2021 Stakeholder Sustainability Report
A MESSAGE FROM OUR
PRESIDENT & CEO
2021 SUSTAINABILITY
HIGHLIGHTS
ABOUT MOODY'S
BETTER BUSINESS
BETTER LIVES
BETTER SOLUTIONS
APPENDIX
Moody's 2021 Stakeholder Sustainability Report
27
22
Risk Management'
We strive to create confidence in
thousands of organizations worldwide
through our ability to help others better
understand, measure and manage risk.
We strive to approach our own risk
management with the same level of
rigor and continue to mature our risk
management practices and capabilities
to better serve our stakeholders.
ENTERPRISE RISK
MANAGEMENT
Our Board of Directors oversees management's
implementation of policies and processes to manage
our company's exposure to risk. The Audit Committee
supports the Board to oversee the company's risk
assessment and risk management processes.
Our Enterprise Risk Management (ERM) function is
designed to establish a standard, organization-wide
understanding of risk management and define roles
and responsibilities based on the 2017 Committee of
Sponsoring Organizations (COSO) framework. Our
Chief Risk Officer (CRO) is responsible for the full
ERM program, which consists of business-focused risk
functions that coordinate with a central independent
group. We continue to integrate ESG considerations
into our ERM processes.
For more information about our risk factors, see our
2021 Annual Report, pages 27-37.
BUSINESS CONTINUITY
MANAGEMENT
We recognize our responsibility to our customers to
continue critical operations during disruptive events.
Our Business Continuity plans are reviewed by Internal
Audit in conjunction with their annual audit plan. The
plans include local crisis management teams and risk
assessments for every office location. We continually
update these plans and assessments in response to
changes in external risks and internal business processes,
and we have integrated lessons learned from the ongoing
COVID-19 pandemic. Additionally, we conduct annual
third-party risk assessments of key vendors and run
a risk-based testing program that includes tabletop
scenario exercises related to cybersecurity.
RISK EDUCATION AND
AWARENESS
We have taken steps to improve our risk education and
culture, with the goal of cultivating a robust understanding
and awareness of risk among employees. As a company
in the business of assessing risk, this concept is deeply
important to and understood by our employees. On
the ground level, we work to foster a culture and work
environment in which all employees feel comfortable
asking questions, seeking advice and raising issues that
are important to them, including reporting allegations of
non-compliance with laws, regulations and policies. For
more information on compliance training and reporting
mechanisms, see Ethics and Integrity.
For more information on our policies regarding risk
management, see Additional Resources.
1 Refers to Moody's Corporation and its wholly-owned subsidiaries.View entire presentation