Ce que chaque administrateur de sociétés devrait savoir à propos de la sécurité infonuagique


Cet article est basé sur un rapport de recherche de Paul A. Ferrillo, avocat conseil chez Weil, Gotshal & Manges, et de Dave Burg et Aaron Philipp de PricewaterhouseCoopers. Les auteurs présentent une conceptualisation des facteurs infonuagiques (cloud computing) qui influencent les entreprises, en particulier les comportements de leurs administrateurs.

L’article donne une définition du phénomène infonuagique et montre comment les conseils d’administration sont interpellés par les risques que peuvent constituer les cyber-attaques. En fait, la partie la plus intéressante de l’article consiste à mieux comprendre, ce que les auteurs appellent, la « Gouvernance infonuagique » (Cloud Cyber Governance).

L’article propose plusieurs questions critiques que les administrateurs doivent adresser à la direction de l’entreprise. Vous trouverez, ci-dessous, les points saillants de cet article lequel devrait intéresser les administrateurs préoccupés par les aspects de sécurité des opérations infonuagiques. Bonne lecture !

 

Cloud Cyber Security: What Every Director Needs to Know

« There are four competing business propositions affecting most American businesses today. Think of them as four freight trains on different tracks headed for a four-way stop signal at fiber optic speed.

First, with a significant potential for cost savings, American business has adopted cloud computing as an efficient and effective way to manage countless bytes of data from remote locations at costs that would be unheard of if they were forced to store their data on hard servers. According to one report, “In September 2013, International Data Corporation predicted that, between 2013 and 2017, spending on pubic IT cloud computing will experience a compound annual growth of 23.5%.” Another report noted, “By 2014, cloud computing is expected to become a $150 billion industry. And for good reason—whether users are on a desktop computer or mobile device, the cloud provides instant access to data anytime, anywhere there is an Internet connection.”

IMG_20140219_205959

The second freight train is data security. Making your enterprise’s information easier for you to access and analyze also potentially makes it easier for others to do, too. 2013 and 2014 have been the years of “the big data breach,” with millions of personal data and information records stolen by hackers. Respondents to the 2014 Global State of Information Security® Survey reported a 25% increase in detected security incidents over 2012 and a 45% increase compared to 2011. Though larger breaches at global retailers are extremely well known, what is less known is that cloud providers are not immune from attack. Witness the cyber breach against a file sharing cloud provider that was perpetrated by lax password security and which caused a spam attack on its customers. “The message is that cyber criminals, just like legitimate companies, are seeing the ‘business benefits’ of cloud services. Thus, they’re signing up for accounts and reaching sensitive files through these accounts. For the cyber criminals this only takes a run-of-the-mill knowledge level … This is the next step in a new trend … and it will only continue.”

The third freight train is the plaintiff’s litigation bar. Following cyber breach after cyber breach, they are viewing the corporate horizon as rich with opportunities to sue previously unsuspecting companies caught in the middle of a cyber disaster, with no clear way out. They see companies scrambling to contend with major breaches, investor relation delays, and loss of brand and reputation.

The last freight train running towards the intersection of cloud computing and data security is the topic of cyber governance—i.e., what directors should be doing or thinking about to protect their firm’s most critical and valuable IP assets. In our previous article, we noted that though directors are not supposed to be able to predict all potential issues when it comes to cyber security issues, they do have a basic fiduciary duty to oversee the risk management of the enterprise, which includes securing its intellectual property and trade secrets. The purpose of this article is to help directors and officers potentially avoid a freight train collision by helping the “cyber governance train” control the path and destiny of the company. We will discuss basic cloud security principles, and basic questions directors should ask when considering whether or not the data their management desires to run on a cloud-based architecture will be as safe from attack as possible. As usual when dealing with cyber security issues, there are no 100% foolproof answers. Even cloud experts disagree on cloud-based data security practices and their effectiveness] There are only good questions a board can ask to make sure it is fulfilling its duties to shareholders to protect the company’s valuable IP assets.

What is Cloud Computing/What Are Its Basic Platforms

“Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services). Cloud computing is a disruptive technology that has the potential to enhance collaboration, agility, scaling, and availability, and provides the opportunities for cost reduction through optimized and efficient computing. The cloud model envisages a world where components can be rapidly orchestrated, provisioned, implemented and decommissioned, and scaled up or down to provide an on-demand utility-like model of allocation and consumption.”

Cloud computing is generally based upon three separate and distinct architectures that matter when considering the security of the data sitting in the particular cloud environment.

……

Cloud Cyber Governance

As shown above, what is commonly referred to as the cloud actually can mean many different things depending on the context and use. Using SaaS to manage a customer base has a vastly different set of governance criteria to using IaaS as a development environment. As such, there are very few accepted standards for properly monitoring/administering a cloud-based environment. There are many IT consultants in the cloud-based computing environment that can be consulted in that regard. Our view, however, is that directors are ultimately responsible for enterprise risk management, and that includes cyber security, a subset of which is cloud-based cyber-security. Thus it is important for directors to have a basic understanding of the risks involved in cloud-based data storage systems, and with cloud-based storage providers. Below are a few basic questions that come to mind that a director could pose to management, and the company’s CISO and CIO:

1. Where will your data be stored geographically (which may determine which laws apply to the protection of the company’s data), and in what data centers?

2. Is there any type of customer data co-mingling that could potentially expose the company data to competitors or other parties?

3. What sort of encryption does the cloud-based provider use?

4. What is the vendor’s backup and disaster recovery plan?

5. What is the vendor’s incident response and notification plan?

6. What kind of access will you have to security information on your data stored in the cloud in the event the company needs to respond to a regulatory request or internal investigation?

7. How transparent is the cloud provider’s own security posture? What sort of access can your company get to the cloud provider’s data center and personnel to make sure it is receiving what it is paying for?

8. What is the cloud servicer’s responsibility to update its security systems as technology and sophistication evolves?

9. What is the cloud provider’s ability to timely detect (i.e., continuously monitor) and respond to a security incident, and what sort of logging information is kept in order to potentially detect anomalous activity?

10. Are there any third party requirements (such as HITECH/HIPAA) that the provider needs to conform to for your industry?

11. Is the cloud service provider that is being considered already approved under the government’s FedRamp authorization process, which pre-approves cloud service providers and their security controls?

12. Finally, does the company’s cyber insurance liability policy cover cloud-based Losses assuming there is a breach and customer records are stolen or otherwise compromised?  This is a very important question to ask, especially if the company involved is going to use a cyber-insurance policy as a risk transfer mechanism. When in doubt, a knowledgeable cyber-insurance broker should be consulted to make sure cloud-based Losses are covered.

High-profile breaches have proven conclusively that cybersecurity is a board issue first and foremost. Being a board member is tough work. Board members have a lot on their plate, including, first and foremost, financial reporting issues. But as high-profile breaches have shown, major cyber breaches have almost the same effect as a high profile accounting problem or restatement. They cause havoc with investors, stock prices, vendors, branding, corporate reputation and consumers. Directors should be ready to ask tough questions regarding cyber security and cloud-based security issues so they do not find themselves on the wrong end of a major data breach, either on the ground or in the cloud. »

Que faire quand la confiance entre le conseil et la direction est faible ? | Le cas d’une OBNL


Voici un cas qui origine du blogue australien de Julie Garland McLellan et qui intéressera certainement tous les membres de conseils d’administration d’OBNL.  J’ai choisi de partager ce cas en gouvernance avec vous car je crois que celui-ci évoque trop souvent les situations vécues par certaines organisations à but non lucratif.

Ce cas présente la situation réelle d’une entreprise dont les liens de confiance entre le C.A. et la direction se sont effrités.

Qu’en pensez-vous ? Que feriez-vous à la place de Jake ? Quelle analyse vous semble la plus appropriée dans notre contexte ? Que pensez-vous des analyses effectuées par les trois experts ?

« Boards operate best when each director trusts each other director to adhere to the jointly accepted governance processes and policies as well as the relevant laws and regulations. This month our real life case study considers what to do when that trust is lost. Consider: What would you advise a friend to do under these circumstances ? »

 

Que faire quand la confiance est perdue ?

 

« Jake is a club chairman. The former chairman resigned after a major disagreement with the rest of the board which arose because the former chairman signed a major contract. When the board discovered what had happened they were furious that a large decision had been made without involving them. The former chairman stormed from the meeting and resigned in writing the following morning.

The Board then acted without a formal chair, directors took turns to chair the meetings, until the next election. During this time the board rewrote the by-laws which previously allowed the chairman to sign contracts after verification by the treasurer that doing so would not lead to insolvency. They adopted new by-laws that stated no director, including – for absence of doubt – the chairman and/or treasurer, could commit the club to any contract, expenditure or course of action unless approved in a duly constituted board meeting.P1110362

Jake was not previously on the board and was elected unopposed after being invited by the treasurer to stand for election. He is a successful businessman but has no experience with consensual board decision-making. He has now discovered that the club is wallowing because recent decisions have not been made in a timely fashion. His fellow directors are numerous, factionated and indecisive. The CEO has low delegations and the constitution envisages that the chairman, CEO and treasurer should make decisions between meetings and use the board to ratify strategy, engage members and provide oversight. The amended by-laws prevent the constitution from working but don’t provide an alternative workable model.

The board reacted with horror to a suggestion that they soften the new by-laws but don’t appear willing to improve their own performance so the club can operate under the new by-laws. Staff performance reviews and bonuses are soon to be agreed and Jake is fairly certain that his board will not make rational decisions or support the CEO’s recommendations. He knows that he needs to act decisively to avert disaster but doesn’t know where to start.

How can Jake create an environment that allows for effective management of the club before this situation spirals out of control? »

Les comités de risques | Maintenant plus « risqués » que les comités d’audit !


Voici un excellent article publié hier par Howard Davies dans le FT portant sur les nouvelles réalités de la gouvernance, particulièrement dans les institutions financières.

En effet, une enquête du Financial Times (The FT’s A-List), montre, de manière convaincante, que les comités de risques sont maintenant plus « redoutés » que les comités d’audit. C’est un phénomène récent qui n’est pas encore bien documenté mais l’expérience des membres de conseils semble indiquer que ces comités sont moins recherchés, principalement parce que les experts en risques siégeant sur les conseils sont trop peu nombreux.

Il y a 10 ans, les administrateurs accordaient peu de temps à la surveillance des risques, faisant ainsi une confiance presqu’aveugle aux experts de la direction. Les préoccupations et les priorités des conseils ont changé radicalement depuis 2008, notamment depuis que les autorités réglementaires rendent obligatoire la constitution de comités de risques sur les C.A. des institutions financières.

Plusieurs autres secteurs d’activité ont suivis en accordant une place prépondérante à la gestion des risques et à la mise en place de comités de risques distincts des comités d’audit.

L’article ci-dessous présente l’état de la situation et les changements qui s’imposent dans la gouvernance des organisations, Voici un extrait de cet article. Bonne lecture !

 

 Audit is no longer the chore the board dreads most

« There is uncertainty about what risk committees should do »

 

Until recently, most non-executive directors would have told you that the audit committee is the one they really wish to avoid. The meetings are long, the papers voluminous, and the duties burdensome. So the conclusion of a recent survey by Per Ardua, an executive search company, came as a surprise. Eighty per cent of respondents in the financial sector now say that the risk committee is the one to dodge – even though audit and remuneration committees have so far more often exposed non-executives to public criticism.

The FT’s A-List

The A-list

The A-List provides timely, insightful comment on the topics that matter, from globally renowned leaders, policy makers and commentators

The survey responses suggest three possible explanations. First, the risk committee has a broad range of responsibilities. For a bank, traditional value-at-risk measures, which reflect the likelihood that the bank’s loans will go bad, are just the beginning. The agenda has broadened into operational, regulatory, legal and reputational risk, demanding detailed knowledge of all areas of the business – and of the relevant rules within which they operate. Regulation is increasingly complex, and varies significantly by country.

Second, whereas audit committees look backwards, risk committees must look forwards – a more difficult task. True, the dividing line is not quite so stark in practice; some auditors do live in the here and now. But overseeing future risks requires greater exercise of judgment, and involves the use of stress testing and other relatively novel techniques.

Third, the regulatory focus on risk committees has grown. Before the Walker review of corporate governance in financial firms, most banks in the UK did not have a separate risk committee. The same was true in the US. The audit committee did the job in its spare time. Now regulators on both sides of the Atlantic look to the risk committee and its chairman to answer for the stability of a bank, to oversee compliance with capital regulation and to take responsibility for its resolution and recovery plans. Those plans are highly technical.

Source: www.linkedin.com

Voir Scoop.itgouvernance

 

 

 

L’étendue de la divulgation des facteurs de risque attribuée aux mesures règlementaires


Je partage avec vous aujourd’hui les résultats d’une étude effectuée par Karen K. Nelson, professeure de comptabilité à l’Université Rice et Adam C. Pritchard,  professeur de droit à l’Université du Michigan. Cette étude est présentée sommairement sur le blogue du Harvard Law School; elle concerne l’étendue de la divulgation des facteurs de risque lorsque l’on compare les mesures règlementaires volontaires aux mesures obligatoires imposées par la SEC.

L’étude montre les différences des deux situations règlementaires en termes de la quantité de risques divulgués, de l’importance des mises à jour annuelles et de la compréhension des facteurs de risques par les lecteurs.

Les auteurs font le constat que la divulgation des facteurs de risque ayant donné lieu à des contestations judiciaires est beaucoup plus complète dans les années qui suivent. L’étude conclue que les mesures de divulgation imposées ont porté fruits.

Voici un extrait de l’article. Bonne lecture !

 

Shift from Voluntary to Mandatory Disclosure of Risk Factors

 

In our paper, Carrot or Stick? The Shift from Voluntary to Mandatory Disclosure of Risk Factors, we investigate public companies’ disclosure of risk factors that are meant to inform investors about risks and uncertainties. We compare risk factor disclosures under the voluntary, incentive-based disclosure regime provided by the safe harbor provision of the Private Securities Litigation Reform Act, adopted in 1995, and the SEC’s subsequent disclosure mandate, adopted in 2005.IMG_20140528_200314

The PSLRA’s safe harbor provision shields firms from liability for forward-looking statements provided they are accompanied by “meaningful cautionary statements identifying important factors that could cause actual results to differ materially from those in the forward looking statement.” The voluntary disclosure of risk factors provides a direct means for firms to reduce the often substantial expected costs of securities fraud class actions. Thus, the safe harbor provides an important incentive for public companies to disclose risk factors, but that incentive is likely to vary with firms’ perception of their potential vulnerability to securities class actions.

Risk factor disclosure shifted from a voluntary, incentive-based regime to a mandatory one in 2005 when the SEC added Item 1A to Form 10-K. Item 1A requires most public companies to disclose risk factors annually and update them quarterly as necessary in Form 10-Q.

We study how these two changes in the law affect the disclosure of risk factors. Our tests focus on three questions: First, we examine whether litigation risk plays an important role in firms’ disclosure practices, particularly during the voluntary disclosure period from 1996 to 2005. Second we test whether the SEC’s 2005 disclosure mandate narrows the gap between firms with a litigation–related incentive to provide risk factor disclosure and those compelled to disclose because of the mandate. Third, we assess whether differences in the quality of the disclosure affect its usefulness to investors in assessing firm risk.

To conduct our analyses, we use three metrics designed to capture characteristics of “meaningful” disclosure suggested by the PSLRA’s legislative history, subsequent court decisions, and the SEC:

(i) the amount of risk factor disclosure;

(ii) the extent to which the risk factors are updated year-to-year; and

(iii) the readability of the risk factors.

All else equal, risk factor disclosure is more “meaningful” if it is comprehensive, if it is not a boilerplate copy from the prior year, and if it can be understood by the average investor.

We use these disclosure metrics to investigate whether firms at greater risk of securities fraud lawsuits provide more “meaningful” risk factor disclosure, and how the SEC’s 2005 mandate affects this disclosure. Controlling for other factors that could affect the disclosure decision, we find that, on average, firms with greater litigation risk provide more risk factor disclosure, revise their disclosure more from year-to-year, and use more readable language than firms with low litigation risk. When we allow these effects to vary with the disclosure regime, we find significant differences in disclosure between high and low risk firms in the voluntary regime. After the SEC mandate in 2005, however, firms with low litigation risk increase converge with high risk firms in their risk factor disclosure.

We conclude that the SEC’s mandate had a material effect on the disclosure decisions of companies that had relatively little incentive to provide meaningful disclosure under the PSLRA’s safe harbor provision alone. We also find, however, that firms with high litigation risk continue to provide a significantly greater amount of risk factor disclosure in the mandatory regime. Moreover, in both disclosure regimes, high risk firms disclose significantly more risk factor information as litigation risk increases.

Finally, we find evidence that risk factor disclosures provide information useful to investors in assessing future firm risk, although here again the findings vary predictably with firms’ disclosure incentives and the disclosure regime. For firms with high litigation risk and hence greater incentive to provide meaningful disclosure, one-year-ahead beta and stock return volatility are increasing in the unexpected portion of risk factor disclosure. Moreover, in the voluntary disclosure regime, firms with high litigation risk provide risk factor disclosures that are significantly more informative about systematic and idiosyncratic risk than firms with low litigation risk. Subsequent to the SEC mandate, however, there is no statistical difference, consistent with a convergence in the meaningfulness of risk factor disclosures.

Overall, our findings suggest managers respond to high ex ante litigation risk with risk factor disclosures designed to reduce the expected costs of litigation. In contrast, low risk firms perceiving little net benefit to disclosure did not provide meaningful risk factor disclosure until compelled to do so by the SEC. Understanding risk factor disclosures is important to managers and legal counsel responsible for formulating a disclosure strategy, to regulators and courts charged with evaluating the quality of these disclosures, and to investors interested in assessing the risks posed by firms.

The full paper is available for download here.

 

Les grands enjeux reliés à la rémunération des administrateurs canadiens


Il y a peu d’informations colligées sur les rémunérations versées aux administrateurs de sociétés canadiennes. Michel Magnan, professeur et titulaire de la chaire de gouvernance d’entreprise Stephen A. Jarislowsky de l’École de gestion John-Molson, Université Concordia, a récemment publié, en collaboration avec l’IGOPP, les résultats d’une étude fort pertinente sur le sujet.

Le rapport fait ressortir plusieurs constats dont les suivants :

(1) Sur la période de 10 ans allant de 2001 à 2010, les honoraires annuels moyens touchés par les administrateurs de sociétés ouvertes canadiennes ont augmenté de 465%. Cette hausse considérable n’est toutefois pas uniforme parmi toutes les sociétés, puisque les augmentations les plus importantes se retrouvent dans les grandes institutions financières ainsi que dans les sociétés pétrolières et minières.

(2) La rémunération des administrateurs de sociétés canadiennes reste significativement inférieure à celle octroyée par des sociétés américaines comparables.

(3) La rémunération des administrateurs n’a pas atteint des niveaux que l’on pourrait juger excessifs compte tenu de l’accroissement des exigences institutionnelles et réglementaires durant la période.

(4) Le débat sur la rémunération des administrateurs et leur indépendance doit être vu comme un enjeu de composition et de fonctionnement du conseil d’administration. Si des cas de rémunération excessive surviennent, ils ne font que refléter des problèmes de gouvernance sous-jacents plus sérieux, lesquels minent la légitimité et possiblement la crédibilité du conseil

(5) Nous sommes dans un contexte de gouvernance fiduciaire. Les administrateurs sont donc préoccupés par la conformité aux lois et règlements, la mise en place et le suivi des mécanismes et des systèmes de contrôle, d’incitation et de reddition des comptes. Leur rémunération est ainsi fonction de ce rôle.

Vous trouverez, ci-dessous, un sommaire du rapport, notamment de ses recommandations.  Bonne lecture !

 

Rémunération des administrateurs et gouvernance : enjeux et défis

 

Les attentes envers les administrateurs en termes de crédibilité, de disponibilité et de légitimité ont considérablement augmenté depuis le début des années 2000. Leur rémunération a suivi mais les jetons de présence ont-ils une incidence sur le comportement et les décisions des membres des conseils ?P1030086

….

Il ressort de cette analyse que la rémunération des administrateurs n’est qu’une facette de la gouvernance du conseil d’administration, et pas nécessairement la plus stratégique, puisqu’elle ajoute peu à des processus de nomination et d’évaluation des administrateurs qui sont déjà rigoureux. La rémunération des administrateurs doit refléter le fait que leur responsabilité est conjointe, continue et orientée vers la veille des intérêts à long terme de l’entreprise dans son ensemble, et non seulement des intérêts à court terme de certains actionnaires. À cet effet, le rapport propose plusieurs recommandations, notamment :

La priorité d’un conseil en matière de gouvernance est de maintenir et accroître sa légitimité et sa crédibilité au moyen de pratiques et processus rigoureux.

La rémunération des administrateurs ne doit pas reposer sur l’atteinte d’objectifs ou de buts à court terme.

La rémunération d’un administrateur doit être suffisamment élevée pour attirer des candidats crédibles, intègres et détenant les compétences spécifiques correspondant aux objectifs de la société.

Les administrateurs doivent détenir un investissement significatif à long terme dans les actions de l’entreprise.

La rémunération des administrateurs devrait être uniforme entre les individus qui ont des tâches similaires.

La rémunération des administrateurs doit refléter de manière rationnelle les risques spécifiques qu’ils encourent.

Les investisseurs n’hésitent pas à remettre en question les compétences et les décisions des administrateurs. Dans un tel contexte, leur rémunération risque de devenir un enjeu de gouvernance important. C’est pourquoi ce rapport de l’IGOPP cadre le débat par une analyse de déterminants potentiels de la rémunération et suggère des principes et recommandations qui permettront de guider le travail des conseils en la matière.

Le vote obligatoire des actionnaires dans les cas de changements importants prévient-il les mauvaises transactions ?


Quelles transactions devraient requérir l’approbation obligatoire de tous les actionnaires ? L’article de Marco Becht, professeur de gouvernance corporative à l’Université libre de Bruxelles; Andrea Polo, du département d’économie et Business à l’Universitat Pompeu Fabra et Barcelona GSE; et Stefano Rossi du département de finance de Purdue University, s’intéresse à la limite du pouvoir qu’il est nécessaire de laisser aux actionnaires plutôt qu’au conseil d’administration.

En Grande-Bretagne (UK), les offres faites à des entreprises-cibles de grandes tailles sont considérées comme des transactions de classe 1 et donc obligatoirement sujettes à l’approbation des actionnaires. Les résultats de cette étude montrent que les bénéfices financiers résultant d’une telle approche sont très importants.

Plusieurs juridictions ont choisi d’exclure les acquisitions de tailles importantes du vote de l’actionnariat, au détriment de l’avoir des actionnaires selon l’étude. Bien entendu, lorsqu’une transaction change profondément la nature de l’entreprise et peut potentiellement avoir des conséquences importantes sur la valeur des actions, celle-ci doit être traitée lors d’une assemblée extraordinaire des actionnaires.

« Our paper infers that mandatory voting makes boards more likely to refrain from overpaying or from proposing deals that are not in the interest of shareholders »

Voici un extrait de l’article publié dans le Harvard Law School Forum on Corporate Governance and Financial Regulation. Vous pouvez télécharger tout le document ici.

Bonne lecture ! Vos commentaires, portant sur la souveraineté des C.A., sont les bienvenus.

Does Mandatory Shareholder Voting Prevent Bad Corporate Acquisitions ?

In our paper, Does Mandatory Shareholder Voting Prevent Bad Corporate Acquisitions?, which was recently made publicly available as an ECGI and Rock Center Working Paper on SSRN, we examine how much power shareholders should delegate to the board of directors. In practice, there is broad consensus that fundamental changes to the basic corporate contract or decisions that might have large material consequences for shareholder wealth must be taken via an extraordinary shareholder resolution (Rock, Davies, Kanda and Kraakman 2009). Large corporate acquisitions are a notable exception. In the United Kingdom, deals larger than 25% in relative size are subject to a mandatory shareholder vote; in most of continental Europe there is no vote, while in Delaware voting is largely discretionary.IMG_20140516_124706

The consequences for Delaware corporation shareholders are well documented in the relevant finance literature. A large percentage of deals initiated by U.S. acquirers destroy shareholder value with aggregate announcement losses running in billions of U.S. dollars. Shareholder voting exists, but it is voluntary and therefore endogenous. Deals facing potential shareholder opposition can be restructured to avoid a vote, as was recently the case with Kraft Inc.’s bid for Cadbury Plc, after public opposition from Warren Buffett. Shareholder voting in the United States is not a binding constraint and previous empirical studies based on U.S. data are rendered inconclusive.

Under the U.K. listing rules, bids for relatively large targets are called “Class 1 transactions” and are subject to mandatory shareholder approval. In a representative sample of acquirers listed on the main market in London, Class 1 transactions are associated with an aggregate gain to acquirer shareholders of $13.6 billion, over 1992-2010. Similar U.S. transactions in terms of size and other observable characteristics that are not subject to shareholder approval are associated with an aggregate loss of $210 billion for acquirer shareholders over the same period; and smaller Class 2 U.K. transactions, also not subject to shareholder approval, are associated with an aggregate loss of $3 billion. The findings are robust to various controls for deal characteristics and also hold at the U.K. mandatory voting threshold, where deals are very similar except in their voting status.

How does mandatory voting bring about these positive Class 1 results? Our paper infers that mandatory voting makes boards more likely to refrain from overpaying or from proposing deals that are not in the interest of shareholders. We find that shareholders never voted against Class 1 transactions ex-post and deals that were poorly received by the market at announcement were often dropped before they reached the voting stage. The results show that giving shareholder a direct decision right over large transactions can have a positive causal impact by discouraging bad corporate acquisitions.

Many jurisdictions have chosen to exclude large acquisitions from the list of fundamental changes that are outside the scope of delegated board authority. The advantages of board delegation such as reduced legal costs and greater speed and flexibility are shown to be preferred to explicit shareholder approval. This study shows that the benefits of mandatory voting on large corporate acquisitions can be large, shedding new light on this trade-off.

 

L’État de l’audit interne à l’échelle internationale | Rapport 2014 de Thompson Reuters Accelus


Denis Lefort, CPA,  expert-conseil en Gouvernance, audit et contrôle, vient de me faire parvenir l’édition 2014 de l’étude Thompson Reuters Accelus sur l’audit interne.

Ce sondage identifie des observations intéressantes pour la profession d’auditeur interne :

(1) Seulement un peu plus de 27% des services d’audit interne vérifient les processus de gouvernance de leur organisation;

(2) Il y a encore des écarts importants de perception entre les services d’audit interne et les comités d’audit quant aux priorités que devraient être celles des services d’audit interne;

(3) Les auditeurs internes investissent 45% de leur temps pour l’audit de la sécurité des TI;

(4) Près de 50% des services d’audit interne interagissent maintenant avec les autres fonctions d’assurance de leur organisation (Conformité, Gestion des risques, etc…).

Ce document sera donc très utile à tout administrateur soucieux de parfaire ses connaissances de l’état de la situation en 2014 dans le monde.

Bonne lecture. Vos commentaires sont les bienvenus. Voici le sommaire de l’étude.

 

 ÉTAT DE L’AUDIT INTERNE – RAPPORT 2014 DE THOMSON REUTERS ACCELUS

 

Thomson Reuters Accelus’ annual State of Internal Audit Survey provides an insight into the experiences and expectations of internal audit professionals around the world. More than 900 internal audit practitioners across 50 countries participated in the 2014 survey sharing their views across a range of subjects, issues and concerns. The experiences shared in this report are intended to help internal audit functions and senior management benchmark the myriad of challenges faced and enable them to leverage the approach taken by their peers.

The survey has demonstrated that the world and work of internal audit continues to be as complex, and challenging as ever. Both the volume and diversity of issues that internal auditors need to understand and assess continues to increase globally and across all industries.

In fact, at a high level the results of the Thomson Reuters Accelus State of Internal Audit Survey have remained relatively unchanged for the last few years.IMG_20140521_164057

This year the results confirmed that the vast majority (81 percent) of internal auditors’ focus remains on providing assurance on the efficacy of internal control process. While assurance work is the traditional mainstay of internal audit there are a wide range of other areas and issues for internal auditors to consider, including:

(1) Nearly a quarter (24 percent) of internal auditors expect their personal liability to increase in 2014. The adequacy of internal auditors’ skills, focus and approach is firmly on the radar of regulators worldwide. It is no surprise, therefore, that internal auditors expect their own personal liability to increase in the near future.

(2) Nearly half (49 percent) of all internal auditors have had no involvement in assessing their firm’s culture. There are distinct regional variations with respondents from South America reporting that three-quarters (77 percent) of internal auditors have not assessed the culture of their firm.

(3) Just over a quarter (27 percent) of internal auditors have had no involvement in assessing their firm’s corporate governance; regionally this figure looks most concerning for North America, with 32 percent of internal auditors having no involvement.

4) Internal auditors spend 45 percent of their time on IT security and risk. Nearly half (48 percent) of respondents said that it should be a top priority for their organization and 35 percent said it would be a top challenge for boards of directors in 2014.

(5) Nearly half of the respondents (48 percent) expect to be spending more time reporting to senior management and tracking remedial actions. This is in addition to almost a quarter (24 percent) of internal auditors anticipating a need to focus on the implementation of industry-specific legislation.

(6) Nearly half of internal auditors interact with risk management (44 percent) and compliance (47 percent) on at least a monthly basis. While these figures are a slight improvement on last year it remains an area where improvements could be made.

(7) It is interesting that areas not considered a priority for internal audit included customer outcomes (6 percent), whistle-blowing (5 percent) and capital and liquidity (4 percent).

(8) Internal auditors’ perception of priorities for the board are not aligned with their own. The key challenges for internal auditors are greater complexity of issues and focus on risk and control, as well as changing business models. In contrast, boards’ priorities are corporate strategy, strategic risk management and legal and regulatory risk.

The growing focus which policymakers and regulators have been placing on culture, corporate governance and risk management has emphasized still further the need for a strong, well-resourced independent audit function operating, and in particular reporting, in close coordination with other risk and compliance functions, all with visible support from the top of the organization. Yet the results show a relatively unchanged picture in these areas from previous years. As the risks increase so does the need for internal audit to react to those changes.

 

La saga d’American Apparel | Une affreuse gouvernance


Voici un article publié par Gael O’Brien dans Business Ethics sur la saga de la gouvernance à American Apparel. Le fondateur Charney est en guerre contre son conseil d’administration pour une foule de raisons, valables à mon point de vue.

La situation est d’autant plus saugrenue que le président Charney est responsable de la nomination des membres du C.A. !

Je vous invite à une lecture pimentée d’une situation surréelle dont vous trouverez un extrait ci-dessous.

 

American Apparel: Sex, Power and Terrible Corporate Governance

The American Apparel story gets crazier by the moment.

Actions taken by the company’s board two weeks ago to attempt to remove founder Dov Charney as chairman and CEO have prompted him to launch a counteroffensive to regain control of American Apparel.  Working with hedge fund investors, Charney has borrowed money to increase his shares in the company to 43 percent and is threatening a proxy fightBut the hedge fund investors working with Charney are now negotiating with the very board that fired him – and there’s a possibility that a new management team could be appointed that does not include Charney.IMG_00000962

Whether Charney is successful or not, the result of his past leadership is an American Apparel characterized by two faces in opposition to each other. When that happens, the worst face eventually outweighs the best. The retail company’s  attempts at socially responsible practices — clothes touted as ethically made in the United States – have ended up being plowed under by the repugnant behavior of its leader, who sexualized the workplace as a stalking ground for employee relationships called consensual, disregarding disparity of age and power.

American Apparel’s drama illustrates two key problems: In companies where there is a dominant founder running the company according to the beat of his (or her) own drum, how hands-on can a hand-picked board be when it is necessary to reign in the founder? And, when ethical issues surface in a company with a sexually provocative brand image, how does a hand-picked board ensure a clear stand is taken?

Charney’s hand-picked board supported him for years through several very public sexual harassment lawsuits — not appearing to reign in his philosophy that a sexually-charged workplace fosters creativity; it authorized a quiet, internal investigation this year which uncovered examples where they said Charney misused company funds and didn’t prevent the posting of naked photos of a former employee who had sued him for sexual harassment a few years before.

___________________________________________________

Gael O'Brien_2012_CropGael O’Brien, a Business Ethics Magazine columnist, is a consultant, executive coach, and presenter focused on building leadership, trust, and reputation. She publishes the The Week in Ethics and is The Ethics Coach columnist for Entrepreneur Magazine.

 

La gouvernance, les cyber risques et la reponsabilité du C.A.


Voici la présentation de M. Luis A. Aguilar, commissaire à la Securities and Exchange Commission (SEC). Le billet paru dans Harvard Law School Forum on Corporate Governance sonne l’alarme en ce qui regarde les menaces posées par les cyber attaques et les rôles et responsabilités des conseils d’administration à cet égard.
C’est un article qui met en perspective les besoins d’un changement significatif dans le focus de la gouvernance des entreprises.
Ci-dessous, un extrait de l’introduction à cet article, Bonne lecture !

I am pleased to be here and to have the opportunity to speak about cyber-risks and the boardroom, a topic that is both timely and extremely important. Over just a relatively short period of time, cybersecurity has become a top concern of American companies, financial institutions, law enforcement, and many regulators. I suspect that not too long ago, we would have been hard-pressed to find many individuals who had even heard of cybersecurity, let alone known what it meant. Yet, in the past few years, there can be no doubt that the focus on this issue has dramatically increased.

 

Boards of Directors, Corporate Governance and Cyber-Risks | Sharpening the Focus

 

Cybersecurity has become an important topic in both the private and public sectors, and for good reason. Law enforcement and financial regulators have stated publicly that cyber-attacks are becoming both more frequent and more sophisticated. Indeed, according to one survey, U.S. companies experienced a 42% increase between 2011 and 2012 in the number of successful cyber-attacks they experienced per week. As I am sure you have heard, recently there have also been a series of well-publicized cyber-attacks that have generated considerable media attention and raised public awareness of this issue. A few of the more well-known examples include:

The October 2013 cyber-attack on the software company Adobe Systems, Inc., in which data from more than 38 million customer accounts was obtained improperly;

The December 2013 cyber-attack on Target Corporation, in which the payment card data of approximately 40 million Target customers and the personal data of up to 70 million Target customers was accessed without authorization;

The January 2014 cyber-attack on Snapchat, a mobile messaging service, in which a reported 4.6 million user names and phone numbers were exposed;

The sustained and repeated cyber-attacks against several large U.S. banks, in which their public websites have been knocked offline for hours at a time; and

The numerous cyber-attacks on the infrastructure underlying the capital markets, including quite a few on securities exchanges.

Official portrait of Securities and Exchange C...
Official portrait of Securities and Exchange Commission (SEC) Commissioner Luis A. Aguilar. (Photo credit: Wikipedia)

In addition to becoming more frequent, there are reports indicating that cyber-attacks have become increasingly costly to companies that are attacked. According to one 2013 survey, the average annualized cost of cyber-crime to a sample of U.S. companies was $11.6 million per year, representing a 78% increase since 2009. In addition, the aftermath of the 2013 Target data breach demonstrates that the impact of cyber-attacks may extend far beyond the direct costs associated with the immediate response to an attack. Beyond the unacceptable damage to consumers, these secondary effects include reputational harm that significantly affects a company’s bottom line. In sum, the capital markets and their critical participants, including public companies, are under a continuous and serious threat of cyber-attack, and this threat cannot be ignored.

As an SEC Commissioner, the threats are a particular concern because of the widespread and severe impact that cyber-attacks could have on the integrity of the capital markets infrastructure and on public companies and investors. The concern is not new. For example, in 2011, staff in the SEC’s Division of Corporation Finance issued guidance to public companies regarding their disclosure obligations with respect to cybersecurity risks and cyber-incidents. More recently, because of the escalation of cyber-attacks, I helped organize the Commission’s March 26, 2014 roundtable to discuss the cyber-risks facing public companies and critical market participants like exchanges, broker-dealers, and transfer agents.

Today, I would like to focus my remarks on what boards of directors can, and should, do to ensure that their organizations are appropriately considering and addressing cyber-risks. Effective board oversight of management’s efforts to address these issues is critical to preventing and effectively responding to successful cyber-attacks and, ultimately, to protecting companies and their consumers, as well as protecting investors and the integrity of the capital markets.

Bien comprendre les droits et responsabilités des actionnaires de sociétés !


Ci-dessous, l’extrait d’un article très simple sur les devoirs attendus de la part des actionnaires. Si vous avez décidé d’investir dans une entreprise, vous possédez une part de la propriété de celle-ci !

Il est donc important de lire la documentation fournie par le conseil d’administration et par la direction de l’entreprise afin de vous former une opinion sur sa gouvernance, et vous devriez vous faire un devoir d’exercer vos droits de votes.

L’article récemment publié par The Canadian Press saura-t-il éveiller chez vous le sens de la responsabilité de l’actionnaire ? En ce qui me concerne, j’ai décidé, il y a quelques années, de me faire un devoir de lire les documents préparatoires à l’AGA et de voter, par la poste, sur les items de l’ordre du jour qui sollicitent l’assentiment des actionnaires.

 

Understand your rights as a shareholder: experts – Business – The Telegram

 

Documents sent to shareholders ahead of the meeting can include the management proxy circular, annual information form and the company’s annual report. The information form and annual report give the financial statements and an update by management on the business and the direction for the company — both key documents for shareholders.

Walmart Shareholders' Meeting 2011
Walmart Shareholders’ Meeting 2011 (Photo credit: Walmart Corporate)

The proxy circular includes information related to the annual meeting, including the nominees for the board of directors and the appointment of the auditors. It can also include shareholder proposals or major changes at the company that require shareholder approval.

Eleanor Farrell, director of the Office of the Investor at the Ontario Securities Commission, says shareholders have the right to vote on matters that affect the company, including the election of the board of directors. “That is a very important governance piece for the company,” Farrell says.

“The board is the one that approves the strategic plan. It sets the direction of the company. They appoint the CEO, they evaluate the CEO and they also approve the compensation plan.” Farrell says if shareholders don’t approve of a nominated director they can withhold their vote and, at most large companies, if a majority of the votes cast withhold a vote for a particular director, that director would be forced to step aside.

“Shareholders in the last few years have certainly become and gotten a lot more powerful and a lot more powers, I would say,” Farrell said. “Corporate governance has been a very big concern for institutional investors, certainly, and companies are much more concerned about corporate governance.”

The information circulars also include detailed descriptions about how much the company’s directors receive in compensation and what the senior executives are paid in salary, shares or options, as well as the size of their bonuses and the value of any other perks. The circular will also include how the board arrived at that compensation as well as comparisons with previous years. Certain provisions, such as how much a chief executive will receive if the company is taken over or if they are let go, are also often included.

 

Modèle de supervision du management | Lignes de défense des parties prenantes


Vous trouverez ci-dessous un document de réflexion publié par Sean Lyon* et paru dans la série Executive Action du Conference Board. Ce document partagé et commenté par Denis Lefort, CPA, CA, CIA, CRMA, fait référence à cinq (5) lignes de défense interne, soit les opérations, les fonctions de surveillance tactiques comme la gestion des risques et la conformité, les fonctions d’assurance indépendante que sont le comité d’audit, l’audit interne et les autres sous-comités du conseil, et, enfin, la direction et le conseil d’administration.

Quatre lignes de défense externe sont aussi proposées, soit: les auditeurs externes, les actionnaires, les agences de notations et les organismes de réglementation.

Le modèle des 5 lignes de défense est aussi comparé au modèle traditionnel des trois lignes de défense.

Finalement, l’auteur insiste sur l’importance pour l’ensemble des lignes de défense d’agir de façon concertée, voire intégrée, pour assurer le succès global des interventions des uns et des autres pour le bénéfice de l’organisation.

Voici un extrait du document. Bonne lecture !

Corporate Oversight and Stakeholder Lines of Defense

Corporate stakeholder responsibility should take intoaccount various stakeholder groups, including shareholders, employees, customers, suppliers, special interest groups,

communities, regulators, politicians, and, ultimately, society. Consequently, a comprehensive corporate oversight framework should be multi-faceted to safeguard the diverse interests and varied expectations of all stakeholders. Increasingly, stakeholders are demanding oversight that safeguards a multitude of their interests, be they financial, economic, social, or environmental. Such an inclusive approach should include an appreciation of the symbiotic relationship that exists between business, society, and nature.

Michael Oxley , U.S. Senator from Maryland.
Michael Oxley , U.S. Senator from Maryland. (Photo credit: Wikipedia)

Organizations should understand the complexity of this interconnectedness to fulfill their social responsibilities. A holistic focus that includes the various lines of defense approach helps provide different stakeholders with the comfort that their interests are safeguarded, if implemented appropriately. A lines-of-defense framework provides stakeholders with a comprehensive system of “checks and balances.”

The existence of such an integrated framework means that stakeholders can reasonably rely on it to ensure that the organization is fulfilling its fiduciary duties, legal obligations, and moral responsibilities, while creating durable value and sustainable economic performance in the process. For this approach to operate effectively, however, each line of defense must play its part both individually and collectively—fulfilling its oversight duties within a holistic framework.

Accordingly, each line of defense collaborates with and challenges the other (complimentary yet antagonistic) lines of defense, as it acts in its own enlightened self-interest. Enhanced cooperation and communication between these lines of defense should be facilitated by better interaction between stakeholders through regular dialogue which is based on mutual understanding of the organization’s objectives. This, however, must be achieved without allowing respective responsibilities or accountabilities to become blurred in the process.

To strengthen corporate defense capabilities, organizations should consider fortifying the second line of defense, which provides the critical link between operational line management and executive management. For many organizations, this is still perhaps the weakest link in the chain. Unfortunately, in many organizations, the defense activities at this layer are operating in a silo; they are not in alignment with other lines, but rather, operate in isolation, with little or no interaction, sharing of information, or collaboration. The activities of an effective second line of defense must be managed in a coordinated and integrated manner.

Each of the other lines of defense requires differing degrees of fortification, but this perhaps has as much to do with best practices rather than any radical makeover. The goal is to reach a more effective balance between the spirit of guidelines based on principle and the interpretation of guidelines that are legal or more prescriptive.

____________________________________

* Sean Lyons is the principal of Risk Intelligence Security Control (R.I.S.C.) International (Ireland) and a recognized corporate defense strategist. He is published internationally and has lectured and spoken at seminars and conferences in both Europe and North America. His contributions have been acknowledged in the Walker Review ofCorporate Governance in UK Banks and Other Financial Institutions, the Financial Reporting Council (FRC)’s Review of the Effectiveness of theCombined Code and the International Corporate Governance Network (ICGN)’s ICGN Corporate Risk Oversight Guidelines. In 2010 Sean was shortlisted as a finalist in the GRC MVP 2009 Awards organized by US based GRC Group (SOX Institute) co-chaired by Senator Paul Sarbanes and Congressman Michael Oxley.

 Articles d’intérêt :

Enhanced by Zemanta

Sept leçons apprises en matière de communications de crise **


Nous avons demandé à Richard Thibault *, président de RTCOMM, d’agir à titre d’auteur invité. Son billet présente sept leçons tirées de son expérience comme consultant en gestion de crise.

En tant que membres de conseils d’administration, vous aurez certainement l’occasion de vivre des crises significatives et il est important de connaître les règles que la direction doit observer en pareilles circonstances.

Voici donc l’article en question, reproduit ici avec la permission de l’auteur. Vos commentaires sont appréciés. Bonne lecture.

 

Sept leçons apprises en matière de communications de crise

Par Richard Thibault*

La crise la mieux gérée est, dit-on, celle que l’on peut éviter. Mais il arrive que malgré tous nos efforts pour l’éviter, la crise frappe et souvent, très fort. Dans toute situation de crise, l’objectif premier est d’en sortir le plus rapidement possible, avec le moins de dommages possibles, sans compromettre le développement futur de l’organisation.

Voici sept leçons dont il faut s’inspirer en matière de communication de crise, sur laquelle on investit généralement 80% de nos efforts, et de notre budget, en de telles situations.

The Deepwater Horizon oil spill as seen from s...
The Deepwater Horizon oil spill as seen from space by NASA’s Terra satellite on May 24, 2010 (Photo credit: Wikipedia)

(1) Le choix du porte-parole

Les médias voudront tout savoir. Mais il faudra aussi communiquer avec l’ensemble de nos clientèles internes et externes. Avoir un porte-parole crédible et bien formé est essentiel. On ne s’improvise pas porte-parole, on le devient. Surtout en situation de crise, alors que la tension est parfois extrême, l’organisation a besoin de quelqu’un de crédible et d’empathique à l’égard des victimes. Cette personne devra être en possession de tous ses moyens pour porter adéquatement son message et elle aura appris à éviter les pièges. Le choix de la plus haute autorité de l’organisation comme porte-parole en situation de crise n’est pas toujours une bonne idée. En crise, l’information dont vous disposez et sur laquelle vous baserez vos décisions sera changeante, contradictoire même, surtout au début. Risquer la crédibilité du chef de l’organisation dès le début de la crise peut être hasardeux. Comment le contredire ensuite sans nuire à son image et à la gestion de la crise elle-même ?

(2) S’excuser publiquement si l’on est en faute

S’excuser pour la crise que nous avons provoqué, tout au moins jusqu’à ce que notre responsabilité ait été officiellement dégagée, est une décision-clé de toute gestion de crise, surtout si notre responsabilité ne fait aucun doute. En de telles occasions, il ne faut pas tenter de défendre l’indéfendable. Ou pire, menacer nos adversaires de poursuites ou jouer les matamores avec les agences gouvernementales qui nous ont pris en défaut. On a pu constater les impacts négatifs de cette stratégie utilisée par la FTQ impliquée dans une histoire d’intimidation sur les chantiers de la Côte-Nord, à une certaine époque. Règle générale : mieux vaut s’excuser, être transparent et faire preuve de réserve et de retenue jusqu’à ce que la situation ait été clarifiée.

(3) Être proactif

Dans un conflit comme dans une gestion de crise, le premier à parler évite de se laisser définir par ses adversaires, établit l’agenda et définit l’angle du message. On vous conseillera peut-être de ne pas parler aux journalistes. Je prétends pour ma part que si, légalement, vous n’êtes pas obligés de parler aux médias, eux, en contrepartie, pourront légalement parler de vous et ne se priveront pas d’aller voir même vos opposants pour s’alimenter.  En août 2008, la canadienne Maple Leaf, compagnie basée à Toronto, subissait la pire crise de son histoire suite au décès et à la maladie de plusieurs de ses clients. Lorsque le lien entre la listériose et Maple Leaf a été confirmé, cette dernière a été prompte à réagir autant dans ses communications et son attitude face aux médias que dans sa gestion de la crise. La compagnie a très rapidement retiré des tablettes des supermarchés les produits incriminés. Elle a lancé une opération majeure de nettoyage, qu’elle a d’ailleurs fait au grand jour, et elle a offert son support aux victimes. D’ailleurs, la gestion des victimes est généralement le point le plus sensible d’une gestion de crise réussie.

(4) Régler le problème et dire comment

Dès les débuts de la crise, Maple Leaf s’est mise immédiatement au service de l’Agence canadienne d’inspection des aliments, offrant sa collaboration active et entière pour déterminer la cause du problème. Dans le même secteur alimentaire, tout le contraire de ce qu’XL Foods a fait quelques années plus tard. Chez Maple Leaf, tout de suite, des experts reconnus ont été affectés à la recherche de solutions. On pouvait reprocher à la compagnie d’être à la source du problème, mais certainement pas de se trainer les pieds en voulant le régler. Encore une fois, en situation de crise, camoufler sa faute ou refuser de voir publiquement la réalité en face est décidément une stratégie à reléguer aux oubliettes. Plusieurs années auparavant, Tylenol avait montré la voie en retirant rapidement ses médicaments des tablettes et en faisant la promotion d’une nouvelle méthode d’emballage qui est devenue une méthode de référence aujourd’hui.

(5) Employer le bon message

Il est essentiel d’utiliser le bon message, au bon moment, avec le bon messager, diffusé par le bon moyen. Les premiers messages surtout sont importants. Ils serviront à exprimer notre empathie, à confirmer les faits et les actions entreprises, à expliquer le processus d’intervention, à affirmer notre désir d’agir et à dire où se procurer de plus amples informations. Si la gestion des médias est névralgique, la gestion de l’information l’est tout autant. En situation de crise, on a souvent tendance à s’asseoir sur l’information et à ne la partager qu’à des cercles restreints, ou, au contraire, à inonder nos publics d’informations inutiles. Un juste milieu doit être trouvé entre ces deux stratégies sachant pertinemment que le message devra évoluer en même temps que la crise.

(6) Être conséquent et consistant

Même s’il évolue en fonction du stade de la crise, le message de base doit pourtant demeurer le même. Dans l’exemple de Maple Leaf évoqué plus haut, bien que de nouveaux éléments aient surgi au fur et à mesure de l’évolution de la crise, le message de base, à savoir la mise en œuvre de mesures visant à assurer la santé et la sécurité du public, a été constamment repris sur tous les tons. Ainsi, Maple Leaf s’est montrée à la fois consistante en respectant sa ligne de réaction initiale et conséquente, en restant en phase avec le développement de la situation.

(7) Être ouvert d’esprit

Dans toute situation de crise, une attitude d’ouverture s’avérera gagnante. Que ce soit avec les médias, les victimes, nos employés, nos partenaires ou les agences publiques de contrôle, un esprit obtus ne fera qu’envenimer la situation. D’autant plus qu’en situation de crise, ce n’est pas vraiment ce qui est arrivé qui compte mais bien ce que les gens pensent qui est arrivé. Il faut donc suivre l’actualité afin de pouvoir anticiper l’angle que choisiront les médias et s’y préparer en conséquence.

En conclusion

Dans une perspective de gestion de crise, il est essentiel de disposer d’un plan d’action au préalable, même s’il faut l’appliquer avec souplesse pour répondre à l’évolution de la situation. Lorsque la crise a éclaté, c’est le pire moment pour commencer à s’organiser. Il est essentiel d’établir une culture de gestion des risques et de gestion de crise dans l’organisation avant que la crise ne frappe. Comme le dit le vieux sage,  » pour être prêt, faut se préparer ! »

____________________________________

* Richard Thibault, ABCP

Président de RTCOMM, une entreprise spécialisée en positionnement stratégique et en gestion de crise

Menant de front des études de Droit à l’Université Laval de Québec, une carrière au théâtre, à la radio et à la télévision, Richard Thibault s’est très tôt orienté vers le secteur des communications, duquel il a développé une expertise solide et diversifiée. Après avoir été animateur, journaliste et recherchiste à la télévision et à la radio de la région de Québec pendant près de cinq ans, il a occupé le poste d’animateur des débats et de responsable des affaires publiques de l’Assemblée nationale de 1979 à 1987.

Richard Thibault a ensuite tour à tour assumé les fonctions de directeur de cabinet et d’attaché de presse de plusieurs ministres du cabinet de Robert Bourassa, de conseiller spécial et directeur des communications à la Commission de la santé et de la sécurité au travail et de directeur des communications chez Les Nordiques de Québec.

En 1994, il fonda Richard Thibault Communications inc. (RTCOMM). D’abord spécialisée en positionnement stratégique et en communication de crise, l’entreprise a peu à peu élargi son expertise pour y inclure tous les champs de pratique de la continuité des affaires. D’autre part, reconnaissant l’importance de porte-parole qualifiés en période trouble, RTCOMM dispose également d’une école de formation à la parole en public. Son programme de formation aux relations avec les médias est d’ailleurs le seul programme de cette nature reconnu par le ministère de la Sécurité publique du Québec, dans un contexte de communication d’urgence. Ce programme de formation est aussi accrédité par le Barreau du Québec.

Richard Thibault est l’auteur de Devenez champion dans vos communications et de Osez parler en public, publié aux Éditions MultiMondes et de Comment gérer la prochaine crise, édité chez Transcontinental, dans la Collection Entreprendre. Praticien reconnu de la gestion des risques et de crise, il est accrédité par la Disaster Recovery Institute International (DRII).

Spécialités : Expert en positionnement stratégique, gestion des risques, communications de crise, continuité des affaires, formation à la parole en public.

http://www.linkedin.com/profile/view?id=46704908&locale=fr_FR&trk=tyah

** Article en reprise

Enhanced by Zemanta

Pouls de la profession | PMI


Voici un documentent recommandé par Denis Lefort, CPA, CA, CIA, CRMA, présentant  le rapport annuel intitulé Pouls de la profession (Pulse of the profession) publié par le Project Management Institute concernant les enjeux en matière de gestion de projets et de programmes.

Ce sondage annuel met en lumière des enjeux de taille, notamment celui à l’effet que 44% des initiatives stratégiques ne sont pas fructueuses en raison de projets non alignés avec la stratégie organisationnelle.

Qui sait, peut-être que certaines observations seront utiles pour la gestion de votre service d’audit interne….

Bonne lecture!

http://www.pmi.org/~/media/PDF/Business-Solutions/PMI_Pulse_2014.ashx

La réputation de l’entreprise : un actif intangible à protéger *


Vous trouverez, ci-joint, la dernière version du Rapport Bourgogne, publié par CIRANO, un centre de recherche multidisciplinaire qui a pour mission l’accélération du transfert des savoirs entre le monde de la recherche et celui de la pratique.

L’étude réalisée par Nathalie de Marcellis-Warin, professeure agrégée à l’École Polytechnique de Montréal et vice-présidente au CIRANO et Serban Teodoresco, Président de Preventa Inc., présentent, en une page, les principales conclusions tirées d’une analyse documentaire des recherches menées au cours des 12 dernières années et les résultats d’une étude exploratoire de 80 grandes sociétés au Québec. À lire.

La réputation de l’entreprise : un actif intangible à protéger

 

« La réputation de l’entreprise est de plus en plus définie comme l’actif stratégique le plus important sur le plan de la création de valeur. L’intérêt des scientifiques à l’égard du concept de réputation de l’entreprise a contribué à quintupler le nombre d’articles et d’études évalués par des pairs au cours de la dernière décennie (Barnett et al., 2006). Pourtant, aucune définition n’est généralement acceptée.

English: Reputation management graphic that br...
English: Reputation management graphic that breaks down the elements of reputation management and how they fit together. (Photo credit: Wikipedia)

Nous proposons une définition de la réputation de l’entreprise fondée sur des sources universitaires et des travaux d’experts : La réputation de l’entreprise est un actif incorporel acquis avec le temps et représente la valeur et la confiance accordées à l’organisation par les parties prenantes.

C’est un élément-clé qui favorise l’atteinte d’objectifs stratégiques, dont la création de valeur, la croissance rentable et l’avantage concurrentiel durable. Notre sondage, mené au Québec, montre que seulement la moitié des sociétés interrogées reconnaissent l’importance de la réputation. Aucune ne semble gérer la réputation de façon proactive… Le présent ouvrage propose un plan d’action à l’intention des sociétés désireuses d’effectuer la transition entre la gestion réactive et la gestion proactive de la réputation ».

______________________________________________

* En reprise

Enhanced by Zemanta

Un guide essentiel pour comprendre et enseigner la gouvernance | Version française *


Plusieurs administrateurs et formateurs me demandent de leur proposer un document de vulgarisation sur le sujet de la gouvernance. J’ai déjà diffusé sur mon blogue un guide à l’intention des journalistes spécialisés dans le domaine de la gouvernance des sociétés à travers le monde.

Il a été publié par le Global Corporate Governance Forum et International Finance Corporation (un organisme de la World Bank) en étroite coopération avec International Center for Journalists.

Je n’ai encore rien vu de plus complet et de plus pertinent sur la meilleure manière d’appréhender les multiples problématiques reliées à la gouvernance des entreprises mondiales. La direction de Global Corporate Governance Forum m’a fait parvenir le document en français le 14 février.

Qui dirige l’entreprise : Guide pratique de médiatisation du gouvernement d’entreprise – document en français

 

Ce guide est un outil pédagogique indispensable pour acquérir une solide compréhension des diverses facettes de la gouvernance des sociétés. Les auteurs ont multiplié les exemples de problèmes d’éthiques et de conflits d’intérêts liés à la conduite des entreprises mondiales. On apprend aux journalistes économiques – et à toutes les personnes préoccupées par la saine gouvernance – à raffiner les investigations et à diffuser les résultats des analyses effectuées.

Je vous recommande fortement de lire le document, mais aussi de le conserver en lieu sûr car il est fort probable que vous aurez l’occasion de vous en servir.

Vous trouverez ci-dessous quelques extraits de l’introduction à la version anglaise de l’ouvrage que j’avais publiée antérieurement.

Who’s Running the Company ? A Guide to Reporting on Corporate Governance

 

À propos du Guide

English: Paternoster Sauqre at night, 21st May...

« This Guide is designed for reporters and editors who already have some experience covering business and finance. The goal is to help journalists develop stories that examine how a company is governed, and spot events that may have serious consequences for the company’s survival, shareholders and stakeholders. Topics include the media’s role as a watchdog, how the board of directors functions, what constitutes good practice, what financial reports reveal, what role shareholders play and how to track down and use information shedding light on a company’s inner workings. Journalists will learn how to recognize “red flags,” or warning  signs, that indicate whether a company may be violating laws and rules. Tips on reporting and writing guide reporters in developing clear, balanced, fair and convincing stories.

Three recurring features in the Guide help reporters apply “lessons learned” to their own “beats,” or coverage areas:

– Reporter’s Notebook: Advise from successful business journalists

– Story Toolbox:  How and where to find the story ideas

– What Do You Know? Applying the Guide’s lessons

Each chapter helps journalists acquire the knowledge and skills needed to recognize potential stories in the companies they cover, dig out the essential facts, interpret their findings and write clear, compelling stories:

  1. What corporate governance is, and how it can lead to stories. (Chapter 1, What’s good governance, and why should journalists care?)
  2. How understanding the role that the board and its committees play can lead to stories that competitors miss. (Chapter 2, The all-important board of directors)
  3. Shareholders are not only the ultimate stakeholders in public companies, but they often are an excellent source for story ideas. (Chapter 3, All about shareholders)
  4. Understanding how companies are structured helps journalists figure out how the board and management interact and why family-owned and state-owned enterprises (SOEs), may not always operate in the best interests of shareholders and the public. (Chapter 4, Inside family-owned and state-owned enterprises)
  5. Regulatory disclosures can be a rich source of exclusive stories for journalists who know where to look and how to interpret what they see. (Chapter 5, Toeing the line: regulations and disclosure)
  6. Reading financial statements and annual reports — especially the fine print — often leads to journalistic scoops. (Chapter 6, Finding the story behind the numbers)
  7. Developing sources is a key element for reporters covering companies. So is dealing with resistance and pressure from company executives and public relations directors. (Chapter 7, Writing and reporting tips)

 

Each chapter ends with a section on Sources, which lists background resources pertinent to that chapter’s topics. At the end of the Guide, a Selected Resources section provides useful websites and recommended reading on corporate governance. The Glossary defines terminology used in covering companies and corporate governance ».

______________________________________________

* En reprise

Enhanced by Zemanta

Le rôle de l’audit interne dans l’identification des risques émergents *


Denis Lefort, CPA, expert-conseil en Gouvernance, audit et contrôle, porte à ma connaissance un document de la firme Thomson Reuters (White Paper) très intéressant sur le rôle de l’audit interne dans l’identification des risques émergents.

EYE ON THE HORIZON : INTERNAL AUDIT’S ROLE IN IDENTIFYING EMERGING RISKS

Key elements of emerging risks

Reinsurance company Swiss Re defines emerging risks as “newly developing or changing risks which are difficult to quantify and which may have a major impact on the organisation.” This identifies their key elements.

Emerging risks may be entirely new, such as those posed by social media or technological innovation. Or they may come from existing risks that evolve or escalate – for example, the way counterparty credit risk or liquidity risk sky-rocketed during the 2008 financial crisis.

Newly developing risks lack precedent or history, and their precise form may not be immediately clear, which makes them difficult to measure or model. Changing risks are at least familiar in their shape and nature, although the rate of transformation and intensity can make them hard to quantify.

The final key element of emerging risks is their potential impact. New or changing risks can be as menacing as those the organisation deals with on a daily basis, and sometimes even more so. To give just one example, the way in which the music business failed to address the implications of digital downloads allowed a complete outsider, the computer company Apple, to step in and define and dominate the new market.

Emerging risks also threaten through their apparent remoteness or their obscurity. US Secretary of State Donald Rumsfeld distinguished between things we know we do not know (‘known unknowns’), and things we do not know we do not know (‘unknown unknowns’). In the first category are risks whose shape might be familiar, but where we do not necessarily understand all of their elements – causes, potential impact, probability or timing. Unknown unknowns are events that are so out of left field or seemingly farfetchedthat it takes great insight or a leap of the imagination to even articulate them. These include the ‘black swan’ events highlighted by the investor-philosopher Nassim Nicholas Taleb, where the human tendency is to dismiss them as improbable beforehand, then rationalise them after they occur. The 9/11 terrorist attack, or the financial crash of 2008, or the invention of the internet show that not only do black swan events happen, but they do so more frequently than is generally recognised, and they have an historically significant impact (and not always negative).

Many emerging risks are characterised by their global nature, their scale or their longer-term horizon – climate change is an example that displays all of these elements. In other cases, it is less the individual events themselves, some of which may be relatively moderate or manageable on their own, as the conflation of circumstances that creates a ‘perfect storm’.

Vous pouvez aussi consulter l’enquête de Thomson Reuters Accelus Survey on Internal Audit dont nous avons parlé dans notre billet du 7 juin.

New duties on horizon for internal auditors

“The clear message from the survey is that internal audit functions need to stop thinking about themselves as compliance specialists and start taking on a much larger, more strategic role within the organization,” Ernst & Young LLP internal audit leader Brian Schwartz said in a news release. “IA is increasingly being asked by senior management and the board to provide broader business insights and better anticipate traditional and emerging risks, even as they maintain their focus on non-negotiable compliance activities.”

New risks

As strategic opportunities emerge, internal auditors also are adjusting to new compliance duties, according to the survey. Globalization has resulted in increased revenue from emerging markets for many companies, so new regulatory, cultural, tax, and talent risks are emerging.

Thomson Reuters Messenger
Thomson Reuters Messenger (Photo credit: Wikipedia)

Internal audit will play a more prominent role in evaluating these risks, according to the survey report. Although slightly more than one-fourth (27%) of respondents are heavily involved in identifying, assessing, and monitoring emerging risks now, 54% expect to be heavily involved in the next two years.

The biggest primary risks that respondents said their organizations are tracking are:

  1. Economic stability (54%).
  2. Cybersecurity (52%).
  3. Major shifts in technology (48%).
  4. Strategic transactions in global locations (44%).
  5. Data privacy regulations (39%).

Survey respondents said the skills most often found to be lacking in internal audit functions are:

  1. Data analytics;
  2. Business strategy;
  3. Deep industry experience;
  4. Risk management; and
  5. Fraud prevention and detection.

“As corporate leaders demand a greater measure of strategy and insight from their internal audit functions, CAEs will need to move quickly to close competency gaps and ensure that they have the right people in the right place, at the right time.” Schwartz said. “If they fail to meet organizational expectations, they risk being left behind or consigned to more transactional compliance activities.”

__________________________________________

* En reprise

Keeping Internal Auditors Up to the Challenge (forbes.com)

Internal Audit Has To STOP Focusing On Internal Controls (business2community.com)

Changement important dans la relation auditeur externe/interne | Financial Reporting Council (FRC) (jacquesgrisegouvernance.com)

Useful Internal Auditing in 4 Easy Steps (isocertificationaustralia.com)

Thomson Reuters Develops Accelus Governance, Risk and Compliance Platform (risk-technology.typepad.com)

Enhanced by Zemanta

Le rôle du C.A. dans la gestion des risques *


La gestion des risques est une activité-clé qui doit être orchestrée par la direction de l’entreprise. Mais quel doit être le rôle du conseil d’administration en matière de surveillance de l’exécution de cette tâche essentielle ?

Quel est effectivement l’étendu du rôle du conseil dans les grandes sociétés publiques américaines. C’est ce que le document du Conference Board, présenté ici, décrit avec moult détails et d’une manière exceptionnellement bien illustrée.

Je vous invite donc à prendre connaissance de ce texte qui traite des aspects suivants :

Responsabilité pour l’établissement des stratégies
Fréquence des révisions des stratégies
Réunion spéciale de planification stratégique
Adoption d’une approche standardisée telle qu’ERM (Enterprise Risk Management)
Responsabilité pour la surveillance des risques
Fréquence des comptes rendus de la direction au C.A. en matière de risque
Le responsable en chef de la gestion des risques (CRO)
Le comité des risques de l’entreprise
 

Risk in the Boardroom

Any business is exposed to risks that can threaten its ability to execute its strategy. For this reason, strategy and risk oversight are inherently connected. Today, more than ever, the board of directors is expected to thoroughly assess key business risks and ensure that the enterprise is equipped to mitigate them. This Directors Notes discusses the current corporate practices on risk oversight by directors of U.S. public companies. Findings detail where the board assigns these responsibilities, whether it avails itself of dedicated reporting lines from senior management on risk issues, and the degree to which it adopts a standardized framework on enterprise risk management (ERM).

ERM - Enterprise Risk Management
ERM – Enterprise Risk Management (Photo credit: Orange Steeler)

Given the correlation between risk and strategy, data on the frequency and forms of strategic reviews is also presented. The findings are from the most recent edition of the Board Practices Survey, which The Conference Board conducts annually in collaboration with NASDAQ OMX and NYSE Euronext (see “The Board Practices Survey” on p. 5). The Dodd-Frank Act mandates that financial institutions strengthen their risk oversight by establishing a dedicated risk committee of the board of directors.

In addition, U.S. Securities and Exchange Commission (SEC) rules require all public companies to disclose the extent of their board’s role in overseeing the organization’s risk exposure, including how the board administers its risk oversight function and how the leadership structure accommodates such a role.

Finally, in October 2009, the SEC reversed a policy under which shareholder proposals relating to the evaluation of risk could be excluded from a company’s proxy materials as related to the company’s ordinary day-to-day business activities. Collectively, these developments are a nod in the direction of addressing the risk oversight failures that played so prominently in the 2008 financial crisis. Most important, they are expected to increase scrutiny of risk management programs and their endorsement and close supervision by senior leaders of corporations.

_______________________________________

* En reprise

Enhanced by Zemanta

La gouvernance dans tous ses états | Huit (8) articles parus dans Lesaffaires.com


Voici une série de huit articles, publiés le 31 mars 2014 par les experts du Collège des administrateurs de sociétés (CAS) dans le volet Dossier de l’édition Les Affaires.com

Découvrez comment les entreprises et les administrateurs doivent s’adapter afin de tirer profit des meilleures pratiques.

  1. Une bonne gouvernance, c’est aussi pour les PME
  2. Les défis de la gouvernance à l’ère du numérique
  3. La montée de l’activisme des actionnaires en six questions
  4. Gouvernance : 12 tendances à surveiller
  5. Gouvernance : huit principes à respecter
  6. Conseils d’administration : la diversité, mode d’emploi
  7. Les administrateurs doivent-ils développer leurs compétences ?
  8. Vous souhaitez occuper un poste sur un conseil d’administration ?

Vos commentaires sont appréciés. Bonne lecture !

La gouvernance dans tous ses états | Huit articles parus dans Lesaffaires.com

 

image

Une bonne gouvernance, c’est aussi pour les PME

Une entrevue avec M. Réjean Dancause, président et directeur général du Groupe Dancause et Associés inc.

image

Les défis de la gouvernance à l’ère du numérique

Une entrevue avec M. Gilles Bernier, directeur des programmes du Collège des administrateurs de sociétés

image

La montée de l’activisme des actionnaires en six questions

Une entrevue avec M. Jean Bédard, titulaire de la Chaire de recherche en gouvernance de sociétés, Université Laval

image

Gouvernance : 12 tendances à surveiller

Une entrevue avec M. Jacques Grisé, auteur du blogue jacquesgrisegouvernance.com

image

Gouvernance : huit principes à respecter

Une entrevue avec M. Richard Drouin, avocat-conseil, McCarthy Tétrault

image

Conseils d’administration : la diversité, mode d’emploi

Une entrevue avec Mme Nicolle Forget, administratrice de sociétés

image

Les administrateurs doivent-ils développer leurs compétences?

Une entrevue avec Mme Louise Champoux-Paillé, administratrice de sociétés et présidente du …

image

Vous souhaitez occuper un poste sur un conseil d’administration ?

Une entrevue avec M. Richard Joly, président de Leaders et Cie

_____________________________________________

Enhanced by Zemanta

La bonne gouvernance selon Munger, vice-président du C.A. de Berkshire *


Aujourd’hui, je vous propose une très intéressante lecture publiée par David F. Larcker et Brian Tayan, de la  Stanford Graduate School of Business qui porte sur la conception que se fait Charles Munger de la bonne gouvernance des sociétés.

Les auteurs nous proposent de répondre à trois questions relatives à la position de Munger, vice-président du conseil de Berkshire :

1. Le système de gouvernance basé sur la confiance avancé par Munger pourrait-il s’appliquer à différents types d’organisations ?

2. Quelles pratiques de gouvernance sont-elles nécessaires et quelles pratiques sont-elles superflues ?

3. Comment s’assurer que la culture organisationnelle survivra à un processus de succession du PCD ?

À la suite de la lecture de l’article ci-dessous, quelles seraient vos réponses à ces questions.

Voici un résumé de la pensée de Munger, suivi d’un court extrait. Bonne lecture !

Charlie Munger

Berkshire Hathaway Vice Chairman Charlie Munger is well known as the partner of CEO Warren Buffett and also for his advocacy of “multi-disciplinary thinking” — the application of fundamental concepts from across various academic disciplines to solve complex real-world problems. One problem that Munger has addressed over the years is the optimal system of corporate governance.
 
Munger advocates that corporate governance systems become more simple, rather than more complex, and rely on trust rather than compliance to instill ethical behavior in employees and executives. He advocates giving more power to a highly capable and ethical CEO, and taking several steps to improve the culture of the organization to reduce the risk of self-interested behavior.

Corporate Governance According to Charles T. Munger

How should an organization be structured to encourage ethical behavior among organizational participants and motivate decision-making in the best interest of shareholders? His solution is unconventional by the standards of governance today and somewhat at odds with regulatory guidelines. However, the insights that Munger provides represent a contrast to current “best practices” and suggest the potential for alternative solutions to improve corporate performance and executive behavior.

Trust-Based Governance

The need for a governance system is based on the premise that individuals working in a firm are selfinterested and therefore willing to take actions to further their own interest at the expense of the organization’s interests. To discourage this tendency, companies implement a series of carrots (incentives) and sticks (controls). The incentives might be monetary, such as performance-based compensation that aligns the financial interest of executives with shareholders. Or they might be or cultural, such as organizational norms that encourage certain behaviors. The controls include policies and procédures to limit malfeasance and oversight mechanisms to review executive decisions.

_______________________________

* En reprise

Enhanced by Zemanta

Dix leçons tirées d’une multitude d’entrevues avec des PCD de PME **


Quelles leçons peut-on tirer des entrevues avec les PCD (CEO) d’entreprises de petites capitalisations. C’est ce que nous présente Adam J. Epstein*, un spécialiste de « hedge fund » qui investit des centaines de millions de dollars dans les petites entreprises. L’article a été publié dans mc2MicroCap par Ian Cassel.

J’ai trouvé les conseils très pertinents pour les personnes intéressées à connaître la réalité des évaluations d’entreprises par des investisseurs privés. Qu’en pensez-vous ?

10 Lessons Learned from Interviewing Hundreds of MicroCap CEOs

1)    Preparation – there is no reason to waste your time and someone else’s by sitting down with a CEO to discuss their company without preparing – really preparing.  To me, “really preparing” doesn’t mean looking at Yahoo Finance for a few minutes in the taxi on the way to the meeting, or flipping through the company’s PowerPoint on your phone.  That kind of preparation is akin to walking up a few flights of stairs with some grocery bags to get ready for climbing Mt. Rainier.  To be really prepared for a first meeting means reading/skimming the most recent 10K, the most recent 10Q, the most recent proxy filing, the management presentation, any previous management presentations (more on this later), a recent sell-side company or industry report, and an Internet search of the management team’s backgrounds (with particular emphasis on any prior SEC, NASD, or other state/federal legal problems).  It’s hard to overemphasize how many would-be micro-cap investing disasters can be headed off at the pass by reading what’s said, and not said, and then having the opportunity to ask the CEO directly about what you’ve found.

Stream Near Mt Rainier

2)    Non-Starters – for better or worse, the micro-cap world is home to some “colorful” management teams.  After all of the time served in this regard, absolutely nothing surprises me anymore.  I have found CEOs who were simultaneously running 3 companies, CEOs who were banned from running a public company by the SEC, management presentations that were largely plagiarized, CEOs who shouted profanities in response to basic questions about their “skin in the game,” and CEOs who not only didn’t understand Reg. FD, but clearly didn’t even know it existed.  When in doubt, it’s much better not to invest at all than to make a bad investment; fortunately there are always thousands of other companies to consider.

3)    Company .PPT – these presentations speak volumes about what kind of company you are dealing with if you’re paying attention: a) my colleagues and I came up with a golden rule during my institutional investing tenure, namely that the length of a .ppt presentation is, more often than not, inversely proportional to the quality of the micro-cap company being presented (i.e., any micro-cap company that can’t be adequately presented in less than 20 slides is a problem, and 15 is even better); b) if the slides are too complex to understand on a standalone basis then either the company has a problem or you’re about to invest in something you don’t sufficiently understand – neither is good; c) NEO bios, market information, service/product/IP, strategy, financials, and use of proceeds should all receive equal billing (when buying a house, would you go and visit a house with an online profile that only features pictures of the front yard and the garage?); d) .ppt formatting and spelling/syntax problems are akin to showing up at an important job interview with giant pieces of spinach in your teeth; e) when reviewing use of proceeds (for a prospective financing) or milestones, look up prior investor presentations to see how well they did with prior promises – history often repeats itself; f) treat forward looking projections for what they typically are – fanciful at best, and violations of Reg. FD at worst; and g) micro-cap companies that flaunt celebrities as directors, partners, or investors should be approached cautiously.

4)    NEO Bios – as Ian Cassel often points out quite rightly in my opinion, micro-cap investing is an exercise in wagering on jockeys more than horses.  One of the principal ways prospective investors have to assess jockeys is the manner in which professional backgrounds are set forth; i.e., management bios.  Like a company .ppt, bios of named executive officers speak volumes about the people being described. Here are some things to look out for: a) bios that don’t contain specific company names (at least for a 10 year historic period) typically don’t for a reason, and it’s unlikely to be positive (e.g., “Mr. Smith has held senior management roles with several large technology companies”); b) it’s a good idea to compare SEC bios with bios you might find for the same people on other websites (remember the “three company CEO” referred to earlier?); c) bios that don’t contain any educational references or only highlight executive programs at Harvard, Wharton, Stanford, etc.; d) company websites that don’t have any management/director bios (surprising how many there are); and e) CEOs and CFOs who have never held those jobs before in a public company (to be clear, lots of micro-cap NEOs are “first-timers,” but it’s something you should at least factor into the risk profile of the investment).

5)    Management Conduct – just as management bios speak volumes, so does their conduct at in person one-on-one meetings.  More specifically: a) organized, professional corporate leaders rarely look disheveled or have bad hygiene; b) service providers chosen by companies also represent the company, so the previous observation applies to bankers/lawyers as well; c) CEOs who are overly chatty about non-business issues might not be keen to talk about their companies; d) if a CEO seems glued to their .ppt presentation (i.e., essentially just reading you the slides), tell them to close their laptops and just talk about the company with no visual aids – you will learn an awful lot about them in the ensuing 5 minutes; e) be on the lookout for NEOs or service providers cutting each other off, disagreeing with each other, or talking over one another;  f) when asking questions of the CEO or CFO watch their body language – moving around in their seats, running hands through their hair, perspiration, and less eye contact are nonverbal signs of duress (it’s one of the reasons why in-person meetings with management are always preferable to phone calls); g) if there are more than one NEOs in attendance, are they listening to each other (it’s rarely a great sign when other execs are looking at their phones during meetings); h) is the CEO providing careful, thoughtful answers or are they shooting from the hip – loose lips virtually always sink ships; i) did the CEO answer any questions with “I don’t know” – even great CEOs can’t possibly know the answer to every question about their companies; and j) something partially tongue-in-cheek just to think about – we know from everyday life that when someone starts a sentence with “with all due respect” what inevitably  follows is, well, something disrespectful, and when a CEO repeatedly says “to be honest” what inevitably follows is….

6)    Service Providers – micro-cap service providers (bankers, lawyers, auditors, IR firms, etc.) can run the gamut from highly professional to so bad that they can actually jeopardize companies with their advice.  While it certainly can take a while to learn “the good, the bad, and the ugly” in the micro-cap ecosystem, you can learn a lot about the CEO by asking him/her to take a few minutes to explain why the company’s service providers are the best choices for the shareholders.  It perhaps goes without saying that if a CEO can’t speak artfully, and convincingly in this regard, then buyer beware.

7)    Corporate Governance – spans the full continuum in micro-cap companies from top-notch to nothing more than a mirage.  One way to quickly ferret out which flavor of governance you’re dealing with is to ask a CEO to succinctly set forth the company’s strategy (i.e., goals, risks, opportunities, customers, etc.), and subsequently ask the CEO to describe how each seated director assists with the fundamental elements of achieving that strategy.  Though oversimplified, material disconnects in this regard are very likely to illustrate some governance challenges.  Also, ask the CEO how each of the directors came to the company; if all of the directors were brought to the company by the CEO, it’s fair to ask the CEO how confident an investor should be that the board is suitably independent to monitor the CEOs performance (one of the principal roles of all boards).

8)    Public Company IQ – easily one of the biggest problems with investing in the micro-cap arena is the conspicuous lack of (relevant, successful) capital markets and corporate finance experience in boardrooms and C-suites.  As alluded to earlier, it’s a fact of life that a large percentage of micro-cap officers and directors lack appreciable tenures in shepherding small public companies (to be clear, this doesn’t mean they aren’t smart, successful, and sophisticated, it just means they haven’t had lots of experience in small public companies).  Unlike larger public companies, small public companies can execute relatively well, and still toil in obscurity creating little or no value for shareholders.   It’s a good idea to evaluate the same when meeting with management, because companies with low “public company IQs” are more likely to underperform all else being equal.  Be on the lookout for CEOs who: a) can’t articulate a sensible strategy for maintaining or increasing trading volume; b) seem to regularly undertake financings that are more dilutive than similarly situated peer companies; c) frequently authorize the issuance of press releases that don’t appear to contain material information; d) blame some or all of their capital markets challenges on short-seller/market-making conspiracy theories; and e) can’t name the company’s largest 5 shareholders, their approximate holdings, and the last time he/she spoke to each.

9)    Follow-Up – CEOs who promise to follow-up after meetings with clarified answers, customer references, or more information but don’t are tacitly underscoring for you that they are either disorganized, disingenuous, don’t care about investors or all three.  The opposite is also not good; for example, if the company’s internal or external IR professionals subsequently convey information that seems inappropriate (from a Reg. FD standpoint) – it probably is.

10) Cautionary Note – Bernard Madoff undoubtedly would have passed these tests and a lot more with flying colors.  Sometimes the “bad guys” are really smart and charming and you’re going to either lose most of your money or get defrauded, or both. It’s happened to me, and it’s maddening and humbling at the same time.  Hence, the apt phrase: high risk, high return.

It’s easy, in my experience anyway, to get so skeptical about micro-cap companies that it can be paralyzing.  But, just when you’re about to throw in the towel, along comes a compelling growth prospect run by management with as much integrity and skill as the day is long, and it serves as a poignant reminder of everything that’s great about investing in small public companies.

Like most “best-of” lists, this isn’t intended to be exhaustive by any stretch of the imagination.  In addition to making money and promoting US jobs/innovation, one of the best parts of investing in small public companies in my opinion is continuing to hone the craft, and learn from other investors and their experiences.  Accordingly, add/subtract per your own experiences, and happy hunting.

_________________________________________

*Adam J. Epstein advises small-cap boards through his firm, Third Creek Advisors, LLC, is a National Association of Corporate Directors Board Leadership Fellow, and the author of The Perfect Corporate Board: A Handbook for Mastering the Unique Challenges of Small-Cap Companies, (McGraw Hill, 2012).  He was co-founder and principal of Enable Capital Management, LLC.

** En reprise

Enhanced by Zemanta