End User Assessor Models

Generated from the Designer Tool and structured according to the risk framework defined in the Designer Tool, End User Assessor Models are used to conduct detailed assessments across the business.

The End User Models provide users with a management tool to enable them to identify, assess, treat and monitor the risk profile within their business area.

Two types of End User Models can be generated from the Designer Tool, a Simple Fixed Model and a Comprehensive Flexible Model.

The Simple Fixed Model (SFM) provides users with the ability to assess risk according to the corporate framework that was defined in the Designer Tool. Users have the ability to add new risk and control information in the SFM, but they cannot alter the underlying risk area framework that was defined in the Designer Tool. This ensures consistent application of the framework across the Company.

The Comprehensive Flexible Model (CFM) provides users with the ability to map the risk framework that was defined in the Designer Tool against their own unique process structure. This allows users to use both generic risk definitions and a flexible entity structure. This gives all of the benefits of a consistent approach, without impacting on the users' ability to accurately document all instances of risk within their business units. It also means that users can report down either the fixed risk category tree that was defined in the Designer Tool, or their own process tree.

The assessment approach adopted in the End User Models is consistent with the Australian / New Zealand Risk Management 4360:1999, and as such supports a three-level risk assessment, inherent risk, controlled risk, and if required, treated risk.


The End User Assessor Models facilitate

Risk Identification
Risk Evaluation
Risk Mitigation
Risk Monitoring
Key Indicators
Risk Events
Reporting

Risk Identification
End User Models provide for the systematic identification and recording of risks and factors giving rise to those risks. Each risk is assigned one risk owner. Designed specifically with end users in mind, the End User Models provide a user-friendly risk management tool. Users familiar with a Windows environment will find the End User Models both easy to navigate and easy to learn.

Risk Evaluation

End User Models provide qualitative risk evaluation based upon the likelihood of a risk being realised and the potential consequence. The parameters used to assess both likelihood and consequence are defined in the Designer Tool.

Each risk is assigned an absolute risk score, a controlled risk score (residual risk) and if required, a treated risk score. Risks can be sorted and filtered on these scores (and other fields such as risk owner) and reports generated accordingly. Online graphing illustrates the movement of risk across the three levels of assessment.


Risk Mitigation

End User Models enable mitigating actions, or treatments to be raised at a risk level. The system captures information specific to each treatment, for example: description; status; priority; who is responsible for the action; treatment cost and key dates to record where in its lifecycle the treatment currently is. Alerts can be raised in the system to help track and monitor treatments.


Risk Monitoring

End User Models provide for the continuous monitoring of risks, controls and treatments.

A full audit trail is available from the End User Model for all changes to risk scoring.


Key Indicators

End User Models allow Key Indicators to be identified and linked to risks. Indicators can be populated from the organisation's core systems through automatic data loading facilities. For each indicator, bounds can be established and users notified by e-mail when an indicator exceeds a bound. Reporting capabilities allow the indicators to be exported into Excel reports allowing a Board / Senior Management report to be generated at a single click. Imported data can be defined with different dimensions allowing users to drill into and pivot the information. For example staff turnover rates can be defined by Position and Function.


Risk Events

Internal and/or external loss events or near misses can be recorded in the system to allow the business to identify potential risk events and failures in controls. The use of HTML forms allows Risk Events to be recorded outside the system and automatically loaded through monitoring of e-mail accounts.

fORM can be populated with loss event classifications, for example Basel, or the British Bankers Association (BBA) classification for loss.


Reporting

Supporting both generic and ad hoc reports, End User Models provide full interface to Microsoft® Word and Excel for reporting and analysis. Report templates can be fully customised to reflect the organisation's current reporting formats. Sophisticated sorting, filtering, graphing and reporting ensure that business managers have ready access to key information in a format that makes sense to them.

With additional functionality such as Word 97 (or later) fORM reporting provides rapid and accurate distribution and consolidation of information from multiple business areas where you do not want to give users direct access to the database. Word 97 Form reporting involves completing a series of risk assessments from the End User Model in a familiar Word document format for completion by individuals. The completed data is then extracted from the documents and loaded into the database for reporting and analysis