IT Risk Management and Compliance PRACTICE CONSULTANTS EXPERTS PROFESSIONALS

Managing IT risks and compliance are major concerns for many organizations, including those in public accounting, business and industry, consulting, and government/ not-for-profit. Organizations that do not understand, or have not considered, the risks associated with information technology are generally not prepared to mitigate such risks. As a result they are ill-prepared to face the pressures that accompany increased vulnerability within the IT environment.

Our clients, especially those in Financial service, Telecommunications, Healthcare, and Government are feeling even greater regulatory and risk management pressures than ever before as issues surrounding IT risks and compliance seem to exponentially increase from year to year. The Regulatory and Risk Management Indicator highlights the concerns that several organizations have with risk management and the obstacles they face in managing those risks effectively.

Categories of Risk

The term “Risk Management” is often used by different groups of professionals to describe rather different, yet related, functions. Risk management might be best thought of as having three different iterations: operational risk management, financial risk management, and enterprise risk management.

  1. Operational Risk Management is the management of the risks that arise from the day to day functions of an organization. Many of these risks are legal, physical, and/or insurable in their nature. Compliance has a role to play in operational risk management by helping to prevent behaviors that can result in loss, such as worker injury or legal liabilities.
  2. Financial Risk Management focuses on portfolio risk—how the organizations’ financial decisions do or do not expose it to larger financial loss. Financial risk management and operational risk management are often considered separate, but related, disciplines. Compliance has a role to play in financial risk management by helping to prevent excessive risk-taking on the part of portfolio managers.
  3. Enterprise Risk Management is the process by which an organization integrates risk management policies and procedures across all aspects of an organization, with one of the aims being to embed a risk management-oriented culture at all levels, from mundane daily operations to strategic board decisions. Compliance has a role to play in ERM in that there are compliance aspects to any portion of an organization, and harmonizing that creates an enterprisewide solution that easily syncs with ERM in philosophy and execution.
  4. ISO 31000 is a one of a number of internationally recognized risk management standards. It was first published by International Organization for Standardization in 2009, and is actually a family of standards meant to provide a best practices framework for any operation concerned with risk management.

It all starts with having a sound risk management policy. Based on our recent engagements, outlined below are three things that your company can do to better align your IT risk management plan with your strategic business initiatives:

  1. Conduct a risk assessment. Conduct a risk assessment, looking at vulnerabilities and threats including those related to emerging technologies like cloud computing, mobile technologies and social media.
  2. Design policies and internal controls. Policies and internal controls should be designed to reduce IT-related risks to an acceptable level and then monitor the effectiveness of those controls.
  3. Monitor override abuse. Your auditors (Internal and/or External) should develop policies to detect management override abuse within IT-dependent systems.

The issue of Managing IT risks and compliance ranked third in the Top Technology Initiatives Survey reports. This concern has gained so much traction in recent years and is now listed alongside (1) managing and retaining data, (2) securing the IT environment, and (3) enabling decision support and analytics; as some of the key topics our current customers are most concerned with.

Most Notable Risk areas of Concern raised by our Clients

  1. Regulatory Risk
  2. Fraud
  3. Asset and Liability Management
  4. IT Risk
  5. Operational Risk
  6. Market Risk
  7. Information Security Risk
  8. Compliance Risk
  9. Credit Risk
  10. Strategy Risk

In contrast, the biggest reported obstacles to managing risk effectively

  1. Regulatory Risk
  2. A disconnection between risk management processes and overall strategic plans
  3. Too many technology systems that are not integrated
  4. Processes that do not empower employees to own and manage risk
  5. Frequency of Changes in Regulations, coupled with Ambigous interpretations of critical Compliance Regulations
ADVANCED ICT » Consultants and Auditors LLP.