Discussions

profileravitej01
C.Response2.odt

The University of Washington (UW) had to implement a robust enterprise risk management (ERM) program after settling a Medicare and Medicaid overbilling investigation. The University had to adopt a committee structure to administer its ERM after paying the largest fine for compliance failure. The new president had to formally charge senior administrators with the task of identifying best practices for managing regulatory affairs at the institutional level by using efficient and effective management techniques (Fraser, 2015). The objective of the University was to create an excellent compliance model built on best practices while protecting its decentralized, collaborative, and entrepreneur culture. The ERM process at UW has been a journey of discovery through development and evolvement from the compliance phase to a mega-risk phase (Fraser, 2015).

The University is currently focusing on two objectives by strengthening oversight top risks and enhancing coordination and integration of ERM activities with decision-making processes at the University. The administering of the ERM by the committee structure at UW would be different but similar in the private industry. Every organization adopts an enterprise risk management program that is in direct coordination with the organization's infrastructure. An ERM program of one organization might not necessarily work for another private industry. The University of Washington can use the ERM program of another organization as a guideline in drafting their ERM program. Every organization needs a Chief Risk Officer to assess and mitigate risks that can negatively affect the organization (Fraser, 2015).

The Chief Risk Officer (CRO) is corporate executives responsible for assessing and mitigating significant competitive, regulatory, and technological threats to an organization's financial earnings. Organizations have been concerned with business risks that threaten their productivity and profitability (Rouse, 2020). The Chief Risk Officers does not only focuses on risk mitigation but also deal with IT security, insurance, financial auditing, fraud prevention, and other internal corporate investigations. The University of Washington needs the CRO to implement operational risk management and mitigation processes to avoid losses from inadequate or failed procedures. Operational risk management includes business continuity and disaster recovery planning (Rouse, 2020).

The responsibilities of the Chief Risk Officers vary depending on the size of the industry. As information technology becomes integral to business processes, the associated risk from data breaches has increased the responsibilities of the CRO (Muse, 2015). The strategies of information protection and risk assurance effort can become a crucial part of the CRO's job. There is a growing interest in the discipline of enterprise risk management within the industry, and the ERM surveys show that about 37 percent of nonprofit organizations have some sort of ERM program in place (Muse, 2015). The result is even higher for organizations with over $100 million in annual revenues, with 62 percent has a formalized program. Organizations can implement ERM in different ways by adopting a formal ERM framework to enhance consistency and provides tangible benefits. The private industry can adopt two popular ERM frameworks such as the COSO ERM – Integrated Framework and ISO 31000 in their infrastructure (Muse, 2015).

1.Evaluate one pro and con above proposed description.

Response Requirements:

1. Be 2 paragraphs in length

2.Be supported by the required textbook and one additional reference

Points deducted if the submission: 

Does not use the required textbook as one of the two reference sources 

    • You CANNOT use Wikipedia, LinkedIn articles, blogs, paid vendors, certification websites, or similar sources in academic writing. You CAN use reputable industry articles from publications similar to ComputerWeekly, PCMag, Wall Street Journal, New York Times, or similar sources. Academic journals and popular industry articles are accessible in the university’s library databases and Google Scholar. All references should not have a publication date older than 2005.

  • Does not respond to the question(s) thoroughly meaning with more than 2 paragraphs

  • Primarily consists of bullet points

  • Uses statements such as “I have gone through your post,” “I have gone through your discussion,” “adding a few more points,” “based on my knowledge,” “according to me,” “as per my knowledge,” or similar

  • Contains contractual phrases, as an example “shouldn't" "couldn't" or "didn't,” or similar

  • Uses vague words or phrases such as "proper," "appropriate," "adequate," “it is obvious,” “it is clear,” “in fact,” or similar to describe a process, function, or procedure

      • As an example, "proper incident response plan," "appropriate IT professional," "adequate security," or similar. These words are subjective because they have different meanings to different individuals.