Bank of America 2011 Annual Report Download - page 66

Download and view the complete annual report

Please find page 66 of the 2011 Bank of America annual report below. You can navigate through the pages in the report by either clicking on the pages listed below, or by using the keyword search tool below to find specific information within the annual report.

Page out of 276

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

64 Bank of America 2011
established by management, and management reflects these
goals and objectives in our risk appetite which is approved by the
Board and serves as a key driver for setting business and risk
strategy.
One of the key tools of the risk management process is the
use of Risk and Control Self Assessments (RCSAs). RCSAs are
the primary method for facilitating the management of Business
Environment and Internal Control Factor data. The end-to-end RCSA
process incorporates risk identification and assessment of the
control environment; monitoring, reporting and escalating risk;
quality assurance and data validation; and integration with the risk
appetite. The RCSA process also incorporates documentation by
either the business or governance and control functions of the
business environment, risks, controls, and monitoring and
reporting. This results in a comprehensive risk management view
that enables understanding of and action on operational risks and
controls for all of our processes, products, activities and systems.
The formal processes used to manage risk represent a part of
our overall risk management process. Corporate culture and the
actions of our employees are also critical to effective risk
management. Through our Code of Ethics, we set a high standard
for our employees. The Code of Ethics provides a framework for
all of our employees to conduct themselves with the highest
integrity. We instill a strong and comprehensive risk management
culture through communications, training, policies, procedures,
and organizational roles and responsibilities. Additionally, we
continue to strengthen the link between the employee performance
management process and individual compensation to encourage
employees to work toward enterprise-wide risk goals.
Board Oversight of Risk
The Board, comprised of a majority of independent directors,
including an independent Chairman of the Board, oversees the
management of the Corporation through a governance structure
that includes Board committees and management committees.
The Board’s standing committees that oversee the management
of the majority of the risks faced by the Corporation include the
Audit and Enterprise Risk Committees, comprised of independent
directors, and the Credit Committee, comprised of non-
management directors. This governance structure is designed to
align the interests of the Board and management with those of
our stockholders and to foster integrity throughout the Corporation.
The chart below illustrates the inter-relationship between the
Board, Board committees and management committees with the
majority of risk oversight responsibilities for the Corporation.
(1) Compliance Risk activities, including Ethics Oversight, are required to be reviewed by the Audit Committee and Operational Risk activities are required to be reviewed by the Enterprise Risk Committee.
(2) The Disclosure Committee assists the CEO and CFO in fulfilling their responsibility for the accuracy and timeliness of the Corporation’s disclosures and reports the results of the process to the Audit
Committee.
Board of Directors
Board Level
Committees
Management
Level
Committees
Credit
Committee
Enterprise
Risk
Committee
Audit
Committee
Corporate
Governance
Committee
Compensation
and Benefits
Committee
Credit Risk
Committee
Asset Liability
and Market
Risk
Committee
Compensation
Committee
Benefits
Committee
Executive
Committee
Enterprise
Credit Risk
Policy
Committee
Allowance for
Credit Losses
Committee
Enterprise
Portfolio
Strategies
Steering Co.
International
Governance
and Control
Committee
Ethics
Oversight
Committee
Operational &
Compliance
Risk
Committee
CFO Risk
Committee
Enterprise
Model Risk
Control
Committee
Operational
Risk
Committee (1)
Disclosure
Committee (2)
Regional Risk
Committee
Risk Rating
Executive
Oversight
Committee
Enterprise
Mortgage Risk
Committee
Global Markets
Risk
Committee
Insider
Oversight and
Monitoring
Committee