INTERNAL CONTROL AND RISK MANAGEMENT
The Risk and the Control options, monitoring risks to
Environment determine how risks have
changed and documenting
● Every organization faces risks, overall risk management
that is, unforeseen obstacles to program.
the pursuit of its objectives. ● Identification, assessment, and
Risks take many forms and can prioritization of risks followed by
originate from inside or outside coordinated and economical
the organization. application of resources to
● All systems of internal control minimize, monitor and control
involve tradeoffs between cost the probability and/or impact of
and benefit and for this reason, unfortunate events and to
no system of internal control maximize the realization of
can be said to be “100% opportunities.
effective” Organization’s accept
the fact that risk can only be Principles of Risk Management
mitigated, not eliminated.
1. Create value
Internal Control 2. Address uncertainty &
assumptions
● Designed and implemented to 3. An integral part of the
address identified business organizational processes and
risks that threaten the decision-making
achievement of reliability of 4. Should be dynamic, iterative,
financial reporting,effectiveness, transparent, tailorable and
and efficiency of operations and responsive to change
compliance with applicable laws 5. Create capability of conditional
and regulations. improvement and enhancement
Risk Management considering the best available
information & human factors.
● The ongoing process of 6. Be systematic, structured and
designing & operating internal continually or periodically
controls that mitigate the risks reassessed.
identified in the organization’s
risk assessment
● A process of measuring or Enterprise Risk Management (ERM)
assessing risk and developing
strategies to manage it. ● A methodology that looks at risk
● A systematic approach in management strategically from
identifying, analyzing and the perspective of the entire firm
controlling areas or events with or organization. It is a top-down
a potential for causing strategy that aims to identify,
unwanted change. assess, and prepare for
● An act or practice of controlling potential losses, dangers,
risk which includes risk hazards, and other potentials
planning, assessing risk areas, for harm that may interfere with
developing risk handling an organization's operations
and objectives and/or lead to 4. Reporting
losses.
● ERM software is cloud-based > create interactive reports
software that helps businesses using data visualization tools
identify and monitor financial, such as graphs
strategic, and operational risks. 5. Incident management
It assists in mitigating the
impact of risks on organizations' > report security breaches and
earnings and operations. ERM fraudulent activities =, manage
software alerts businesses escalations, track
about potential risks to prevent investigations, analyze
losses and subsequent resolutions, and generate
business failure. insightful reports
Components of ERM System
1. Internal environment Benefits of ERM
2. Objective Setting 1. Alignment of entity’s strategy
3. Event Identification 2. Improvement in risk response
4. Risk Assessment decisions
5. Risk Response 3. Reduction in the number &
6. Control Activities impact of operational surprises
7. Information & Communication & losses
8. Monitoring 4. Identification & Management of
Common features of ERM Software multiple & cross-enterprise risks
5. Improved ability to seize (act )
1. Entity management on opportunities that arises
> manage, store, and track 6. Improved utilization of capital
organizational documents and and resources of the company
records to analyze and mitigate Elements of Risk Management
risks across processes
● Identification, characterization,
2. Risk mitigation tracking and assessment of threats.
> build a repository of mitigation ● Assessment of the vulnerability
activities, controls, and of critical assets to specific
procedures to detect risk-prone threats
operational areas and ● Determination of the risk (i.e.
resources. Assess these the expected likelihood and
resources and operational consequences of specific types
areas to spot process gaps of attacks on specific assets)
● Identification of ways to reduce
3. Compliance management those risks
● Prioritization of risk reduction
> receive automated reminders measures based on a strategy
for deadlines, maintain a record
of each change or action with Main types of Risks
the help of an automatic logging
system, and track compliance 1. Strategic Risks
requirements by 2. Operational Risks
jurisdiction/geography 3. Financial Risks
4. Hazard Risks
Risk Associated with Investments Information Risk (completeness
& accuracy), Financial
1. Business risk Reporting Risk
2. Financial risk
3. Liquidity risk
4. Default risk
5. Interest rate risk 2. Non-Financial Risk
6. Management risk ● Operational Risk (systems,
7. Purchasing power risk customer satisfaction, human
resources, fraud & illegal acts,
Risk Associated with bankruptcy)
Manufacturing, Trading & Service ● Regulatory Risk (capital
Concerns adequacy, compliance, taxation,
changing laws & policies)
1. Market Risk
● Product Risk
3. Environment Risk
Complexity, obsolescence, research & ● politics, natural disasters,
development, packaging, delivery of war, terrorism
warranties
● Competitor Risk
4. Integrity Risk
Pricing strategy, market share, market ● reputation
strategy
2. Operational Risk
5. Leadership Risk
process stoppage, health & daety, ● turnover, succession
after sales service failure,
environmental, technological SEC requirement to Enterprise Risk
obsolescence, integrity Management of Publicly-Listed
Corporation
3. Financial Risk
SEC Code of Governance
interest rates volatility, foreign Recommendations 2.11 &
currency, liquidity, derivative, viability corresponding explanation provide the
4. Business Risk ff:
regulatory change, reputation, political, “The Board should oversee that a
regulatory and legal, shareholder spund enterprise risk management
relations, credit rating, capital (ERM) framework is in place to
availability, business interruptions effectively identify, monitor, assess and
manage key business risks. The risk
management framework should guide
Risk Associated with Financial the Board in identifying units/business
Institutions (5) lines and enterprise-level risk
exposures, as well as the
1. Financial Risks effectiveness of risk management
● Liquidity Risk, Market Risk, strategies.
Credit Risk, Market Liquidity
Risk, Hedged Positions Risk, Risk Management policy is part and
Portfolio Exposure Risk, parcel of a corporation’s corporate
Derivative Risk, Accounting strategy. The Board is responsible for
defining the company’s level of risk Potential Risk Treatments
tolerance and providing oversight over
its risk management policies and 1. Risk Avoidance – includes
procedures. performing an activity that could
carry risk. However, avoiding
Principle 12 means also losing out on the
potential gain that accepting or
“ To ensure the integrity, transparency retaining the risk may have
and proper governance in conduct of allowed or avoiding the risk of
its affairs, the company should have a loss may avoid the possible
strong and effective internal control earning profits.
system and enterprise risk 2. Risk Reduction – also called
management framework”. optimization involves reducing
the severity of the loss or the
likelihood of the loss occurring .
Risk Management Framework This is also finding the tolerance
Risk Management Framework oversee between the negative risk and
that a sound ERM framework is in the benefit of the operation or
place to effectively identify, monitor, activity; and between risk
assess and manage key business reduction & effort applied.
risks. The risk management framework 3. Risk Sharing – sharing with
should guide the Board in identifying another party the burden of loss
units , business lines and or the benefit of gain, from a
enterprise-level risk exposures, as well risk and the measures to reduce
as the effectiveness of risk the risk.
management strategies. 4. Risk Retention – involves
accepting the loss or benefit of
Depending on the corporation’s size, gain from a risk when it occurs.
risk profile and complexity of All risks that are not avoided are
operations, the Board should estab;ish transferred or retained by
a separate Board Committee for Risk default. This is acceptable if the
Oversight. chance of a very large loss is
small or if the cost to insure for
Risk Management Framework
greater coverage involves a
Objective/Goal Setting
substantial amount that could
1. Event or Risk Identification hinder the goals of the
2. Risk Assessment organization.
3. Risk Response
Risk Management Process
4. Review/Verify Control Functions
5. Information and Communication 1. Risk Identification
6. Monitoring 2. Risk Assessment
3. Risk Prioritization (Ranking)
Steps:
4. Response Planning
1. Event or Risk Identification 5. Risk Monitoring
(identify units of risk, threats
Step by Step:
and opportunities within the
department or business units 1. Set-up a separate risk
2. Risk Assessment (evaluate the management committee chaired
risk identified) by a Board Member (this
ensures commitment to adopt a
company wide risk years or in the next five years.
management process) The risks shoulf be mapped
2. Ensure that a comprehensive according to potential impact
risk management system is in and the ability to control the
place. risk.
● Risk organization structure
should include formal charters, RISK PRIORITIZATION
levels of authorization reporting ● Risk prioritization is the process
lines and job description (A fully of identifying the most critical
documented formal system will risks so they can be addressed
provide a clear vision of the first. Priorities should be set
board’s desire for an effective using the likelihood of a risk and
company-wide risk the potential impact it poses to
management as well as the company.
awareness of risks that the
company faces) RESPONSE PLANNING
● Risk response planning is the
process of developing options
RISK IDENTIFICATION and determining actions to
● determination of source and enhance opportunities and
measurement represents the reduce threats to the project's
foundation of the rest of the objectives. It includes the
procedures and performed by identification and assignment of
the responsible managers, individuals or parties to take
finance officers, human responsibility for each agreed
resource managers, etc. Ex of risk response.
identified risks, loss of a major ● Once identified, ranked
customer, failure of a key according to their potential
supplier, appearance of a impact and likelihood .
significant competitor. Risk Catalyst
Risk Catalyst ● technology’ /org
● technology’ /org change/processes/people/exter
change/processes/people/exter nal factors.
nal factors RISK MONITORING
RISK ASSESSMENT ● monitoring is done by all
● development of action plans concerned parties such as
Reduce, Avoid, Retain, Transfer senior managers, process
or Exploit. owners and risk owners. An
● Risks that can lead to frequent independent reviewer can also
losses such as increasing be appointed to validate results
incidence of employee related ● assess regularly the level of
problems , or difficulties with sophistication of the firm’s risk
suppliers are harder to quantify management system.
and must therefore have ● See to it that best practices as
different assessment than those well mistakes are shared by all,
risk with little likelihood of this involves regular
occurring say, happens every 5
communication of results and to reduce costs. Useful in managing
feedback to all concerned. the sales mix, cost structure,
production capacity, forecasting &
Practical Considerations in budgeting
Managing & Reducing Financial
Risk d. Controlling cost-
Improve Profitability 1. focus on the big items of
expenditure 20% of costs or above
1. variance analysis major or minor or peripheral items)
2. assessment of market entry and
exit barriers, 2. Be cost aware (casualness is the
3. break-even analysis enemy of cost control). , it may also be
4. Controlling costs possible to cut the cost of peripheral
items
Interpreting the differences between
actual and planned performance is 3. Maintain a balance between costs
crucial. Variance analysis is used to and quality
monitor and manage the results of
past decisions, assess the current 4. Use budgets for dynamic financial
situation and highlight solutions. management (monthly budget
Common causes of variances include: variances in the Income Statement)
-inefficiency , poor or flawed planning, 5. Develop a positive attitude to
ex relying on historical information). budgeting
b. Your assessment to either enter or 6. Eliminate waste , process analysis,
leave a market is crucial in strategic mapping and re-engineering of the
decision making. Every barrier Japanese.
includes the need to compete with Internal Control
businesses that enjoy economies of
scale, or established differentiated ● Internal Control System is the
products. whole system of
controls(financial & otherwise)
economies of scale- Economies of established by management to
scale are cost advantages reaped by carry on the business of the
companies when production becomes enterprise in an orderly &
efficient. Companies can achieve efficient manner, to ensure
economies of scale by increasing adherence to management
production and lowering costs. This policies, safeguard the assets,
happens because costs are spread and ensure as far as possible
over a larger number of goods. the completeness and accuracy
Established differentiated products - of the records. (CMA, Gleim
product differentiation is the process of 2018)
identifying and communicating the ● Internal Control is a process,
unique qualities of a brand compared effected by an entity’s board of
to its competitors. (Jollibee’s chicken directors, management and
joy). other personnel , designed to
provide reasonable assurance
c. Break-even or CVP is used to regarding the achievement of
decide whether to continue developing objectives relating to
a product, after the price, provide or operations, reporting &
adjust a discount or change suppliers
compliance. (COSO Effectiveness & efficiency of
Framework operations
3. Compliance
COSO, the Committee of Sponsoring Compliances with applicable
Organizations, is an advisory group laws & regulations
that designs frameworks to help
organizations with risk management Elements/Components of Internal
issues. One of its most popular Control
frameworks is the COSO framework 1. Control environment
for effective internal control. ● Control Environment is a set of
The COSO internal control framework standards, processes and
was first introduced in 1992; an structures that pervasively
overhauled, more modern version affects the system of internal
arrived in 2013. Perhaps the most control.
well-known image of the framework is 5 principles related to control
the famed COSO cube, a environment
three-dimensional diagram showing
how the various elements of an a. Commitment to integrity &
internal control system work together. ethical values
b. The Board demonstrates
The “sponsoring organizations” behind independence from
COSO are five professional management & exercises
associations that support risk oversight for internal control
management disciplines. They are: c. Management establishes (with
1. American Institute of Certified board oversight) the structures,
Public Accountants (AICPA) reporting lines, and appropriate
2. The National Association of authorities and responsibilities.
Accountants, now called the d. The organization demonstrates
Institute of Management commitment to attract, develop,
Accountants (IMA) and retain competent
3. American Accounting individuals in alignment with
Association (AAA) objectives.
4. The Institute of Internal Auditors e. The organization holds
(IIA) individuals accountable for their
5. Financial Executives internal control responsibilities
International (FEI) in pursuit of objectives.
2. Risk Assessment
● This process encompasses an
Objectives of an Internal Control assessment of the risks
System themselves and the need to
manage organizational change.
1. Reporting This is the basis for determining
> Reliability of the entity’s how the risks should be
financial reporting managed.
2. Operations
4 Principles related to risk expected and procedures that
assessment: put policies into action.
a. The organization specifies
objectives with sufficient clarity
to enable the identification & 4. Information & Communication
assessment of risk relating to ● Information systems enable the
these objectives. organization to obtain,
b. The organization identifies the generate, use, and
risks to the achievement of its communicate information to
objectives across the entity and 1)maintain accountability and 2)
analyzes risks to determine how measure & review performance.
the risks should be managed. Principles:
c. The organization considers the
potential for fraud in assessing a. The organization obtains or
fraud risks to the achievement generates and uses relevant,
of objectives. quality information to support
d. The organization identifies and the functioning of internal
assesses changes that could control.
significantly affect the system of b. The organization internally
internal control. communicates information,
including objectives and
responsibilities for internal
3. Control Activities control necessary to support the
● These policies and procedures function of internal control.
help ensure that management c. The organization communicates
directives are carried out. with external parties regarding
Whether automated or manual, matters affecting the functioning
they are supplied at various of internal control.
levels of the entity and stages of
processes. They may be
preventive or detective, and 5. Monitoring Activities
segregation of duties is usually ● Control systems and the way
present. control is applied change over
time. Monitoring is a process
Principles: that assesses the quality of
a. The organization selects & internal control performance
develops control activities that over time to ensure that controls
contribute to the mitigation of continue to meet the needs of
risks to the achievement of the organization.
objective to acceptable levels. Principles:
b. The organization develops
general control activities a. The organization selects,
through policies that establish develops, and performs ongoing
what is expected and or separate evaluation (or both)
procedures that put policies into to determine whether the
action. components of internal control
c. The organization deploys are present & functioning.
control activities through
policies that establish what is
b. The organization evaluates and
communicates control
deficiencies in a timely manner.
Controls
The costs of internal control must not
be greater than its benefits.
Types of Controls:
1. Primary Controls
2. Secondary Controls
3. Time-Based Classification
4. Financial vs Operating (Admin
Controls)
5. People Based vs System Based
Controls
6. Control Activities
7. Segregation of Duties (ARCR-
Authorization, Recordkeeping,
Custody, Reconciliation)
8. Independent Checks &
Verification
9. Safeguarding Controls
10.Prenumbered Forms
11.Compensating Controls
12.Fraud