Conference Day Two: Tuesday, 30 June 2020

9:40 am - 9:40 am Registrations & networking

9:40 am - 9:50 am Opening remarks by IQPC

9:50 am - 10:00 am Opening remarks by Chairperson and day one round up

Gregory Irgin - Global Risk Leader, Emirates Global Aluminium
img

Gregory Irgin

Global Risk Leader
Emirates Global Aluminium

Risk Culture

10:00 am - 10:20 am Building a risk intelligent culture

Dr. Sadar Abdul Rasheed - Head of Financial Risk Management, Al Ghurair
  • Best practices and pitfalls to avoid towards a risk aware organisation
  • Top to down approach – How the management can set the tone in an organisation and how to get their buy in
  • Internal reporting: Encouraging a speak-up culture and constructing a risk-reporting system
img

Dr. Sadar Abdul Rasheed

Head of Financial Risk Management
Al Ghurair

10:20 am - 10:35 am CASE STUDY: Risk management is dead, long-live risk management – Yahsat’s risk management journey

Roy Knaven - VP - Internal Audit & ERM, Yahsat

Yahsat, the leading global satellite communications solutions provider from Abu Dhabi (a Mubadala company) has been revising its risk management approach. From a rather traditional approach to a more customised approached for a SME sized company.

Every approach comes with their own unique opportunities and challenges, strategies and process

  • Learn how Yahsat started and implemented a sensible risk management approach
  • Understand the change in their risk culture, risk ownership and accountability
  • Outcomes of Yahsat’s ERM model so far and their benchmarking methods
img

Roy Knaven

VP - Internal Audit & ERM
Yahsat

  • Stakeholder and supplier engagement – how to communicate and bring other stakeholders involved
  • Encouraging risk ownership and building risk accountabilities
  • Benchmarking and assessing risk culture and the tools needed for the same
img

Dimitris Kitsios

Risk Leader
Risk Leader

img

Waqas Haider

Director Control Management, Risk & Compliance
EITC (du telecom, Edara, Virgin Mobile) - UAE

img

Alexander Larsen

President
Baldwin Global Risk Services Ltd.

img

Abhishek Nayak

Head - Risk Management
HDFC INTERNATIONAL LIFE AND RE COMPANY LIMITED

10:55 am - 11:10 am The route to a strong risk culture - from theory to execution

People talk about having an organisational culture that recognises risks, and where risk management is embedded throughout the layers of the company.

But what does that actually mean?

A strong ‘Risk Culture’ has often been identified as a pre-requisite for improving risk management in resilient organisations. ‘Risk culture’ denotes: “The norms of behavior for individuals and groups within an organisation that determine the collective ability to identify, understand, openly discuss, and act on the organisation’s current and future risks”

It is a way of thinking and embedded within the organisation’s DNA through core values, patterns of behaviour, involvement, empowerment, transparency and tone at the top. Risk culture is a key component of integrated risk management focusing on the behavior of individuals with respect to risk. Embed & simplify risk management practices to be into normal business operations, planning and budgeting processes, and organizational culture. It is no longer an add-on or a management fad.

11:10 am - 11:25 am TECH TALK: Embedding Environmental, Social and Governance (ESG) initiatives in the risk culture

ESG initatives have never been more important for organisations. Research has shown a direct relation between both financial and reputational performances to that of organisations ESG practices. Investors, suppliers, external stakeholders and employees, all have started to pay close attention to organisation’s ESG practices as indicators of future performance and safety.

  • Assessing the importance of ESG factors to organisations and stakeholders
  • Creating a full proof ESG plan with clear cut objectives and goals
  • Applying the COSO ERM Framework to ESG-related risks and communicating ESG efforts

Cyber risks

Amongst all risks to watch out for in this year, cyber crime and risks come out on top. With technology advancing, cyber crime and activities advance at the same pace, sometimes faster. Risk and IT leaders need to have the right infrastructure, know-how, trainings and incident response plans at all times to ensure their organisation can refrain themselves from a cyber attack which can damage reputation, cost millions of dollars and create legal issues.

11:25 am - 11:40 am The rising use of technology and the cyber risks that follow suit

Mohammad Yousef AlTarakma - Group Director of Risk Management, Zain Group
img

Mohammad Yousef AlTarakma

Group Director of Risk Management
Zain Group

11:40 am - 12:00 pm Security Operations Centers (SOCs) resurgence to guide SRM leaders

Viji Mohan - Head - Information and Physical Security Governance, ADCB

Cyber attacks take place every day, for different purposes. As attacks grow in intensity, there has been a resurgence in SOCs because of their role indetecting and neutralising threats. According to a recent report by Gartner, by 2022, 50% of SOCs will integrate with threat intelligence and incident response tools, putting risk leaders in a better position to protect their valuable data.

  • From threat prevention to threat detection and the role of SOCs
  • Building or outsourcing SOCs to integrate intelligence, incident response and mitigation
img

Viji Mohan

Head - Information and Physical Security Governance
ADCB

Internal Audit

12:00 pm - 12:15 pm Audit Committee – Role and responsibilities towards risk and internal audit

Hesham ElGindy - Chief Audit Executive, SISCO Holding

Executives and boards of directors have one of the most demanding jobs today. Each board committee face its own challenge, with the audit committee facing its own rising challenges. Corporate failures and scandals across countries and industries have raised concerns and debates on the audit and governance function, exposing serious governance and audit failures.

Audit committees, the board and the management all have a collective responsibility for the integrity and accuracy of an organisation’s reporting.

With the increased uncertainty in geopolitical, business and regulatory environments, audit committees today have their hands full.

  • Widening audit committee responsibilities
  • Understanding the effect of all kinds of risks that impact businesses and their reporting
  • Ensuring internal audit is evolving with the evolving nature
  • The ever increasing role of environmental, social and governance on reporting
img

Hesham ElGindy

Chief Audit Executive
SISCO Holding

12:15 pm - 12:30 pm The internal audit and risk management relationship

Tanu Goel - Chief Internal Auditor, Emirates Development Bank

A classic topic of discussion is the ever evolving relationship within an organisation’s internal audit and risk management departments and practices.

  • The basics between internal audit and risk management and risk assessment versus internal audit
  • Three lines of defenses and its implications
  • Link between risk-based internal auditing and overall ERM
  • Aiding risk management through internal audits
img

Tanu Goel

Chief Internal Auditor
Emirates Development Bank

12:30 pm - 12:45 pm Relation between risk appetite and key risk indicators (KRI’s) effective management

Ozge Gurgur - Senior Enterprise Risk Manager, Petrofac

Key risk indicators (KRI`s) are vital predictors of unwanted events which can impact organisations in a negative way.

Understanding the power of the key risk indicators, how to define and develop them leads to the increase of the organisation’s risk appetite.

Key question – Do you know key indicators combined with risk appetite can contribute to make better decisions?

  • Creating a comprehensive risk appetite framework
  • Understanding and developing key risk indicators (KRI)
img

Ozge Gurgur

Senior Enterprise Risk Manager
Petrofac

12:45 pm - 1:00 pm IA and ERM: Contributions and collaboration in the pursuit of organisational objects

Hashem Al-Asiri - Chief Audit Executive, King Fahad Medical City

As organisations continue to navigate rapidly changing business environments, regulatory requirements, technology disruptions, and more, the need for IA to be agile and help organisations respond to risks is ever-increasing. To provide the greatest value, IA must find opportunities to add value and make improvements in organisations’ controls, risk management and governance while aligning itself with the organisational strategies and goals.

img

Hashem Al-Asiri

Chief Audit Executive
King Fahad Medical City

1:00 pm - 1:20 pm From reverse to radical – 30 years of growth

Horst Simon - Risk Culture Builder and Business Risk Officer, Capricorn Investment Group
  • Where did we come from?
  • What worked and what not?
  • Where are we going?
img

Horst Simon

Risk Culture Builder and Business Risk Officer
Capricorn Investment Group

1:30 pm - 1:30 pm End of conference