Events, within the context of ERMA, are defined as any occurrences or potential scenarios that might adversely impact Waystone, be it financially, operationally, or from a regulatory or legal standpoint.
These events are meticulously logged by personnel spanning across Waystone’s diverse business units. Upon logging, these events undergo a comprehensive review process by both the Compliance and Risk departments, which contribute their insights for the formulation of appropriate Corrective Actions. Furthermore, these events can be categorized into several types such as pre-emptive (Internal Audit findings), non-events, breaches, or incidents that transpire.
On the other hand, Decisions encapsulate situations where a business unit (BU) necessitates guidance from a pertinent Risk Committee or other control functions. Decisions may pertain to policy and procedure exceptions, establishment of new outsourcing partnerships, data privacy impact assessments, recommendations for existing high-risk clientele, or the introduction of new products, licenses, or business lines requiring a decision from a relevant Risk Committee.