Internal Audit & Enterprise Risk Management.pptx

AhmedAmrRashad 141 views 28 slides May 17, 2024
Slide 1
Slide 1 of 28
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28

About This Presentation

Risk management


Slide Content

Working Together Luis Fernandez March 10 th , 2015 Internal Audit & Enterprise Risk Management 19/05/2022 1

19/05/2022 2 Let’s think about risk… …and find ways to better align our process.

Let’s talk about… Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 3

Objective Collaboration of risk-management and internal-audit functions is helping organizations improve efficiency , decision-making , and results . ( Reference 1 ) 19/05/2022 4 Is this happening?

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 5

Overview 19/05/2022 6 In 1999 IIA revised the definition of internal auditing to include both assurance and consulting activities. In 2004 the Commission of Sponsoring Organizations of the Treadway Commission (COSO) released its integrated framework for ERM. IIA issues a position paper delineating the core roles of IA in regard to ERM. (IIA, 2004a). ( Reference 2 )

ERM is defined by COSO (2004, 2) as: “…a process, effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.” Overview…cont’d 19/05/2022 7 ( Reference 2 )

Overview…cont’d 19/05/2022 8 When announcing the release of the COSO framework, the IIA issued a statement commenting on the internal auditor’s role in risk management (IIA, 2004b). “Internal auditors should assist both management and the audit committee in their risk management responsibilities and oversight roles by examining, evaluating, reporting, and recommending improvements on the adequacy and effectiveness of management’s risk processes.” ( Reference 2 )

Overview…cont’d 19/05/2022 9

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 10

Trends in Financial Services 19/05/2022 11 Convergence Barriers separating Banks, Brokerage and Insurers are coming down. CROSS SELLING! Consolidation Acquisitions. Reduce operating expenses and increase market share. Changing Business Models Ways to make more profit (Technology, etc.) Challenge: Customization and Personalization of product lines. Changes in structure for revenue models.

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 12

IA’s challenge: 19/05/2022 13 It needs to reconsider its role! Board Oversight Execution – A clear differentiator Change Management Operating style and culture – Critical to execution effectiveness Change the mindset! From control oriented to risk oriented.

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 14

Is audit focused on the real risks? 19/05/2022 15 6% 12% 68% 13% Financial Compliance Operational Strategic/Business 12% 6% 13% 68% ( Reference 6 ) However, a significant percentage of internal audit resources are focused on financial controls in most organizations.

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 16

What should be the approach? 19/05/2022 17 Audit Plan Traditional Transformed ( Reference 6 ) Evaluate impact of risks within universe. Identify different risks (financial, operational, Compliance). Define Audit Universe. Identify shareholders value by creating business assessment activities. Understand Enterprise Risks (Strategic, Financial, Ops, Compliance). Evaluate impact to shareholder value. √ √ √

ERM three-dimensional matrix: 19/05/2022 18 ( Reference 5 )

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 19

How do we assess risk priorities? 19/05/2022 20 ( Reference 6 ) Result : Audit universe is prioritized based on impact on shareholder value drivers, and the current and targeted maturity of the processes, programs and initiatives

Sample Risk Assessment Framework 19/05/2022 21 ( Reference 6 ) Result : A practical framework is created based on risk information and judgment.

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 22

Audit Plan 19/05/2022 23 ( Reference 6 ) Result : Audit plan is based on impact on shareholder value drivers, regulatory requirements/priorities and audit judgment.

How do we continue the process? 19/05/2022 24 ( Reference 6 ) Result : The relevance of the framework is driven per behavior of each of the elements of the audit program/plan, and audit judgment.

Table Content Objective Overview Trends in Financial Services Internal Audit Challenge Real Risks? Approach Assessment Framework Audit Plan Role of IA in ERM 19/05/2022 25

Summarizing - Role of IA in ERM 19/05/2022 26 Core Internal Auditing Roles in ERM Giving assurance on risk management processes Giving assurance that risks are correctly evaluated Evaluating risk management processes Evaluating the reporting of risks Reviewing the management of key risks ( Reference 2 ) Roles internal auditing should not undertake Setting the risk appetite Imposing risk management processes Management assurance on risks Taking decisions on risk responses Implementing risk responses on management’s behalf Accountability for risk management

19/05/2022 27 Luis Fernandez [email protected] (704) 724-2481

References Kristina Narvaez & John Bugalla , October 22,2012, CFO.com Laura de Zwaan , Jenny Stewart and Nava Subramaniam , Internal Audit Involvement in ERM, Griffith University, Queensland Australia, No. 2009-02 Andre Brodeur & Martin Pergler , Top- dow ERM: A pragmatic Approach to Managing Risk from the C-Suite, McKinzey working papers on risk, #22 Institute of Internal Auditors, The Professional Practices Framework, January 22 COSO – ERM Enterprise Risk Management - Integrated Framework, Executive Summary, September 2004. Mike Brown & Rich Reynolds, Applying Risk Assessment to Your Audit Plan, The Future of Internal Audit, Corp Executive Board, 2010. Walter Festand - GARP (Global Association of Risk Professionals, Common Themes in SEC and FINRA Exam Priorities, February 12, 2015 19/05/2022 28
Tags