SlideShare une entreprise Scribd logo
1  sur  15
www.nicsa.org
Third-Party Risk Management:
Implementing a Strategy
Part I of II
1
SPONSORED BY:
www.nicsa.org
The use of third-party service providers has become increasingly pervasive, complex, and
interconnected within the investment management industry
• Increased number of core operations and IT
services being outsourced
• Third parties also outsource - common
providers can create layering and unforeseen
concentration risk
• Dispersed dependencies create increased
reliance and risk exposure from entities outside
of your direct control
This growth of the extended enterprise model calls for continued evolution of the Extended
Enterprise Risk Management (EERM) strategy, with mature programs applying a consistent,
enterprise-wide level of discipline that extends across the entire third-party lifecycle.
An evolving landscape
:
Copyright © 2015 Deloitte Development LLC. All rights reserved.
www.nicsa.org
 Enhanced quality of risk management processes through centralized execution on the business’ behalf
 Transparency into third-party performance and risk exposure by improving information flow through the organization
 Improved efficiency through centralized tools and processes
 Reduced risks through centralization of controls and quality gates
 Increased consistency scale and common communication
Strategy & Planning
Contract &
On-board
Evaluate
& Select
Terminate
Off-board
Manage &
Monitor
Third-Party
Management
Lifecycle
Strategy & planning – Develop sourcing strategy,
consider cost/benefits and develop business
Evaluate & select - Identify and assess risks / perform
due diligence
Contract & on-board - Incorporate risk, compliance,
and performance requirements in contracts
Manage & monitor - Perform risk management and
ongoing monitoring & coordinating with each third
party
Terminate & off-board - Determine need to terminate the
third party and manage the off-boarding process
Some benefits of an EERM Framework
Many companies are moving toward an end-to-end framework to create a controlled and efficient process to effectively manage the
business and regulatory requirements. A well-designed and sustainable framework can help manage third-party risks and provide
structure for governance and monitoring the process.
Maintaining control &
managing third-party risk
:
Copyright © 2015 Deloitte Development LLC. All rights reserved.
www.nicsa.org
CPE CODE:
897
www.nicsa.org
Governance and
Oversight
The organizational
structure, committees,
and roles and
responsibilities for
managing third parties
EERM Framework
Risk
Domains
Operating
Model
Components
Business
Objectives
Risk and Compliance
Management
Growth / Innovation Client Experience Cost Reduction
Improved Time to
Market
Reputation Risk Strategic RiskGeopolitical Risk
Contractual Risk
Information Security
Risk
Transaction /
Operational Risk
Financial Stability
Risk
Business Continuity
Risk
Compliance / Legal
Risk
Credit Risk
Plan, Evaluate and Select Contract and On-board Manage and Monitor Terminate and Off-boardManagement
Process
Detail
Our EERM framework—based on the Office of the Comptroller of the Currency (OCC) and other regulatory requirements, as well as
industry practices—provides a structured review of the operating model components required to support an effective program.
 An effective EERM program supports business objectives including growth, innovation, reduced cost, and risk and compliance.
 Delivering effective EERM requires a comprehensive operating model that includes governance and oversight, policies and standards, management
processes, tools and technology, risk metrics and reporting, and risk culture.
 Management and risk domains support delivery of EERM capabilities and the management of risk. Each domain is comprised of its own set of management
activities/capabilities and related risks.
Deloitte Advisory’s EERM framework
Risk Culture
Tone at the top, clarity
on risk appetite,
appropriate training
and awareness. to
promote positive risk
culture
Policies and
Standards
Management
expectations for the
management of third
parties and related
risks
Risk Metrics and
Dashboard
Reports identifying
risks and performance
associated with third
parties, tailored
toward multiple levels
of management
Management
Processes
Processes to manage
risks across the third-
party lifecycle
Tools and
Technology
Tools and technology
that support EERM
processes
:
Copyright © 2015 Deloitte Development LLC. All rights reserved.
www.nicsa.org
Stages of EERM Capability Maturity
StakeholderValue
Integrated
Risk
Intelligent
Top Down
FragmentedInitial
• Ad hoc/chaotic
• Depends primarily on
individual heroics,
capabilities, and verbal
wisdom
• Independent EERM
activities
• Limited focus on the
linkage of third-party
risks with the
company’s overall
strategic risks
• Limited alignment of
risks to strategies
• Disparate monitoring &
reporting functions
• Common framework,
program statement,
policy
• Routine risk
assessments
• Communication of
risks to the key
stakeholders
• Awareness activities
• Dedicated team
• Coordinated risk
management activities
across identified
segments
• Risk appetite is fully
defined
• Risk monitoring,
measuring, and
reporting to the board
• Contingency plans and
escalation procedures
in place
• EERM discussion is
embedded in the
company’s strategic
planning, capital
allocation, product
development, etc.
• Risk-sensing, early
warning risk indicators
used
• Risk modeling
/scenarios applied
• Industry benchmarking
used regularly
Representative Attributes Describing Each Maturity Level
Initial Fragmented Top Down Integrated
Risk
Intelligent
Capability Maturity Stages
1. How capable is the organization today to manage its extended enterprise risks?
2. How capable does it need to be?
3. How can it get to its desired state? By when?
4. How can we leverage existing extended enterprise risk management practices?
:
Copyright © 2015 Deloitte Development LLC. All rights reserved.
www.nicsa.org
This presentation contains general information only and Deloitte is not, by means of this presentation, rendering
accounting, business, financial, investment, legal, tax, or other professional advice or services. This presentation is not a
substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may
affect your business. Before making any decision or taking any action that may affect your business, you should consult a
qualified professional advisor.
Deloitte shall not be responsible for any loss sustained by any person who relies on this presentation.
About Deloitte
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”),
its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and
independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. Please see
www.deloitte.com/about for a detailed description of DTTL and its member firms. Please see www.deloitte.com/us/about
for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to
attest clients under the rules and regulations of public accounting.
www.nicsa.org
CPE CODE:
430
www.nicsa.org
• Broker approval
• CP approval and
monitoring
• CP exposure reporting
• Best Execution reporting
• Risk Contribution
monitoring and reporting
• Scenario analysis
Head of Risk
Management US
• Analytics monitoring
and reporting
• Performance Attribution
• Fund Performance
monitoring
• GIPS reporting
• Peer analysis
Global Risk
US CEO
Operational
Risk
Broker-Counterparty
Risk
Performance
Analytics &
Attribution
Investment Risk
VENDOR ASSESSMENT TEAM
Vendor Relationship Owners
Vendor Universe
Vendor
Governance
Office Information
Security
Business
Continuity
Operational
Risk
Finance
Compliance
incl. Privacy
Purchasing
Legal
Op Risk Management System
- Relationship Owner
Attestations
- Framework Attestations
Emerging Risks
- Compliance-Risk Oversight
- Top Risks
• Risk and event
identification and
assessment
• Monitoring and
reporting
9
www.nicsa.org
Vendor Governance Purview
Assessment Areas
• Business Continuity
• Data Integrity and Security
• Financial Terms & Stability
• Insurance
• Internal Controls
• Losses / Legal Actions
• Regulatory Compliance
• Reputation
• Service Levels
VG Office
• Maintain framework
• Coordinate Initial Assessment / Take-on
• Coordinate Periodic Due Diligence
• Raise Concerns
• Track Remediation Actions
• Report out
• Participate in Compliance-Risk Oversight
Discussions
Vendor Universe *
Tier 1 (Core A)
• Functionally critical
• Financially critical
• Subject to laws / regulations
• Necessary to legal / regulatory
obligations
• Central to control functions
Tier 2 (Core B)
• Failure could cause serious
damage
• Annual outlay > $500k
Tier 3 (Non-core)
* Exceptions
• Financial distributors
• Brokers and Counterparties
VENDOR ASSESSMENT TEAM
• Op Risk Management System
• Vendor Assessment System
• SIG Questionnaire (Shared
Assessments Group)
Vendor Universe
Vendor
Governance
Office
10
www.nicsa.org
Board
Oversight
Custodian
Fund Accounting
Financial Reporting
Tax Compliance
Transfer Agent
SubTAs & Omnibus Providers
Sub-Advisors
Pricing Services
Others For
Management
Consideration
Printing and Mailing
15c Materials
Blue Sky Reporting
Escheatment Services
Proxy Solicitation Services
Others
11
Third-Party
Oversight
Independent
Director
Viewpoint
www.nicsa.org
CPE CODE:
755
12
www.nicsa.org
Board Oversight
Independent Director Viewpoint
Consider Board
Committee Structure
– Committees: Audit;
Compliance; Contracts
– Where should oversight
reside?
– Interdisciplinary approach
13
Frequency of
Board Reporting
Level of Detail
– Dashboards
www.nicsa.org
Inventory of Third-Party Service Providers
Independent Director Viewpoint
14
Name
Nature of Services Provided
Primary Management oversight: “Business Owner” of
Each Relationship
Summary of Management’s Oversight Functions
Summary of Board Reporting on Each Provider
www.nicsa.org
High Level “Sub-TA Dashboard”
Independent Director Viewpoint
15
For each relationship:
AUM Date last visit Risk Rank
Review
Status
SSAE#16 or
FICCA
Reports

Contenu connexe

Tendances

Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
Rishabh Software
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
Ceyeap
 
Risk assessment presentation
Risk assessment presentationRisk assessment presentation
Risk assessment presentation
mmagario
 

Tendances (20)

KRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & ITKRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & IT
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
 
Risk Appetite: A new Menu under Basel 3? Pieter Klaassen (UBS) voor het Zande...
Risk Appetite: A new Menu under Basel 3? Pieter Klaassen (UBS) voor het Zande...Risk Appetite: A new Menu under Basel 3? Pieter Klaassen (UBS) voor het Zande...
Risk Appetite: A new Menu under Basel 3? Pieter Klaassen (UBS) voor het Zande...
 
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
 
Key risk indicators shareslide
Key risk indicators shareslideKey risk indicators shareslide
Key risk indicators shareslide
 
Risk Management Overview
Risk Management OverviewRisk Management Overview
Risk Management Overview
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard
 
Introduction to Risk Management
Introduction to Risk ManagementIntroduction to Risk Management
Introduction to Risk Management
 
Third-Party Risk Management: A Case Study in Oversight
Third-Party Risk Management: A Case Study in OversightThird-Party Risk Management: A Case Study in Oversight
Third-Party Risk Management: A Case Study in Oversight
 
Enterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and PerformanceEnterprise Risk Management - Aligning Risk with Strategy and Performance
Enterprise Risk Management - Aligning Risk with Strategy and Performance
 
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
 
Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...
 
Risk assessment presentation
Risk assessment presentationRisk assessment presentation
Risk assessment presentation
 
Cybersecurity Risk Management Program and Your Organization
Cybersecurity Risk Management Program and Your OrganizationCybersecurity Risk Management Program and Your Organization
Cybersecurity Risk Management Program and Your Organization
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Risk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation SlidesRisk Management Process And Procedures PowerPoint Presentation Slides
Risk Management Process And Procedures PowerPoint Presentation Slides
 
GRC Fundamentals
GRC FundamentalsGRC Fundamentals
GRC Fundamentals
 
Risk Management
Risk ManagementRisk Management
Risk Management
 

En vedette

Petronas Project Oversight and Corporate Governance System Requirements
Petronas Project Oversight and Corporate Governance System RequirementsPetronas Project Oversight and Corporate Governance System Requirements
Petronas Project Oversight and Corporate Governance System Requirements
Darren Surin, BSc, MBA, PMP, ITIL
 
Case Study on Risk management in M&A_Anuj Kamble_Veronica Barreda
Case Study on Risk management in M&A_Anuj Kamble_Veronica BarredaCase Study on Risk management in M&A_Anuj Kamble_Veronica Barreda
Case Study on Risk management in M&A_Anuj Kamble_Veronica Barreda
Anuj Kamble
 
GRC15620_Report_-_Third_party_risk_exposing_the_gaps
GRC15620_Report_-_Third_party_risk_exposing_the_gapsGRC15620_Report_-_Third_party_risk_exposing_the_gaps
GRC15620_Report_-_Third_party_risk_exposing_the_gaps
Kate Tomlinson
 
9-22-11 Anti-Bribery and Corruption Prevention
9-22-11 Anti-Bribery and Corruption Prevention9-22-11 Anti-Bribery and Corruption Prevention
9-22-11 Anti-Bribery and Corruption Prevention
Kendal Peterson
 
Singapore Training - Copy
Singapore Training  - CopySingapore Training  - Copy
Singapore Training - Copy
Ahmed HAMDY
 
Top 10 Mega Trends- to understand the China Landscape
Top 10 Mega Trends- to understand the China LandscapeTop 10 Mega Trends- to understand the China Landscape
Top 10 Mega Trends- to understand the China Landscape
Dr Neale O'Connor, CPA (Aust)
 

En vedette (11)

Project Management Office (PMO)
Project Management Office (PMO)Project Management Office (PMO)
Project Management Office (PMO)
 
Third Party Risk Management Introduction
Third Party Risk Management IntroductionThird Party Risk Management Introduction
Third Party Risk Management Introduction
 
Petronas Project Oversight and Corporate Governance System Requirements
Petronas Project Oversight and Corporate Governance System RequirementsPetronas Project Oversight and Corporate Governance System Requirements
Petronas Project Oversight and Corporate Governance System Requirements
 
Case Study on Risk management in M&A_Anuj Kamble_Veronica Barreda
Case Study on Risk management in M&A_Anuj Kamble_Veronica BarredaCase Study on Risk management in M&A_Anuj Kamble_Veronica Barreda
Case Study on Risk management in M&A_Anuj Kamble_Veronica Barreda
 
viaLegal Webinar_ FCPA Training for a Global Workforce
viaLegal Webinar_ FCPA Training for a Global WorkforceviaLegal Webinar_ FCPA Training for a Global Workforce
viaLegal Webinar_ FCPA Training for a Global Workforce
 
GRC15620_Report_-_Third_party_risk_exposing_the_gaps
GRC15620_Report_-_Third_party_risk_exposing_the_gapsGRC15620_Report_-_Third_party_risk_exposing_the_gaps
GRC15620_Report_-_Third_party_risk_exposing_the_gaps
 
9-22-11 Anti-Bribery and Corruption Prevention
9-22-11 Anti-Bribery and Corruption Prevention9-22-11 Anti-Bribery and Corruption Prevention
9-22-11 Anti-Bribery and Corruption Prevention
 
Singapore Training - Copy
Singapore Training  - CopySingapore Training  - Copy
Singapore Training - Copy
 
Clifton Gunderson IT Oversight
Clifton Gunderson IT OversightClifton Gunderson IT Oversight
Clifton Gunderson IT Oversight
 
Top 10 Mega Trends- to understand the China Landscape
Top 10 Mega Trends- to understand the China LandscapeTop 10 Mega Trends- to understand the China Landscape
Top 10 Mega Trends- to understand the China Landscape
 
Singapore company compliance
Singapore company complianceSingapore company compliance
Singapore company compliance
 

Similaire à Third-Party Risk Management: Implementing a Strategy

Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
Nidhi Gupta
 
Weaver - Financial Institutions Consulting
Weaver - Financial Institutions ConsultingWeaver - Financial Institutions Consulting
Weaver - Financial Institutions Consulting
Andrew Topa
 
Applying risk management_to_your_business_continuity_management_efforts
Applying risk management_to_your_business_continuity_management_effortsApplying risk management_to_your_business_continuity_management_efforts
Applying risk management_to_your_business_continuity_management_efforts
Subhajit Bhuiya
 
Deloitte Risk Consulting Flyer - Lapman Lee Netherlands Lead
Deloitte Risk Consulting Flyer - Lapman Lee  Netherlands LeadDeloitte Risk Consulting Flyer - Lapman Lee  Netherlands Lead
Deloitte Risk Consulting Flyer - Lapman Lee Netherlands Lead
Lapman Lee ✔
 
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
Egyptian Engineers Association
 

Similaire à Third-Party Risk Management: Implementing a Strategy (20)

Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Erm talking points
Erm talking pointsErm talking points
Erm talking points
 
Enterprise governance risk_compliance_fcm slides
Enterprise governance risk_compliance_fcm slidesEnterprise governance risk_compliance_fcm slides
Enterprise governance risk_compliance_fcm slides
 
Risk, Fraud Management and Current Issues and Challenges for Digital Financia...
Risk, Fraud Management and Current Issues and Challenges for Digital Financia...Risk, Fraud Management and Current Issues and Challenges for Digital Financia...
Risk, Fraud Management and Current Issues and Challenges for Digital Financia...
 
It62015 slides
It62015 slidesIt62015 slides
It62015 slides
 
IT Services Development
IT Services DevelopmentIT Services Development
IT Services Development
 
Erm overview of auditing fraud and revenue assurance
Erm   overview of auditing fraud and revenue assuranceErm   overview of auditing fraud and revenue assurance
Erm overview of auditing fraud and revenue assurance
 
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
 
How to Drive Value from Operational Risk Data - Part 2
How to Drive Value from Operational Risk Data - Part 2How to Drive Value from Operational Risk Data - Part 2
How to Drive Value from Operational Risk Data - Part 2
 
Insight into Security Leader Success Part 2
Insight into Security Leader Success Part 2Insight into Security Leader Success Part 2
Insight into Security Leader Success Part 2
 
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
 
Weaver - Financial Institutions Consulting
Weaver - Financial Institutions ConsultingWeaver - Financial Institutions Consulting
Weaver - Financial Institutions Consulting
 
Applying risk management_to_your_business_continuity_management_efforts
Applying risk management_to_your_business_continuity_management_effortsApplying risk management_to_your_business_continuity_management_efforts
Applying risk management_to_your_business_continuity_management_efforts
 
Gaining Greater Control Over Commodity Planning & Procurement for Manufacturers
Gaining Greater Control Over Commodity Planning & Procurement for ManufacturersGaining Greater Control Over Commodity Planning & Procurement for Manufacturers
Gaining Greater Control Over Commodity Planning & Procurement for Manufacturers
 
GP for Risk Management product sheet
GP for Risk Management product sheetGP for Risk Management product sheet
GP for Risk Management product sheet
 
Deloitte Risk Consulting Flyer - Lapman Lee Netherlands Lead
Deloitte Risk Consulting Flyer - Lapman Lee  Netherlands LeadDeloitte Risk Consulting Flyer - Lapman Lee  Netherlands Lead
Deloitte Risk Consulting Flyer - Lapman Lee Netherlands Lead
 
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
138 مبادرة #تواصل_تطوير المحاضرة ال 138 من المبادرة دكتور مهندس / أكرم حسن اس...
 

Plus de NICSA

Plus de NICSA (20)

Understanding ROI: The Real Impact of Data Quality
Understanding ROI: The Real Impact of Data QualityUnderstanding ROI: The Real Impact of Data Quality
Understanding ROI: The Real Impact of Data Quality
 
The Reality Behind Buzzwords Series: Blockchain
The Reality Behind Buzzwords Series: BlockchainThe Reality Behind Buzzwords Series: Blockchain
The Reality Behind Buzzwords Series: Blockchain
 
Industry Leaders Outlook: Product & Marketing Roundtable
Industry Leaders Outlook: Product & Marketing RoundtableIndustry Leaders Outlook: Product & Marketing Roundtable
Industry Leaders Outlook: Product & Marketing Roundtable
 
Understanding Regulation Best Interest
Understanding Regulation Best InterestUnderstanding Regulation Best Interest
Understanding Regulation Best Interest
 
Trends in the Advisor Market
Trends in the Advisor Market Trends in the Advisor Market
Trends in the Advisor Market
 
New Challenges on the TA Compliance Landscape
New Challenges on the TA Compliance LandscapeNew Challenges on the TA Compliance Landscape
New Challenges on the TA Compliance Landscape
 
Navigating Turbulent Changes to the Sanctions Landscape
Navigating Turbulent Changes to the Sanctions LandscapeNavigating Turbulent Changes to the Sanctions Landscape
Navigating Turbulent Changes to the Sanctions Landscape
 
Engaging and Empowering A Diverse Workforce
Engaging and Empowering A Diverse WorkforceEngaging and Empowering A Diverse Workforce
Engaging and Empowering A Diverse Workforce
 
Retirement 2020: Maximize Participation,Boost Efficiency & Accelerate Outcomes
Retirement 2020: Maximize Participation,Boost Efficiency & Accelerate OutcomesRetirement 2020: Maximize Participation,Boost Efficiency & Accelerate Outcomes
Retirement 2020: Maximize Participation,Boost Efficiency & Accelerate Outcomes
 
Building Deeper Advisory Relationships with Data
Building Deeper Advisory Relationships with DataBuilding Deeper Advisory Relationships with Data
Building Deeper Advisory Relationships with Data
 
FinReg Outlook: Clouds on the Horizon
FinReg Outlook: Clouds on the HorizonFinReg Outlook: Clouds on the Horizon
FinReg Outlook: Clouds on the Horizon
 
Preparing for the Next-Gen Client Base
Preparing for the Next-Gen Client BasePreparing for the Next-Gen Client Base
Preparing for the Next-Gen Client Base
 
Tax & Reporting Update: Avoiding Fund Reporting Traps
Tax & Reporting Update: Avoiding Fund Reporting TrapsTax & Reporting Update: Avoiding Fund Reporting Traps
Tax & Reporting Update: Avoiding Fund Reporting Traps
 
Next Generation Proxy Voting
Next Generation Proxy VotingNext Generation Proxy Voting
Next Generation Proxy Voting
 
Best Practices in Building a Global Compliance Program
Best Practices in Building a Global Compliance ProgramBest Practices in Building a Global Compliance Program
Best Practices in Building a Global Compliance Program
 
AI Trends with Traction
AI Trends with TractionAI Trends with Traction
AI Trends with Traction
 
Rule 30e-3: Best Practices for Notice, Access & E-Delivery
Rule 30e-3: Best Practices for Notice, Access & E-DeliveryRule 30e-3: Best Practices for Notice, Access & E-Delivery
Rule 30e-3: Best Practices for Notice, Access & E-Delivery
 
Rethinking Product Development
Rethinking Product DevelopmentRethinking Product Development
Rethinking Product Development
 
The Bottom Line: Exploring the Benefits of Wellness in the Workplace
The Bottom Line: Exploring the Benefits of Wellness in the WorkplaceThe Bottom Line: Exploring the Benefits of Wellness in the Workplace
The Bottom Line: Exploring the Benefits of Wellness in the Workplace
 
Data Analytics 301: Converting Analysis into Business Strategy
Data Analytics 301: Converting Analysis into Business StrategyData Analytics 301: Converting Analysis into Business Strategy
Data Analytics 301: Converting Analysis into Business Strategy
 

Dernier

CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
anilsa9823
 
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
dipikadinghjn ( Why You Choose Us? ) Escorts
 

Dernier (20)

The Economic History of the U.S. Lecture 19.pdf
The Economic History of the U.S. Lecture 19.pdfThe Economic History of the U.S. Lecture 19.pdf
The Economic History of the U.S. Lecture 19.pdf
 
High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur EscortsHigh Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
High Class Call Girls Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
 
(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7
(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7
(Vedika) Low Rate Call Girls in Pune Call Now 8250077686 Pune Escorts 24x7
 
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(ANIKA) Budhwar Peth Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Gomti Nagar Lucknow best sexual service
 
The Economic History of the U.S. Lecture 22.pdf
The Economic History of the U.S. Lecture 22.pdfThe Economic History of the U.S. Lecture 22.pdf
The Economic History of the U.S. Lecture 22.pdf
 
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
 
Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.
 
Independent Call Girl Number in Kurla Mumbai📲 Pooja Nehwal 9892124323 💞 Full ...
Independent Call Girl Number in Kurla Mumbai📲 Pooja Nehwal 9892124323 💞 Full ...Independent Call Girl Number in Kurla Mumbai📲 Pooja Nehwal 9892124323 💞 Full ...
Independent Call Girl Number in Kurla Mumbai📲 Pooja Nehwal 9892124323 💞 Full ...
 
Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaign
 
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
Best VIP Call Girls Noida Sector 18 Call Me: 8448380779
 
The Economic History of the U.S. Lecture 23.pdf
The Economic History of the U.S. Lecture 23.pdfThe Economic History of the U.S. Lecture 23.pdf
The Economic History of the U.S. Lecture 23.pdf
 
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure serviceWhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure service
 
Indore Real Estate Market Trends Report.pdf
Indore Real Estate Market Trends Report.pdfIndore Real Estate Market Trends Report.pdf
Indore Real Estate Market Trends Report.pdf
 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
 
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
VVIP Pune Call Girls Katraj (7001035870) Pune Escorts Nearby with Complete Sa...
 
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
 
The Economic History of the U.S. Lecture 20.pdf
The Economic History of the U.S. Lecture 20.pdfThe Economic History of the U.S. Lecture 20.pdf
The Economic History of the U.S. Lecture 20.pdf
 
Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...
 
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service NashikHigh Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
High Class Call Girls Nashik Maya 7001305949 Independent Escort Service Nashik
 

Third-Party Risk Management: Implementing a Strategy

  • 1. www.nicsa.org Third-Party Risk Management: Implementing a Strategy Part I of II 1 SPONSORED BY:
  • 2. www.nicsa.org The use of third-party service providers has become increasingly pervasive, complex, and interconnected within the investment management industry • Increased number of core operations and IT services being outsourced • Third parties also outsource - common providers can create layering and unforeseen concentration risk • Dispersed dependencies create increased reliance and risk exposure from entities outside of your direct control This growth of the extended enterprise model calls for continued evolution of the Extended Enterprise Risk Management (EERM) strategy, with mature programs applying a consistent, enterprise-wide level of discipline that extends across the entire third-party lifecycle. An evolving landscape : Copyright © 2015 Deloitte Development LLC. All rights reserved.
  • 3. www.nicsa.org  Enhanced quality of risk management processes through centralized execution on the business’ behalf  Transparency into third-party performance and risk exposure by improving information flow through the organization  Improved efficiency through centralized tools and processes  Reduced risks through centralization of controls and quality gates  Increased consistency scale and common communication Strategy & Planning Contract & On-board Evaluate & Select Terminate Off-board Manage & Monitor Third-Party Management Lifecycle Strategy & planning – Develop sourcing strategy, consider cost/benefits and develop business Evaluate & select - Identify and assess risks / perform due diligence Contract & on-board - Incorporate risk, compliance, and performance requirements in contracts Manage & monitor - Perform risk management and ongoing monitoring & coordinating with each third party Terminate & off-board - Determine need to terminate the third party and manage the off-boarding process Some benefits of an EERM Framework Many companies are moving toward an end-to-end framework to create a controlled and efficient process to effectively manage the business and regulatory requirements. A well-designed and sustainable framework can help manage third-party risks and provide structure for governance and monitoring the process. Maintaining control & managing third-party risk : Copyright © 2015 Deloitte Development LLC. All rights reserved.
  • 5. www.nicsa.org Governance and Oversight The organizational structure, committees, and roles and responsibilities for managing third parties EERM Framework Risk Domains Operating Model Components Business Objectives Risk and Compliance Management Growth / Innovation Client Experience Cost Reduction Improved Time to Market Reputation Risk Strategic RiskGeopolitical Risk Contractual Risk Information Security Risk Transaction / Operational Risk Financial Stability Risk Business Continuity Risk Compliance / Legal Risk Credit Risk Plan, Evaluate and Select Contract and On-board Manage and Monitor Terminate and Off-boardManagement Process Detail Our EERM framework—based on the Office of the Comptroller of the Currency (OCC) and other regulatory requirements, as well as industry practices—provides a structured review of the operating model components required to support an effective program.  An effective EERM program supports business objectives including growth, innovation, reduced cost, and risk and compliance.  Delivering effective EERM requires a comprehensive operating model that includes governance and oversight, policies and standards, management processes, tools and technology, risk metrics and reporting, and risk culture.  Management and risk domains support delivery of EERM capabilities and the management of risk. Each domain is comprised of its own set of management activities/capabilities and related risks. Deloitte Advisory’s EERM framework Risk Culture Tone at the top, clarity on risk appetite, appropriate training and awareness. to promote positive risk culture Policies and Standards Management expectations for the management of third parties and related risks Risk Metrics and Dashboard Reports identifying risks and performance associated with third parties, tailored toward multiple levels of management Management Processes Processes to manage risks across the third- party lifecycle Tools and Technology Tools and technology that support EERM processes : Copyright © 2015 Deloitte Development LLC. All rights reserved.
  • 6. www.nicsa.org Stages of EERM Capability Maturity StakeholderValue Integrated Risk Intelligent Top Down FragmentedInitial • Ad hoc/chaotic • Depends primarily on individual heroics, capabilities, and verbal wisdom • Independent EERM activities • Limited focus on the linkage of third-party risks with the company’s overall strategic risks • Limited alignment of risks to strategies • Disparate monitoring & reporting functions • Common framework, program statement, policy • Routine risk assessments • Communication of risks to the key stakeholders • Awareness activities • Dedicated team • Coordinated risk management activities across identified segments • Risk appetite is fully defined • Risk monitoring, measuring, and reporting to the board • Contingency plans and escalation procedures in place • EERM discussion is embedded in the company’s strategic planning, capital allocation, product development, etc. • Risk-sensing, early warning risk indicators used • Risk modeling /scenarios applied • Industry benchmarking used regularly Representative Attributes Describing Each Maturity Level Initial Fragmented Top Down Integrated Risk Intelligent Capability Maturity Stages 1. How capable is the organization today to manage its extended enterprise risks? 2. How capable does it need to be? 3. How can it get to its desired state? By when? 4. How can we leverage existing extended enterprise risk management practices? : Copyright © 2015 Deloitte Development LLC. All rights reserved.
  • 7. www.nicsa.org This presentation contains general information only and Deloitte is not, by means of this presentation, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This presentation is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this presentation. About Deloitte Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. Please see www.deloitte.com/about for a detailed description of DTTL and its member firms. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.
  • 9. www.nicsa.org • Broker approval • CP approval and monitoring • CP exposure reporting • Best Execution reporting • Risk Contribution monitoring and reporting • Scenario analysis Head of Risk Management US • Analytics monitoring and reporting • Performance Attribution • Fund Performance monitoring • GIPS reporting • Peer analysis Global Risk US CEO Operational Risk Broker-Counterparty Risk Performance Analytics & Attribution Investment Risk VENDOR ASSESSMENT TEAM Vendor Relationship Owners Vendor Universe Vendor Governance Office Information Security Business Continuity Operational Risk Finance Compliance incl. Privacy Purchasing Legal Op Risk Management System - Relationship Owner Attestations - Framework Attestations Emerging Risks - Compliance-Risk Oversight - Top Risks • Risk and event identification and assessment • Monitoring and reporting 9
  • 10. www.nicsa.org Vendor Governance Purview Assessment Areas • Business Continuity • Data Integrity and Security • Financial Terms & Stability • Insurance • Internal Controls • Losses / Legal Actions • Regulatory Compliance • Reputation • Service Levels VG Office • Maintain framework • Coordinate Initial Assessment / Take-on • Coordinate Periodic Due Diligence • Raise Concerns • Track Remediation Actions • Report out • Participate in Compliance-Risk Oversight Discussions Vendor Universe * Tier 1 (Core A) • Functionally critical • Financially critical • Subject to laws / regulations • Necessary to legal / regulatory obligations • Central to control functions Tier 2 (Core B) • Failure could cause serious damage • Annual outlay > $500k Tier 3 (Non-core) * Exceptions • Financial distributors • Brokers and Counterparties VENDOR ASSESSMENT TEAM • Op Risk Management System • Vendor Assessment System • SIG Questionnaire (Shared Assessments Group) Vendor Universe Vendor Governance Office 10
  • 11. www.nicsa.org Board Oversight Custodian Fund Accounting Financial Reporting Tax Compliance Transfer Agent SubTAs & Omnibus Providers Sub-Advisors Pricing Services Others For Management Consideration Printing and Mailing 15c Materials Blue Sky Reporting Escheatment Services Proxy Solicitation Services Others 11 Third-Party Oversight Independent Director Viewpoint
  • 13. www.nicsa.org Board Oversight Independent Director Viewpoint Consider Board Committee Structure – Committees: Audit; Compliance; Contracts – Where should oversight reside? – Interdisciplinary approach 13 Frequency of Board Reporting Level of Detail – Dashboards
  • 14. www.nicsa.org Inventory of Third-Party Service Providers Independent Director Viewpoint 14 Name Nature of Services Provided Primary Management oversight: “Business Owner” of Each Relationship Summary of Management’s Oversight Functions Summary of Board Reporting on Each Provider
  • 15. www.nicsa.org High Level “Sub-TA Dashboard” Independent Director Viewpoint 15 For each relationship: AUM Date last visit Risk Rank Review Status SSAE#16 or FICCA Reports

Notes de l'éditeur

  1. 6