Senior member of FTI Consulting s Bank Governance & Regulation practice Over 20 years of diverse banking, regulatory and consulting experience Focus on risk management, federal regulatory governance, litigation support, capital markets and corporate finance Worked for the Federal Deposit Insurance Corporation (FDIC) Division of

The Office of the Comptroller of the Currency - OCC

Risk appetite is an integral part of the OCC s Enterprise Risk Management framework. Risk appetite articulates the level and type of risk the agency will accept while conducting its mission and carrying out its strategic plan.

Enterprise Risk Management A risk‑intelligent approach

Risk Intelligence (RI) is Deloitte s risk management philosophy that is focused on maintaining the right balance between risk and reward. Simply put, organisations create value by taking risks and lose value by failing to manage them. An effective risk management programme focuses simultaneously on value protection and value creation.


Independent Risk Management (IRM), which oversees risk taking and assesses risks independent of the first line of defense. IRM complements the frontline unit s risk-taking activities through its monitoring and reporting responsibilities, including compliance with the bank s risk appetite. IRM also provides input into key risk decisions.

3 Appendix 2 - Paragraph 3 795-799

Management in HL and LAS Risk identified, in the fourth quarter of 2010 that risk management practices in the Home Loans business did not align fully with BAC s Risk Framework and moved aggressively to staff and build out the processes required by the Framework.

Department of the Treasury Federal Deposit Insurance Corporation

Corrective Action, (3) evaluate the Federal Deposit Insurance Corporation's (FDIC) supervision and monitoring of WaMu as deposit insurer, and (4) assess the FDIC's resolution process for WaMu. The fourth objective will be addressed in a later report after ongoing litigation is completed.


professionals in general: This risk management process-cum-general management discipline has staying power. There is still work to do. Enterprise risk management is a proven way to boost risk management practices and even overall firm value.1 Yet, only a quarter of organizations are using this powerful discipline in a fully integrated way.

More Articles on Enterprise Risk Management Published in The

Enterprise Risk Management Beverly J. Foster, RMA The paths taken by large banks have been chronicled far more than those of smaller ones. The RMA Journal asked risk officers at four banks in the Western U.S. to respond to seven questions about their enterprise risk management efforts. May 2006:Judgment versus Risk Management

FSSCC Cybersecurity Profile: - Midsize Banks-

Part 1: Impact Assessment s Risk Tiers s - Industry-wide scaling achieved through collaboration with NIST, Federal Reserve, OCC, FDIC, SEC, FINRA. - Over 40 firms implementing the Profile or actively exploring implementation for 2019/2020. National or Global Impact Tier 1 Subnational (Regional) Impact Tier 2

The FDIC s Implementation of Enterprise Risk Management

Federal Deposit Insurance Corporation Office of Inspector General Office of Program Audits and Evaluations July 8, 2020 Subject The FDIC s Implementation of Enterprise Risk Management. Federal government leaders manage complex missions that have risks across their organizations. Enterprise Risk Management (ERM) is tool that can assist a

FEDERAL RESERVE SYSTEM - archive.fdic.gov

management, and risk management expectations. This proposed guidance would apply to all Federal Reserve-supervised, FDIC-supervised, and OCC-supervised financial institutions substantively engaged in leveraged lending activities. The number of community banking organizations with substantial exposure to leveraged lending is very small


Bank s capital or earnings. The Enterprise Risk Management program (or ERM) is a formal representation of the Board s risk management efforts. The program s goal is to identify and manage potential risks, both external and internal, that will most likely impact the Bank s ability

views - DHG

Jun 05, 2019 Enterprise Risk Management Program for Your Community Bank: Ten Tips to Get Started Mike Dempsey, Senior Manager DHG Financial Services June 2019 As community banks continue to grow in size and complexity, one important consideration for the future is the implementation of an enterprise risk management (ERM) program.

Frequently Asked Questions - COSO

enterprise risk management, and accommodates expectations for governance and oversight. What documents are being updated? The 2004 Enterprise Risk Management-Integrated Framework: Executive Summary and Framework are both being updated. The Updated Document is titled the Enterprise Risk Management Aligning Risk with Strategy and Performance.

FFIEC Cybersecurity Assessment Tool ver.1.1 to FFIEC IT

enterprise risk management program and identifies, measures, mitigates, and monitors risk. IS.WP.6.3: Determine whether the institution continually assesses the capability of technology needed to sustain an appropriate level of information security based on the size, complexity,

Corporate and Risk Governance - OCC

a bank s BSA/AML compliance program create a presumption that the bank s management component rating will be adversely affected because its risk management practices are less than satisfactory. For purposes of this booklet, the term board refers to the board of directors unless otherwise stated.

GAO-20-519, Accessible Version, BANK SUPERVISION: FDIC Could

FDIC s approach to enterprise risk management (ERM). We assessed these documents against Office of Management and Budget (OMB) guidance on risk management and federal internal control standards. To address all three objectives, we interviewed officials from the Division of Risk Management Supervision (RMS) the FDIC unit responsible for


ENTERPRISE RISK MANAGEMENT Selected Agencies Experiences Illustrate Good Practices in Managing Risk What GAO Found Enterprise Risk Management (ERM) is a forward-looking management approach that allows agencies to assess threats and opportunities that could affect the achievement of its goals.

10 Steps to Enterprise Risk Management White Paper Fiserv

assessing risk across the enterprise. Risk management is a hot topic in today s banking industry with the OCC, FDIC and other regulators issuing specific guidance for bank directors on risk management. Enterprise risk management (ERM) is often touted as the most effective management approach. While most financial institutions

O˜ce of Inspector General - Oversight.gov

aspects of the FDIC s shared-loss agreements, risk management enforcement actions, appraisals, loan work-outs, and private capital investments. With respect to investigative work, as a result of cooperative efforts with U.S. Attorneys throughout the country, numerous individuals were pros-ecuted for financial institution fraud, and we also

Information technology risk management for financial institutions

On June 30, 2005, the Federal Deposit Insurance Corporation (FDIC) implemented a new Information Technology Risk Management Program (IT-RMP) for conducting IT examinations of FDIC-supervised financial institutions. IT-RMP examination procedures apply to all FDIC-supervised banks, regardless of size, technical complexity or prior examination rating.

FDICIA Reporting for Financial Institutions

management and the effectiveness of the board s audit committee in its high-level oversight of financial reporting. 2 RISK ASSESSMENT Understanding the processes, data points, and judgements that feed into the company s financial reports and their associated risks is essential. A process

Current State of Enterprise Risk Management Practices in the

2010). Consequently, without good corporate governance, risk management cannot be successfully carried out. As well, with a good risk management, the corporate governance could be beefed up. The board of directors has a critical role to play in the implementation of risk management practices (Daud, Haron& Ibrahim, 2011).

Management - FFIEC

the institution has a formal risk management function, risk management staff should participate in an advisory capacity. The steering committee typically is responsible for reporting to the board on the status of IT activities. The reports enable the board to make decisions without having to be involved in routine activities.

Risk Management for a Small Business - SBA

Risk Management for a Small Business Participant Guide Money Smart for a Small Business Curriculum Page 6 of 23 Risk Management Risk management applies to many aspects of a business. Your business is subject to internal risks (weaknesses) and external risks (threats). Generally, you can control internal risks once you identify them.


The Federal Deposit Insurance Corporation ( FDIC ) is the appropriate Federal banking agency for Pan American Bank, Los Angeles, California ( Bank ) under Section 3(q) of the Federal Deposit Insurance Act ( FDI Act ), 12 U.S.C. § 1813(q)(3). The California Department


a bank s financial condition, a bank s model risk management framework should be more extensive and rigorous. Model risk management begins with robust model development, implementation, and use. Another essential element is a sound model validation process. A third element is governance, which sets an

Evaluation of the Division of Enterprise Regulation s 2013

level of risk(s), steps to assess risk management, and steps to complete testing and analysis of Enterprise information, data, documents, and other materials. Analysis Memorandum Documents the analysis, conclusions, and findings of the targeted examination. Conclusion Letter Communicates to the Enterprise the final conclusions of

FDIC Office of Inspector General Semiannual Report to the

the FDIC s Readiness for Crises; its Implementation of Enterprise Risk Management; its Regional Automated Document Distribution and Imaging System; the causes of the failure of Enloe State Bank and the FDIC s supervision of this bank; and Preventing and Addressing Sexual Harassment. We made a total of 44 recommendations for


Enterprise Risk Management: Regulators may expect a formalized function to exist shortly after crossing the $1 billion threshold. 5 FDIC Rules & Regulations § 363.2 (b)(3)(i) 6 FDIC Rules & Regulations § 363.2 (b)(3)(ii-iii) 7 FDIC Rules & Regulations § 363.3 (b) 8. FDIC Rules & Regulations § 363.5 (a)(1)

Developing A Marketing Plan Fdic

ALLY FINANCIAL INC. - Federal Reserve

AFI s Enterprise Risk Management program ( ERM Program ). Appendix IV summarizes the components of the risk management program for the Mortgage Servicing Companies ( Mortgage Risk Program ), whereas Appendix V references a framework for common allocation of roles and responsibilities relative to risk management.

Cyber Risk Metrics Survey, Assessment and Implementation Plan

FRB, OCC, & FDIC. (2016, October). Enhanced Cyber Risk Management Standards (FRB Docket No. R-1550; RIN 7100-AE 61; Docket ID OCC-2016-0016; FDIC RIN 3064-AE45). BMO & CIBC. (2017, January). Enhanced Cyber Risk Management Standards: Joint Response from Bank of Montreal (BMO) and Canadian Imperial Bank of Commerce (CIBC). Retrieved from

Senior Advisor Program - Deloitte

legal and regulatory advice across its U.S. intermediary holding company, FDIC-insured depository subsidiary, U.S. branches of UBS AG, and other entities. Rich served as a member of the UBS Americas Enterprise Risk Management Committee, was a liaison to the U.S. federal banking agencies, and was responsible for UBS Americas corporate governance.

2019 FDIC Annual Report

The FDIC s enterprise risk management and internal control program considers the potential for fraud and incorporates elements of Principle 8 Assess Fraud Risk from the GAO Standards of Internal Control in the Federal Government. The FDIC implemented a Fraud Risk Assessment Framework as a basis for identifying potential

Information Security - Federal Financial Institutions

with the board s risk appetite. 6 Aligns the information security program with the enterprise risk management program and identifies, measures, mitigates, and monitors risk. Because risk mitigation frequently depends on institution-specific factors, this booklet describes

FSSCC Cybersecurity Profile: A NIST-based Cybersecurity

FDIC: That was one of the things, at the FDIC, that we were most interested in is looking at the tiering. SEC: to the extent that we can rationalize and cut down on that duplication, allowing those scarce resources to start driving toward protecting the enterprise, I think we're in a good space.

Financial Institution Letters

enterprise-wide basis? An enterprise-wide risk assessment using skills and knowledge from across the enterprise, from technical staff to management, should be conducted. Institutions may supplement their own knowledge with outside expertise. Less complex institutions may require fewer resources. 4. Is the risk assessment part of a formal risk

Regulatory Change Management - FIS

MANAGEMENT 3 KEY TAKEAWAYS 5 IMPLEMENTATION STRATEGIES AND Enterprise Risk FDIC Guidance on Sound Incentive Compensation Policies