Showing posts with label reputation risk. Show all posts
Showing posts with label reputation risk. Show all posts

Thursday, April 26, 2012

20 Questions Businesses Should Ask About Privacy

Privacy has become a significant business risk to organizations that collect, use, retain and disclose personally identifiable information about customers and employees. As a result, business owners, board members and executive management need to assess whether their handling of personally identifiable information complies with numerous privacy laws and regulations. To provide guidance, the AICPA issued a Business Brief on April 10, 2012 called 20 Questions Businesses Should Ask About Privacy. It was prepared by Nancy Cohen, CPA.CITP, CIPP, CGMA, Senior Technical Manager, AICPA Member Specialization & Credentialing.


The questions contained in that Brief were adapted from the guidance booklet, 20 Questions BusinessesShould Ask About Privacy previously published by the Canadian Institute of Chartered Accountants (CICA). They are key questions a business should ask with the aim of understanding privacy risk, implementing a privacy program, managing privacy risk and obtaining privacy assurance.

Tuesday, February 14, 2012

Sustainability 2.0: Using sustainability to drive business innovation and growth

Sustainability can be a game changer. It can drive innovation by introducing new design constraints that shape how key resources— energy, carbon, water, materials and waste—are used in products and processes. It can also suggest areas where innovation can pay off especially well. These five resources are ubiquitous throughout an organization’s supply chain, and the potential to boost efficiency and cut costs across these resources is significant.

Sustainability-driven innovation goes beyond designing green products and packaging solely on their inherent virtue. It entails improving business operations and processes to become more efficient, with a goal of dramatically reducing costs and waste. It’s also about insulating a business from the risk of resource price shocks and shortages. Taken together these enhancements can deliver business benefits that go far beyond the bottom line—whether it’s improving the overall carbon footprint, enhancing the brand image or engaging employees in a more profound way.

Often, there are significant opportunities for organizations to use sustainability to drive innovation and improve how they do business. A methodical analysis can highlight areas ripe for attention. Taking it a step further, that analysis may yield even greater benefits if it is extended beyond the company’s own walls through collaboration with suppliers, customers and alliance partners. Changes to each link in the supply chain can affect everything upstream and downstream and create financial benefits for everyone involved.

To reach this new frontier, leading organizations are taking a hard look inside their operations and across their supply chains, assessing where they are, prioritizing initiatives, and then formulating a broad sustainability strategy to foster product and process innovation to achieve their goals. They are also adopting metrics that more accurately measure their progress and improve their image in the marketplace. Companies that achieve this vision have the opportunity to enhance revenue and brand value, engage effectively with key stakeholders, manage risks and reduce costs.

To learn more, read the complimentary article reprint “Sustainability 2.0: Using sustainability to drive business innovation and growth” in Deloitte Review, Issue 10, January 2012. The article is also available for reading online.

Thursday, October 27, 2011

Highlights of Corporate Governance Research

Several corporate governance developments have occurred in the wake of the high-profile scandals of the past decade. Some of these developments are motivated by legislation, such as the Sarbanes-Oxley Act of 2002 (SOX). Others are best practices enhancements intended to shore up investor confidence. Academic research has monitored these developments. The article “Highlights of Corporate Governance Research” in the September 2011 issue of the Journal of Accountancy summarizes important academic findings and observations recently published in prominent accounting and finance journals.

This article is part of a series that samples accounting research and distills key findings for busy practitioners and preparers. These summaries explain the implications of a wide range of research and give CPAs the opportunity to apply the results in day-to-day activities. Readers interested in more detail should review the full text of each article to explore the hypothesis, research process, statistical analysis, supporting theories and conclusions.

Tuesday, October 4, 2011

Global Anti-bribery and Corruption Survey 2011


In Canada, managing bribery and corruption risks has not assumed the importance and urgency seen in other jurisdictions. To date, Canada’s Corruption of Foreign Public Officials Act (CFPOA), has received little attention from corporations and enforcement by officials. This is in stark contrast to the situation in the United States where the Foreign Corrupt Practice Act (FCPA) is robustly and strictly enforced.


However, there have been important developments on the Canadian anti-bribery and corruption (AB&C) front. The new reality for Canadian companies is one of increased AB&C enforcement activity, both at home and abroad.

KPMG Forensic commissioned a survey of 214 executives (106 in the US and 108 in the UK) who consider themselves “one of the most senior persons in charge of day-to-day AB&C matters at their company.” The three most significant AB&C compliance challenges cited by both US and UK respondents are auditing third parties for compliance, difficulty in performing effective due diligence on foreign agents/third parties, and variations in country requirements and local laws on issues, such as data privacy and facilitating payments. (Read the Global Anti-bribery and Corruption Survey 2011.)

Tuesday, July 12, 2011

Transocean: No Apologies Over Gulf Oil Spill

"Fourteen months after the Deepwater Horizon drilling rig exploded 50 miles southeast of Venice, La., killing 11 men and setting off the largest offshore oil spill in U.S. history, Transocean (RIG), the company that owned and ran the ill-fated 32,600-ton vessel, finally issued its official account of what happened and why. It produced a report on June 22 of no fewer than 854 pages, divided into two volumes, and spared no detail. The bottom line, though, isn’t complicated:It was BP’s (BP) fault." (Read the full story "Transocean: No Apologies Over Gulf Oil Spill" at Bloomberg Businessweek online.)

Wednesday, June 15, 2011

Data-Centric Security - A CICA White Paper

In most organizations, data that was once static and stored in one place now moves freely from platform to platform throughout the organization and beyond. Because data is now often generated and modified by users and is resident in different forms and versions in different places simultaneously, maintaining a secure environment is a growing challenge. A White Paper issued by the Canadian Institute of Chartered Accountants (CICA) suggests that a data-centric policy should be the focus for management, auditors and others involved in securing data in this new mobile environment. The term “security” is taken in its broadest sense to include confidentiality, integrity (accuracy, completeness and validity) and availability. (Read the CICA publications on Data-Centric Security and

Monday, June 13, 2011

A Framework for Board Oversight of Enterprise Risk

The Risk Oversight and Governance Board of the Canadian Institute of Chartered Accountants (CICA) has developed "A Framework for Board Oversight of Enterprise Risk" to provide a practical approach to risk oversight, including a methodology and tools designed specifically for boards of directors. The framework includes a nine-part process to assist boards in better identifying and addressing critical risk as well as understanding the inter-connectivity of risks.

Monday, April 4, 2011

The whys behind sustainability

Compliance with legal and regulatory requirements is the most frequently cited driver of company sustainability initiatives in Canada, the UK and the US, according to a survey conducted jointly by the Canadian Institute of Chartered Accountants, the Chartered Institute of Management Accountants and the American Institute of Certified Public Accountants. Managing risk to the reputation of the company brand was the next most likely response, followed by achieving competitive advantage and long-term profitability. Read the article “The whys behind sustainability” in CAmagazine online.

Friday, March 18, 2011

Preparing for the Unexpected

Operational risk is an evolving discipline in which many global banks are either currently improving their scenario analysis processes or actively thinking about doing so. This executive summary is the outcome of a study by KPMG in conjunction with the ORX Association, the leading global operational risk data exchange and association in the industry. Visit the KPMG website and read the full report on Preparing for the Unexpected. Also, view KPMG's Financial Services Risk and Regulatory Centers of Excellence video.

Wednesday, March 16, 2011

AICPA/CICA Privacy Maturity Model

The AICPA/CICA Privacy Maturity Model (PMM) is based on Generally Accepted Privacy Principles (GAPP) and the Capability Maturity Model which has been in use for almost 20 years. In developing the PMM, it was recognized that each organization’s personal information privacy practices may be at various levels, whether due to legislative requirements, corporate policies or the status of the organization’s privacy initiatives. It was also recognized that, based on an organization’s approach to risk, not all privacy initiatives would need to reach the highest level on the maturity model. Each of the 73 GAPP criteria is broken down according to the five maturity levels. This allows entities to obtain a picture of their privacy program or initiatives both in terms of their status and, through successive reviews, their progress. (For more information, visit the CICA Privacy Resource Centre online.)

Wednesday, March 9, 2011

Smarter Evidence and Discovery Management

"There is no question that the influence and role of eDiscovery in litigation in Canada continues to develop. While eDiscovery has been a fixture in the US for many years, there has been a slower, pragmatic and perhaps sensible approach to the disclosure of electronic documents in this country. However, as documents are now overwhelmingly formed and maintained primarily in electronic form, it is acknowledged that eDiscovery has arrived in Canada and is here to stay." Visit the KPMG website and read the publication Smarter Evidence and Discovery Management.

Tuesday, February 22, 2011

FINTRAC ANNUAL REPORT 2010 - Ten Years of Connecting the Money to the Crime

During 2010, FINTRAC, as Canada’s financial intelligence unit, celebrated its tenth anniversary. (Refer to the publication FINTRAC ANNUAL REPORT 2010 - Ten Years of Connecting the Money to the Crime.)

FINTRAC made 579 (556 in 2008-09) disclosures of information relevant to investigations of money laundering, terrorist financing, and/or threats to the security of Canada. Turnaround time on cases improved 17%, and requests for assistance went up 36%. By using electronic media for case disclosures, it sharply reduced delivery times, and provided a more flexible product for law enforcement and intelligence partners to work with.

FINTRAC published a new series of strategic intelligence assessments focusing on terrorist groups and countries arousing national security concerns, as well as reports informing partners about current and emerging typologies and trends in money laundering and terrorist financing. It was also the Canadian lead for the FATF typology project about the use of new payment methods for money laundering purposes.

The Office of the Privacy Commissioner (OPC) issued a report praising the Centre's management of personal information, and recommended the appointment of a Chief Privacy Officer. FINTRAC was pleased to implement this and other OPC recommendations.

(See Highlights from FINTRAC's 2010 Annual Report.)

Wednesday, February 16, 2011

Top 10 CSR Research Findings in 2010

The Network for Business Sustainability has prepared a list of the Top 10 CSR Research Findings in 2010 related to Corporate Social Responsibility (CSR). Taken from top management journals, these research insights help senior leaders to kick-start their sustainability planning for 2011. The best research findings related to CSR include: Innovation + Sustainability = Profit; Beat Burnout, Boost Performance; Promote CSR Internally to Engage Staff; Put Product Quality First, CSR Second; Get Buy-In Today for CSR Projects Tomorrow; Prioritize Your CSR Activities; Understand How CSR Drives Performance; Revisit Your Reputation; Do Right by Your Stakeholders; and Use Standardized Metrics for Carbon.

Friday, February 11, 2011

Global Survey Findings on Accounting for Sustainability Practices

The Chartered Institute of Management Accountants (CIMA), the American Institute of Certified Public Accountants (AICPA), and the Canadian Institute of Chartered Accountants (CICA) have published a survey measuring the state of accounting for sustainability in the UK and North America. It shows that compliance with regulatory requirements remains the most common driver of business sustainability (34% of large companies and 24% of small companies). In addition, 32% of large companies said managing reputation risk is a key driver while 19% of small companies identified cost-cutting efficiency. Also, 79% of large companies have a formal sustainability strategy, compared to 33% of small companies. The survey, called Evolution of corporate sustainability practices: Perspectives from the UK, US and Canada,  is available online.

Friday, November 12, 2010

NYSE issues report on core governance principles

The New York Stock Exchange's Commission on Corporate Governance has released a report that identified core governance principles it believed could be widely accepted and supported by issuers, investors, directors and other market participants. The Commission, formed in response to the financial crisis of 2008 and 2009, considered numerous issues, including the proper role and scope of a director's authority, management's responsibility for governance and the relationship between a shareholder's trading activities, voting decisions and governance.

Thursday, November 11, 2010

Novo Nordisk - Awards and Recognitions

Awards and recognitions can be seen as an indicator of stakeholders' perception of a company based on its activities or the quality of its communications. Such accolades contribute to shaping the company's reputation in the public domain and among key opinion-formers and stakeholders. In 2009, Novo Nordisk received a number of honours and awards relating to its performance and its Triple Bottom Line approach to doing business. For examples of the corporate awards, visit the Novo Nordisk website and view the Novo Nordisk Annual Report 2009.

Wednesday, June 9, 2010

Time to prepare a comprehensive risk management plan

For thousands of years, people have been predicting disasters, each more catastrophic than the last. Without resorting to Hollywood-style dramatics, can we really say that major events disrupt business operations? And if so, can we guard against such contingencies? Any organization’s risk management plans should provide answers to those questions. (Read the article "Get ready, now" in the June/July edition of CAmagazine online.)

Monday, June 7, 2010

Global State of Information Security Survey

For many years, information technology and, by extension, information security was among the most likely cost centres to encounter cutbacks in funding when companies fell upon difficult economic times. To find out if this is true, PwC surveyed more than 7,200 CEOs, CFOs, CIOs, CISOs, CSOs and other executives responsible for their organization’s IT and security investments in 130 countries. What are the implications of these trends on how your business is addressing the challenges of the economic downturn? What expectations should you be placing on your information security function at this time? Which areas of focus offer the best opportunities for security to provide concrete business value—not just over the long run but right now, during an unusual economic period? (Read the Global State of Information Security Survey Trial by Fire.)

Wednesday, May 19, 2010

Social Media Best Practices for Business

Social networks and blogs are changing how consumers find places and services, how and where they share their experiences, and eventually, where they will spend their time and money. Without an understanding of, and participation in, social networks, you can miss shaping and contributing to the decision-making process of those who define the success of your business. (Read "Social Media Best Practices for Business" at Open Forum online.)

Tuesday, May 18, 2010

Link Between Decision-Making and ERM: A Case Study

Enterprise Risk Management (ERM) is not a separate, isolated process performed outside of normal business processes. Quite the contrary, ERM, similar to fraud prevention, ethics and internal controls, is integral to an organization’s success. It should be imbedded into and integrated within organizational strategy and incorporated into an organization’s core activities. ERM needs to become part of organizational culture. (Read the May 2010 AICPA Business Brief Link Between Decision-Making and ERM: A Case Study.)