NAVEX > Case Studies > Fintech Company Strengthens Its Lines of Defense with NAVEX IRM

Fintech Company Strengthens Its Lines of Defense with NAVEX IRM

NAVEX Logo
Company Size
1,000+
Product
  • NAVEX IRM
Tech Stack
  • Risk Management Software
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Digital Expertise
  • Productivity Improvements
Technology Category
  • Application Infrastructure & Middleware - Data Exchange & Integration
Applicable Industries
  • Finance & Insurance
Applicable Functions
  • Business Operation
Services
  • System Integration
About The Customer
The customer is a fintech company looking to expand into consumer-facing technology. They have a strong internal audit program that identifies breakdowns and gaps within the organization. However, these issues were not always getting the attention they deserved across the rest of the organization. The management of risks associated with daily operational activities was weak, leading to low audit ratings. Stakeholders were concerned whether the business could make risk-based decisions necessary to safely implement cutting-edge fintech. The company has over 1,000 employees.
The Challenge
The fintech company was looking to expand into consumer-facing technology, but they had to address their processes for identifying, mitigating, and reducing risk. They had a strong internal audit program, but the issues identified were not getting the necessary attention across the organization. The management of risks associated with daily operational activities was weak, leading to low audit ratings. Stakeholders were concerned whether the business could make risk-based decisions necessary to safely implement cutting-edge fintech. The organization’s management committee charged their risk management function with building a traditional three-lines of defense program. This meant cultivating accountability and ownership at the first line of the business, where risks are introduced to the organization. It required standing up a true second-line defense reporting to the Chief Risk Officer. Most importantly, it necessitated a risk culture in which everyone is responsible for identifying and reporting issues.
The Solution
To meet the mandate of building a traditional three-lines of defense program, the fintech company started by plotting processes and mapping out how they wanted to manage self-identified issues (SII) and risks. They quickly recognized the importance of utilizing a purpose-built solution and selected NAVEX IRM. The key to their decision was NAVEX IRM’s ability to centralize and automate processes. They were able to build records right into NAVEX IRM’s platform, resulting in the capture of additional information for root cause analysis and addressing emergent issues. The organization also developed new workflows that allowed executives to accept some risks when appropriate, and dashboards that helped first-line defense employees take increased ownership.
Operational Impact
  • Improved internal audit ratings by identifying and remediating issues at the very first line of the business.
  • First-line employees now own and manage operational risks. They conduct risk assessments, participate in risk roundtables, and receive training on how to use the dashboards and tools available to them.
  • Implemented second lines of defense, including Ethics and Compliance, Operational Risk Management, Business Continuity, and Privacy Officers, all reporting up to the Chief Risk Officer.
  • Created a risk-aware culture built around prioritizing and adopting the work they put into their lines of defense.
Quantitative Benefit
  • Substantial decrease in the number of internal audit findings and issues to remediate.
  • Decreases in self-reported issues as the organization became better at proactively managing risks.
  • Reduced the number of resources required to drive success.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.