4.6 Result of Control Assessment
4.6 Result of Control Assessment
Effectiveness of the control monitoring program depends on following parameters:
Accuracy of the data on the basis of which controls are evaluated
Timely reporting on risk to management for taking corrective action
Skill set of risk practitioner to properly evaluate the controls
Maturity Model Assessment and Improvement Techniques
Risk management program should be a dynamic process and should evolve and improve on a continuous basis.
Risk management programs should be improved on the basis of learnings from past events.
Adoption of a capability maturity model (CMM) helps to indicate the maturity of the risk management process year over year.
CMM helps an organization to understand its level of maturity by analyzing the operational effectiveness, efficiency and readiness. It provides insight into an organization's risk management capabilities.
Maturity can be determined by analyzing the risk aware culture of the organization. Employees of a matured organization are aware about the risk of their processes and willing to resolve the same.
With the help of the maturity model, the level of competence of the organization can be benchmarked and compared with the peers.
Objective of adopting a maturity model is to strive for continuous improvement. This can be done by assessing the current maturity level of the business process and comparing the same with desired level. Gaps, if any, needs to be addressed to improve the process and maturity level.