Program Management
Example BoK 7 PgM #1
1. What was performed?
- The managing of the DR program is under the responsibility of the Operational Risk Department. Our DR initiatives are embedded as part of the Operational Risk Framework and Policy.
2. When was it done?
- December 20x7 ended mid-May 20x0 and
3. How was it carried out?
-
From January 20x7 till January 20x0
-
Risk Control Self-assessment, Loss Event Reporting and Key Risk indicators
Among my job responsibilities, I had to ensure that the risk control self-assessment, Loss event reporting and Key Risk indicators are being implemented and maintained properly during the years. Business Continuity risk and event are part of this update and reporting.
The major following ups have to be done to capture all the Key Risk Indicators and random verification checks in being done to ensure that the results are genuine on monthly basis. -
January 20x8 – Ongoing
-
Training of Coordinator
Regular semi-annual DR training is been carried out to reinforce the framework implementations and assist in addressing any type of doubts and confusion.
The DR training and awareness exercise is being conducted and the objectives are explained every year to the staff participating to ensure the success of the exercise and serve as a reminder.
The DR Policy is part of the Operational Risk Policy. The Operational Risk Department performs an annual gap analysis on Operational Risk Policy to ensure that the department is performing as per policy. As reinforcement, the Internal Audit department is auditing the Operational Risk Framework on annual basis as well. -
January 20x9 – Ongoing
-
Testing of Operational Risk Reporting
Currently, every department has a designated Operational Risk Coordinator which needs to ensure that all loss events are being reported to Operational Risk and ensures the success of the Risk Control Self Assessment exercise
A semi-annual workshop is being held for all Operational Risk Coordinators (also responsible for business continuity) to help maintain the Operational Risk framework within their departments. As a testing mechanism, a specific department every quarter needs to participate in a meeting with the top management to demonstrate the effectiveness of the framework and how it is implemented. -
January 20x1 – Ongoing
-
Management Reporting
The Operational Risk department also prepares a Management Information Report that is submitted on a monthly basis to demonstrate to the management the department critical performance indicators. - March 20x0 – Ongoing
- Program Management Process
I have developed the DR Program Management process during March 20x0 with management approval that will be used to sustain and update the different stages of the DR program. This DR plan includes cycle testing and exercises that increase in complexity after each test to assist departments in being prepared for different types of disasters.
At this stage, we have assigned the committees that will be leading the bank during a disaster and they have got the appropriate training and guidance to ensure they can perform as expected during April 20x0. Also, BU DR Coordinators for each department has been assigned and their role during May 2010. Their role will be to ensure that the BIAs, RAs and call trees are being maintained and kept up to date. As one of their many responsibilities, they would need to increase the awareness in their departments by applying what is being discussed during the quarterly Business Continuity meetings prepared and done by Operational Risk. - From June 20x1 ongoing
- Call Tree Exercise
The Call Tree tests have been initiated after developing the hierarchy for each department and having an awareness meeting with all the departments to introduce the concept. The test went better than expected as the passing percentage has reached more than 60% of the total bank departments. - From June 20x1 ongoing
- Awareness
An Awareness meeting has been conducted with respective departments to guide them on how to populate and update the BIAs and RAs for their departments. Another meeting is scheduled during December to ensure that BIAs and RAs are up to date at all times.