Tuesday, May 17, 2011
Should the Big-4 be Broken Up?
My view? External audit is now largely out-dated. The binary nature of the opinion renders it useless and instead of focussing on backward looking KPI’s (aka “the accounts” or “financial report”) it is time we moved on to a more meaningful method of providing assurance to external stakeholders.
Of course this is not just a UK problem, and there probably is not a good way yet of dealing with this on an international basis.
Saturday, May 7, 2011
Risk Appetite and Risk Tolerance
The paper has been prompted in part by the Financial Reporting Council’s new UK Corporate Governance Code. I am also finding myself debating risk appetite with more and more clients, all of whom are looking for practical and meaningful ways of implementing risk appetite as the next step on their risk management development. In this paper, we have sought to pull together some of the existing thinking in this area, and we have also sought to inject some fresh ideas. Both the IRM and I would greatly welcome your feedback.
I am very conscious of the fact that the document is framed in the context of the UK Corporate Governance Code: it therefore could appear to be (a) UK-centric and (b) only relevant to listed companies. In fact I think it is entirely transferable anywhere in the world and is as relevant to small private organisations and those in government and the third sector as it is to large quoted companies. However, I acknowledge that it will take some interesting further development to stretch the ideas to fit all organisations. But if we keep in mind that the aim is to develop helpful guidance, rather than develop yet another tick-in-the-box approach to governance, we should be able to do that!
The link (http://www.theirm.org/publications/risk_appetite.html) will take you to the IRM website and on that webpage you will find two further links: one for the Executive Summary, and one for the full document (which also includes the Executive Summary). To badly misquote George Bernard Shaw: we could not write a short document until we had written a long one. I hope that this represents a helpful contribution to the debate about the board’s responsibilities for risk appetite and risk tolerance. I do not think that we have written the last word on the subject, but rather I hope that we have set the debate going.
The IRM is circulating this document widely and would very much welcome your views. Does it provide useful guidance to organisations in defining their risk appetite? Does the approach make sense? What is missing? What would you remove? We would very much like to hear.
Please feel free to circulate the document widely within your organisation and then to forward any comments to Carolyn Williams, Head of Thought Leadership at IRM on carolyn.williams@theirm.org by Tuesday 31 May 2011. Needless to say, I am also interested in hearing your thoughts! Personally I am particularly interested in hearing about your experiences with risk appetite and understanding how you have overcome some of the interesting challenges it poses!
We are aiming to publish a final version of the document later in the Summer, taking account of comments received.
Monday, March 8, 2010
r-NXD's (this may be a UK-centric descriptor - but read on...)
However, I am equally interested in the non-executive side of the equation. We need NXD's (non-executive directors - if that is indeed a UK-centric descriptor) who are business-savvy, numbers-savvy and now, I would argue, risk-savvy.
I would be interested to hear of examples of non-executive directors who have a business risk background in boardrooms with which you are familiar. Does that work? Do they add value? Is there a role? Do they help deliver the all important assurance environment?
I would also be interested to hear your views as to whether there is a need for what I am calling the r-NXD.
Kind regards
Richard
Thursday, February 25, 2010
Strategic Risk
I have a view that we should be looking a lot more at strategic risk, and I like to tie it back to value drivers (via objectives?) such as those that drive shareholder value (or whatever your equivalent might be for our organisation).
This leads me to pose several questions:
- Do we as a profession have enough face time with the CEO and Chairmen of our organisations?
- Do we get involved in strategic plans before or after they happen? eg, do we get involved in risk based due diligence after the transaction is announced, or when options for acquisitions are being discussed?
- How often do we, as a profession, facilitate board awaydays focussing on more distant strategy (say 5 to 10 years out)?
- Does anyone have any really good war stories on this that you are happy to share on line?
Thanks
Richard
Wednesday, February 17, 2010
Ethics and Risk Management
A number of things have cropped up over the recent years:
- Clearly Toyota has some "ethical" questions to answer with regard to brakes, accelarators and now steering systems.
- It seems unutterbaly proven that there were dubious (at best) ethics in banking which allowed the situation to arise for the financial crisis.
- A few politicians in the UK have exhibited less than the highest standards in the ethical field.
- Greece (aided and abetted by at least one bank) appears to have been cooking the books, with disastrous consequences for other Eurozone countries.
- BAe has paid a stinging penalty to the US and a modest one in the UK.
- We have a new bribery act coming onto the statute book in the UK (if it gets through before the election).
I believe that risk management can ONLY work where there is an ethical dimension to the organisation. And yet, perversely, this allows free-riding unethical corporations to duck and weave unhindered and leave the ethical corporation trailing - at least for a period of time.
I would welcome people's views on the interaction of ethics and risk management.
As ever, I am likely to turn the discussion into a paper in due course, summarising the contributions - if you are uncomfortable with that, let me know in your response.
Thanks
Richard
Monday, January 25, 2010
Management Rheumatism
Feedback welcome, as always!
Risk Appetite - reality v. aspirations
I look forward to feedback: I thrive on feedback!
Thanks
Richard
Tuesday, December 15, 2009
Target Risk was written following a recent enquiry about the subject. In particular I was asked whether I knew of any other organisations that was using the concept of target risk, and if so how were they defining it? In essence I was asked whether my client was being consistent with best practice and with general usage. Given that this exercise was done by talking to other clients, contacts and consultants, I am now sharing the results of that exercise. To see a copy of the paper, click here.
Governance article: while I am writing, you might be itnerested to see a very short article that was published in "Governance" recently on my views as to whether the Walker Report will make the slightest difference to the state of Corporate Governance in the UK. To see a copy click here.
I thrive on feedback - let me know what you think.
Thanks
Tuesday, October 13, 2009
Three Lines of Defence - Dead or Alive?
I argued that Three Lines of Defence (TLD from now on) had not worked... witness RBS and HBOS and others in the States etc. To which this participant replied, but had it been done better it would have provided clear guidance on what should have been done.
My contention is that TLD allows assurance (actually that should be Assurance with a capital A) should not be divided. What we need is: a balanced view to risk, ethical programmes, mature risk management, a risk management and assurance framework, and an organisational structure that works. Now TLD might do that, but it is not the only way at all.
So I am arguing that TLD is fine if you really want it, but don't depend on TLD to protect you next time round. It wasn't that we were slightly wrong in our approach to risk management, we were fundamentally inadequate and TLD did not spot that...
I would welcome your comments, either here, on LinkedIn, or via my website.
Regards
Richard
Friday, October 2, 2009
Risk oversight committees in Banks and Other Financial Institutions
My main recommendations are fourfold (excuse the numbering...):
- I continue to believe that we need to see a paradigm shift in Corporate Governance. In order to make incumbent boards and individual directors take this seriously we need to see new fiduciary duties relating to Corporate Governance responsibilities, which should be discharged with due and diligent care.
- I applaud the recommendation to create effective board risk oversight committees. I happen to believe that the remit as described in Sir David's paper is insufficient for the purpose. The remit and mechanics should:
- Encompass the development of a balanced view of risk;
- Include the oversight of the development and implementation of a robust ethics programme;
- Encompass the periodic assessment of the maturity of risk management maturity;
- Include the development of a risk management and assurance framework that is fit for purpose; and
- Address the development of an appropriate risk management organisation.
- Although it may well be difficult, in the context of the worst dereliction of Corporate Governance responsibilities of recent economic history, I continue to believe that we should find ways to make a form of permanent, full time non-executive director role work in BOFIs (and other organisations) that have a major societal impact.
- I continue to believe that the most important attribute of a non-executive director is an ability to act in a challenging, and yet supportive manner. Akin to risk management, the role of such directors is to periodically pierce the “perfect place arrogance” that develops in large corporate organisations. I am therefore less interested in the sectoral background, while of course acknowledging the need for a number of the directors to have BOFI backgrounds.
I set out more detail supporting my recommendations in my letter to Sir David, a copy of which can be found at http://randerson-assocs.co.uk/WalkerConsultationPaper.aspx. I would be pleased to hear what you think of (a) Sir David's consultation paper, (b) my responses and whether you believe Corporate Governance will improve as a consequence of his work.
Kind regards
Richard
Thursday, August 6, 2009
Is ERM becoming more important or not???
Let me know what you think.
Richard
Tuesday, May 12, 2009
The frailty of VaR
Friday, April 17, 2009
OECD Report
What people have said about the report:
- Insightful"
- a "pithy summary"
- "This is a strong, impressive report. Your grasp of the issues in a still-unfolding international financial disaster is not only impressive, but lends credibility to your recommendations which, taken together, are peerless. I hope that they are widely read, debated and, ultimately, implemented. I will not comment on each of your recommendations, nor your analyses and arguments in support of them, because there would be nothing substantive that I could add."
- "I have to read about risk day in and day out on the day job so for balance I prefer to read about other topics. But ... I made myself read it and I am glad I did. You paint a valuably comprehensive picture, and propose many innovative solutions."
I would welcome your feedback and thoughts as to how we can take the debate further.
Also, go to the OECD's website to see what else they are doing on the governance front.
Wednesday, April 15, 2009
Myners and boards
I am not sure about having a "Devil's Advocate" in that sounds a bit like having someone on the board just to be contrary. But I do agree that we need to do something about creating a counter-balance to what I have described elsewhere as the "red-blooded, testosterone-charged" CEOs of this world.
I would be interested in feedback
Thursday, March 26, 2009
The SFO calls... Recessionary tales of the unexpected
What are the business implications? What can you be doing right now?
Here we are in the worst recession in ages, if not since records began, and employees are under incredible pressure to produce results. Investors want results, boards are demanding results, managers are shouting for results, and who produces them? But staff cannot pull rabbits out of hats, so they are feeling coerced into manufacturing results that simply do not exist.
People who have led blame free lives, who would not say boo to a goose, are being encouraged to come up with results for their managers, or risk losing their jobs. Accountants and others are losing sleep over the “temporary” adjustments they have made – all in the expectation of making good next month. Except next month is even worse. Ask Bernie Madoff – and look where he ended up.
These staff, who are under excruciating pressure need to be able to let off steam. So who will they call: someone in your organisation, or the SFO? Indications are that more and more people are calling the SFO. And while we can all applaud the efforts to catch the crooks – is this really where you want to be spending your hard-earned management time: dealing with an SFO investigation?
So what can you do?
1. Review your ethics and compliance approaches: do you have an ethics programme? Do you know that you are in compliance with legal and regulatory requirements? Is it time to dust your programme down and remind people that is exists? Or do you need to create a framework right now?
2. Ensure that you have space for staff to let off steam. Vague whistleblowing policies about letting someone know somewhere in the organisation don’t usually work: there needs to be an independent (but that does not necessarily mean outsourced) mechanism that is both credible and seen to work. Make sure that communication programmes are in place, and that people feel that ethics is as much there to support them as it is for the organisation. This needs two-way risk-free communication.
3. Conduct an independent, anonymous survey of attitudes amongst senior managers and front line accountants – those who are most likely to know what is going on. Surveys in the States have shown that whereas a typical whistleblowing facility may have 1% of the staff using it for its primary purpose, a further 4% might explore ideas which could prevent abuses. And yet as many as 50% of staff, according to surveys, claim to have witnessed illegal or potentially seriously embarrassing unethical behaviour. Where did that 45% go?
4. Talk to partners, suppliers and customers – proper engagement with them, so that you have a dialogue which helps to reveal where pressure points are in the value chain.
5. Review those reconciliations and funny accounts – all the ones that are full of judgemental values. This is often where dodgy results start – implement a zero-tolerance policy with regard to unauthorised adjustments to these accounts.
6. Get your internal auditors on to the case: a few deep dives into trial balances and transactions sends out a message.
7. Bring your risk management down from the Olympian heights of governance compliance and turn to operational risks.
And if all of that sounds like yet more expense – well its better than having your collar felt by the SFO because you never got round to it...
Oh, and while this has a UK flavour (note the "u" in that word) it is relevant right round the world.
Monday, March 23, 2009
Turner Report
The brief section on governance and risk management is nontheless interesting in that it illustrates the thrust of likely changes. I have reproduced this section in full below
2.8 Risk management and governance: firm skills, processes and structures
Analysis of the causes of the crisis suggests that there is a limit to the extent to which risks can be identified and offset at the level of the individual firm. Chapter 1.1 described how the origins of the crisis lay in macroeconomic imbalances and systemic developments: Chapter 1.4 argued that there are limits to the effectiveness of market discipline; and Section 1 of this chapter stressed that the crucial shift required in regulatory philosophy is towards one which focuses on macro-analysis, systemic risks and judgements about business model sustainability, and away from the assumption that all risks can be identified and managed at a firm specific level. As a result most of the changes proposed in this review relate to the redesign of regulation combined with a major shift in supervisory approach.
But improvements in the effectiveness of internal risk management and firm governance are also essential. While some of the problems could not be identified at firm specific level, and while some well run banks were affected by systemic developments over which they had no influence, there were also many cases where internal risk management was ineffective and where boards failed adequately to identify and constrain excessive risk taking.
Achieving high standards of risk management and governance in all banks is therefore essential. Detailed FSA proposals will await the outcome of the Walker Review (described below) but the key dimensions of required improvement are likely to be
- Improved professionalism and independence of risk management functions. As already outlined in Section 2.7 above, the FSA will therefore in future play a more active role in assessing the technical competence of senior risk managers. And it will consider whether governance structures for risk oversight need to be changed, with a more direct relationship between senior risk management and Board risk committees
- Risk management considerations embedded in remuneration policy, in the fashion described in Section 2.5 (ii). This has implications for the remit of remuneration committees and for the non-executive time commitments required
- Improvements in the skill level and time commitment of non-executive directors. The crisis has revealed the extreme complexity of large banking groups and the difficulties which nonexecutive directors (NEDs) face in understanding all dimensions of the risks being taken, within the time commitments typically required of NEDs. It has also raised questions about the degree of technical skill and experience required to perform risk committee functions, and whether existing bank boards have sufficient people with these technical skills. In addition it has demonstrated the vital importance of non-executive challenge to dominant chief executives pursuing aggressive growth strategies
- Shareholder discipline over corporate strategies. As Section 1.4(iv) described, shareholder influence seems to have been relatively ineffective in the past in constraining risky strategies. There may be ways of improving the effectiveness with which shareholder views are communicated to non-executives
These issues and the implications for overall governance principles and structures need to be looked at in an integrated fashion. One question they prompt is whether the governance arrangements appropriate for banks are different from those which apply to the generality of companies, and whether therefore codes and rules which go beyond the general Combined Code are required
These issues will be in part addressed by the review of bank governance being conducted by Sir David Walker which the government announced on Monday 9 February and which will report in October 2009. The FSA, which is providing the secretariat for this review, will work closely with Sir David Walker in consideration of these issues. Once the review has reported, the FSA will consider what changes to its rules and process are required to ensure that problems are addressed, making specific proposals by the fourth quarter of 2009
It will be interesting to see how this turns out under both the FRC review of the Combined Code and also the Walker review. For what it is worth, my view is that there is nothing intrinsically different about the governance of financial institutions just because they are financial institutions. While clearly there are differences in the technical aspects of risk, what seems to me to be more important is the potential societal impact of poorly handled risk in an organisation. Poorly handled risk in say chemical companies can be as (or even more) devastating than in banks: look at Bhopal or the BP refinery problems in the US. I am more interested in big v small impact organisations. One key difference may be whether there are Critical National (or International) Infrastructure implications, or whether there is scope for major disasters. I add the latter, because I am not sure whether Pharma companies are part of the CNI, but they can have devastating impacts (eg Thalidomide)
For the full detail of the Turner Report, click here...
Sunday, March 15, 2009
Gordon Brown on Changes Needed
Saturday, March 14, 2009
GSO Finance Ministers
Thursday, March 12, 2009
Be frightened, very frightened
(Or be prepared...)