【正文】
aaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaa Residual Risk Action Plan Resp XYZ XYZ ABC NOP Milestone Dec ‘97 Mar ‘98 Jun ’98 Jan ‘98 Oct ‘97 Feb ‘98 Action Planned to Mitigate Risk aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaa Opinion S U P S Residual Risks aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa Probability of risk event occurring Transfer risk or contingency plan Manage by improving controls if cost justified Cease activity unless rewards high manage closely Accept risk Low High High Management of residual risks Migrating IA to embrace operational risk ?? Change IA skills base ?? Innovate or die ?? Obtain buy in Where are you now? ?? Risk based audit? ?? Positioning ?? Credibility Where do you want to be? ?? Positioning ?? Meet board needs re. Turnbull? ?? What operational risk functions? How do you get there? ?? Establish credibility ?? Establish business case ?? Obtain mandate Skill set for IA going forward ?? Customer focus ?? Mind set / profile ?? Wider business experience ?? Facilitation skills ?? Less is more ?? Staff development I survived the migration