Compliance Week Podcasts …

This week’s podcast features Russ Berland of the law firm Stinson Morrison & Hecker talking about how to use new guidance from the Organization of Economic Cooperation and Development as a blueprint for better FCPA compliance programs. Hear the podcast now.

… and Compliance Week on Twitter!

You can also follow Compliance Week Editor Matt Kelly on Twitter, for the latest regulatory observations and updates. More than 2,100 followers and ranked the most influential Twitter feed on compliance!

Compliance Week LinkedIn Group

Visit the Compliance Week has a companion group on LinkedIn, where members can network and discuss the compliance and governance news of the day among themselves. Open to all, free to join.

Webcast of the Week

Risk Oversight and the New SEC Rule
Sponsored by OpenPages

Help Wanted: Ad of the Week

Chief Ethics & Compliance Officer
Submitted by Morgan Samuels

Event of the Week

Is Employee Ethics Training Mandatory?
Sponsored by ELT

Thought Leadership of the Week

Global survey into the integration of GRC
Courtesy of KPMG

The Resource Exchange

Sample Risk Acceptance Request
Submitted by Circuit City

Risk Inventory
Submitted by Cognizant Technology

Featured Databases

CEO, CFO Disclosure Certifications
CEO, CFO Certifications From 3,000 Cos.

Management Discussion & Analysis
Compare How Peers Disclose Risk

GRC Illustrated Series

The IFRS Ripple Effect
The 23rd Installment in This Exclusive Series

Compensation Survey

Compliance, Audit & Risk Compensation Survey
Empsight’s 2010 Compensation Survey is now open for participation. It is the leading source of its kind and reports on Fortune 500 and other large multinationals.

Global Integrity Survey

2009 Global Integrity Survey
Download the findings of the 2009 Global Integrity Survey, compiled by Compliance Week and sponsored by Integrity Interactive.

The Filing Cabinet

RSS
“The Filing Cabinet” is written by Melissa Klein Aguilar, a long-time business journalist who first began writing for Compliance Week in 2005. She closely follows all issues related to SEC registrants, Sarbanes-Oxley compliance, evolving securities rules, and executive compensation, among other areas. She welcomes questions, comments and statements from readers on SEC filing matters, and where appropriate she will try to address them here. She can be reached via email at Melissa@complianceweek.com.

 

June 30, 2009

Report: Disclosures on ERM Lacking

The financial crisis has put risk-management practices under the microscope, but public company disclosures related to the subject apparently still have a long way to go.

That’s according to governance research and rating firm GovernanceMetrics International, which found that standardized disclosure of company-wide risk management is lacking.

Of 4,162 global companies covered by GMI, only one-third provide comprehensive disclosure on their enterprise risk management policies in the annual report or other publicly available sources. Far fewer (8.4 percent) disclose they have implemented a nationally or internationally recognized risk-management charter or standard such as COSO’s Integrated Framework for Enterprise Risk Management, according to GMI.

Risk committees of the board are even less common and are sector-specific, according to GMI. Just over one-quarter of companies (27.6 percent) disclose having a combined audit and risk committee, while roughly 6 percent of companies covered by GMI disclose a stand-alone board level risk committee or sub-committee. Those were most often found among banks (35.1 percent), life Insurers (21.3 percent),  and Non-life Insurers (17.6 percent).

Only 1 percent of the companies tracked by GMI have at least one non-executive board member who has general expertise in risk management. Meanwhile, of 1,659 new board members tracked by GMI so far in 2009, 1.4 percent have risk-management expertise, with the banking sector leading the way. Of 227 new board members tracked by GMI at banks so far in 2009, 3.5 percent had risk-management expertise. GMI also noted that the Australia - New Zealand region disclosed the widest use of stand-alone board level risk committee or sub-committees, at 12.1 percent versus 5.9 percent worldwide.

Howard Sherman, GMI President and CEO, noted that “there clearly is a need for increased transparency concerning companies’ overall approach to risk management.”

Given that ratings agencies such as Standard & Poor’s and Moody’s have begun factoring risk-management practices into their credit ratings, even for non-financial firms, companies may want to pay more attention to their disclosures.

“Our expectation going forward is that companies seen to be taking serious steps to augment risk oversight, especially in the financial sector, will be rewarded by the market,” Sherman said in a statement. GMI noted that it recently added new metrics related to risk oversight to its rating model.

Moreover, a paper prepared jointly by GMI and the Risk Consulting Practice of Marsh Inc., entitled The Importance of ERM During Times of Economic Upheaval (registration required), found that while ERM is gaining momentum globally, it isn’t regularly communicated to investors. The paper, based on a survey of 149 global public companies with average revenue of $4.74 billion in the last fiscal year, found that 75 percent of companies responding currently don’t provide information to investors on their approach to ERM. Of those, 73 percent reported that they have no plans to increase the amount of information they provide within the next 12 months.

While the vast majority of respondents to that survey (79 percent) indicated their companies employ a formal ERM program, most are either in the infancy of formal development (28 percent) or mature with opportunities for improvement (48 percent), according to the report. Of the companies that currently don’t have a formal ERM program, approximately 40 percent said they intend to employ a formal ERM program in the next 12 months.

Posted by: maguilar @ 2:51 pm

Filed under: Disclosures, Enterprise Risk Management

1 Comment »

  1. Interesting, but not surprising given that there is no regulatory requirement to implement a “formal ERM program”, whatever that means. All registrants will disclose risk factors in their filings and will do something around the risk management topic given existing compliance / listing standards requirements, but until there is a regulatory requirement to do so, implementing a “formal ERM program” will remain a “good practice” - i.e., optional, much as use of the COSO Framework for internal control reporting purposes was pre-Sarbanes.

    Frameworks, although a good starting point, are not a panacea. I do, however, commend your effort to generate discussion on this topic.

    Comment by H.W. Willoughby — July 8, 2009 @ 5:02 pm

RSS feed for comments on this post. TrackBack URL

Leave a comment