When developing Key Risk Indicators, or KRIs, knowledge of the organization and its operations—plus knowledge of its potential risks, threats, and vulnerabilities—are the essential starting points. Without an understanding of the organization, it is difficult to identify where it may be at risk. This course provides an internal and external view of Key Risk Indicators and how to map them to critical operational aspects of the organization to identify how those key attributes could be disrupted and effectively managed to ensure sustainable growth.
Course Methodology
This course is highly interactive, with participants engaged in identifying risks, threats, and vulnerabilities the organization faces and developing action plans to improve a firm's ability to mitigate such events. Participants will rank the business attributes based on how important they are to the organization and the risks based on how much damage they could do. They will then link them, as well as the metrics and review processes, using relevant exercises, tools, templates, and case studies.
Course Objectives
By the end of the course, participants will be able to:
Explain key components of effective KRI capability and how to integrate them into the overall Enterprise Risk Management framework
Identify and design an effective and robust set of relevant KRIs, and rank them based on their criticality to the business
Develop strong KRIs with efficient processes related to data collection, recording, and reporting
Set appropriate thresholds to reflect risk appetite/tolerance, and report them in a meaningful way
Develop critical skills to carry out KRI identification workshops with management teams
Target Audience
This course is ideal for operational risk managers, risk analysts or officers, risk modeling experts, risk appetite and culture advocates, risk reporting officers, internal auditors, and compliance officers.
Target Competencies
Identification of Key Risk Indicators
Risk management
Risk analysis
Risk compliance
Risk avoidance
Risk management
Risk reporting
Business process analysis
Risk assessment and quantification
Business understanding
Course Outline
KRIs as Part of an ERM Framework
Revisiting risks and controls — what are we “indicating”?
The risk bow tie: Causes, events, and impacts
A risk framework – where do KRIs fit?
The KRI framework
KRI roles and responsibilities
Case study: Developing a risk bow tie
Defining and Identifying KRIs
What is a KRI? Comparing KRIs, KCIs , and KPIs
Defining the objectives of KRIs
What are we trying to track?
Identifying KRIs
Identifying key risks: How?
Mapping key risks to identify “red flags” and “symptoms”
Identifying KRIs around the key risks
Criteria to assess the quality of KRIs
KRIs to track ERM performance
Types of KRIs
Single KRIs
Composite KRIs
Qualitative KRIs
Generic and specific KRIs
Leading and lagging KRIs
Case Study: Identifying KRIs
The KRI Library and Assessing the Quality of a KRI
Purpose of a KRI library
Maintaining and improving the library
Using the library
Assessing the quality of KRIs
Strength of relationship to what is being tracked
The importance of risk velocity
Leading or lagging
Ease of collection
Setting Up KRIs and the KRI Process
Linking KRIs to risk and controls
Setting KRI thresholds
Determining collection and reporting frequency
Assigning responsibility
Case study: Setting up KRIs
The KRI process
Collecting KRIs
Evaluating and scoring KRIs
Investigating and explaining KRIs
Escalation, follow up, and workflow
Case Study: Conducting a KRI collection procedure
Reporting and Using KRIs
Types of reports: Aggregated dashboards and drill down reports
Using KRIs in an overall risk profile
As a risk monitoring tool
As a feedback and incentive tool
As a management tool
As an input into the risk quantification and capital modeling
As a benchmarking tool
KRIs in an integrated risk management process
Linking KRIs to risk and controls self-assessment, compliance, incident management, and action tracking