×
Case Study

Fragrances and Flavors Manufacturer Enhances Harmonization and Agility in Risk Mitigation and Issue Resolution with MetricStream

A multinational manufacturer of fragrances and flavors for home, personal, beauty care, and the food industry, wanted to structure and organize all risk management processes and activities. The company was struggling to meet its risk management requirements with excel spreadsheets. It identified the need to implement a unified tool for better management of all risk-related activities at the enterprise level.

The company chose MetricStream to achieve these goals and revamp its risk management program. Since 2020, the customer is using MetricStream Enterprise Risk Management, built on the MetricStream platform and running on the Amazon Web Services (AWS) cloud, and has successfully automated its risk processes.

Industry

Manufacturing

Product

Solution

Enterprise GRC

From Scattered and Siloed to Standardized and Streamlined

With its presence in over 145 locations, the company started building business continuity plan strategies globally couple of years ago. In the process, it realized the need to manage operational risks to limit the likelihood of any business disruption.

As an initial approach, the company started managing operational risks with excel spreadsheets, rolling them out to all sites. However, the approach soon turned out to be inefficient as it became extremely difficult to manage risks, do consolidations, define mitigation strategies, in addition to roles, responsibilities, and ownerships through individual excel spreadsheets.

The company was also struggling with disparate risk definitions and siloed processes.

To overcome these challenges, the company started looking for a structured and organized risk management tool to consolidate all risk registers and streamline risk and issue management with clear action plans and ownerships. The company chose MetricStream for its ability to facilitate automated workflows and streamlined processes and establish a centralized data model that helps storing all risk and control data at a central place.

The Implementation

The company implemented MetricStream Enterprise Risk Management out-of-the-box and mapped the processes of risk management teams to it. As a result, it has benefited from common risk language and taxonomy with standardized definitions across the organization. There is improved accuracy of data leading to increased harmonization and agility in risk mitigation and issue resolution. The company has also gained increased visibility into risks and key issues with clear and faster reporting.

“Keeping the solution simple was one of our main criteria for selecting an ERM/ORM solution. The ease of use of the MetricStream product is what caught our attention as well as the fact we can evolve to more complex structures when we will be mature enough. The implementation has helped us strengthen decision-making process with clearer visibility into key risk areas and effectiveness of controls,” the Chief Risk Officer at the company said.

Common Risk Taxonomy and Centralized Repository

Previously, the company had inconsistent risk taxonomies and definitions which led to limited visibility and understanding of risks by different business units. In addition, siloed systems and processes and use of spreadsheets made data normalization and aggregation extremely difficult, resulting in incomprehensive information which hampered overall risk identification and mitigation activities.

Using MetricStream, the company was able to standardize risk taxonomy across the enterprise, which facilitated a cross-organizational risk understanding. In addition, a centralized risk repository, which maps risks to policies and controls, provided a single source of truth and a 360-degree view of the organization’s overall risk and compliance posture. The clarification of roles, responsibilities, and accountability has further strengthened the effective enforcement of risk management program and standardization.
 

Challenge

  • Lack of consistent risk taxonomy
  • Multiple disparate and siloed systems and processes
  • No standardized and harmonized risk reporting
  • Dependency on basic office software

Business Value Realized

 

Common risk language and single source of truth

 

Identical risk reporting at any level of the organization / location

 

Streamlined issue and mitigation actions management

 

Unified tool for managing various risks, improved accuracy of risk data, and enhanced risk visibility

 

Better Risk Reporting

Earlier, the company lacked complete visibility into risks with each location and business unit having their own way of risk reporting. With the implementation of the MetricStream product, it now has standardized reporting across all organizational levels and locations. With MetricStream’s multi-dimensional risk aggregation and other dashboards, the senior management and board now have better risk visibility at multiple levels of organizational hierarchy as well as at the enterprise level. They are also better equipped to quickly identify the underlying factors for risk events and take better decisions on risk mitigation plans by knowing control effectiveness.

In addition, interactive dashboards, advanced heat maps, and reports offer the company deeper risk insights, thereby strengthening its risk foresight and driving agility and risk-based decision making.

Integrated Risk Management Approach & Flexible Risk Assessments

Previously, the company had several different ways of managing risks--every single function performed risk assessments on their own with their own definitions-- which often led to inconsistencies and redundancies. With MetricStream, it now has all cross-functional risks and associated details such as risk description, category, hierarchy, and ownership at one place, which has helped streamline the risk assessment and management process.

The company aims to implement MetricStream in all other functions that are still using spreadsheets. MetricStream technology will enable it to have different risk assessments models and algorithms, which will help meet the majority of the risk management needs.

Streamlined Issue Management

With MetricStream, the company now has a systematic issue management process which streamlines documenting, investigating, and resolving all issues related to risk, compliance, and controls. It has improved visibility on the issues faced either in sites or across the organization at any level. As a result, it has become much easier to define relevant mitigation actions and see their positive impact on the next risk assessments.

Conclusion

Overall, MetricStream has helped the company to effectively tackle risks by enhancing the harmonization and agility in risk mitigation, issue resolution, and mitigation actions processes. In addition, increased visibility into risks and key issues with clear identification and faster reporting has bolstered partner confidence in the company.

“Facing different types of risks on a daily basis is part and parcel of doing business. MetricStream’s centralized and automated approach has helped us gain a comprehensive view into cross-functional risks and understand risk relationships and accountabilities, thereby enabling us to make risk-aware business decisions,” the Chief Risk Officer at the company added.

Related Stories

Case Study

Leading International Energy Services Company Improves Resilience With Faster, Better Visibility Into Risks

Case Study

Top Entertainment Company Digitally Transforms Internal Audit, Risk, and Compliance Management to Thrive on Risk With MetricStream

Case Study

A Leading South African Financial Services Group Embarks On Digitized GRC Journey To Strengthen Combined Assurance Framework With MetricStream

lets-talk-img

Ready to get started?

Speak to our experts Let’s talk