Risk Management Products

Included in this section:

Downloads for ERA Risk Management software by Methodware

Review of RiskLabs RMIS (all good!)

Tripwire in action, using Change Management to control risk: The Movie

Gartner provides to paying clients, comprehensive review of risk management products.  Although we were happy to see all the products we like in their top right quadrant, we can't link to the report.  Some of the clients reviewed have posted the document.  Since we feel it is meant to be paid for, we are not posting the Gartner link.

Aon RiskConsole Aon RiskConsole download  Paisley Risk Navigator  - download Providus RiskResolve download ORM/Resolver by FRS

NISTPUBS NIST Special Publications (NIST 53A Guidance from Dr. Stu Katz)

Are your tools as robust as required in your audit universe?

Methodware  ERA
Enterprise Risk Advisor Please can I get a demo

Enterprise Risk Assessor (ERA) provides your organisation with:

  • the ability to automate all aspects of your risk approach to include Operational Risk Management, Project Risk Management etc within one dynamic tool
  • a risk framework tailored to your organisational needs
  • a shared central repository that can be accessed by Risk Managers, Business Managers, the Board, Internal Auditors, and all other stakeholders
  • consolidation, tracking and monitoring of your risk and audit information over time
  • a record of Loss Incidents and Near Misses plotted against risks
  • the ability to track Key Risk Performance Indicators

SARBANES-OXLEY Implementation Guide using Enterprise Risk Assessor

ClientServerMethodware

About Methodware

Methodware specializes in providing software for Risk Management, Operational Risk Management, Enterprise-wide Risk Management, Internal Audit, and Financial Institution Risk Management. Methodware was established in 1993 and for more than a decade Methodware has been developing and supplying internal audit software solutions and risk management software solutions to organizations worldwide. Methodware has an established Partner network, and Methodware's software can be made available in most European languages. We can meet your company's risk management and/or internal audit needs no matter your company's location or organization size. Methodware's software for Risk Management, and Methodware's software for Internal Audit incorporates industry recognized standards and guidelines including:

Methodware has developed risk management and internal audit software using consultants who have real life experience in Risk Management or Internal Auditing to ensure that it is relevant to your company and industry requirements.

Requirements

  • Methodware Software Requirements:Operating System Requirements
  • Methodware software solutions run under the following operating systems:Windows® 98/2000/2003/XP/NT 4.0*
    *Note - fORM and ERA require NT 4.0, Windows 2000 or XP operating systems.Hardware
  • Requirements
  • Pentium II processor
  • 128MB or higher of available RAM
  • 100MB free disk space
  • Software Requirements
  • Methodware Software integrates with:Microsoft® Word 97 or higher
  • Microsoft® Excel 95 or higher
  • Netscape 4.0 or higher/Internet Explorer 4.0 or higher    (download: below)

Have you narrowed and refined your RegWatch™?  Can you manage and respond to your specific industry and internal corporations validated and evaluated risk?

Maybe you need RMIS support.  In that case, you need to know about RiskLabs.

RiskLabsRiskConsole

We believe you MUST NOT skip understanding, trying and implementing AON-Risklab's RiskConsole.

Scalable, managable, intuitive, developed and managed by an entirely US based seasoned development team, you will quickly fall in love with this platform and suite of product.  As fast as you can identify the rules and values of risk in your business, the client services team is there to assist your immediate control over business impacting events.

RiskConsole is the core product of AON RiskLabs.  Sometimes referred to as “Console”, the platform is used both internally by business units including Information Technology, and externally by AON clients. RiskConsole is a web-based Risk Management Information System (RMIS) that uses claim, exposure, policy, and other risk-  related data to provide risk managers with a comprehensive view of their organization's risk. The RiskLabs Data Center provides highly available Internet-based solutions for   the risk management industry. These service offerings include sufficient bandwidth to suport large organization use, secure per user authentication, encryption of all system   traffic, delivery of HTML system interface, as well as storage and management of confidential client data. RiskConsole integrity, functionality and availability is the primary   goal for all of Information Technology.  RiskConsole uptime is above 99.9%, and with highly structured maintenance agreements between AON and it’s clients.  System  enhancements and optimization is a full time committement at AON RiskLabs.  Product Management works through committee to capture and respond to all client  requirements, requests and concerns.  Changes to the RiskConsole platform are controlled by formal Product Management Release and approved Change Management.
 
Aon RiskConsole RMIS software meets the challenge of being both highly secure and configurable based in customized needs ("user-friendly"). It is one of a variety of client  applications including AonLine, Risk Control, and Enterprise Risk Management, all managed by  a Aon eSolutions. Aon RiskConsole is a risk management system designed    to reduce an organization's overall costs and improve their risk management practices.  Within RiskLabs, RiskConsole is a part of internal IT operations, where the product is used to capture many enterprise functions to include Support Management, Risk Management, Internal Controls Assessment and Change Management. RiskConsole products include a series of integrated modules, which have been designed to accommodate the administrative, reporting, and analytical needs of sophisticated  insurance and risk management operations. These modules are centered on the "Organization module", which includes details on the corporate reporting structure, activities, and roles. This structure enables drill-down analysis of corporate data, including operational data such as payroll, turnover, etc.

  • The Claims module provides access to all claim records.
  • The Fleet module stores information, including vehicles, drivers, driver training, and finance companies.
  • The Policy module provides a basic policy-tracking tool and a comprehensive program management facility.
  • The Litigation module stores legal actions brought against organizations.
  • The Property module stores all construction, occupancy, protection, and exposure information and financial information about each location.
  • The product as defined to the market must provide:
  • One-touch access to key data speeds decision-making
  • Improved communication through distribution of timely risk-related data throughout the organization
  • An enterprise-wide solution for international organizations, including multi-currency and multi-lingual options
  • Maximum return on RMIS investment, thanks to the hands-on, consultative approach of our experienced service team

 

FRS FinancialAnalytics RiskResolveResolver

© Copyright 2005, FRS Belgium. All Rights Reserved. Legal terms & notices.

Operational Risk Management and Sarbanes-Oxley Compliance

In the drive for corporate transparency, accountability and good governance, there is no turning back. The immediate pressures of Sarbanes-Oxley compliance have provided financial institutions with a powerful impetus to enhance visibility and oversight of internal controls.

Basel II offers additional motivation for banks to modernize their risk practices, holding out the promise of reduced economic and regulatory capital requirements. Market forces that create additional risk — such as globalization and time-to-market — further heighten the need for effective risk strategies.

Operational risk management (ORM) identifies, manages and mitigates risks and losses that are associated with people, processes, IT systems and external events. ORM encompasses risks and losses that are associated with compliance initiatives, such as fines for non-compliance.

Moving beyond immediate compliance objectives, financial institutions realize they can no longer treat operational risk, compliance and corporate governance as separate concerns — addressed via "stovepipe" applications or repurposed applications. Instead, institutions are seeking converged ORM solutions that address the shared needs for transparency, mandated financial disclosures and timely reporting across complex organizational structures.

Detecting Risk. Protecting Value.

RiskResolve™ is the first Operational Risk Management (ORM) solution to provide strategic value for protecting financial institutions from unexpected risks and financial losses. Designed expressly for the needs of financial institutions, RiskResolve empowers managers to actively and continuously manage operational risks and controls across all lines of business and at the enterprise level — providing real-time visibility into early warning signals that indicate corrective action may be required.

RiskResolve reflects the intimate knowledge that FRS has of operational risk management and compliance requirements in complex financial institutions. In contrast to single-purpose solutions or repurposed applications, FRS RiskResolve software provides financial institutions with a true enterprise-class solution for scoring, tracking and managing risks and controls in a disciplined, consistent manner. This real-time transparency and reporting of risks, associated controls, as well as control failures and loss events translates into an Active Risk Management™ discipline that aligns with the organization's strategic objectives and risk tolerance levels. This approach sheds unprecedented light on operational risks so that managers can make more informed decisions — improving operational efficiencies and financial performance.

Download the RiskResolve Datasheet

Business Benefits:

  • Provide unprecedented insight, offering executives and business managers with real-time visibility as well as a consolidated, enterprise-wide view of risk exposures, internal controls, and loss events across multiple risk and compliance objectives.
  • Bring a new level of discipline and consistency to risk management, facilitating best practices and timely, systematic execution of risk-management and compliance mandates across complex organizations.
  • Foster a culture of risk awareness and accountability, providing line-of-business managers with the information and tools they need to be active, informed managers of operational risk.
  • Create an Active Risk Management Environment, which combines line-of-business risk assessment with loss data to improve the accuracy of risk exposure estimates, enhance control effectiveness, and continually reduce losses.
  • Strengthen financial performance through the ability to proactively prevent risks by responding to RiskResolve's real-time feedback and insight about a potential risk, the weakness of a control and the impact of a loss event; firms will benefit from a risk-informed culture that promotes awareness and accountability.
  • Accelerate time to value, ensure low TCO, with an open and standards-based solution. RiskResolve is easily deployed into existing environments, with deployments being completed in less than 90 days. The software integrates seamlessly with third-party applications and data sources, allowing institutions to leverage their existing investments without requiring costly, time-consuming integration efforts.

Resolver

CobiT4.0Internal Control and Control Self Assessment 

CobiT® On Line from ISACA and ITGI and CobiT Advisor 3rd Ed from Methodware™

CobiT®.components include:   Other works based on the CobiT®.framework include:
  • Executive Summary
  • Framework
  • Control Objectives
  • Control Practices
  • Audit Guidelines
  • Implementation Tool Set
  • Management Guidelines
 
  • CobiT®.Quickstart™
  • CobiT®.Online®
  • CobiT®.in Academia™
  • CobiT®.Security Baseline™

Grand slams go to the teams producing harmonization and synergy across standards and regulatory requirements. 

CobiT® 4.0 and the recent release of Aligning CobiT®., ITIL® and ISO 17799® for Business Benefit: A Management Briefing, as well as the combined Booz Allen Hamilton, ISACA, ISSA and ASIS release "Convergence of Enterprise Security Organizations"

To paraphrase just a few of the points by Gary Hardy and Erik Guldentops, who introduced CobiT®.4.0 in Volume 6, 2005 Information Systems Control Journal, (Professional publication produced by The Information Systems Audit and Control Association), CobiT®.4.0 adds to the already valuable framework:

  • Business requirements
  • Harmonization—(ITIL®, ISO 17799®, PMBOK® and PRINCE2)
    Value creation—balance between risk and value, draws on recent new research on IT value management.
  • Enterprise architecture—CobiT®.4.0 provides RACI charts (who is Responsible, Accountable, Consulted and Informed) to address process roles and responsibilities for each IT process, and enterprise architecture principles are now explained within the framework, linking goals, resources, information and processes.
  • Process definitions and process flows—To improve understanding of the IT process model, CobiT®.4.0 now contains descriptions of each process together with process inputs and outputs with cross-references to other processes.

"CobiT®.Online is a web-based resource where you can browse and search the very latest best practices, download customized guidance, perform benchmarking and more. A variety of subscription levels are available, each allowing different amounts and types of access and functionality. ISACA membership provides for Basic access rights and discounts on purchasing Full access."

Resources and Publications on Internal Audit:

isaca  iiasmallspacer bsi aicpa  pmi 

Excellence takes teams, time and money:   Pay your dues, buy your tools, because none of us is as smart as all of us...

new Leading IIA Guidance Reports, Papers, and Publications:

Good stuff :

...more links in the security and IT resources section

Special Thanks to Bruce Winters for his article Compliance CHOOSE THE RIGHT TOOLS FOR INTERNAL CONTROL REPORTING Bruce I. Winters New federal regulations require public companies to assess the effectiveness of their internal control structure and financial reporting procedures. Complex software is essential to such analysis. Here’s how to determine what kind is needed and how it should link to—or replace—a company’s existing systems., Dan Swanson, ISACA List Serve Community.  Special Thanks to the IIA and again especially, Dan Swanson, CIA, CMA, CISA, CISSP, CAP, who coauthored with others mentioned on every page of this site in his long and productive career as Director of Professional Practices, The Institute of Internal Auditors. He frequently writes on IT audit, IT security, and various management practices. He is a past Winnipeg chapter president for both The IIA and ISACA and chaired ISACA International's publication committee for two years. Swanson has also been on the Board of Directors of The IIA

JOA   spacerspacerspacerspacer  itgi

iiabanner

ITSMFspacerspacer       cobit

spacerspacer     OGCspacerspacer       spacerspacer    isaca

The following text is directly quoted from ITGI starting at page 6, "Aligning CobiT®. ITIL and ISO 17799 for Business Benefit" © ITGI 2005  - OGC is a UK government organization responsible for procurement and efficiency improvements in the UK public sector. OGC has produced world-class best practice guidance, including PRINCE (project management), MSP (Managing Successful Programs) and ITIL (IT service management). ITIL is used throughout the world and is aligned with the ISO/IEC 20000 international standard in service management. www.ogc.gov.uk

ITGI is a not-for-profit research organization affiliated with the Information Systems Audit and Control Association® (ISACA®), a global not-for-profit professional membership organization focused on IT governance, assurance and security, with more than 47,000 members in more than 140 countries. ITGI undertakes research and publishes CobiT®. an open standard and framework of controls and best practice for IT governance. www.itgi.org

 

Logos belong to affiliated organizations and suggest PB&SP support and sponsorship/ membership. Use of logos is based in written agreement with the third party.  They are not meant to imply ownership, creation or collaboration in any product.  We stand behind experience and consensus among our clients to suggest these highlighted products / organizations are the best audit and compliance resources in the world. We are not paid to advertise and we do not sell software. Westand behind their greatness because we witness their results.

MethodwareProductDownloadsRisk Management Software

More Information Compare these products

ENTERPRISE RISK ASSESSOR Enterprise Risk Management software for organisations requiring a company wide, systemic and consistent approach to operational risk management. [More...]

ENTERPRISE RISK ASSESSORLITE Risk management tool for the single user in charge of risk management or for consultants performing one-off risk assessments. [More...]

ORCAS Operational risk management software tool for organisations that require Basel & FSA compliance. [More...]

Downloading English Demonstration Software Downloading the Spanish engine and Spanish Demonstration Software


DOWNLOADING ENGLISH DEMONSTRATION SOFTWARE

To download English Demonstration Software please simply complete the English Demo Registration Form.

After you have submitted the form, if you select to download only one Demo, a Download window should appear, in which case follow the instructions below. If the download process does not happen automatically, then follow the instructions on the page that appeared after you clicked 'Submit.'

If you selected to download a number of Demos, a Download window should appear with links to each of the demo install files. Simply click on each link and follow the instructions below.

In Internet Explorer: After you have clicked on the link choose the 'Save this program to Disc' option and click 'OK', select the directory on your PC where you want to save the file to (eg, demo_proaudit3.exe) and click 'Save.'

Once the download is complete (ie - you have saved the file to your PC), you then need to run the install file (eg, demo_proaudit3.exe) to install the Demo on your PC. Locate where on your PC you saved the (eg, 'demo_proaudit3.exe') file to, and then double-click on the file to begin the installation of the Demo. At some stage in the installation process you will need to enter a code. Code/s and full installation instructions are included in the email that we send to you within one working day of you having completed the Demo registration form.

Please note - when evaluating our demos please bear in mind the software has had limitations placed in it that do not appear should you purchase the full product - eg you are limited in the number of items you can add into the structure, some reports are limited in the number of items shown on them, etc.


DOWNLOADING THE SPANISH ENGINE AND SPANISH DEMONSTRATION SOFTWARE

The Spanish Demo Methodware Engine needs to be downloaded and then installed on your PC before you can use any of our Spanish Demo software. It helps to power the functionality in our software. Please note - the Spanish Demo Methodware Engine provides less functionality than the Spanish Methodware Engine that is provided when you purchase Methodware software. As a result, when evaluating our demos you are limited in the number of items you can add into the structure, some reports are limited in the number of items shown on them, etc.

If you have already installed the Spanish Demo Methodware Engine on your PC and it was prior to the date listed in the link below, we recommend that you download the most recent Spanish Demo Methodware Engine as shown below. Make sure that you close out of any Methodware applications before you proceed below. To start downloading the install for it please click on the link below:

Download the Spanish Demo Methodware Engine (12 Mb - approx)

To download the engine install from an alternative link on another server click here

In Internet Explorer: After you have clicked on the link choose the 'Save this program to Disc' option and click 'OK', select the directory on your PC where you want to save the file to (install_engineS.exe) and click 'Save.'

Once the download is complete (ie - you have saved the file to your PC), run the install file to install the Spanish Demo Methodware Engine on your PC. Locate where on your PC you saved the 'install_engineS.exe' file to, and then double-click the 'install_engineS.exe' file to begin the installation of the Demo Methodware Engine. After that process is complete, download/install the Demo that you are interested in.

To download Spanish Demonstration Software, please complete the Spanish Demo form and follow the instructions on the form.

After you have submitted the form, if you select to download only one Demo, a Download window should appear, in which case follow the instructions below. If the download process does not happen automatically, then follow the instructions on the page that appeared after you clicked 'Submit.'

If you selected to download a number of Demos, a Download window should appear with links to each of the demo install files. Simply click on the link and follow the instructions below.

In Internet Explorer: After you have clicked on the link choose the 'Save this program to Disc' option and click 'OK', select the directory on your PC where you want to save the file to (eg, demo_proaudit3.exe) and click 'Save.'

Once the download is complete (ie - you have saved the file to your PC), you then need to run the install file (eg, demo_proaudit3.exe) to install the Demo on your PC. Locate where on your PC you saved the (eg, 'demo_proaudit3.exe') file to, and then double-click on the file to begin the installation of the Demo. At some stage in the installation process you will need to enter a code. Code/s and full installation instructions are included in the email that we send to you within one working day of you having completed the Demo regsitration form

Please click here to email Methodware with any questions or comments you have about Methodware products, services, or website. .

Please select Contact PB&SP for US based support in selection of any compliance product as aligned to your unique corporation's needs.

Using Tripwire to manage compliance and reduce risk as defined by CobiT and COSO...the movie

 

Headlines

Visio fails blood test, found to be on Steriods full story...

Visio On Steriods Miccrosoft denies all knowledge IIA releases practice guidelines for risk management full story...

COSO - ERM offers small business guidance on IT Controls and more full story...

ISACA - Harmonization full story...

Announcing successful SAS 70 and a truly great product for managing and measuring risk ... full story

rlbs-rmis

  rlbs-rmis

ERA overview presentation

Resolver

greatideas

Tripwire

CobiT®. 4.0: Major Update to International Standard,  Helps Businesses Increase IT Value, Decrease Risk  full story... and Complimentary Webcast

Proving Control of the Infrastructure: Tripwire full story...