enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

EY Oceania and EY Asia-Pacific Governance Risk and Compliance (GRC) Technology Leader

Building NextGen Enterprise Risk Management Capabilities

Chee Kong Wong, EY Oceania and EY Asia-Pacific Governance Risk and Compliance (GRC) Technology Leader

Enterprise Risk Management (ERM) has re-emerged atop the board agenda and is regularly discussed among the c-suite now that organizations have experienced major disruptions resulting from the COVID-19 pandemic. How many organizations were prepared for the pandemic? Are they prepared for another disruption? How effective is their ERM and how can the ERM help to predict and manage future risk events?

ERM is evolving, and expectations are rapidly increasing from a focus on protecting the enterprise, to ERM becoming a strategic priority for organizations for building the trust of stakeholders. Four new trends in ERM are requiring organizations to fundamentally revamp their traditional ERM programs:

1. Boards and c-suite executives are placing greater emphasis on more insightful risk reporting.

2. More focus is being directed to going beyond risk avoidance, expanding to risk optimization.

3. Businesses are seeking to understand financial risk exposures and are embracing risk quantification.

4. Organizations need ERM to be integrated into existing business planning processes.

Technology will be the enabler for realizing the expectations of next-generation ERM (NextGen ERM).

Adopt rapid risk assessments to align with the pace of today’s world

When designing ERM, organizations can’t rely solely on ‘check-the-box’ annual risk assessment processes, nor piggy-back on internal audit risk assessment processes. Organizations should focus on risk management through rigorous risk response planning and ongoing risk monitoring using data and metrics. Recognizing that stakeholders of risk information are usually the same across an organization will help drive the function to align their processes and data. Amplifying risk capabilities by using technology and aligning towards a common risk taxonomy, risk tolerances, and appetites, and driving efficiencies in reporting across all lines of risk can make the risk function more agile.

"NextGen ERM quantifies risk exposures using scenario planning and stress testing to equip leadership with the data points needed to understand a range of potential outcomes (e.g. best case, expected case, and worst case)."

To enhance rapid risk assessments, leading organizations are utilizing digital collaboration platforms to perform quick risk assessments which can deliver a refreshed risk profile in as short as one to two weeks. The real value of ERM is in risk response planning and on-going risk monitoring, not an exhaustive enterprise risk assessment, with quick insights that can be immediately acted upon.

Build upon qualitative risk assessments to quantitative risk insights

NextGen ERM quantifies risk exposures using scenario planning and stress testing to equip leadership with the data points needed to understand a range of potential outcomes (e.g. best case, expected case, and worst case). NextGen ERM then leverages costs-versus-benefit analysis to understand where to most effectively make risk mitigation investments, and how much to invest. Instead of alerting leadership to risk (e.g. pandemic or cybersecurity), NextGen ERM transforms discussions by using data to support risk-informed decision-making to understand how to most efficiently apply resources to manage risk exposures.

ERM requires forward-looking risk insights to track mitigation plan effectiveness and support risk escalation routines. This is where quantitative key risk indicators (KRIs) come into play. For each top risk, quantitative KRIs must be defined to help anticipate when a risk might occur. The goal is to create metrics that help identify risk before it occurs so that ERM isn’t caught flat-footed. Once established, KRIs must have clearly defined acceptable thresholds (upper and lower limits) to support risk escalation and risk monitoring routines. In practice, risk owners need to know when and how to escalate risks for leadership discussions and actions. KRIs serve as triggers to support actionable risk monitoring. NextGen ERM encourages action, not simply reporting.

Embrace technology at speed to realize NextGen ERM

Quick risk assessment and insightful data required for proactive risk management and response demand the innovative use of technology and data. Organizations can leverage a suite of trusted technologies, such as advanced data analytics, artificial intelligence (AI), and robotics to build a risk intelligence engine that provides risk sensing and augmented decision-making capabilities. This technology should provide the organization with the ability to rapidly synthesize large amounts of internal and external information to provide actionable enterprise intelligence, enable dynamic risk management, and fact-based decision making. The innovative use of digital twin scan then be used to test risk mitigation scenarios.

In other more simplistic areas, robotic process automation (RPA) has been proven to enable continuous risk monitoring. Simply using chatbots with RPA can ensure a resilient and reliable process for incident reporting and handling, capturing complete and accurate data required for improved risk assessment and profiling.

In Asia-Pacific, some organizations have taken innovative steps to implement selected technologies for enabling targeted ERM capabilities, especially in the area of risk sensing, to rapidly test and subsequently scale the deployment of additional capabilities. These organizations have hired data scientists and AI specialists to build their capabilities in risk management.

ERM is no longer limited to risk professionals. It requires bringing together different skills in risk, technology, and data. Organizations that know how to harness data and technology to optimize upside risk and anticipate outside risk can maximize business opportunities to achieve competitive advantage and create long-term value.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief