Treasury management rose in prominence during the financial crisis. Companies that were best able to manage their cash, investments and portfolios were in much stronger competitive positions than peers who did not implement proper treasury management.
Working with our partner KESDEE, Vast Talent can now offer their thorough (and timely) course on Treasury Management. Its 30 modules give you everything you need to know about how to do this right.
Topics include:
- Interest Rate Risk Management
- Foreign Exchange Management
- Funding and Investments
- How to implement Treasury Management
- Treasury Analytics
...and lots of case studies and interesting background.
Showing posts with label Risk Management. Show all posts
Showing posts with label Risk Management. Show all posts
Thursday, August 13, 2009
How to Manage a Retail Bank
We've just launched a new series of financial training courses on Vast Talent's website, these ones focused on Bank Branch Management.
The online courses have everything you need to know about how to run a retail bank, including sales, marketing, operations, risk management, security, human resources and more. This really is an excellent course for anyone who manages a bank or any banks with large retail presence. The course has 36 detailed modules in twelve topic areas.
Given the pace of expansion at many of China's large banks, the skills required to properly manage retails banks will be very valuable in the coming years.
The online courses have everything you need to know about how to run a retail bank, including sales, marketing, operations, risk management, security, human resources and more. This really is an excellent course for anyone who manages a bank or any banks with large retail presence. The course has 36 detailed modules in twelve topic areas.
Given the pace of expansion at many of China's large banks, the skills required to properly manage retails banks will be very valuable in the coming years.
FRM Exam - only 100 days to go
This year's Financial Risk Manager (FRM) exam, offered by GARP, takes place in just 100 days (on Saturday, November 21st).
So if you haven't started yet, today is the perfect day to start preparing for the FRM exam. Sign up for the test on GARP's website and make a realistic study plan for yourself. The FRM takes many hundreds of hours of study to successfully pass, so pace yourself and make sure you have all the right tools.
As part of your FRM study plan, considering using an online certification course. The diagnostic exams and other interactive features can give your confidence and boost and guide you to success on November 21st.
Good luck with the FRM!
So if you haven't started yet, today is the perfect day to start preparing for the FRM exam. Sign up for the test on GARP's website and make a realistic study plan for yourself. The FRM takes many hundreds of hours of study to successfully pass, so pace yourself and make sure you have all the right tools.
As part of your FRM study plan, considering using an online certification course. The diagnostic exams and other interactive features can give your confidence and boost and guide you to success on November 21st.
Good luck with the FRM!
Tuesday, July 21, 2009
APRIA 2009 Follow up
I promised to post the slides from my presentation to APRIA. I gave the audience a preview of the Basic Standard for Enterprise Internal Control, specifically focusing on how it will impact insurance companies in China.
Had a great questions from the audience - in fact, it's a question that I get almost anytime I talk about China SOX (or Sarbanes Oxley or any similar risk management regulation). The question goes something like this: "If we have all these great risk management systems and regulation in place, why didn't they prevent or foresee the financial crisis?"
I think that's a really great question. When I answer, I usually point out that the problem is not so much with the laws/regulations themselves as what people do with them. The main point is that it's not what these regulations say that's important, it's how they are implemented. You can have the best regulation in the world written by really smart people, but unless they are put in place as intended and adhered to constantly, you are going to have problems.
That's why it's important to think of risk management as a culture change for the company. Risk management awareness has to be instilled throughout the entire company. It's not enough to pay lip service to risk management and not implement it properly.
Obviously, there were also lapses in government oversight (around the world) that caused these problems too. But my main focus is on how companies can get real business benefit from implementing China SOX.
Had a great questions from the audience - in fact, it's a question that I get almost anytime I talk about China SOX (or Sarbanes Oxley or any similar risk management regulation). The question goes something like this: "If we have all these great risk management systems and regulation in place, why didn't they prevent or foresee the financial crisis?"
I think that's a really great question. When I answer, I usually point out that the problem is not so much with the laws/regulations themselves as what people do with them. The main point is that it's not what these regulations say that's important, it's how they are implemented. You can have the best regulation in the world written by really smart people, but unless they are put in place as intended and adhered to constantly, you are going to have problems.
That's why it's important to think of risk management as a culture change for the company. Risk management awareness has to be instilled throughout the entire company. It's not enough to pay lip service to risk management and not implement it properly.
Obviously, there were also lapses in government oversight (around the world) that caused these problems too. But my main focus is on how companies can get real business benefit from implementing China SOX.
Friday, July 17, 2009
Presentation on China SOX at APRIA 2009 Conference
I am going to be speaking next week at the 13th Annual APRIA Conference, hosted by the China Center for Insurance and Social Security Research (CCISSR), at Peking University, Beijing, China. This is a big gathering of insurance industry people from around the world.
I will be presenting in the plenary session titled “The Financial Crisis and the Future of Risk Management” on Tuesday, July 21st. My talk is called “A Preview of New Corporate Governance Regulations in China in Response to the Financial Crisis” and will focus on the operational impact to insurance companies of the Basic Standard for Enterprise Internal Control (C-SOX).
Here are the details:
Who: Alex Raymond, Vast Talent;
What: 2009 APIRA Beijing Annual Conference: “The Financial Crisis and the Future of Risk Management” plenary session;
When: Tuesday, 21 July 20009, from 10:30am to 12:00 pm;
Where: Beijing Friendship Hotel, Beijing, China.
More about the Asia-Pacific Risk and Insurance Association:
Founded in Singapore in 1997, the Asia-Pacific Risk and Insurance Association (APRIA) is a global learned society for all academics, executives, researchers and government leaders with an interest in risk management, insurance, actuarial science and related areas.
After the talk, I will post my slides and pictures (if any) up here.
Click for our press release about the talk at APRIA.
I will be presenting in the plenary session titled “The Financial Crisis and the Future of Risk Management” on Tuesday, July 21st. My talk is called “A Preview of New Corporate Governance Regulations in China in Response to the Financial Crisis” and will focus on the operational impact to insurance companies of the Basic Standard for Enterprise Internal Control (C-SOX).
Here are the details:
Who: Alex Raymond, Vast Talent;
What: 2009 APIRA Beijing Annual Conference: “The Financial Crisis and the Future of Risk Management” plenary session;
When: Tuesday, 21 July 20009, from 10:30am to 12:00 pm;
Where: Beijing Friendship Hotel, Beijing, China.
More about the Asia-Pacific Risk and Insurance Association:
Founded in Singapore in 1997, the Asia-Pacific Risk and Insurance Association (APRIA) is a global learned society for all academics, executives, researchers and government leaders with an interest in risk management, insurance, actuarial science and related areas.
After the talk, I will post my slides and pictures (if any) up here.
Click for our press release about the talk at APRIA.
Monday, July 13, 2009
Only 5.88% of Companies in China Train on Internal Controls!
According to a recent survey by Deloitte China, only 5.88 percent of companies in China train their staff on internal controls. This is a very interesting article which you should definitely look at if you are interested in internal control and risk management in China. It shows that there is lots of activity on internal control related to the Basic Standard for Enterprise Internal Control (C-SOX) but still no clear direction as to where the market is going.
Consider other interesting statistics from the Deloitte survey:
- “88.24% of listed companies have raised their awareness of internal control and risk management”
- “58.82% of the enterprises have established designated departments to implement risk management and internal control”
- “23.53% of them have their focus of internal control progressed from written procedures to practical implementation”
- “Only 17.65% have carried out quality review of their internal control initiatives”
- “58.82% of the enterprises consider that the execution of internal control measures cannot achieve their expected results”
- “52.94% of the enterprises believe that a lack of information system relevant to internal control is one of the major problems to internal control implementation”
My read of this? Lots of companies are trying to take China SOX and internal controls and risk management seriously because they expect it to benefit their business. But they are not yet clear on how to achieve their objectives and what steps to take first.
My suggestion is to start with staff training to raise awareness and create a common language about risk management. Also make sure to prepare an organizational map showing areas of responsibility and who will need more advanced training. Once those are in place, companies can start finding IT systems that meet their internal control needs.
We published a whitepaper last month on how to get started with your C-SOX implementation. Click for more details – it’s free and you don’t have to register.
Consider other interesting statistics from the Deloitte survey:
- “88.24% of listed companies have raised their awareness of internal control and risk management”
- “58.82% of the enterprises have established designated departments to implement risk management and internal control”
- “23.53% of them have their focus of internal control progressed from written procedures to practical implementation”
- “Only 17.65% have carried out quality review of their internal control initiatives”
- “58.82% of the enterprises consider that the execution of internal control measures cannot achieve their expected results”
- “52.94% of the enterprises believe that a lack of information system relevant to internal control is one of the major problems to internal control implementation”
My read of this? Lots of companies are trying to take China SOX and internal controls and risk management seriously because they expect it to benefit their business. But they are not yet clear on how to achieve their objectives and what steps to take first.
My suggestion is to start with staff training to raise awareness and create a common language about risk management. Also make sure to prepare an organizational map showing areas of responsibility and who will need more advanced training. Once those are in place, companies can start finding IT systems that meet their internal control needs.
We published a whitepaper last month on how to get started with your C-SOX implementation. Click for more details – it’s free and you don’t have to register.
Wednesday, July 8, 2009
Risk Management Certifications help with China SOX
Nice to see that PRMIA agrees that certified risk managers (notably with their own certifications, the PRM and APRM) will play an important role in the development and execution of China SOX. In launching their new Chinese language tests the other day, they and their local partners made reference to China SOX as an emerging theme in risk management here.
Click here for the PDF version of their press release: http://www.prmia.org/PRMIA-News/PECC-PRMIA%20Press%20Release.pdf
Of course, the FRM and CFA certifications are also useful tools for anyone tackling the C-SOX challenge. But kudos to PRMIA for claiming the ground first.
Click here for the PDF version of their press release: http://www.prmia.org/PRMIA-News/PECC-PRMIA%20Press%20Release.pdf
Of course, the FRM and CFA certifications are also useful tools for anyone tackling the C-SOX challenge. But kudos to PRMIA for claiming the ground first.
Friday, June 5, 2009
10 Questions to ask Before Starting Your China SOX Compliance Project
China’s Basic Standard for Enterprise Internal Control (C-SOX) is coming into effect soon, and while some of the implementation guidelines have not been specified, the core of the regulation is in place.
The main purpose of C-SOX is to increase the effectiveness of internal controls in listed Chinese companies, thus reducing risks for companies and their stakeholders. Companies must evaluate their internal controls, publish an evaluation report on an annual basis and audit the effectiveness of their internal controls. These are new concepts to many organizations in China, and as a result there is some resistance and confusion to deal with.
Below is a list of ten questions to address before starting your C-SOX implementation process.
1) Do we have an organization map? This document is the backbone of your C-SOX implementation because it shows the roles and responsibilities for the departments and employees. It will be used to assign areas of responsibility and internal control approval levels. If your organization does not have a recent map, work with your human resources department to put one together.
2) Who “owns” C-SOX? The answer should be the CEO and Board of Directors. If top management doesn’t own the C-SOX process, it means that the company is not putting in the right amount of resources needed to make the implementation work. Companies that delegate C-SOX implementation to a specific department risk failure due to lack of support.
3) What is our current risk management framework? An existing risk management framework is a great starting point for C-SOX. It could be based on COSO, ERM or ISO 31000 – the point of departure is less important that the discipline that comes with a risk management process. If you do not have an existing risk management framework, you should hire an outside consultant or expert to help you.
4) How will IT help us? IT will play a key role in your C-SOX process, so it helps to get the IT team involved early. Part of the implementation will be buying new software (in fact, the Basic Standard for Enterprise Internal Control mandates the use of IT systems with in-built controls) and the IT department can help to draft a strategy and execute it.
5) What is our training plan? Your compliance initiative will not succeed if you don’t train your staff. The training plan should include at least the following elements: why internal control is important, key internal controls, company policies and procedures, and who to go to with questions. Use e-learning to get the training out quickly and with maximum consistency.
6) Where is the expertise? If you don’t have experts on internal control and risk management within your company, you should hire externally to jump start your project. There are many specialist consultants who can help you develop and execute your strategy and who will train your staff (this will reduce your costs in the long term).
7) What constitutes success? Make sure the CEO and top management have a shared vision of what C-SOX success looks like. This is a long process and there will be many steps along the way. Your implementation plan should detail key milestones and metrics for your business.
8) How do we evaluate staff performance? Several elements of C-SOX are related to human resources. Managers have to perform self-evaluations against internal control metrics, meaning that department managers will have to disclose information about their goals and objectives, and rate themselves on their performance. Furthermore, the Basic Standard for Enterprise Internal Control requires that compensation of executives be linked to internal control. These are new concepts for many companies, and setting up a performance management process is the best way to implement these requirements.
9) What’s in it for me? Unless managers understand the benefits of C-SOX compliance, they are not likely to want to invest time and money in the process. Make sure you have an education campaign so staff understand where they fit in the process and the benefits to them.
10) What’s next? C-SOX compliance is an on-going process, not a one-time event. There are always next steps and future plans and strategies that need to be implemented. You need a team that is able to implement existing requirements and plan ahead for what comes next.
The Basic Standard for Enterprise Internal Control is a wide-ranging rule which will impact every area of a company’s business. You need to take care to address these fundamental questions before starting your implementation process.
Click for more C-SOX. Chinese version of our China SOX solution.
The main purpose of C-SOX is to increase the effectiveness of internal controls in listed Chinese companies, thus reducing risks for companies and their stakeholders. Companies must evaluate their internal controls, publish an evaluation report on an annual basis and audit the effectiveness of their internal controls. These are new concepts to many organizations in China, and as a result there is some resistance and confusion to deal with.
Below is a list of ten questions to address before starting your C-SOX implementation process.
1) Do we have an organization map? This document is the backbone of your C-SOX implementation because it shows the roles and responsibilities for the departments and employees. It will be used to assign areas of responsibility and internal control approval levels. If your organization does not have a recent map, work with your human resources department to put one together.
2) Who “owns” C-SOX? The answer should be the CEO and Board of Directors. If top management doesn’t own the C-SOX process, it means that the company is not putting in the right amount of resources needed to make the implementation work. Companies that delegate C-SOX implementation to a specific department risk failure due to lack of support.
3) What is our current risk management framework? An existing risk management framework is a great starting point for C-SOX. It could be based on COSO, ERM or ISO 31000 – the point of departure is less important that the discipline that comes with a risk management process. If you do not have an existing risk management framework, you should hire an outside consultant or expert to help you.
4) How will IT help us? IT will play a key role in your C-SOX process, so it helps to get the IT team involved early. Part of the implementation will be buying new software (in fact, the Basic Standard for Enterprise Internal Control mandates the use of IT systems with in-built controls) and the IT department can help to draft a strategy and execute it.
5) What is our training plan? Your compliance initiative will not succeed if you don’t train your staff. The training plan should include at least the following elements: why internal control is important, key internal controls, company policies and procedures, and who to go to with questions. Use e-learning to get the training out quickly and with maximum consistency.
6) Where is the expertise? If you don’t have experts on internal control and risk management within your company, you should hire externally to jump start your project. There are many specialist consultants who can help you develop and execute your strategy and who will train your staff (this will reduce your costs in the long term).
7) What constitutes success? Make sure the CEO and top management have a shared vision of what C-SOX success looks like. This is a long process and there will be many steps along the way. Your implementation plan should detail key milestones and metrics for your business.
8) How do we evaluate staff performance? Several elements of C-SOX are related to human resources. Managers have to perform self-evaluations against internal control metrics, meaning that department managers will have to disclose information about their goals and objectives, and rate themselves on their performance. Furthermore, the Basic Standard for Enterprise Internal Control requires that compensation of executives be linked to internal control. These are new concepts for many companies, and setting up a performance management process is the best way to implement these requirements.
9) What’s in it for me? Unless managers understand the benefits of C-SOX compliance, they are not likely to want to invest time and money in the process. Make sure you have an education campaign so staff understand where they fit in the process and the benefits to them.
10) What’s next? C-SOX compliance is an on-going process, not a one-time event. There are always next steps and future plans and strategies that need to be implemented. You need a team that is able to implement existing requirements and plan ahead for what comes next.
The Basic Standard for Enterprise Internal Control is a wide-ranging rule which will impact every area of a company’s business. You need to take care to address these fundamental questions before starting your implementation process.
Click for more C-SOX. Chinese version of our China SOX solution.
Tuesday, May 12, 2009
FRM vs. PRM?
Since we launched our online courses for PRM and FRM last month, I have been receiving lots of questions about which is the more relevant qualification and which to pursue. In general, both are helpful and both will help you grow in your risk management career.
From my experience in China and Hong Kong, the FRM certification is better known because GARP is a larger organization than PRMIA and has been established in Asia for a longer time. You find lots of professionals with the FRM certification in banks, insurance companies and with the regulators. FRM has a scheduled exam (ever November) which is good because it gives you a date to aim for while you are studying. The FRM Examination is a 5-hour, approximately 140 question multiple-choice examination. The examination is split into two sections of 2.5 hours. The exam is given in booklet form.
PRMIA is making a big push in China at the moment and just set up their office in Beijing. Furthermore, they recently appointed a Chinese partner to run the PRM exams and will translate the exams into Chinese. So they are obviously looking to grow in this market and get access to a whole new generation of risk professionals. The PRM exam can be taken any business day of the year at centers around the world. This is good because it’s convenient but it also means that you can procrastinate if you aren’t disciplined. The complete PRM exam consists of 120 multiple choice questions. Exam questions are randomly drawn, according to the syllabus order and weightings, from the exam database.
PRMIA also offers the Associate PRM (APRM) which is a useful certification if you day-job isn’t in risk management. According to PRMIA, the Associate PRM is designed for staff entering the risk management profession, for those with two or three years risk management experience but need to demonstrate the breadth of their skills, and those who interface with risk management such as auditors, compliance officers, accounting, legal, and risk IT departments. The Associate PRM Exam is computer-based with 90 multiple choice questions.
From my experience in China and Hong Kong, the FRM certification is better known because GARP is a larger organization than PRMIA and has been established in Asia for a longer time. You find lots of professionals with the FRM certification in banks, insurance companies and with the regulators. FRM has a scheduled exam (ever November) which is good because it gives you a date to aim for while you are studying. The FRM Examination is a 5-hour, approximately 140 question multiple-choice examination. The examination is split into two sections of 2.5 hours. The exam is given in booklet form.
PRMIA is making a big push in China at the moment and just set up their office in Beijing. Furthermore, they recently appointed a Chinese partner to run the PRM exams and will translate the exams into Chinese. So they are obviously looking to grow in this market and get access to a whole new generation of risk professionals. The PRM exam can be taken any business day of the year at centers around the world. This is good because it’s convenient but it also means that you can procrastinate if you aren’t disciplined. The complete PRM exam consists of 120 multiple choice questions. Exam questions are randomly drawn, according to the syllabus order and weightings, from the exam database.
PRMIA also offers the Associate PRM (APRM) which is a useful certification if you day-job isn’t in risk management. According to PRMIA, the Associate PRM is designed for staff entering the risk management profession, for those with two or three years risk management experience but need to demonstrate the breadth of their skills, and those who interface with risk management such as auditors, compliance officers, accounting, legal, and risk IT departments. The Associate PRM Exam is computer-based with 90 multiple choice questions.
Lecture Friday at Beida University CCISSR
I am going to be giving a talk this Friday to faculty and students at Beida University’s China Center for Insurance and Social Security Research (CCISSR) titled “Analyzing the Operational Impact of China’s Basic Standard for Enterprise Internal Control.” The audience will mostly be made up of risk management researchers and academics, so I am purposely focusing on the operational elements of corporate governance and internal control improvements.
The main emphasis of the talk is to show that companies can have real business benefits from properly implementing internal control structures and other forms of corporate governance. Examples from the US (from Sarbanes-Oxley experience) show that companies who do this well gain competitive advantages in the marketplace through improved efficiency and that they value of their stock goes up because they are perceived to have better management. These are great lessons to learn for the Chinese companies that are going to be implementing C-SOX later this year and in 2010.
Furthermore, I will outline the key operational challenges related to implementation and show the areas of highest impact for getting started.
p.s. - here's a press release from Beida about the event: http://econ.pku.edu.cn/index_mod2.php?mesid=4378
The main emphasis of the talk is to show that companies can have real business benefits from properly implementing internal control structures and other forms of corporate governance. Examples from the US (from Sarbanes-Oxley experience) show that companies who do this well gain competitive advantages in the marketplace through improved efficiency and that they value of their stock goes up because they are perceived to have better management. These are great lessons to learn for the Chinese companies that are going to be implementing C-SOX later this year and in 2010.
Furthermore, I will outline the key operational challenges related to implementation and show the areas of highest impact for getting started.
p.s. - here's a press release from Beida about the event: http://econ.pku.edu.cn/index_mod2.php?mesid=4378
Tuesday, March 31, 2009
Creating a Culture of Risk Awareness
One of the biggest challenges in implementing C-SOX control effectively is making sure that risk awareness is taken seriously by the entire organization, not just top management or the finance department. This can be especially problematic in organizations that have poor lines of control or do not have the business systems (IT and otherwise) needed to get a clear picture of their operations.
The Basic Standard for Enterprise Internal Control will require a mindset change for many companies in China because they do not currently take a systematic view of operational risk and they may not have the human resources needed to properly implement desired controls. Companies can therefore invest in training and education to increase the level of risk awareness.
This training has several components:
1) Broad training covering topics such as risk management, risk identification, corporate governance, etc.
2) Industry-specific training such as anti-money laundering or fraud awareness, health and safety, or data privacy.
3) Training of specific company policies, processes and procedures related to lines of business.
To effectively create a corporate culture where risks are identified and properly managed, all three types of training have to take place, and management has to be willing to sponsor and fund the training. This means not only holding training classes, but also assessing knowledge and skills of the participants, reinforcing key messages and behaviors and keeping risk as a top priority for the business.
Proper implementation of internal controls is a multi-year process that will require efforts throughout the company. Management teams need to make sure they have all the resources needed to finish the process.
The Basic Standard for Enterprise Internal Control will require a mindset change for many companies in China because they do not currently take a systematic view of operational risk and they may not have the human resources needed to properly implement desired controls. Companies can therefore invest in training and education to increase the level of risk awareness.
This training has several components:
1) Broad training covering topics such as risk management, risk identification, corporate governance, etc.
2) Industry-specific training such as anti-money laundering or fraud awareness, health and safety, or data privacy.
3) Training of specific company policies, processes and procedures related to lines of business.
To effectively create a corporate culture where risks are identified and properly managed, all three types of training have to take place, and management has to be willing to sponsor and fund the training. This means not only holding training classes, but also assessing knowledge and skills of the participants, reinforcing key messages and behaviors and keeping risk as a top priority for the business.
Proper implementation of internal controls is a multi-year process that will require efforts throughout the company. Management teams need to make sure they have all the resources needed to finish the process.
Subscribe to:
Posts (Atom)
