Sei sulla pagina 1di 15

Ferma Risk Management Forum 2009

Prague, 4-7 October

The Global Village

Future of Risk Management

Considerations elaborated by Alex Dali & Christopher Lajtha


Ferma Risk Management Forum 2009
Prague, 4-7 October

“ISO 31000:2009, an incentive or a constraint for


implementing Risk Management in an organization?”

Things to watch out for….


Alex Dali
Managing Partner ATLASCOPE
ARM, EFARM, Master in Risk Management & Insurance

Member of the AFNOR French Commission on RISKS


Co-author of the article “ISO 31000 : the Gold Standard”
published by StrategicRISK, September 2009

Considerations elaborated by Alex Dali & Christopher Lajtha


Ferma Risk Management Forum 2009
Prague, 4-7 October

Internationally-recognised reference

• International consensus
• single global reference for stakeholders
• wide application
• “umbrella” for more than 60 standards

• should not be ignored


Considerations elaborated by Alex Dali & Christopher Lajtha
Ferma Risk Management Forum 2009
Prague, 4-7 October

ISO Standard vs ISO Guideline ?

• Risk Management – Principles and


Guidelines
• Voluntary application, not prescriptive, no
legal requirement
• specifically not intended for certification

• ISO  certifiable standard ? NO !


Considerations elaborated by Alex Dali & Christopher Lajtha
Ferma Risk Management Forum 2009
Prague, 4-7 October

Simple risk management architecture

• 3-pillar structure
• robust and simple to apply
• Opportunity to review existing RM
practices

• Track similarities and differences

Considerations elaborated by Alex Dali & Christopher Lajtha


a) Creates value Mandate Ferma Risk Management Forum 2009
and Establishing
Prague, 4-7 October
b) Integral part of C
Commitment the context (5.3)
organizational o M
processes (4.2)
m o
c) Part of decision u Risk assessment n
making n (5.4) i
d) Explicitly addresses Design of i t
uncertainty framework c o
e) Systematic, Risk
a r
structured and timely (4.3) identification
t i
f) Based on the best (5.4.2)
i n
available information Continual o g
Implementing
g) Tailored improvement n
risk Risk analysis
h) Takes human and of the & &
Management (5.4.3)
cultural factors into Framework c
(4.4) r
account (4.6) o
i) Transparent and e
n Risk
inclusive v
s evaluation
j) Dynamic, iterative and i
u (5.4.4)
responsive to change Monitoring e
l
k) Facilitates continual and review w
t (5.6)
improvement and of the a
enhancement of the Framework t Risk treatment
organization (4.5) i (5.5)
o
n
5.2

Principles Framework Process


(Clause 3) (Clause 4) (Clause 5)

ISO 31000:2009 Figure 1 – Relationship between the principles, framework and process

Considerations elaborated by Alex Dali & Christopher Lajtha


Ferma Risk Management Forum 2009
Prague, 4-7 October

… not a parallel management system

• avoid the troubled implementation of ISO


9000 series
• Promote business performance

• No bureaucratic compliance reporting


system

Considerations elaborated by Alex Dali & Christopher Lajtha


Ferma Risk Management Forum 2009
Prague, 4-7 October

Text of the ISO 31000 standard

• The text is short and clear


• Not radically new

• Exaggeration and self-serving


statements

Considerations elaborated by Alex Dali & Christopher Lajtha


Ferma Risk Management Forum 2009
Prague, 4-7 October

Vocabulary ISO Guide 73


Engineer  risk = danger
Modéliste  risk = event
Manager  risk = uncertainty towards
objectives
Health  risk = threat (purely negative)
Finance  risk = return
Public sector  risk = disruption of service or job losses
 All activities of an organization involve risks
 All activities of an organization involve combinations of
probabilities of events and their consequences !!!
 All activities of an organization involve effects of
uncertainty on its objectives
Considerations elaborated by Alex Dali & Christopher Lajtha
Ferma Risk Management Forum 2009
Prague, 4-7 October

Vocabulary ISO Guide 73

• Review by the same committee


• 51 definitions related to RISK
• Many improvements

• use language meaningful to your organisation


• remove terms and definitions invented locally

Considerations elaborated by Alex Dali & Christopher Lajtha


Ferma Risk Management Forum 2009
Prague, 4-7 October

Credit Rating Agency enquiries…

 S&P - Development of ERM analysis in response…


 Points of interest : Strategy, management vision,
diagnostic, communications
 Exclusions : Treatment (risk-control measures)
e  Existing ERM processes not very formalized
x
tr  A decentralized ERM organization
a
c  Underfunded and underintegrated ERM
t
s  Weak ERM culture and strategic risk management
Considerations elaborated by Alex Dali & Christopher Lajtha
Ferma Risk Management Forum 2009
Prague, 4-7 October
Standards & Poors

Rating and cost of capital

Considerations elaborated by Alex Dali & Christopher Lajtha


Ferma Risk Management Forum 2009
Prague, 4-7 October

Quality OH&S Finance Supply Information Equipements


chain security safety
Environment Food safety
Considerations elaborated by Alex Dali & Christopher Lajtha
Ferma Risk Management Forum 2009
Prague, 4-7 October

COSO - ERM

« ERM is effective if management has reasonable


assurance that they understand the following :
 Strategic objective are being achieved
 Operational objectives are being achieved
 Reporting is reliable
 Laws and regulations are being complied with »

Is it risk management or compliance ?


Considerations elaborated by Alex Dali & Christopher Lajtha
Ferma Risk Management Forum 2009
Prague, 4-7 October

Reference by law remain

AZ/NZS
4360 : 2009

AS/NZS4360 FERMA:2004 COSO ERM


2004 Europe USA
Certification of RM ?
Certification
Australia/NZ
ONR 49000:2008 BSI 31100
CAN/CSA- ONR 49000 AIRMIC, ALARM,
JIS Q 200x CAN/CSA-
Q850-1997 BSI 31100
IRM:2002
Q850-20xx Austria
Japan ? Canada
Considerations elaborated by Alex Dali & Christopher Lajtha
(Germany/Switzerland
Great-Britain.
)

Potrebbero piacerti anche