{"id":17959,"date":"2020-04-03T14:15:52","date_gmt":"2020-04-03T18:15:52","guid":{"rendered":"https:\/\/www.insurance-canada.ca\/?p=65809"},"modified":"2020-04-03T14:15:52","modified_gmt":"2020-04-03T18:15:52","slug":"coronavirus-exposes-outdated-risk-management-practices-gartner","status":"publish","type":"post","link":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/2020\/04\/03\/coronavirus-exposes-outdated-risk-management-practices-gartner\/","title":{"rendered":"Coronavirus Exposes Outdated Risk Management Practices: Gartner"},"content":{"rendered":"<h3>Dynamic risk governance is significantly more effective than traditional approaches<\/h3>\n<p>Stamford, CT (Mar. 26, 2020) \u2013 Organizations\u2019 current approach to risk governance is not sufficient to tackle the complex risk environment organizations are facing today, according to Gartner, Inc. The COVID-19 pandemic is just the latest in a line of recent risk events showing how organizations are not properly set up to manage risk, especially fast-moving ones.<\/p>\n<p>Gartner research showed that 87% of audit departments say their organization uses a \u201dthree lines of defense\u201d (3LOD) model for risk governance. This model states that line management should act as the first line of defense, identifying risks and implementing controls. Risk and assurance functions such as legal, compliance and enterprise risk management (ERM) should act as a second line, overseeing and monitoring risk management processes. Finally, internal audit should act as a third line, taking a birds\u2019 eye view of the effectiveness of controls and risk management.<\/p>\n<p>\u201cThe response to the coronavirus pandemic is a perfect example of when the 3LOD and traditional risk governance don\u2019t work very well,\u201d said Malcolm Murray, vice president and fellow, research for the Gartner Audit and Risk practice. \u201cTraditional approaches fail because they can\u2019t effectively deal with fast-moving and interconnected risks. Pandemic is a rapidly developing type of risk that needs a dynamic risk governnance (DRG) set-up.\u201d<\/p>\n<p>\u201cThe coronavirus pandemic demonstrates why organizations need a new approach for governing the management of the many complex risks they face in today\u2019s world,\u201d said Mr. Murray. \u201cAdopting the DRG principles helps organizations ensure they have the appropriate governance for different kinds of risks, with the right kind of risk management activities and the right people involved.\u201d<\/p>\n<h4><strong>Dynamic Risk Governance<\/strong><\/h4>\n<p>The effectiveness of DRG was measured in a Gartner survey to over 200 organizations, looking at whether traditional or dynamic approaches to governing risk management led to better risk management behaviors and better risk outcomes. The three pillars of DRG each increased the occurrence of high-quality risk management behaviors:<\/p>\n<ul>\n<li><strong>Risk-tailored governance (18% increase)<\/strong> \u2013 The governance model should depend on the risk\u2019s speed, the organization\u2019s risk tolerance and internal constraints rather than relying on a one-size-fits-all level of scrutiny, such as centralized oversight for all risks or models based on industry norms. Corporate leaders should have the final say here, because the governance model should be determined based on the company strategy. A benefit of placing this authority with senior management rather with than the board and the assurance functions is more rapid response. These top executives can take faster action.<\/li>\n<li><strong>Activity-based risk governance (22% increase)<\/strong> \u2013 This means dispensing with the idea that only the first line owns all risk activities, and assigns accountability for risk management tasks without regard for the borders between first\/second\/third line. Senior management \u2013 not assurance functions \u2013 should determine who will decide the task owners for a particular risk. For some risks, it will not matter which exact function is accountable for each activity \u2013 as long as there is specific accountability assigned.<\/li>\n<li><strong>Digital-first risk governance (18% increase)<\/strong> \u2013 This means considering digital solutions during creation of the governance framework for the risk, not as an afterthought. For instance, if large parts of the risk management can be automated, then fewer functions need to be involved.<\/li>\n<\/ul>\n<p>When looking at the risks related to the coronavirus pandemic specifically, adopting the DRG principles is beneficial at all three stages of dealing with the risk \u2013 response, recovery and restoration. For the first stage, adopting DRG means quickly identifying who in senior management should own the governance of the risk and quickly setting up an initial governance model that considers the fast speed of the risk. It means identifying the key risk management activities for this stage of the risk and assigning clear accountability for these to appropriate parties.<\/p>\n<p>In subsequent stages, when attention shifts towards recovery and restoration, applying the DRG principles allows organizations to regularly revisit whether the risk is governed in the right way. Once there is more visibility to the path of the risk, additional risk management activities can be added, such as adding a focus on monitoring the risk and assessing longer-term impact.<\/p>\n<p>\u201cThis isn\u2019t just about risk managers, this is about the board of directors and senior management making risk governance a key consideration so that organizations become more resilient against fast-emerging risks, such as coronavirus,\u201d said Mr. Murray. \u201cThe DRG methodology applies equally to the many fast-emerging risks presented by digitalization.\u201d<\/p>\n<p>Gartner clients can access the full research at <a href=\"https:\/\/www.cebglobal.com\/member\/audit\/research\/issue-explorer\/20\/dynamic-risk-governance-is-the-new-risk-mandate.html?referrerTitle=What%E2%80%99s%20New&amp;referrerContentType=browsepage&amp;referrerURL=https%3A%2F%2Fwww.cebglobal.com%2Fmember%2Faudit%2Fwhats-new.html&amp;referrerComponentName=Browse&amp;pageRequestId=7872151d-6119-441a-a5f7-1b081001a619&amp;totalCount=196&amp;currentIndex=5\">Dynamic Risk Governance Is the New Risk Mandate<\/a> and find more information and download various related resources at Gartner\u2019s <a href=\"https:\/\/www.cebglobal.com\/member\/audit\/home.html\">Audit Leadership Council<\/a> home page.<\/p>\n<p>Nonclients can find a collection of coronavirus resources at the <a href=\"https:\/\/www.gartner.com\/en\/insights\/coronavirus\">Coronavirus Resource Center<\/a>.<\/p>\n<h4 class=\"smallhead\"><b>About the Gartner Audit Leadership Council<\/b><\/h4>\n<p>The Gartner Audit Leadership Council helps internal audit leaders and their teams build audit plans that drive results, strengthen department skills and technology capabilities, and minimize exposure to risk. Learn more at <a href=\"https:\/\/www.gartner.com\/en\/audit-risk\/role\/audit-leaders\">gartner.com\/en\/risk-audit\/audit-leaders<\/a>.<\/p>\n<h4 class=\"smallhead\"><b>About Gartner<\/b><\/h4>\n<p>Gartner, Inc. <em>(NYSE: IT)<\/em>, is the world\u2019s leading research and advisory company and a member of the S&amp;P 500. We equip business leaders with indispensable insights, advice and tools to achieve their mission-critical priorities today and build the successful organizations of tomorrow.<\/p>\n<p>Our unmatched combination of expert-led, practitioner-sourced and data-driven research steers clients toward the right decisions on the issues that matter most. We are a trusted advisor and an objective resource for more than 15,000 enterprises in more than 100 countries \u2014 across all major functions, in every industry and enterprise size.<\/p>\n<p>To learn more about how we help decision makers fuel the future of business, visit <a href=\"https:\/\/www.gartner.com\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">www.gartner.com<\/a>.<\/p>\n<p class=\"referencetext\"><i>Source: Gartner<\/i><\/p>\n<p> Tags: <a href=\"https:\/\/www.insurance-canada.ca\/tag\/best-practices\/\" rel=\"tag\">best practices<\/a>, <a href=\"https:\/\/www.insurance-canada.ca\/tag\/coronavirus\/\" rel=\"tag\">coronavirus<\/a>, <a href=\"https:\/\/www.insurance-canada.ca\/tag\/epidemic\/\" rel=\"tag\">epidemic<\/a>, <a href=\"https:\/\/www.insurance-canada.ca\/tag\/gartner\/\" rel=\"tag\">Gartner<\/a><br \/>\n<a href=\"https:\/\/www.insurance-canada.ca\/2020\/04\/03\/gartner-outdated-risk-management-practices-pandemic\/\">Read the original article at Insurance-Canada.ca <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dynamic risk governance is significantly more effective than traditional approaches Stamford, CT (Mar. 26, 2020) \u2013 Organizations\u2019 current approach to risk governance is not sufficient to tackle the complex risk environment organizations are facing&#46;&#46;&#46;<\/p>\n","protected":false},"author":578,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/17959"}],"collection":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/users\/578"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/comments?post=17959"}],"version-history":[{"count":0,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/17959\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/media?parent=17959"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/categories?post=17959"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/tags?post=17959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}