Fourth Report On The Implementation Of Sec Organizational Reform Recommendations - U.s. Securities And Exchange Commission - 2013 Page 25

ADVERTISEMENT

F
R
I
SEC O
R
R
OURTH
EPORT ON THE
MPLEMENTATION OF
RGANIZATIONAL
EFORM
ECOMMENDATIONS
• The SEC continued to build the internal ORM capability by hiring senior ORM
leadership and staff to continue operationalizing the program’s vision.
• The SEC established the ORM Oversight Committee to assist the agency in achieving its
strategic and operational objectives by increasing operational risk awareness and
fostering the continued development of a culture that supports enhanced operational risk
identification and management. The Committee’s mission is to monitor the operational
risk environment, including high priority risk areas, and to provide direction and
guidance on risk management systems, processes, structures and procedures.
• The SEC expanded the Management Assurance process to include 100 percent
participation from Divisions and Offices. This process helps to identify, assess, respond
to, control, and monitor risks at the Division and Office levels. An improved agency-
wide framework and structure is under development.
• The SEC updated the Governance Risk and Compliance (GRC) tool first deployed in
fiscal year 2011 (FY11) to enhance cataloging of information about risks, controls,
deficiencies, and corrective action plans. In total, the GRC captured and catalogued more
than 460 operational risks and 812 related controls during FY12. Additional
improvements include the ability to better capture corrective action plans.
These
collective enhancements not only made the GRC a more user-friendly resource, but also
improved the quality of risk and control data across the agency
• Future plans to further operationalize ORM include: (1) improving policies to effectively
manage operational risk; (2) reviewing the risk appetite and tolerances established for
Divisions and Offices; (3) recommending an overall risk appetite for the Commission; (4)
continuing to identify, prioritize, and manage top agency operational risks identified; and
(5) understanding the extent to which the operational risks align with the strategic
initiatives, risk appetite and risk tolerance of the Commission.
Analysis, Design and/or Recommendations in Process
The following workstreams are at various stages of their analysis and/or recommendations.
P
25
AGE

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Legal