Skip to main content

Policy 600 2 risk management plan 2018

Page 1

2018 Risk Management Plan

Cremorne Capital Limited 8 Chapel Street, Richmond Vic, 3121 ACN 006 844 588 AFSL 241175


CONFIDENTIAL – INTERNAL USE ONLY

Table of Contents 1

Introduction...................................................................................................................................... 4

2

Objective of the Risk Management Plan ....................................................................................... 4

3

Scope of Activities .......................................................................................................................... 4

4

Risk Management Process ............................................................................................................. 5

7

Risk Categories ............................................................................................................................... 9 7.1

Relevant to the Business ....................................................................................................... 9

7.2

Not Relevant to this Plan ..................................................................................................... 10

8

Responsibilities and Resources .................................................................................................. 11

9

Stakeholders .................................................................................................................................. 12

10

Risk Management Tasks and Reporting ................................................................................ 13 10.1

Business Resources (Board and Staff) ............................................................................... 13

10.2

Board of Directors ............................................................................................................... 13

10.3

Compliance Manager .......................................................................................................... 14

10.4

Key Service Providers ......................................................................................................... 14

11

Risk Management Tools .......................................................................................................... 15

12

Risk Treatment and Action Plan ............................................................................................. 16

Annexure A – Continuous Risk Management Diagram ................................................................... 17 Annexure B – Organisational Chart ................................................................................................... 18 Annexure C – Other Risk Management Terms ................................................................................. 19 Annexure D – Rating of Risks ............................................................................................................ 20 Annexure E – Line of Business Risk Management Tools ............................................................... 23 Annexure F – Annual Risk Assessment Report (template) ............................................................. 24

Cremorne Capital Limited

Risk Management Plan

Page 2 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Document Control File details Compliance Policies and Procedures Chapter

Plans

Section

Plans

File name

Policy 600-2_Risk Management Plan 2018

Document number

600-2

Description

Document describing the identification, assessment and management of risks within Cremorne Capital Limited.

Original author(s)

Steven O’Connell

Creation date

3 December 2013

Current revision author(s)

Steven O’Connell

Revision history Version

Revision date

Author(s)

Revision notes

1.0

3 December 2013

Steven O’Connell

Initial draft

1.1

4 December 2014

Steven O’Connell

2015 Plan

1.2

23 November 2015

Steven O’Connell

2016 Plan

1.3

24 November 2016

Steven O’Connell

2017 Plan

1.4

31 October 2017

Steven O’Connell

2018 Plan

Released by

Release notes

Release control Version

Release date

Cremorne Capital Limited

Risk Management Plan

Page 3 of 27


CONFIDENTIAL – INTERNAL USE ONLY

1

Introduction Cremorne Capital Limited (Cremorne) operates in a complex regulatory and commercial environment. It is the policy of Cremorne to manage risk at the business process level. The Directors, management and each material service provider of Cremorne is responsible for actively identifying, assessing and managing the risks they face, and for the development of a continuous risk management process. Cremorne’s approach to risk management is to ensure that all material risks are defined, understood, and effectively mitigated by well-designed policies and controls. In addition, all material risks must be monitored by appropriate leading and lagging key risk indicators. Risk is the potential that an event or action, expected or unanticipated could lead to errors that have a visible impact on customers, financial losses, breaches or reputation damage. The risk management framework of Cremorne is contained within this Risk Management Plan. This plan includes risk categories and definitions, reporting requirements and the risk management responsibilities of individuals at various levels within Cremorne. The Risk Management Plan is part of a risk management system that includes the execution of preventive and detective controls, which include policies, procedures, tools, and training used by qualified personnel to identify measure, monitor, elevate, mitigate and control risk. Reference should also be made to the annual Compliance Plan at Policy 600-1.

2

Objective of the Risk Management Plan The objective of this document is to describe the process for the implementation of Cremorne’s risk management framework.

3

Scope of Activities Cremorne operates in the Australian financial services market, focusing on the asset management (investment) activities of its clients predominantly as a responsible entity for a resources fund, land and forestry schemes. At the present time, Cremorne is in a start-up phase of its life cycle for the forestry schemes. Cremorne will continue to specialise in core Australian resource securities, forestry schemes and land trusts.

Cremorne Capital Limited

Risk Management Plan

Page 4 of 27


CONFIDENTIAL – INTERNAL USE ONLY

4

Risk Management Process Detailed below, the continuous risk management framework outlines the risk management principles and key elements of the risk management process. Annexure A – Continuous Risk Management Diagram provides an illustration of this process. Cremorne seeks to maintain a continuous risk management framework within the business to ensure risk is appropriately managed at all times. This continuous risk management framework includes requirements of all staff to: (a)

IDENTIFY and UNDERSTAND key business processes and risks. All Board should regularly review and identify key risks and understand the business processes underlying those risks. Such identification is the first step in being able to mitigate all material risks inherent in the business processes.

(b)

DESIGN and DOCUMENT appropriate and cost effective controls, including policies, procedures, tools and training to mitigate all material risks. Once the risks inherent in business processes are identified, controls, including policies, procedures and tools must be put in place and documented in order to effectively mitigate the risks and to reduce the potential for errors, losses, compliance breaches and reputation damage. In addition, training in how to properly execute the controls and comply with policies must be developed.

(c)

EXECUTE the controls at the business process level. Once the appropriate controls, including policies, procedures, tools and training, are designed and documented, all Staff must ensure that these risk mitigation techniques are followed. It is not sufficient simply to develop controls, policies, procedures, etc. Risk mitigation practices must ensure that controls are consistently executed at the business process and operational level.

(d)

MONITOR key risk and performance indicators against standards. Periodic and consistent monitoring of both leading and lagging key risk and performance indicators against the standards that have been developed for key business processes ensures that any deviations from predetermined results can be identified. Once identified, these issues must be brought to the attention of the Compliance Manager, in order to determine the course of action that should be taken to remedy them.

(e)

REPORT, in a transparent manner, on key indicator performance, aged reconciliation items, near misses, control breakdowns, errors, losses and the actions taken to resolve these issues. Reporting should also encompass other situations that give rise to higher levels of risk such as process changes, changes in regulatory requirements, etc. These items must be reported on a regular basis, as appropriate, to the Compliance Manager. The Compliance Manager reports on these areas to the Audit, Risk and Compliance Committee (Compliance Committee). Note: “Near misses” are situations where losses, control breakdowns or errors that could have an impact on Cremorne’s customers, financial results or reputation were narrowly avoided. A near miss does not include those situations where proper functioning of risk controls causes the item to be discovered.

(f)

ELEVATING items of concern promptly to the Compliance Manager is a critical component of risk reporting. Such elevation allows Cremorne to put in place an action plan when there are uncleared aged reconciliation items, near misses, control breakdowns, errors or losses, or whenever an indicator deviates by a predetermined amount from the standard. The elevation of issues involves judgment, and should be based on materiality and risk potential. Elevation should be completed promptly upon identification of the problem or potential problem.

(g)

ANALYSE key risk indicators that have breached predetermined standards, uncleared aged reconciliation items, near misses, errors, control breakdowns and losses and determine their root cause. Conducting a root cause analysis (i.e., analysing what went wrong and which controls and processes must be changed to avoid such situations in the future) is an integral part of the reporting process. The root cause analysis should

Cremorne Capital Limited

Risk Management Plan

Page 5 of 27


CONFIDENTIAL – INTERNAL USE ONLY

provide enough specific detail about the situation so that the Compliance Manager can determine the appropriate course of action. (h)

STRENGTHEN controls, including policies, procedures, tools and training to minimise the impact of the root cause in a cost-effective manner. Based on the findings of the root cause analysis, the Compliance Manager should take appropriate, cost-effective steps to strengthen the risk mitigation practices to minimise the impact of the root cause.

(i)

REASSESS the impact on risk and controls of any business process changes, and UPDATE risks and controls accordingly. The management of risk is a continuous cycle. Material changes in how a business is conducted should cause the Board to reconsider and update its risk assessments and controls (including policies, procedures, tools and training) accordingly. Examples of such changes include the introduction of a new product or service, the addition of large client contract(s) or system conversions.

Cremorne Capital Limited

Risk Management Plan

Page 6 of 27


CONFIDENTIAL – INTERNAL USE ONLY

5

Risk Appetite / Tolerance In accordance with ASIC Regulatory Guide RG259, a responsible entity should document its risk appetite in a policy or statement. This policy or statement should outline the responsible entity’s attitude towards risk taking while carrying out its business plans, including the amount of risk (which may refer to the level of losses) it is willing to take to pursue its business strategies and achieve its objectives. It should also address the risks relevant to the responsible entity’s overall strategy to achieve its objectives and set out the limits to these risks. During this process the risk tolerance for each material risk should be identified (see Risk Treatment & Action Plan). Cremorne’s risk appetite will be reviewed at least annually. The board approves the Risk Management Plan including its policy or statement on risk appetite. This Risk Management Plan, including all policies and procedures to implement and monitor risk are communicated to staff, so that they are applied to support day-to-day operational decision making.

5.1

Risk Appetite Statement Risk appetite is focussed on the pursuit of risk and the parameters that Cremorne must employ in deciding whether or not to take on the risk. It defines what types of risks an organisation will pursue; which types of markets, products, services, clientele and customers it will target. Whilst recognising the need to grow the business will involve a level of risk, Cremorne has recently determined that the Lowell Resources Fund (“LRF”) should become a listed investment trust and therefore also subject to the rules and regulations of the ASX. Given the additional compliance requirements to be implemented in Cremorne and that Cremorne has not previously operated a listed investment trust, the organisation considers that its overall appetite for risk will be lower in the short term. Until the Board is comfortable with the implementation of new polices, checklists and monitoring processes, it will remain with this lower level of risk appetite. An example of the lower risk appetite would be the stronger emphasis on compliance with ASX requirements following the listing of LRF. Whilst recognising that some risks may be assessed as Inherently “High” or “Extreme”, In assessing Inherent Risk of the risks identified in the Risk Treatment & Action Plan, Cremorne’s risk appetite requires that any Inherent Risk rating (using the table in Annexure D) that is assessed at any time to be greater than “Moderate” requires immediate escalation to the Board for implementation of controls or actions to reduce the inherent risk to an acceptable level. Should the Board accept the Inherent level of risk at a level greater than “Moderate” it must document the reasons by Board minute or paper and amend this Risk Appetite Statement accordingly.

5.2

Risk Tolerance Statement Risk tolerance defines or quantifies the maximum amount of risk that Cremorne is technically able to assume. For example, this may be the maximum level of risk Cremorne can absorb or manage before breaching factors such as its capital base, liquidity levels, covenants, reputational and regulatory requirements, operational constraints and obligations to shareholders, customers and other stakeholders. In accordance with Cremorne’s risk appetite (above) no inherent risk rating of higher than “Moderate” would be accepted unless agreed in accordance with Clause 5.1 requirements.

Cremorne Capital Limited

Risk Management Plan

Page 7 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Additionally, the Board will not accept a Risk Likelihood of greater than “Unlikely” unless such matters are outside of the control of Cremorne (e.g. legislative changes). Should the likelihood of any identified risk be considered greater than “Unlikely” and outside the control of Cremorne, the Board is to take immediate steps to implement an action plan to provide stronger controls within Cremorne and advise all relevant parties. In some circumstances, the risk tolerance accepted by the Board of Cremorne may be less than “Moderate” (e.g. where market norms would dictate that a likely risk would be rated “Rare” and/or the impact should be considered “Insignificant”). Again, in accordance with Cremorne’s risk appetite (above) where the inherent risk rating is greater than the Risk Tolerance level it would only be accepted if agreed in accordance with Clause 5.1 requirements. The Risks identified in Risk Treatment & Action Plan will highlight a “Risk Tolerance” to be reviewed by the Compliance Committee and / or Board at least annually.

6

Stress Testing / Scenario analysis

While terminology varies, stress testing and scenario analysis are generally used to assess how Cremorne or its managed investment schemes will be affected and respond in different extreme scenarios. This is essentially a ‘what if’ exercise that examines what may happen if certain risks materialise. Cremorne will conduct review of the liquidity risks identified for each of the schemes it operates as frequently as appropriate to the Scheme (i.e. as regularly as unit pricing occurs) and will update or revise arrangements if required should results identify anomalies or concerns leading to greater risk. At a minimum, a review of the testing of the risks will be undertaken annually. In accordance with Cremorne’s Compliance Framework and program, Cremorne will review the framework for stress testing and scenario analysis at least annually. The testing and analysis will include short-term and prolonged adverse environmental impacts, and take into account entity-specific and market-wide ‘shocks’. For example: (a) the impact of significant market movements; (b) liquid assets becoming illiquid; (c) significant regulatory change; (d) significant reductions in net cash inflows through reduced applications or increased redemption requests; or (e) significant asset revaluations. The results of any stress testing or scenario analysis will inform future risk identification, assessment, evaluation and management. A range of approaches that may be used by Cremorne will include: (a) sensitivity analysis; (b) stress testing based on experience or historical events; (c) reverse stress testing designed to identify a stress scenario that would cause failure; (d) longer term scenarios (e.g. prolonged low interest rate environment) and short-term scenarios (e.g. natural disasters); or (e) a combination of scenarios (e.g. a series of less significant events occurring within a short timeframe).

Cremorne Capital Limited

Risk Management Plan

Page 8 of 27


CONFIDENTIAL – INTERNAL USE ONLY

7

Risk Categories

7.1

Relevant to the Business The categories of risk relevant to Cremorne are: (a)

OPERATIONAL RISK is the risk of direct or indirect loss resulting from inadequate or failed internal processes, people, and systems or from external events. It is the potential for loss that arises from problems with operating processes, human error or omission, breaches in internal controls, fraud or unforeseen catastrophes.

(b)

TRANSACTION RISK is the risk arising from problems with product or service delivery, error or fraud.

(c)

DATA SECURITY RISK is the risk arising from Cremorne’s inability to manage adequately the confidentiality, integrity and availability of its information resources, which in turn can cause loss or damage either directly or indirectly to the organization. Information resources include the operating systems used to run Cremorne’s computers, information networks, data stores or files, and the application systems it uses to process information. (1)

Confidentiality relates to Cremorne’s ability to protect sensitive information from unauthorised disclosure or interception by either internal or external parties not authorised to have or use the information.

(2)

Integrity relates to Cremorne’s ability to safeguard the accuracy and completeness of its data and its software.

(3)

Availability relates to ensuring that vital data and services are available to authorized users when required.

Reliably assessing data security risk can be more difficult than assessing other risks because information on the likelihood and costs associated with data security risk factors are often more limited and because risk factors are constantly changing. Data Security Risk has an impact on Operational Risk and Reputation Risk. (d)

FIDUCIARY RISK is the risk arising from serving in the best interests of clients in accordance with governing documents, "prudent person" principles and applicable laws, rules and regulations. The management of other risk factors such as Market Risk, Compliance Risk and Transaction Risk directly impacts Fiduciary Risk.

(e)

COMPLIANCE RISK (refer also to the Compliance Plan at Policy 600-1) is the risk arising from violations of or non-conformance with laws and regulations, prescribed practices or ethical standards. Compliance Risk also arises in situations where laws or rules governing certain products or activities of Cremorne’s clients may be ambiguous or untested. It exposes Cremorne to fines, civil money penalties, loss of licences, payment of damages, voiding of contracts, and/or increased reputation risk. It encompasses all laws as well as prudent ethical standards and contractual obligations and includes litigation from all aspects of financial services.

(f)

REPUTATION RISK is the risk arising from negative public opinion. Reputation risk impacts Cremorne’s ability to establish new relationships or services, or continue servicing existing ones. This risk is inherent in all activities, including asset management and agency transactions, but is very difficult to identify and quantify.

(g)

CREDIT RISK is the risk arising from an obligor’s failure to meet the terms of any contract with Cremorne or failure to otherwise perform as agreed. Credit risk arises anytime funds are extended, committed, invested or otherwise exposed through actual or implied contractual agreements, whether reflected on or off the balance sheet.

(h)

MARKET RISK is the risk arising from changes in the value of portfolios of financial instruments or other assets. Market Risk can be thought of as Price Risk and arises from market-making, dealing and position-taking activities in interest rate, foreign exchange, equity and other commodities markets. The primary accounts affected by Market or Price

Cremorne Capital Limited

Risk Management Plan

Page 9 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Risk are those that are re-valued for financial presentation (e.g., trading accounts for securities, derivatives and foreign exchange products). (i)

7.2

LIQUIDITY RISK is the risk arising from Cremorne’s ability to meet its obligations when they come due, without incurring unacceptable losses. Liquidity Risk includes the inability to manage unplanned increases or decreases in funding sources. It also arises from a company’s failure to recognise or address changes in market conditions that affect the ability to liquidate assets quickly and with minimal loss in value.

Not Relevant to this Plan Risk definitions that are not encompassed by this plan include: (a)

Personal risk – this refers to the risk to staff (including contractors) of injury or illness. This risk may be because of working conditions or the physical environment surrounding work locations. Personal risk also includes the exposure of the work location to incidents that may put staff at risk (e.g., toxicity, nearness to landmarks).

(b)

Property risk – this relates to the exposure of Cremorne to damage or theft of property including intellectual property – consideration of premises, security and contractual protection.

Cremorne Capital Limited

Risk Management Plan

Page 10 of 27


CONFIDENTIAL – INTERNAL USE ONLY

8

Responsibilities and Resources (a)

The BOARD is responsible for ensuring that an appropriate risk management system and plan is in place for the business.

(b)

The BOARD, in consultation with the independent auditors, is responsible for reviewing significant risk exposures and the steps management has taken to monitor, control and report such exposures. The Board evaluates risk exposure and tolerance.

(c)

ALL STAFF own the risks of the business and the responsibility for identifying, monitoring and managing risk according to the principles of risk management outlined above.

(d)

The FUND MANAGERS AND FUND ADMINISTRATORS are responsible for ensuring that the Cremorne achieves the following: (1)

(e)

Ensuring appropriate controls over the trading record reconciliation process and resolution of open reconciliation items including: (A)

Maintaining a complete inventory of reconciliation activity, updating new and old account information regularly and revising process maps accordingly.

(B)

Employing a process to ensure proper completion of reconciliations.

(C)

Creating and verifying that adequate management reports are in place to enable various levels of supervision to manage and monitor the process and facilitate elevation of problems.

(D)

Ensuring appropriate separation and fair allocation of mandates and other existing product offerings.

(E)

Escalating and investigating errors, losses and near misses, identifying the root causes and implementing corrective actions.

(F)

Reviewing the impact on inherent risks and controls of changes in business processes.

The COMPLIANCE MANAGER is responsible for ensuring that the Cremorne achieves the following: (1)

Identifying and documenting, through mapping of key business processes, all material risks, assessing the effectiveness of control design, and ensuring that control gaps are closed.

(2)

Developing and implementing standards and policies appropriate for the business that conform to the principles and guidelines of Risk Management.

(3)

Reporting and investigating errors, losses and near misses, identifying the root causes and implementing corrective actions.

(4)

Participating in the acceptance of new business, including Request for Proposal preparation, contract acceptance and compliance, and challenging whether Cremorne is being compensated appropriately for the assumption of risk.

(5)

Reviewing the impact on inherent risks and controls of changes in business processes.

(6)

Ensuring that processes, risks, and controls are continually reassessed for appropriateness and completeness.

(7)

Ensuring that the business has an effective overall risk management framework.

(8)

Evaluating the regulatory environment for impact to Cremorne and coordinate responses as needed.

Refer to Annexure B – Organisational Chart for a pictorial representation of these responsibilities and resources. Cremorne Capital Limited

Risk Management Plan

Page 11 of 27


CONFIDENTIAL – INTERNAL USE ONLY

9

Stakeholders Stakeholders are those individuals or entities who are, or perceive themselves to be, affected by a decision or activity of Cremorne. A number of potential stakeholder groups have been identified below: (a)

Cremorne Board and management.

(b)

Compliance Committee members

(c)

Business or other commercial partners and competitors.

(d)

Clients, potential clients and past clients.

(e)

Members / investors in entities to which Cremorne provides services.

(f)

Insurers of the organisation (e.g., providers of D&O insurance, PI insurance, fraud insurance).

(g)

Regulators and other government bodies such as committees.

(h)

Cremorne shareholders.

(i)

Cremorne material service providers

This list should be regularly reviewed as stakeholders may change with changes to the strategic direction of Cremorne. The interests of various stakeholders will be taken into account in the risk management process.

Cremorne Capital Limited

Risk Management Plan

Page 12 of 27


CONFIDENTIAL – INTERNAL USE ONLY

10 Risk Management Tasks and Reporting 10.1 Business Resources (Board and Staff) (a)

(b)

Cremorne is required to complete the following risk management tasks: (1)

Identify the key processes carried out by the business.

(2)

Identify risks specific to the business.

(3)

Identify the risk category(ies) affected by each risk.

(4)

Identify the most appropriate risk treatment option or state the risk treatment that has already been implemented.

(5)

Rate the risk according to the likelihood vs. consequence tables provided in Annexure D – Rating of Risks.

(6)

Note whether or not the risk has a fraud aspect.

(7)

Analyse the cost versus benefit implications of the selected treatment option and have supporting documentation available upon request.

(8)

Ensure staff undergo appropriate training.

Cremorne is required to complete the following reporting requirements: (1)

Provide input as required by the Compliance Committee for the completion of a Risk Management Plan.

(2)

Provide quarterly updates to the Compliance Manager of the most significant risks identified and their treatment plans.

10.2 Board of Directors The Board is required to complete the following risk management tasks: (a)

Ensure reporting requirements are completed on time and that there is supporting documentation to justify the various decisions made.

(b)

Ensure relevant staff undergo appropriate training.

(c)

Assess and approve activities, assessments, treatment options and reports provided.

(d)

Approve acceptable risk levels determined by Cremorne.

(e)

Annual review of the Risk Management Plan.

In addition, the Directors are required to complete the following risk management tasks: (1)

Consult with the Compliance Manager to ensure risk management activities are undertaken.

(2)

Ensure resources are available to facilitate adequate training and ongoing assistance to facilitate risk management activities outlined in this document.

(3)

Review Cremorne reports and make recommendations via the Board concerning prioritisation, risk reviews / audits, adequacy and assessment of selected treatment options and acceptable risk levels.

(4)

Monitor acceptable risk levels determined by Cremorne.

(5)

Make recommendations for risk reviews and audits.

(6)

Assess all compliance and risk management reporting to determine whether Cremorne is continuing to comply with licence and corporate obligations.

(7)

Ensure fair and prudent process for individual mandate compliance.

Cremorne Capital Limited

Risk Management Plan

Page 13 of 27


CONFIDENTIAL – INTERNAL USE ONLY

10.3 Compliance Manager (c)

(d)

Cremorne’s Compliance Manager (incorporating risk management) is required to complete the following risk management tasks: (1)

Provide adequate training and ongoing assistance to facilitate risk management activities outlined in this document.

(2)

Collate Cremorne reports and make recommendations to the Compliance Committee concerning prioritisation, risk reviews / audits, adequacy and assessment of selected treatment options and acceptable risk levels.

(3)

Ensure that the Compliance Committee is included in the risk reporting process (e.g., projects and strategic risks).

(4)

Assess and maintain a risk register in relation to any projects.

(5)

Ensure fair and prudent process for individual mandate compliance

Cremorne’s Compliance Manager is required to complete the following reporting requirements: (1)

Provide reports as requested by the Board.

(2)

Provide reports as requested by the Compliance Committee.

10.4 Key Service Providers Key Service Providers are required to complete the following risk management tasks: (1)

Identify the key processes carried out by their business.

(2)

Identify risks specific to the business that may affect Cremorne.

(3)

Ensure staff undergo appropriate training.

Key Service Providers are required to complete the following reporting requirements: (4)

Provide input as required by the Compliance Committee for the completion of a Risk Management Plan.

(5)

Provide updates as required to the Compliance Manager of the compliance with relevant contracts held with Cremorne.

Cremorne Capital Limited

Risk Management Plan

Page 14 of 27


CONFIDENTIAL – INTERNAL USE ONLY

11 Risk Management Tools A Risk Treatment and Action Plan template is included at Section 12 of this document. Refer to Annexures C to F for documents that Cremorne can use to record its risk assessments and analysis of existing controls. It is important that these spread sheets/templates are used appropriately as they provide an audit trail of analysis and determinations. The completed Risk Treatment and Action Plan is a separate document reviewed by the Compliance Manager and Board on a quarterly basis.

Cremorne Capital Limited

Risk Management Plan

Page 15 of 27


CONFIDENTIAL – INTERNAL USE ONLY

12 Risk Treatment and Action Plan (template) Clients Risk Description Risk #

Risk Classification

1

Market

Causes  Consequences  Impact

Likelihood

Inherent Risk Rating

Control Description  Action Plans  Responsible Person/s

Risk Tolerance (Inherent Risk):

Cremorne Capital Limited

Risk Management Plan

Page 16 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Annexure A – Continuous Risk Management Diagram

Controls - Design, Execute & Reassess

Risk Identification

Risk Analysis

Risk Monitoring, Review, Reassess

Risk Mitigation

Risk Evaluation

Cremorne Capital Limited

Risk Management Plan

Page 17 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Annexure B – Organisational Chart

ASIC

HVT Land Scheme Fund Administrator

Board

Terrain Capital Ltd

Compliance Plan Auditor

Compliance Committee

Secretarial / Accounting Terrain Capital Ltd

Compliance Manager

Forestry Management AMAT Pty Ltd

Scheme Accounting - LRF Lowell Accounting Services Pty Ltd

Investment Management - LRF Lowell Resources Funds Management Ltd

External service providers are used for the provision of unit registry, accounting, fund administration & land management

Unit Registry - LRF Security Transfer Registrars Pty Ltd

External service providers

Cremorne Capital Limited

Risk Management Plan

Page 18 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Annexure C – Other Risk Management Terms This section summarises a number of other terms used in risk management. The terms and definitions are derived from AS/NZA 4360:2004 – Risk Management. Sources of Risk

Explanation

Human Resources

Succession planning, ensure correct skills mix, enterprising bargaining, EEO, OH&S, key staff, terminations, behavioural, contractors, management, company policies, working environment, ability to attract desired staff

Operational

Poor client service, scheduling/planning, lack of resources/equipment

Contractual/Legal

Breach of legislation, breach of contracts, loose contracts, lack of monitoring of contracts, director’s responsibilities, statutory reporting, public liability

Financial

Audit risk, business interruption, fraud, funds availability, bad debts, inaccurate accounting/reporting systems, asset/liability management, over reliance on a small number of clients, no business development, poor cash flow

Key Staff

Lack of succession planning, disaster impact (e.g. accident, death), epidemic amongst staff, terrorism/targeted attack, natural disasters, community impact (e.g. majority of staff/key staff residing in one community), power/water cuts, exposure to hazards, pollution, illness

Political Change

Change in government, change in direction/policy

Technological

Loss of advantage against competitors, lack of innovation leading to costly maintenance or obsolete manual processes

Economic/Marketing

Lack of strategic direction and communication to sales staff, lack of understanding of market and competitors, brand confusion, undetected changes in market requirements, product mismatch

Cremorne Capital Limited

Risk Management Plan

Page 19 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Annexure D – Rating of Risks Risks are assigned an overall risk rating of Low, Moderate, High or Extreme. Each risk rating represents a combination of the likelihood that the risk will eventuate combined with the potential impact of the risk if it eventuates.

Likelihood Risk Likelihood (over 5 years)

Definitions of Likelihood

Percentage Range (guide only)

Almost certain

Will occur in most circumstances

90-100%

Likely

Will probably occur at least once

60-90%

Moderate

Is expected to occur at some time

15-60%

Unlikely

Not expected to occur but could occur in some circumstances

5-15%

Rare

May only occur in exceptional circumstances

0-5%

Cremorne Capital Limited

Risk Management Plan

Page 20 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Determination of Impact Insignificant

Minor

Moderate

Major

Extreme

Revenue Stream

Less than $10,000

$10,000 to $50,000

$50,000 to $500,000

$500,000 to $1,000,000

$1,000,000 +

Safety

First aid treatment

Medical treatment

Extensive injury

Death

Multiple deaths

Asset & Resource

Less than $10,000

$10,000 to $50,000

$50,000 to $250,000

$250,000 to $500,000

$500,000 +

Professional Liability

Threats of claims

Difficulties in obtaining insurance

Minor court action

Long-term court action with substantial costs

Damages awarded against the Company

Reputation

Letter to local/state press

Articles in local/state news

Extended negative local/state coverage

Short term nationwide negative media coverage

Extensive long term media coverage

Regulatory

Minor administrative breach by single staff member

No fine and no disruption

Fine but no disruption

Fine and disruption

Significant disruption

Management Effort

Event absorbed by normal activity

Management effort required to minimise impact of event

Significant event that is capable of being managed

Critical event capable of being endured

Disaster leading to collapse of business.

Technological

Short term system failure > 1 hour

Day long failure > 1 day

Substantial system failure requiring repairs and down time

Loss of information on failure of back-up tape > 2 days

Sustained systems failure and loss of data resulting in loss of clients

Cremorne Capital Limited

Risk Management Plan

Page 21 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Risk Rating As identified above, the risk ratings represent a combination of the likelihood ratings and the impact ratings as follows:

Likelihood

Impact Insignificant

Minor

Moderate

Major

Extreme

Almost Certain

Moderate

High

Extreme

Extreme

Extreme

Likely

Moderate

Moderate

High

Extreme

Extreme

Moderate

Low

Moderate

Moderate

High

Extreme

Unlikely

Low

Low

Moderate

Moderate

High

Rare

Low

Low

Low

Moderate

Moderate

Cremorne Capital Limited

Risk Management Plan

Page 22 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Annexure E – Line of Business Risk Management Tools (template) Risk Register Date of Risk Review Compiled by Reviewed by

Function/Activity: Describe the function or activity under assessment (e.g. adding new scheme, adequacy of financial resources, etc.)

This page is used to describe the function being assessed. Ideally, the page would have the indicative details (e.g. date of review and signatures) as well as a flow chart or process map describing the function under assessment. This would be attached to the risk analysis page.

Cremorne Capital Limited

Risk Management Plan

Page 23 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Annexure F – Annual Risk Assessment Report (template) This document is a Cremorne reporting requirement. Instructions: 1.

Select the risk categories that apply to Cremorne.

2.

For each of those categories selected, rate the risk environment in Cremorne using the categories below: Inherent Risk

Risk Management System Conclusion

Direction of Residual Risk

High

Strong

Increasing

Moderately High

Adequate

Stable

Moderate

Weak

Decreasing

Moderately Low Low 3.

If within any Category, the Quantity of Risk, Quality of Risk Management, Level of Residual Risk or Direction of Risk has changed since the last report, complete “changes” box.

4.

Provide an explanation for why the risk element has changed (short form in table) at the bottom of the page.

5.

Under Item 1, Line of Business Metrics, provide details of your conclusion regarding the quality of risk management.

6.

Under Item 2, Business Line Metrics, discuss and lowly rated audits, regulatory criticisms, control breakdowns or dollar losses outside the normal course of business.

7.

Under Items 3 & 4, Line of Business Metrics, provide business unit metrics related to the business unit’s risk categories.

8.

Obtain the signature of the Compliance Manager and date the form. Send a copy of the form to the Board.

Compliance Manager:

_______________________________

Signature:

_______________________________

Cremorne Capital Limited

Risk Management Plan

Page 24 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Risk Category

Inherent Risk

Risk Management System Conclusion

Direction of Residual Risk

Changes? Y/N. If Yes, provide details.

Compliance Credit Data security Fiduciary Liquidity Market Operational Reputation Transactional

Cremorne Capital Limited

Risk Management Plan

Page 25 of 27


CONFIDENTIAL – INTERNAL USE ONLY

Business Metrics 1.

Assess the overall quality of the business’ control components:

Strong

Adequate

Weak

Policies Processes Personnel Control Systems

Changes to policies, processes, personnel, and/or control systems since last report:

2.

Since the last report, has the business experienced either:

Control Breakdowns

Lowly Rated Audit (Qualified Audit)

Dollar Losses (outside the

Regulatory Criticism

ordinary course of business)

Control Gaps

Details/steps taken to address:

Cremorne Capital Limited

Risk Management Plan

Page 26 of 27


CONFIDENTIAL – INTERNAL USE ONLY

3.

What are the key reports reviewed by the Compliance Manager to assure that the business is operating appropriately?

4.

Using those reports, provide information on the business unit’s key indicators.

Attach pages as necessary.

Cremorne Capital Limited

Risk Management Plan

Page 27 of 27


Turn static files into dynamic content formats.

Create a flipbook
Policy 600 2 risk management plan 2018 by Cremorne Capital - Issuu