From: Security By Haywood Marsh, General Manager of Risk Services, NAVEX Global
The pandemic tested corporations in 2020 like never before, and the fallout of the pandemic has sparked a host of additionally destructive risks: cybersecurity, supply chain, health and safety, financial fraud, and regulatory compliance.
If the experiences of 2020 taught us anything, it’s that risk in the modern world cannot be understood or sufficiently mitigated with a siloed approach. Individual threats, such as regulatory risk and IT security, converge. Lacking a high-level view, it’s difficult to see the web of cause and effect – making it more difficult to anticipate, prepare, or mitigate the biggest risks. 2020 may be over, but the challenges remain in 2021. Compliance and risk management will need a shared umbrella of information and communication to tackle the complex, integrated risks of today’s landscape.
This year, the most successful organizations will:
- Integrate compliance, IT, operational, reputational, third-party, and corporate social responsibility (CSR) processes and practices.
- Appoint more Chief Risk Officers (CROs) or Chief Risk and Compliance Officers (CRCs) and/or establish risk and compliance committees to manage an integrated risk strategy and to establish clear lines of responsibility.
- Respond to board-level committees tasked with addressing enterprise-wide risk.
The Future of Risk Integration
The U.S. Department of Justice (DOJ) and other regulators scrutinize organizations’ ability to prevent misconduct from happening; other risks, like those arising from climate change or supply chain failures that threaten enormous operational disruption, don’t fall within the scope of regulatory enforcement concerns. But they are no less important to a company’s financial and reputational health.
Social media advocates can easily draw public attention to corporate missteps, asking, essentially: How did the company not see this coming? That’s a question corporate boards and CEOs never want to ask.
In 2021, boards will need tools and information to assess, manage, and report enterprise risks. Risk integration isn’t new, but the pandemic and instability of 2020 has accelerated the need for effective corporate governance. Spreadsheets, standalone systems and working in silos aren’t enough to track and weigh the many complex risks of the near future; purpose-made integrated risk management technology is the most effective way to monitor risk on an ongoing basis.
Integration of Risk Management Processes is Inevitable
Governments around the world are already responding to the complex, new risk landscape by pushing organizations toward increased transparency and accountability. In the U.S., the DOJ updated its guidance for evaluating effective compliance programs in 2020; and the new Biden Administration has already indicated it will seek more disclosure from corporations on climate change and racial equity. The European Union’s new whistleblower protection rule will go into effect at the end of 2021. Enforcement of anti-corruption, anti-money laundering, data privacy, and human trafficking laws has also increased dramatically, and new laws around these issues are already on the books.
These dynamic social, regulatory, and economic pressures require an integrated approach to risk management.
The board, senior executives, and business unit leaders should have a comprehensive understanding of organizational risks. Companies who can evolve and meet these new demands will have the advantage of informed decision-making and improved performance.
4 Steps to Future-proof Your Risk Management Program
1. Build Company-wide Support for IRM
Integrated risk management affects the legal, internal audit, IT, and compliance functions, as well as any existing risk management functions. In addition to working with other departments, advocates for IRM need to identify and cultivate the support of in-house partners, senior management, and the board, which has the ultimate responsibility for assuring effective risk management.
2. Clarify Roles and Responsibilities
How will compliance and risk management functions intersect? This can be a delicate question, but decision-making hierarchy, and ultimately, accountability, requires clarity around roles and responsibilities. If you don’t have a CRO or CRCO, or at the least a risk and compliance steering committee, consider designating a member of senior management to assume these duties and/or form the committee.
3. Define Risks and Mitigation Steps
Leaders throughout the enterprise will need to use risk assessments to map risks to processes and requirements, such as:
- supply chain management
- IT risks
- compliance risks
- reputational risks
- financial liquidity
- litigation threats
- workplace operations risks, like extreme weather events or pandemics
Use risk management frameworks to identify and mitigate risks. This can be an ambitious undertaking; role clarification is an important prior step.
- Enhance Your Monitoring and Reporting Capability
For quick mitigation, risks must be monitored on an ongoing basis. Further, new risks should generate an alert and be reported to key stakeholders so risk management leaders can prioritize the organization’s high-level risks, pressing concerns, and less urgent considerations, and mount a strategic response.
It is tempting to view 2020 as an anomaly, and in many ways, it was. However, the events that sparked the many crises of 2020 - political instability, weakening institutions and norms, social unrest, increasingly complex supply chains, trade wars and sanctions, ecological disruption, and accelerated climate change, just to name a few – will be with us for years.
Businesses that isolate compliance risk from other business risks will not be able to strategically respond.
Those companies that bring risk and compliance together under the same umbrella will be poised to respond when the next storm hits. Which it inevitably will.