000 is a one of a number of internationally recognized risk management standards. It was first published by International Organization for Standardization in 2009, and is actually a family of standards meant to provide a best practices framework for any operation concerned with risk management.