StatementsonManagementAccountingENTERPRISERISKANDCONTROLCREDITSTITLEIMA®wouldliketoacknowledgetheworkofWilliamG.Shenkir,Ph.D.,CPA,andPaulL.Walker,Ph.D.,CPA,bothoftheMcIntireSchoolofCommerce,UniversityofVirginia,whoweretheauthorsofthisSMA.ThanksalsogotoTimLeechofPaisleyConsultingandCOSOboardmemberJeffThomsonofIMAwhoservedasreviewersandRaefLawson,Ph.D.,CMA,CPA,ofIMAwhoservesasserieseditor.ENTERPRISERISKMANAGEMENT:TOOLSANDTECHNIQUESFOREFFECTIVEIMPLEMENTATIONPublishedbyInstituteofManagementAccountants10ParagonDriveMontvale,NJ07645-1760www.imanet.orgCopyright©2007byInstituteofManagementAccountantsAllrightsreservedStatementsonManagementAccountingTABLEOFCONTENTSEnterpriseRiskManagement:ToolsandTechniquesforEffectiveImplementationENTERPRISERISKANDCONTROLI.ExecutiveSummary................1II.Introduction.....................1III.Scope..........................2IV.RiskIdentificationTechniques.........3Brainstorming.....................4EventInventoriesandLossEventData...5InterviewsandSelf-Assessment........6FacilitatedWorkshops...............7SWOTAnalysis....................7RiskQuestionnairesandRiskSurveys...8ScenarioAnalysis..................8UsingTechnology..................9OtherTechniques..................9V.AnalysisofRiskbyDrivers...........10VI.RiskAssessmentTools.............11Categories......................12Qualitativevs.Quantitative..........12RiskRankings....................13ImpactandProbability..............13KeystoRiskMaps................14LinktoObjectivesatRiskorDivisionsatRisk.........................15ResidualRisk....................16ValidatingtheImpactandProbability...17Gain/LossCurves.................17TornadoCharts...................18Risk-AdjustedRevenues.............18ACommonSenseApproachtoRiskAssessment.....................19ProbabilisticModels...............19SeeminglyNonquantifiableRisks......20VII.PracticalImplementationConsiderations23ERMInfrastructure................23ERMMaturityModels..............23StagingERMAdoptionforEarlyWins...24TheRoleoftheManagementAccountant25ERMEducationandTraining.........25Technology......................25AligningCorporateCulture...........26BuildingaCaseforERM............26TheROIofERM..................27X.Conclusion.....................27Glossary...........................27ReferenceList......................28AdditionalResources..................28StatementsonManagementAccountingTABLEOFCONTENTSExhibitsExhibit1:AContinuousRiskManagementProcess................2Exhibit2:IndustryPortfolioofRisks..5Exhibit3A-D:RiskIdentificationTemplate6-7Exhibit4:InfluenceDiagram.......10Exhibit5:QuantifyingRisk:DeterminetheDrivers...............11Exhibit6:QualitativeandQuantitativeApproachestoRiskAssessment...........12Exhibit7:RiskMap..............13Exhibit8:RiskMapModel.........14Exhibit9:Gain/LossProbabilityCurve16Exhibit10::TornadoChart:EarningsVariabilitybySampleRisks.17Exhibit11:ActualRevenuevs.Risk-CorrectedRevenue.......18Exhibit12:GoalsofRiskManagement.19Exhibit13::EarningsatRiskbyRiskFactor................20Exhibit14:EarningsatRiskHedgeEffectivenessComparisons.21Exhibit15:ExpectedEarningsandEaR21Exhibit16:ProbabilityAssessmentofEarningsOutcomes......22Exhibit17:ERMMaturityModel......24EnterpriseRiskManagement:ToolsandTechniquesforEffectiveImplementationENTERPRISERISKANDCONTROLI.EXECUTIVESUMMARYEnterpriseriskmanagement(ERM)tak...