Tuesday, May 17, 2011

Should the Big-4 be Broken Up?

See the BBC news item story here about an OFT review of the Big-4: See here.
My view? External audit is now largely out-dated. The binary nature of the opinion renders it useless and instead of focussing on backward looking KPI’s (aka “the accounts” or “financial report”) it is time we moved on to a more meaningful method of providing assurance to external stakeholders.

Of course this is not just a UK problem, and there probably is not a good way yet of dealing with this on an international basis.

Saturday, May 7, 2011

Risk Appetite and Risk Tolerance

The Institute of Risk Management released a consultation paper on Risk Appetite and Risk Tolerance this week. The paper can be found here. I know that there is a wide divergence of views on risk appetite, ranging from outright hostility to making risk management any more complicated (a subject to which I will return in due course) and firm support for the development of thinking in this area. Personally, I believe that it could be a turning point for making risk management an important tool in the management of our organisations.

The paper has been prompted in part by the Financial Reporting Council’s new UK Corporate Governance Code. I am also finding myself debating risk appetite with more and more clients, all of whom are looking for practical and meaningful ways of implementing risk appetite as the next step on their risk management development. In this paper, we have sought to pull together some of the existing thinking in this area, and we have also sought to inject some fresh ideas. Both the IRM and I would greatly welcome your feedback.

I am very conscious of the fact that the document is framed in the context of the UK Corporate Governance Code: it therefore could appear to be (a) UK-centric and (b) only relevant to listed companies. In fact I think it is entirely transferable anywhere in the world and is as relevant to small private organisations and those in government and the third sector as it is to large quoted companies. However, I acknowledge that it will take some interesting further development to stretch the ideas to fit all organisations. But if we keep in mind that the aim is to develop helpful guidance, rather than develop yet another tick-in-the-box approach to governance, we should be able to do that!

The link (http://www.theirm.org/publications/risk_appetite.html) will take you to the IRM website and on that webpage you will find two further links: one for the Executive Summary, and one for the full document (which also includes the Executive Summary). To badly misquote George Bernard Shaw: we could not write a short document until we had written a long one. I hope that this represents a helpful contribution to the debate about the board’s responsibilities for risk appetite and risk tolerance. I do not think that we have written the last word on the subject, but rather I hope that we have set the debate going.

The IRM is circulating this document widely and would very much welcome your views. Does it provide useful guidance to organisations in defining their risk appetite? Does the approach make sense? What is missing? What would you remove? We would very much like to hear.

Please feel free to circulate the document widely within your organisation and then to forward any comments to Carolyn Williams, Head of Thought Leadership at IRM on carolyn.williams@theirm.org by Tuesday 31 May 2011. Needless to say, I am also interested in hearing your thoughts! Personally I am particularly interested in hearing about your experiences with risk appetite and understanding how you have overcome some of the interesting challenges it poses!

We are aiming to publish a final version of the document later in the Summer, taking account of comments received.

Monday, March 8, 2010

r-NXD's (this may be a UK-centric descriptor - but read on...)

Since I left PwC in 2001 I have firmly been of the view that risk management was going to be represented in the boardroom (or C-Suite) with a CRO type person. In the UK they would join the board, in the USA perhaps the C-suite. I am now seeing this come to fruition.

However, I am equally interested in the non-executive side of the equation. We need NXD's (non-executive directors - if that is indeed a UK-centric descriptor) who are business-savvy, numbers-savvy and now, I would argue, risk-savvy.

I would be interested to hear of examples of non-executive directors who have a business risk background in boardrooms with which you are familiar. Does that work? Do they add value? Is there a role? Do they help deliver the all important assurance environment?

I would also be interested to hear your views as to whether there is a need for what I am calling the r-NXD.

Kind regards

Richard

Thursday, February 25, 2010

Strategic Risk

Risk management has a history of sloshing about in the nether regions of the organisation: focussing on operational type risks, processes, insurance, that type of thing. Don't get me wrong, I think those things are important, but shouldn't we be dealing with the strategic issues? You know, M&A, what is the future of the organisation? What is coming at us over the horizon?

I have a view that we should be looking a lot more at strategic risk, and I like to tie it back to value drivers (via objectives?) such as those that drive shareholder value (or whatever your equivalent might be for our organisation).

This leads me to pose several questions:
  • Do we as a profession have enough face time with the CEO and Chairmen of our organisations?
  • Do we get involved in strategic plans before or after they happen? eg, do we get involved in risk based due diligence after the transaction is announced, or when options for acquisitions are being discussed?
  • How often do we, as a profession, facilitate board awaydays focussing on more distant strategy (say 5 to 10 years out)?
  • Does anyone have any really good war stories on this that you are happy to share on line?

Thanks

Richard

Wednesday, February 17, 2010

Ethics and Risk Management

It is my contention, as I have often said, that Corporate Ethics is one of four key attributes of Risk Management, and that is is often in tension with a performance culture (another of my four key attributes).

A number of things have cropped up over the recent years:
  • Clearly Toyota has some "ethical" questions to answer with regard to brakes, accelarators and now steering systems.
  • It seems unutterbaly proven that there were dubious (at best) ethics in banking which allowed the situation to arise for the financial crisis.
  • A few politicians in the UK have exhibited less than the highest standards in the ethical field.
  • Greece (aided and abetted by at least one bank) appears to have been cooking the books, with disastrous consequences for other Eurozone countries.
  • BAe has paid a stinging penalty to the US and a modest one in the UK.
  • We have a new bribery act coming onto the statute book in the UK (if it gets through before the election).

I believe that risk management can ONLY work where there is an ethical dimension to the organisation. And yet, perversely, this allows free-riding unethical corporations to duck and weave unhindered and leave the ethical corporation trailing - at least for a period of time.

I would welcome people's views on the interaction of ethics and risk management.

As ever, I am likely to turn the discussion into a paper in due course, summarising the contributions - if you are uncomfortable with that, let me know in your response.

Thanks

Richard

Monday, January 25, 2010

Management Rheumatism

I have been thinking about the need for a cure for what I describe as Management Rheumatism: a disease that typically occurs in older organisations, where the need for security (and therefore control) far outweighs the ability to embrace and implement change. For more see here...

Feedback welcome, as always!

Risk Appetite - reality v. aspirations

I have a new paper on risk appetite which has been written following on from a discussion on LinkedIn about Risk Appetite. The on-line discussion was followed by a real discussion at the Institute of Risk Management (www.theirm.org). The aim is to develop some practical guidance on the subject, which will be the subject of a follow on paper in due course. I am truly grateful to all those who took part in the discussion and especially to those who have allowed me to quote them in the paper. The paper is here...

I look forward to feedback: I thrive on feedback!

Thanks

Richard

Tuesday, December 15, 2009

I have recently added a new section to my website, where I will publish a series of "Working Papers" on topical risk management subjects. The first of these is on Target Risk, others will follow.

Target Risk was written following a recent enquiry about the subject. In particular I was asked whether I knew of any other organisations that was using the concept of target risk, and if so how were they defining it? In essence I was asked whether my client was being consistent with best practice and with general usage. Given that this exercise was done by talking to other clients, contacts and consultants, I am now sharing the results of that exercise. To see a copy of the paper, click here.

Governance article: while I am writing, you might be itnerested to see a very short article that was published in "Governance" recently on my views as to whether the Walker Report will make the slightest difference to the state of Corporate Governance in the UK. To see a copy click here.

I thrive on feedback - let me know what you think.

Thanks

Tuesday, October 13, 2009

Three Lines of Defence - Dead or Alive?

I went to a hearing at the European Commission yesterday. They wanted to know what professionals, experts, regulators, bankers and others thought about Corporate Governance, the role of shareholders, and risk management. There were three panels, but the one that I participated on, and which is prompting this post, was the one on risk management. One of the panelists put forward the view that internal control and risk management really needs the Three Lines of Defence (1: Line Mangers manage risks, 2: Risk Managers set policy, 3: Internal audit confirms compliance with policy etc).

I argued that Three Lines of Defence (TLD from now on) had not worked... witness RBS and HBOS and others in the States etc. To which this participant replied, but had it been done better it would have provided clear guidance on what should have been done.

My contention is that TLD allows assurance (actually that should be Assurance with a capital A) should not be divided. What we need is: a balanced view to risk, ethical programmes, mature risk management, a risk management and assurance framework, and an organisational structure that works. Now TLD might do that, but it is not the only way at all.

So I am arguing that TLD is fine if you really want it, but don't depend on TLD to protect you next time round. It wasn't that we were slightly wrong in our approach to risk management, we were fundamentally inadequate and TLD did not spot that...

I would welcome your comments, either here, on LinkedIn, or via my website.

Regards

Richard

Friday, October 2, 2009

Risk oversight committees in Banks and Other Financial Institutions

You will all be aware that Sir David Walker issued his consultation paper on Corporate Governance in UK Banks and Other Financial Services Entities (BOFIs for short) on 16 July. There may well be some overlap here with the SEC recommendations. In my view there is a lot to be welcomed in Sir David's report, however there are a few areas where further fresh thinking would be merited.

My main recommendations are fourfold (excuse the numbering...):
  1. I continue to believe that we need to see a paradigm shift in Corporate Governance. In order to make incumbent boards and individual directors take this seriously we need to see new fiduciary duties relating to Corporate Governance responsibilities, which should be discharged with due and diligent care.
  2. I applaud the recommendation to create effective board risk oversight committees. I happen to believe that the remit as described in Sir David's paper is insufficient for the purpose. The remit and mechanics should:
  • Encompass the development of a balanced view of risk;
  • Include the oversight of the development and implementation of a robust ethics programme;
  • Encompass the periodic assessment of the maturity of risk management maturity;
  • Include the development of a risk management and assurance framework that is fit for purpose; and
  • Address the development of an appropriate risk management organisation.
  1. Although it may well be difficult, in the context of the worst dereliction of Corporate Governance responsibilities of recent economic history, I continue to believe that we should find ways to make a form of permanent, full time non-executive director role work in BOFIs (and other organisations) that have a major societal impact.
  2. I continue to believe that the most important attribute of a non-executive director is an ability to act in a challenging, and yet supportive manner. Akin to risk management, the role of such directors is to periodically pierce the “perfect place arrogance” that develops in large corporate organisations. I am therefore less interested in the sectoral background, while of course acknowledging the need for a number of the directors to have BOFI backgrounds.

I set out more detail supporting my recommendations in my letter to Sir David, a copy of which can be found at http://randerson-assocs.co.uk/WalkerConsultationPaper.aspx. I would be pleased to hear what you think of (a) Sir David's consultation paper, (b) my responses and whether you believe Corporate Governance will improve as a consequence of his work.

Kind regards

Richard

Thursday, August 6, 2009

Is ERM becoming more important or not???

I have created a small poll on LinkedIn about ERM and its mounting importance following the financial crisis. Click HERE to go to the poll.

Let me know what you think.

Richard

Tuesday, May 12, 2009

The frailty of VaR

A great article from way back when in January by Joe Nocera of the New York Times. It looks at the frailty of VaR and should be required reading! Click here.

Friday, April 17, 2009

OECD Report

As I have either said, or hinted at elsewhere, I was commissioned by the OECD to review Corporate Governance, risk management and remuneration in the banking sector in the UK, the US and France. My report has now been published, and can be found in full here. The same link will also take you to a shorter summary report. Be warned that the full report is over 50 pages long...

What people have said about the report:
  • Insightful"
  • a "pithy summary"
  • "This is a strong, impressive report. Your grasp of the issues in a still-unfolding international financial disaster is not only impressive, but lends credibility to your recommendations which, taken together, are peerless. I hope that they are widely read, debated and, ultimately, implemented. I will not comment on each of your recommendations, nor your analyses and arguments in support of them, because there would be nothing substantive that I could add."
  • "I have to read about risk day in and day out on the day job so for balance I prefer to read about other topics. But ... I made myself read it and I am glad I did. You paint a valuably comprehensive picture, and propose many innovative solutions."

I would welcome your feedback and thoughts as to how we can take the debate further.

Also, go to the OECD's website to see what else they are doing on the governance front.

Wednesday, April 15, 2009

Myners and boards

I think Lord Myners comments on boards are well worth reading. See here.

I am not sure about having a "Devil's Advocate" in that sounds a bit like having someone on the board just to be contrary. But I do agree that we need to do something about creating a counter-balance to what I have described elsewhere as the "red-blooded, testosterone-charged" CEOs of this world.

I would be interested in feedback

Thursday, March 26, 2009

The SFO calls... Recessionary tales of the unexpected

Who will your disgruntled employee talk to first? You or the SFO? The SFO is putting paid for advertising into the media asking for whistleblowers to come forward see here, or for a legal perspective, see DLA Piper’s note on the subject: see here.

What are the business implications? What can you be doing right now?

Here we are in the worst recession in ages, if not since records began, and employees are under incredible pressure to produce results. Investors want results, boards are demanding results, managers are shouting for results, and who produces them? But staff cannot pull rabbits out of hats, so they are feeling coerced into manufacturing results that simply do not exist.

People who have led blame free lives, who would not say boo to a goose, are being encouraged to come up with results for their managers, or risk losing their jobs. Accountants and others are losing sleep over the “temporary” adjustments they have made – all in the expectation of making good next month. Except next month is even worse. Ask Bernie Madoff – and look where he ended up.

These staff, who are under excruciating pressure need to be able to let off steam. So who will they call: someone in your organisation, or the SFO? Indications are that more and more people are calling the SFO. And while we can all applaud the efforts to catch the crooks – is this really where you want to be spending your hard-earned management time: dealing with an SFO investigation?

So what can you do?

1. Review your ethics and compliance approaches: do you have an ethics programme? Do you know that you are in compliance with legal and regulatory requirements? Is it time to dust your programme down and remind people that is exists? Or do you need to create a framework right now?
2. Ensure that you have space for staff to let off steam. Vague whistleblowing policies about letting someone know somewhere in the organisation don’t usually work: there needs to be an independent (but that does not necessarily mean outsourced) mechanism that is both credible and seen to work. Make sure that communication programmes are in place, and that people feel that ethics is as much there to support them as it is for the organisation. This needs two-way risk-free communication.
3. Conduct an independent, anonymous survey of attitudes amongst senior managers and front line accountants – those who are most likely to know what is going on. Surveys in the States have shown that whereas a typical whistleblowing facility may have 1% of the staff using it for its primary purpose, a further 4% might explore ideas which could prevent abuses. And yet as many as 50% of staff, according to surveys, claim to have witnessed illegal or potentially seriously embarrassing unethical behaviour. Where did that 45% go?
4. Talk to partners, suppliers and customers – proper engagement with them, so that you have a dialogue which helps to reveal where pressure points are in the value chain.
5. Review those reconciliations and funny accounts – all the ones that are full of judgemental values. This is often where dodgy results start – implement a zero-tolerance policy with regard to unauthorised adjustments to these accounts.
6. Get your internal auditors on to the case: a few deep dives into trial balances and transactions sends out a message.
7. Bring your risk management down from the Olympian heights of governance compliance and turn to operational risks.

And if all of that sounds like yet more expense – well its better than having your collar felt by the SFO because you never got round to it...

Oh, and while this has a UK flavour (note the "u" in that word) it is relevant right round the world.

Monday, March 23, 2009

Turner Report

Lord Turner, Chairman of the FSA, set out his proposals for reforming the regulation of banking in the UK on 18 March 2009. The report emphasises, amongst other aspects, the importance of changing from a "light touch" approach to managing on a systemic basis. However, he does acknowledge the importance of Corporate Governance and internal risk management procedures, although final proposals await the Walker Report which will be published in October 2009.

The brief section on governance and risk management is nontheless interesting in that it illustrates the thrust of likely changes. I have reproduced this section in full below

2.8 Risk management and governance: firm skills, processes and structures

Analysis of the causes of the crisis suggests that there is a limit to the extent to which risks can be identified and offset at the level of the individual firm. Chapter 1.1 described how the origins of the crisis lay in macroeconomic imbalances and systemic developments: Chapter 1.4 argued that there are limits to the effectiveness of market discipline; and Section 1 of this chapter stressed that the crucial shift required in regulatory philosophy is towards one which focuses on macro-analysis, systemic risks and judgements about business model sustainability, and away from the assumption that all risks can be identified and managed at a firm specific level. As a result most of the changes proposed in this review relate to the redesign of regulation combined with a major shift in supervisory approach.

But improvements in the effectiveness of internal risk management and firm governance are also essential. While some of the problems could not be identified at firm specific level, and while some well run banks were affected by systemic developments over which they had no influence, there were also many cases where internal risk management was ineffective and where boards failed adequately to identify and constrain excessive risk taking.

Achieving high standards of risk management and governance in all banks is therefore essential. Detailed FSA proposals will await the outcome of the Walker Review (described below) but the key dimensions of required improvement are likely to be

  • Improved professionalism and independence of risk management functions. As already outlined in Section 2.7 above, the FSA will therefore in future play a more active role in assessing the technical competence of senior risk managers. And it will consider whether governance structures for risk oversight need to be changed, with a more direct relationship between senior risk management and Board risk committees
  • Risk management considerations embedded in remuneration policy, in the fashion described in Section 2.5 (ii). This has implications for the remit of remuneration committees and for the non-executive time commitments required
  • Improvements in the skill level and time commitment of non-executive directors. The crisis has revealed the extreme complexity of large banking groups and the difficulties which nonexecutive directors (NEDs) face in understanding all dimensions of the risks being taken, within the time commitments typically required of NEDs. It has also raised questions about the degree of technical skill and experience required to perform risk committee functions, and whether existing bank boards have sufficient people with these technical skills. In addition it has demonstrated the vital importance of non-executive challenge to dominant chief executives pursuing aggressive growth strategies
  • Shareholder discipline over corporate strategies. As Section 1.4(iv) described, shareholder influence seems to have been relatively ineffective in the past in constraining risky strategies. There may be ways of improving the effectiveness with which shareholder views are communicated to non-executives

These issues and the implications for overall governance principles and structures need to be looked at in an integrated fashion. One question they prompt is whether the governance arrangements appropriate for banks are different from those which apply to the generality of companies, and whether therefore codes and rules which go beyond the general Combined Code are required

These issues will be in part addressed by the review of bank governance being conducted by Sir David Walker which the government announced on Monday 9 February and which will report in October 2009. The FSA, which is providing the secretariat for this review, will work closely with Sir David Walker in consideration of these issues. Once the review has reported, the FSA will consider what changes to its rules and process are required to ensure that problems are addressed, making specific proposals by the fourth quarter of 2009

It will be interesting to see how this turns out under both the FRC review of the Combined Code and also the Walker review. For what it is worth, my view is that there is nothing intrinsically different about the governance of financial institutions just because they are financial institutions. While clearly there are differences in the technical aspects of risk, what seems to me to be more important is the potential societal impact of poorly handled risk in an organisation. Poorly handled risk in say chemical companies can be as (or even more) devastating than in banks: look at Bhopal or the BP refinery problems in the US. I am more interested in big v small impact organisations. One key difference may be whether there are Critical National (or International) Infrastructure implications, or whether there is scope for major disasters. I add the latter, because I am not sure whether Pharma companies are part of the CNI, but they can have devastating impacts (eg Thalidomide)

For the full detail of the Turner Report, click here...

Sunday, March 15, 2009

Gordon Brown on Changes Needed

Gordon Brown on the changes needed: This article highlights the changes that GB is looking for in the global financial system. Well worth looking at. More...

Saturday, March 14, 2009

GSO Finance Ministers

G20 Communiqué from the G20 Finance Ministers. It will be interesting to see whether Corporate Governance forms part of the stronger regulatory and oversight regime: hard to imagine that it won't. More...

Thursday, March 12, 2009

It gets better and better

See the report on Hector Sants in the FT... More...

Be frightened, very frightened

Just to prove my point on the change in mood music, see this article reporting on Hector Sants and Alastair Darling's views on regulation. Be frightened, very frightened...

(Or be prepared...)