Community
I recently met with a former colleague of mine who recounted a story that as first seems extreme, but which I have subsequently established to be a common problem:
My contact was a risk manager in a large financial institution and he was recounting to me his experiences in implementing a risk and compliance governance system. The system had entailed a substantial investment in software licenses and an even larger amount for professional services associated with implementation. The objective of the system was to engage the whole enterprise in the management of operational risks. The compliance and risk deaprtments ere tasked with establishing a repository of risk & regulatory issues togther with associated guidance for compliance and risk mitigation. Line management would be responsible for identifying, assessing and confirming risks and compliance issues associated with their activities were being managed in accordance with policies, guidelines etc. This seemed like a great plan, leveraging collaborative web technologies and ditching the mountain of dosuments and spreadsheets. Yet, in around 12 months following the implementation of the system, the system had fallen into redundancy outside of the risk function. A couple of data entry staff had been recruited to re-input spreadsheets that the rest of the organisation emailed to them so that the "main risk system" could be updated and MIS produced. What went wrong?
Basel II and regulatory requirements have established a requirement to demonstrate the existence of a regulatory compliance management programme and maintain associated records. It's therefore a generally accepted "good idea" to establish some kind of IT solution to manage the enterprise risk management process. Acting as the organisation's "conscience", a repository and automated governance tool identifies responsibilities, tracks actions and remedial activity, identifies exceptions, enforces risk ownership and creates an environment where no risk remains ignored
But, as my former colleague found out, it didn't happen. The systems were devised, marketed, procured and implemented. Then what? The majority of them fell into misuse because:
All in all, what seems like a great idea in principle - getting an efficient and transparent risk governance system in place - is a bit like trying to push jelly up a hill with a stick.
We need to rethink our approach to technology and how we expect the wider organisation with many ad-hoc users to engage with risk governance systems. A good risk governance system will provide all of the "expected" features such as:
But more importantly, to ensure that the system is widely adopted and ingrained within the firm, system designers are going to have to learn that users want to perform these activities via application interfaces that they are already familiar with. Which means that the application not only sends out emails telling users that they need to do something, it allows them to use familiar tools to complete their activities such as:
Although there are some application design challenges here, there's a simple message; let users operate through applications interfaces that they are familiar with and ensure that the system shields the users from its design complexities. That way you stand a fighting chance of the system's use being sustained within the organisation.
This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.
Prakash Pattni MD, Financial Services Digital Transformation at IBM Cloud
11 November
Mouloukou Sanoh CEO and Co-Founder at MANSA
Brian Mahlangu VP Product: Digital Platforms Mobile at Absa Bank, CIB.
Roman Eloshvili Founder and CEO at XData Group
Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.
Please read our Privacy Policy.