Author: RB

Casualty Actuarial Society (CAS) ERM
Risk Management

Casualty Actuarial Society (CAS) ERM

What is the Casualty Actuarial Society ERM Framwork (CAS ERM)? The Casualty Actuarial Society (CAS) is an international credentialing and professional education entity. The organization focuses exclusively on property and casualty risks in insurance, reinsurance, finance, and enterprise risk management.  Background on the CAS ERM Framework In 2003, the Casualty Actuarial Society (CAS) defined ERM as the discipline by which an organization in any industry assesses, controls, exploits, finances, and monitors risks from all sources for the purpose of increasing the organization's short- and long-term value to its stakeholders. The CAS, Society of Actuaries (SOA), and Canadian Institute of Actuaries (CIA) sponsor a risk management website with ERM education r...
Johnson & Johnson (J&J) ERM
Business

Johnson & Johnson (J&J) ERM

What is the Johnson & Johnson (J&J) ERM? The Johnson & Johnson ERM framework helps identifypotential events that may affect the enterprise,manage the associated risks and opportunities, andprovide reasonable assurance that our Company’sobjectives will be achieved. Johnson & Johnson is one of the largest healthcare enterprises in the world. The company created a custom ERM framework, guided by the COSO ERM framework, to address healthcare-specific risks such as reduced business vitality due to healthcare reform. What is the J&J's approach to ERM? Johnson & Johnson's approach to ERM is informed by principles outlined by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). COSO defines ERM as “the culture, capabilities, and pra...
Committee of Sponsoring Organizations (COSO) ERM
Reputation

Committee of Sponsoring Organizations (COSO) ERM

What is the Committee of Sponsoring Organizations (COSO) ERM Framework? The COSO Framework is a system used to establish internal controls to be integrated into business processes. Collectively, these controls provide reasonable assurance that the organization is operating ethically, transparently and in accordance with established industry standards. History of the COSO ERM Framework The committee created the framework in 1992, led by Executive Vice President and General Counsel, James Treadway, Jr. along with several private sector organizations, including the following: American Accounting AssociationFinancial Executives InternationalThe Institute of Internal AuditorsAmerican Institute of Certified Public AccountantsThe Institute of Management Accountants (formerly the Na...
CCPA vs CPRA: What are their differences?
Reputation

CCPA vs CPRA: What are their differences?

Summary of the CCPA The California Consumer Privacy Act (CCPA) grants consumers rights related to the collection, use, and sale of their personal data—and prevents businesses from discriminating against them for exercising those rights. Signed into law in June 2018, the new regulation comes as a response to a multitude of businesses, targeting Silicon Valley firms that are making headlines for mishandling or exploiting private data. The CCPA focuses on making sure organizations have a business purpose for why they need personal information while enabling Californians to readily request, delete, or protect their personal information (PI) collected and governed by a business. Summary of the CPRA The California Privacy Rights Act (CPRA) is a new state-wide data priv...
California Privacy Rights Act (CPRA)
Compliance, CPRA, Data Protection, Privacy Act, Risk Management, Security

California Privacy Rights Act (CPRA)

What is the California Privacy Rights Act (CPRA)? The California Privacy Rights Act of 2020 (CPRA), also known as Proposition 24, is a California ballot proposition that was approved by a majority of voters after appearing on the ballot for the general election on November 3, 2020. This proposition expands California's consumer privacy law and builds upon the California Consumer Privacy Act (CCPA) of 2018, which established a foundation for consumer privacy regulations. CPRA History and Summary The California Privacy Rights Act (CPRA) is a new state-wide data privacy bill passed into law on November 3, 2020. It underscores California’s position as the US frontier in data privacy legislation, as it significantly expands upon the existing Californi...
California Consumer Privacy Act (CCPA)
Reputation

California Consumer Privacy Act (CCPA)

What is the California Consumer Privacy Act (CCPA)? The California Consumer Privacy Act (CCPA) grants consumers rights related to the collection, use, and sale of their personal data—and prevents businesses from discriminating against them for exercising those rights. Signed into law in June 2018, the new regulation comes as a response to a multitude of businesses, targeting Silicon Valley firms that are making headlines for mishandling or exploiting private data. The CCPA focuses on making sure organizations have a business purpose for why they need personal information while enabling Californians to readily request, delete, or protect their personal information (PI) collected and governed by a business. Who Must Comply with the California Consumer Privacy Act?  Organi...
NIST Risk Management Framework (NIST RMF)
Risk Management

NIST Risk Management Framework (NIST RMF)

What is the NIST Risk Management Framework (NIST RMF)? The NIST Risk Management Framework (RMF) provides a comprehensive, flexible, repeatable, and measurable 7-step process that any organization can use to manage information security and privacy risk for organizations and systems and links to a suite of NIST standards and guidelines to support the implementation of risk management programs to meet the requirements of the Federal Information Security Modernization Act (FISMA).   What are the NIST RMF Steps? Overview Overview of the RMF seven-step process: Prepare - Essential activities to prepare the organization to manage security and privacy risks Categorize - Categorize the system and information processed, stored, and transmitted based on ...
Environment, Social and Governance (ESG) – Part 2
Business

Environment, Social and Governance (ESG) – Part 2

Part 1: Environment, Social and Governance (ESG) – Part 1 Are there any standards to measure these? The Environmental criteria can be measured based on a company’s energy use, waste, pollution, natural resource conservation, and treatment of animals. The Social criteria can be measured based on a company's business relationships such as relationships with suppliers, shared values with suppliers, donations to the local community, encouraging employees' volunteer work, good employee health, and safety rights. The Governance criteria can be measured based on a company's accuracy and transparency in accounting methods, stockholders voting priorities on important issues, avoiding conflicts of interest on the choice of board members, not using political contributions to obtain f...
Environment, Social and Governance (ESG) – Part 3
Business

Environment, Social and Governance (ESG) – Part 3

Part 2: Environment, Social and Governance (ESG) – Part 2 What can a small/medium company with limited budget do to manage ESG risks? To cover the basics of ESG as an SME is not difficult. SMEs should consider a journey where there are clear benefits at every stage post:   Environmental: An SME should start thinking of ways to cut energy, water, and waste usage. In order to be on a cost-saving exercise. Social: An SME should strive to have an attractive business culture by maintaining a low staff turnover. This would attract bright talents that are looking for secure growth to the SME. Governance: An SME should focus on the governance of their business, particularly by focusing on risk management. Doing this would not only appeal to SME investors but to their customers...
Business

Environment, Social and Governance (ESG) – Part 1

Shot of architectural model on the table in the office What is ESG? Environment, Social, and Governance (ESG) refer to a trio of business standards used by socially conscious investors to screen potential investments. Investors are increasingly applying these non-financial factors as part of their analysis process to identify material risks and growth opportunities. Environment: Investors will evaluate the environmental risks a company might face and how these risks are being managed Environmental factors that businesses would address are: - Climate change and carbon emissions- Air and water pollution- Biodiversity- Deforestation- Energy efficiency- Waste management- Water scarcity Social: Investors will evaluate a company's business relationships and social facto...