enterprise risk management (erm) integrating strategy, capital and risk

28
Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk GARP 2008 Presented by: Joe Rizzi CapGen Financial February, 2008 The views expressed are those of the author and do not necessarily reflect those CapGen Financial

Upload: joseph-brewer

Post on 30-Dec-2015

30 views

Category:

Documents


4 download

DESCRIPTION

Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk. GARP 2008 Presented by: Joe Rizzi CapGen Financial. February, 2008. The views expressed are those of the author and do not necessarily reflect those of CapGen Financial. Table of Contents. 1. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

Enterprise Risk Management (ERM)Integrating Strategy, Capital and Risk

GARP 2008

Presented by: Joe RizziCapGen Financial

February, 2008

The views expressed are those of the author and do not necessarily reflect those of CapGen Financial

Page 2: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

2

Table of Contents

Enterprise Risk Management2

Current State of Risk Management1

Enterprise Risk Management Program3

Integrating Strategy, Capital and Risk4

Conclusion5

Page 3: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

3

OverviewImportance of Risk Management is driven by four key forces

Risk Management

Complex and VolatileBusiness Environment

ShareholderExpectations

CompetitiveRivalry

RegulatoryEnvironment

Risk Management lies somewhere between astrology and alchemy

Page 4: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

4

Attitudes, Values and Objectives

Out with the old...

Line of Business

My job is: To grow earnings / do business

Risk is: A normal cost of doing business

Memory horizon: Short-term: What are the prevailing market conditions?

Stereotypical attitude: No risk, no return. Don’t handcuff me relative to the competition

Metrics: Volume in front-line positions; Profit for senior positions

Risk Management

My job is: To prevent losses/risky activity

Risk is: Volatility to be avoided

Memory horizon: Long-term: What’s the worst thing that has ever happened?

Stereotypical attitude: ‘The Cautious Librarian’: best way to keep books from being damaged is not to let anyone borrow them Metrics: Volume in front-line positions; Profit for senior positions

Business focuses on the center, while Risk Management focuses on the tails of the distribution

Page 5: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

5

Attitudes, Values and Objectives

...and in with the new.

Partnership

Our job is: To create shareholder value through earnings growth and appropriate returns to capital

Risk is: A potential source of competitive advantage as shareholders require us to manage risk prudently.

Memory horizon: Appropriately long to anticipate future cycles, informed by changes in the market over time

Metrics: RAROC; SVA

Line of Business

Manages the budget / P&L Acts as primary risk manager

Risk Management

Manages performance information Serves advisory and control function

Risk Management does not make you safer –just more efficient

Page 6: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

6

Risk Management Continuum

Silo-ed Approach

Aggregated Approach

Integrated Approach

ERM

According to recent RMA survey, most firms indicate that they have “closed in” on the integrated approach.

Moving beyond exposure accounting and control

Page 7: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

7

Table of Contents

Enterprise Risk Management2

Current State of Risk Management1

Enterprise Risk Management Program3

Integrating Strategy, Capital and Risk4

Conclusion5

Page 8: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

8

Vision:

Manage all material risks and opportunities across the organization

Objective:

Improve decision making through portfolio management of interrelated risks

Result (Value Proposition):

Increase value by managing to objectives consistent with stakeholder expectations

Enterprise Risk Management (“ERM”)

Strategic not transaction focus

Page 9: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

9

ERM is… ERM is NOT…

• Integrated view and awareness of risk across organizational disciplines

• Standardized risk-related information, metrics, and communication

• Common definitions

• Coordination of risk related projects

• Just Risk Management

• Just a centralized body for aggregation and translation of data

• Meant to discourage specialization

• Organizational restructuring

• ONLY for Control/Regulatory Compliance

Scope of ERM – Top level Risk view…

…as a strategic input, not an afterthought

Page 10: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

10

Analytical Solution: Economic Capital

Organizational Solution: Chief Risk Officer

Informational Solution: Dashboard

Management Solution: Governance actions

Cultural Solution: Communications

Enterprise Risk Management Big Ideas

It works in practice, but will never work in theory

Page 11: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

11

ERM – a work in progress

Source: Deloitte Global Risk Survey, 2006

35%

18%

32%

15%

Yes, program in place

No, but plan to create one

Yes, currently implementing one

No, and do not plan to create one

…need to tailor to your governance and operating philosophy

Page 12: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

12

Table of Contents

Enterprise Risk Management2

Current State of Risk Management1

Enterprise Risk Management Program3

Integrating Strategy, Capital and Risk4

Conclusion5

Page 13: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

13

The four pillars of an ERM Program

Risk Foundation

Risk Philosophy

Value Creation

EnterpriseRisk Management

Program

Man

agem

ent

Info

rmat

ion

Ris

k O

vers

ight

an

d In

depe

nden

ce

Com

mun

icat

ions

and

Esc

alat

ion

I II III IV

Str

ateg

ic P

lann

ing

and

Alig

nmen

t

Value creation through RiskManagement not minimization

Page 14: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

14

ERM Dashboard – make things as simple as possible

Vision

Efficiency

Efficiency

Eff & Grow th

Grow th

Grow th

Grow th

Controls

Controls

People

People

Key Risk Indicators Management Priorities

Key Performance IndicatorsTop 10 Risks – Heat Map

ComprehensiveRisk Assessment

Integrated Risk, Rewardand Strategy View

Forward looking, actionable, risk escalation tool

Executive sponsorship

…but no simpler

Com'l PFS Total

Business

Credit

Operational

Market

Interest

Liquidity

Strategic

Compliance

ALM - RWAALM - EC

Human Cap.

IT

Legal

SOX

Audit

Qu

anti

tati

ve R

isk

Qu

alit

ativ

e R

isk

ALAsset Mgmt. Services

GlobalMarkets

Global Clients

Transaction

Banking

Private ClientsBusiness Units

Overall YTD Target StatusEfficiency Ratio

Revenue Growth (YoY)Return on ARC

Page 15: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

15

Governance Actions

ERM Governance Model defines three legs — Businesses that take and manage risk,

Risk Management to provide policy and analysis, and Audit to provide assurance.

Board of Directors

Business Areas ERM Committee

Risk identification

Risk assessmentsCRO & Risk Committees Internal Audit

Strategy & Action to address Risk

Within Policy

Policies, governance and

information flowValidation of controls

Provide assertions on risk

exposure for business / functionRisk assessment methods

Objective review of risk

management process

Ownership of risk and

responsibility for management and

mitigation

Measurement, aggregation

rules and tools Assurance to Senior

Executive management and

Board on assertions of risk

exposure

Monitor risk exposure

status and provide

reporting to Board

Governance allocates decision rights

Page 16: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

16

ExternalConferences /

Communication

Develop Tactical

Communicationsplan

ERM Communications Strategy

Adopt theme: “Everyone is aRisk Manager”

Align withcompliance-

related policies and procedures

Standards of Conduct toinclude risk

issue escalation

Promote learningculture

Escalation

Clarification ofescalation

expectations

ERM Culture Development and Escalation

Culture as organizational DNA

Page 17: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

17

Align Finance & Risk Strategic

Agendas

Performancecontract

process toembrace ERM

Agree ERM role and PfC

process

Enterprise Strategy

Risk Appetite

Strategic Risk Management

People do what you pay them to do, not what you tell them to do

Page 18: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

18

Sponsorship

1. Successful Risk Management implementations require senior management and Board support.

Change Management

2. Significant effort will be required to overcome organizational inertia and change a mindset to a risk-reward culture

Sustainability

3. To sustain progress and momentum, maintain program team continuity.

Project Management

4. Do not underestimate launch complexities or cultural challenges.

5. Pilot programs prior to global roll outs.

66

Enterprise Risk Management

Program

Enterprise Risk Management

Program

Risk Management Framework

Lessons Learned

Risk as a senior management responsibilitynot a specialist function

Page 19: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

19

Table of Contents

Enterprise Risk Management2

Current State of Risk Management1

Enterprise Risk Management Program3

Integrating Strategy, Capital and Risk4

Conclusion5

Page 20: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

20

ERM Value Creation Framework – if you can make money

InternalStakeholders

CEO

CFO CRO

ExternalStakeholders

Regulators

Shareholders Rating Agencies

Assets(Return)

CapitalRequired

(Risk)

CapitalAllocation

(Funding)

CapitalManagement

Value Creation

Portfolio ofEnterprise

Risks

Portfolio ofCapital

Resources

Capital Structure

Cost of Capital

Return onRisk

Risk Structure

Economic Capital

(Use)

Risk Appetite

…You can lose money

Page 21: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

21

Risk Appetite – Total risk exposure an organization is willing to accept and prepared to lose in the execution of its strategy.

Factors impacting Risk Appetite:

Financial Objectives

Competitive Situation

Market Conditions

Risk Appetite

Do you want to eat well...

...or sleep well?

Page 22: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

22

Risk types: Include hard to measure risks and interrelationships

Risk Appetite

Risk may be one word...

...but it is not one number

Risk Tolerance: Credit

Market

Liquidity

Operational

Reputation

Compliance

Strategic

Page 23: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

23

ERM involves moving Risk Management to an integrated Risk and Capital Strategy

Comprehensive

Earnings fluctuations from strategic or business factors can exceed those from financial risk exposures

Risk appetite for financial risk must reflect the current level of business risk

Business risks cannot be measured in the same manner as financial risk, and are largely ignored by economic capital

Interrelationships

Overcome silos: unintended consequences

Top down perspective: integrated one firm view

Enterprise Risk and Risk Appetite

Translate statistics into...

...shareholder value

Page 24: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

24

Enterprise-level Risk Appetite (RA)

Source: Deloitte Global Risk Survey, 2006

16%

6%

12%

29%

14%

23%No, we do not have a statement of ourRA

We are currently defining or seekingapproval for our RA

We have an informally defined or notapproved statement of RA

Yes, our RA is qualitatively definedand approved

Yes, our RA is quantitatively definedand approved

Yes, our RA is both quantitatively andqualitatively defined and approved

Page 25: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

25

Choose target debt rating based on financial distress considerations.

Maintain ability to access capital markets under most conditions

Requires high investment grade (A+/AA-) rating

Estimate asset risk based on investment decisions and risk appetite.

Estimate capital requirement to support asset risk and target rating.

Optimize capital and risk combinations to maximize shareholder value subject to target rating based on market considerations.

Reduce risk given fixed capital level

Hedging – direct cost

Underwriting selection - opportunity loss

Increase capital given fixed investment plan

Increased capital charge

ERM in Practice

Integrating strategy, capital and capital

Conservatism of risk principle – Risk never disappears

LG

D (

Se

veri

ty)

PD (Likelihood)

Cap

ital

Return

A

B

Out of Risk Appetite

Within Risk Appetite

Page 26: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

26

Value Implications of Risk Appetite Changes

Not all Risk is the sameE

xpec

ted

Pro

fita

bil

ity

Perceived Risks(Economic Capital)

A

C

B

Optimal Portfolios

A = Group’s actual portfolioB = Alternative portfolioC = Group’s Target portfolio

Efficient Frontierfor Group

Business Portfolio

Risk Management is not free

Page 27: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

27

Table of Contents

Enterprise Risk Management2

Current State of Risk Management1

Enterprise Risk Management Program3

Integrating Strategy, Capital and Risk4

Conclusion5

Page 28: Enterprise Risk Management (ERM) Integrating Strategy, Capital and Risk

28

Conclusion – Things will improve

ERM:

Integrates risk, strategy and capital to create shareholder value

Risk Paradox:

Conservatism of risk principle - Risk never disappears

Risk Management does not make you safer – just more efficient

Risk Management is not free

Transaction Costs

Opportunity Costs

Direct Costs

Capital Costs

…despite our efforts to improve them