Manni Group improves decision making and operational efficiency through an integrated approach
Challenges
- Breaking silos and improving communication between the different legal entities of the group
- Implementing a modern approach to internal control assessment and risk management
- Creating a shared repository to ensure visibility on controls and assessments
- Reducing the time of control activities
Results
- Standardization of risk and control processes
- Optimization of communication between functions
- Process automation
The size of Manni Group Holding, with a global presence in several countries, requires an integrated method for assessing risks and controls. Internal audit activities only began in 2016, replacing what was previously called "management control" and thus creating the Internal Audit function, which did not exist before. The latter is one of the reasons why the methodology used by the group presented various difficulties. The approach used to evaluate controls was outdated; the assessment was carried out using questionnaires created using different Excel and Word files.
Breaking silos and modernizing risk assessment activities
The Internal Audit and Risk Management functions were treated as two separate functions, although the work carried out by the two functions was interconnected. The risk manager's role was to assess risks, while the internal auditor was responsible for determining the maturity of controls. The workflow of the risk management activities was not automated, all risks were recorded in Excel, and each control associated with that risk had to be searched manually for each company group involved. As a result, the different functions worked in silos, leading to costly results in both time and efficiency.
This methodology also entailed many risks related to the security of the information stored in the files. This reason and the others mentioned above have led Manni Group to initiate a process of progressive integration between Risk Management, Internal Audit, and Internal Control activities. To improve processes and obtain shared visibility of risk management activities, Manni Group had to implement a methodology to:
- Manage risks in a holistic and structured way
- Promote a risk-aware culture
- Reduce time to value
- Standardize operations
- Improve communication between different legal entities of the group
An integrated methodology to optimize risk management processes
In 2020, Manni Group realized that it could not achieve a structured and integrated risk management methodology without its business processes' modernization and digitalization.
For the project, Manni Group conducted an intensive search, evaluating all alternatives to find the solution that was deemed most inherent to the Manni Group workflow. HOPEX Integrated Risk Management (IRM) suited the best Manni Group's working method, allowing them to maintain their methodology while optimizing their risk management processes.
Given the size of the group, the stakeholders involved in the audit and risk processes interacted with dozens of risk owners each day located in different locations. With the solution, they can dialogue with the risk owners through simplified questionnaires to which the different functions had to respond.
Manni Group's main objective was to have a more integrated and structured system. HOPEX allowed them to have detailed reports of 5 main attributes identified by the client: organization, controls, risks, processes, and management. The solution builds a dense network the user can shape until obtaining a representative description of the organization's ecosystem.
The group also had additional customizations when needed at its disposal, including duplication of controls to associate multiple questionnaires, which created a more articulated system.
With this integrated methodology, all the requirements have been met:
- Ability to have risks, controls, and processes in a single repository
- A flexible and customizable solution
- Simplified collaboration between all Risk Management functions
- Automation of reports generated by the system
“MEGA shows constant development and solution innovation which to me, from a customer point of view, leaves me feeling secured. A team that is committed and passionate, displaying a human side with great added value.”
Michele Breda, Integrated Risk Manager at Manni Group
Standardizing audit processes
The project was implemented in fewer days thanks to an agile approach characterized by initial workshops to define objectives and methodologies. In just six months, 12 internal audit campaigns have been created, 100 questionnaires sent out, and most have already been answered.
The standardization of audit processes and the structure given to work has reduced time and boosted productivity. Information shared between control functions and risk managers is now structured and functional due to communication optimization.
Manni Group now has a holistic and shared view of all the mitigation plans related to the controls that have been assessed - instead of having several Excel files for each session. HOPEX IRM has made it possible to have all mitigation plans on one screen in a shared repository (e.g., open, closed, expired, high priority/low priority), creating a system that allows users to create a network of processes and have a more optimal and efficient structure.
Simplifying Business Processes to reduce risks
The project's next step is concerned with the segregation of duties in which the main user has visibility on all questionnaires and processes of all users to ensure a higher security level within the organization. Following this implementation, access will also be given to contributors (users), making the information in HOPEX accessible to all functions according to the security level assigned.
To further ensure risks are mitigated and improve efficiency, future objectives include integration with SAP Solution Manager to import the main KRIs (Key Risk Indicators) into HOPEX and the access of Risk Owners to the system according to a Segregation of Duties logic.
Next Steps
- SAP Solution Manager Integration
- Segregation of duties
Solutions
- HOPEX Integrated Risk Management
- HOPEX Business Process Analysis
- HOPEX Platform
- MEGA Services Team