Member question: âHas anyone, recently or in the past, conducted broad wide-scale open-ended (i.e., not scripted Q&A) risk interviews of top management and leaders as the primary means to collect risk-identification inputs?
- âI am looking to share thoughts and experiences regarding the effectiveness, as well as methods to summarize, quantify and present the key findings.
- âI have interviewed board members, executive staff, management VPs+, totaling in the range of 75-100 one-on-one discussions. I am seeking recommendations on the process.â
Peer answer 1: âYes, I use this process. Two years ago, we implemented an âintegratedâ risk discussion process where the chief audit executive (CAE), chief compliance officer (CCO) and chief information security officer (CISO) jointly meet with leaders across the org.
- âWe aggregate our key takeaways in a PowerPoint deck and organize them by main themes (for example Covid-19 was a main risk theme last year).
- âPrior to me joining audit, they used a survey for a period of time and had difficulty getting responses and/or the quality of information was not as good as that obtained through face-to -face meetings.â
Peer answer 2: âWe do an annual assessment in which we ask leaders to select from a 22-risk framework and have the leaders provide narrative responses. Not individual interviews, however.â
Peer answer 3: âWe are in the midst of this process right now, so weâre very much in learning mode. Our interviews will be complete in mid-July, and weâll be summarizing the inputs and presenting in September. Happy to share our experiences and ideas.â