Response

profileRak1993
NeedResponse.docx

COMMITTEE STRUCTURE TO ADMINISTER ITS ERM 5

"UW adopted a committee structure to administer its ERM. Would such a structure work in private industry, or is a Chief Risk Officer required?"

 

The University of Washington (UW) had to implement a robust enterprise risk management (ERM) program after settling a Medicare and Medicaid overbilling investigation. The University had to adopt a committee structure to administer its ERM after paying the largest fine for compliance failure. The new president had to formally charge senior administrators with the task of identifying best practices for managing regulatory affairs at the institutional level by using efficient and effective management techniques (Fraser, 2015). The objective of the University was to create an excellent compliance model built on best practices while protecting its decentralized, collaborative, and entrepreneur culture. The ERM process at UW has been a journey of discovery through development and evolvement from the compliance phase to a mega-risk phase (Fraser, 2015).

The University is currently focusing on two objectives by strengthening oversight top risks and enhancing coordination and integration of ERM activities with decision-making processes at the University. The administering of the ERM by the committee structure at UW would be different but similar in the private industry. Every organization adopts an enterprise risk management program that is in direct coordination with the organization's infrastructure. An ERM program of one organization might not necessarily work for another private industry. The University of Washington can use the ERM program of another organization as a guideline in drafting their ERM program. Every organization needs a Chief Risk Officer to assess and mitigate risks that can negatively affect the organization (Fraser, 2015).

The Chief Risk Officer (CRO) is corporate executives responsible for assessing and mitigating significant competitive, regulatory, and technological threats to an organization's financial earnings.  Organizations have been concerned with business risks that threaten their productivity and profitability (Rouse, 2020). The Chief Risk Officers does not only focuses on risk mitigation but also deal with IT security, insurance, financial auditing, fraud prevention, and other internal corporate investigations. The University of Washington needs the CRO to implement operational risk management and mitigation processes to avoid losses from inadequate or failed procedures. Operational risk management includes business continuity and disaster recovery planning (Rouse, 2020).

The responsibilities of the Chief Risk Officers vary depending on the size of the industry. As information technology becomes integral to business processes, the associated risk from data breaches has increased the responsibilities of the CRO (Muse, 2015). The strategies of information protection and risk assurance effort can become a crucial part of the CRO's job. There is a growing interest in the discipline of enterprise risk management within the industry, and the ERM surveys show that about 37 percent of nonprofit organizations have some sort of ERM program in place (Muse, 2015). The result is even higher for organizations with over $100 million in annual revenues, with 62 percent has a formalized program. Organizations can implement ERM in different ways by adopting a formal ERM framework to enhance consistency and provides tangible benefits. The private industry can adopt two popular ERM frameworks such as the COSO ERM – Integrated Framework and ISO 31000 in their infrastructure (Muse, 2015).

 

References

 

Fraser, B. J. (2015).   Implementing Enterprise Risk Management. Case Studies and Best Practices,   KOLB SERIES IN FINANCE, Essential Perspectives, 155-178.

Muse. (2015). Adopting   a new enterprise risk management program. Retrieved from   https://rsmus.com/our-insights/newsletters/muse/adopting-a-new-enterprise-risk-management-program.html.

Rouse, M. (2020). chief   risk officer (CRO) . Retrieved from   https://searchcompliance.techtarget.com/definition/Chief-risk-officer-CRO.