|

A Structured Approach to Assessing Data Risk

Is your organization effectively managing its data risks? Most organizations might, at first glance, answer yes. You may have implemented SOX controls, you may have a mature risk management process in place, and you may have no audit findings related to data risk.

Unfortunately, you may only be seeing the tip of the iceberg (see the blog Knowing What Lies Beneath by my colleague, Steve Zagoudis for more). Data risk management is often not consolidated in one organizational group or coordinated across groups. IT security may be handling access control at the software application level, Legal may be handling content management related to crown jewel data and document retention, IT operations may be assuring availability, backup, and recovery. These are table stakes for data risk management.

What about other data risks?

Are multiple copies of the same data being used in your organization? If so, are known copies of the same data identified? Which copy of data is being used in the financial reports being certified by you or members of your executive team?

  • Is your PII data properly secured? Where are all copies of your PII data?
  • Is confidential data encrypted? Who has access to this data? Where is it located?
  • Does any of your data have quality issues that could impact risk models or financial reporting?
  • What is your riskiest data? That data, if it leaks out of your organization, can cause your organization the most harm, via enabling competitors, legal issues, headline issues, or financial issues. Do you know where that data lives within your organization? Who is responsible for data quality in your organization?
  • Is data quality measured within siloed applications only rather than across the organization?
  • Is responsibility for data assigned or handled at the siloed application level?
  • Is data generated and distributed from user developed applications considered in the risk framework?
  • Are reporting accuracy, currency, and timeliness measured and monitored within your business intelligence environment?

The list could go on.

What can you do?

One way to evaluate the level of data risk in an organization is to measure the standard activities of data management across the standard components of a comprehensive risk framework.

Typical Risk Framework:

  • Responsibilities are established.
  • Policies, procedures, and standards are in place and followed.
  • Management and board oversight is defined and executed.
  • Activities follow procedures and are completed in a timely manner.
  • Risks and issues are identified; metrics are defined and monitored.
  • Risks and issues are reported to responsible parties, ERM, Executive, and Board, according to policies.
  • Risks and issues are mitigated on a timely basis.

(Adapted from Federal Housing Finance Agency Advisory Bulletin AB AB2020-16)

Typical Data Management Activities:

  • Governance and Metadata
  • Data generated and used by user developed applications and models
  • Data Architecture, Modeling, and Integration
  • Data Storage, Availability, and Operations
  • Data Security
  • Documents and Content Management
  • Master, Reference, Warehousing, and BI
  • Data Quality

(Adapted from Federal Housing Finance Agency Advisory Bulletin AB AB2016-04, Data Management and Usage and DAMA-DMKOK Data Management Body of Knowledge, Second Edition)

In the typical risk assessment, one measures the likelihood of a risk event within a management function along with the impact of the event. In the case of data management, another important consideration is the expected timing of the event. Some risks are more likely to occur in the short term. Other risks can occur if some management activity is neglected over a longer period. The impact of these longer-term risks may be different than the short-term risks.

Getting your mind around all these dimensions of data risk can be daunting.

MetaGovernance, through years of experience, has developed an easy-to-use risk assessment tool based on the dimensions referenced above to help you evaluate the degree to which you are managing your data risk.

The tool provides you with a quick assessment tool. We also include a more detailed assessment if you are interested in taking a deeper dive into your data risk gaps and exposures. The more detailed assessment has been cross-referenced with standards created by the National Institute of Standards and Technology (NIST) as well as the Federal Housing Finance Agency Advisory Bulletins cited above.

We encourage you to take 15 minutes to evaluate your current data risk profile. The tool is available to download here.

If you would like to discuss the results of your risk profile or seek advice on next steps once you have completed the assessment, click here.

Similar Posts