0% found this document useful (0 votes)
3 views6 pages

Chapter 5 (Review Notes)

Chapter 5 introduces risk management auditing, emphasizing the role of internal auditing in evaluating and improving risk management processes. It outlines the objectives of effective risk management, the influence of COSO's framework, and the essential components necessary for effective risk management. The chapter also discusses the internal audit's expanding role, tools used in risk management, challenges faced, and the importance of balancing risk aversion with opportunity identification.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views6 pages

Chapter 5 (Review Notes)

Chapter 5 introduces risk management auditing, emphasizing the role of internal auditing in evaluating and improving risk management processes. It outlines the objectives of effective risk management, the influence of COSO's framework, and the essential components necessary for effective risk management. The chapter also discusses the internal audit's expanding role, tools used in risk management, challenges faced, and the importance of balancing risk aversion with opportunity identification.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CHAPTER 5:

Introduction to Risk Management Auditing

Internal Auditing Definition: An independent, objective assurance and consulting activity.


● Purpose: Designed to add value and improve an organization's operations.
● Approach: Helps accomplish objectives by bringing a systematic, disciplined approach
to evaluate and improve the effectiveness of risk management, control, and governance
processes.

Objectives of Risk Management

Effectiveness Defined: In the context of risk management, "effectiveness" means the


"achievement of objectives".

IIA Standard 2120: Guides the evaluation of risk management effectiveness. Internal audit
must evaluate effectiveness and contribute to the improvement of risk management processes.

Core Objectives of Effective Risk Management (IIA Interpretation)


The Institute of Internal Auditors (IIA) interpretation outlines four pillars for effective risk
management:
● Organizational objectives support and align with the organization's mission.
● Significant risks are identified and assessed.
● Appropriate risk responses are selected, aligning risks with the organization's risk
appetite.
● Relevant risk information is captured and communicated timely across the organization.

COSO's Influence on Risk Management Objectives


COSO's Objectives for Governance, Operations, and Information Systems: Broader risk
exposures include:
● Reliability and integrity of financial and operational information.
● Effectiveness and efficiency of operations.
● Safeguarding of assets.
● Compliance with laws, regulations, and contracts.
* (The strategic objective was not explicitly in this COSO list but was later added for
ERM).

COSO's Enterprise Risk Management (ERM) Objectives: ERM is a process applied in


strategy setting and across the enterprise, designed to identify potential events and manage risk
within risk appetite to achieve entity objectives.

Four Categories of Objectives:

1. Strategic—high-level goals, aligned with and supporting its mission


2. Operations—effective and efficient use of its resources
3. Reporting—reliability of reporting
4. Compliance—compliance with applicable laws and regulations.

(Also, Safeguarding of Resources is often considered).

Essential Components of Effective Risk Management (COSO's ERM Framework)


COSO identifies eight essential components that must be in place for effective risk
management. These are summarized on the front face of COSO's ERM "Rubik cube":
1. Internal Environment: The ethical values, competence, and operating philosophy of an
entity (formerly "Control Environment").
2. Objective Setting: Establishing objectives aligned with the entity's mission and risk
appetite.
3. Event Identification: Identifying potential events that could affect the entity's objectives.
4. Risk Assessment: Analyzing risks for their likelihood and impact.
5. Risk Response: Deciding how to manage identified risks (avoid, accept, reduce, share).
6. Control Activities: Policies and procedures to ensure risk responses are carried out.
7. Information & Communication: Relevant information is identified, captured, and
communicated timely.
8. Monitoring: The entire ERM process is monitored and modified as necessary.

VII. The Scope of Internal Audit’s Role in Risk Management

Internal audit plays a vital and expanding role in enterprise risk management (ERM), beyond
just offering assurance. This summary outlines the key aspects of internal audit’s involvement in
risk management as per Standard 2120 and associated guidance.

1. Expanded Internal Audit Remit (Standard 2120.A1)

Internal audit’s role is not limited to evaluating risk management processes—it includes
assessing the entire risk exposure of the organization. This means internal auditors must:

● Advise the board and management on how adequate and effective current risk
management processes are.

● Identify significant risks that may be inadequately managed or overlooked by


management.

2. Categories of Internal Audit Roles in Risk Management

According to the Institute of Internal Auditors (IIA), internal audit’s activities in ERM fall into three
categories:

A. Core Internal Audit Roles (Assurance Role)

These are fundamental and expected responsibilities:


● Giving assurance on the risk management process.
● Giving assurance that risks are correctly evaluated.
● Evaluating the risk management processes.
● Evaluating the reporting of key risks.

B. Legitimate Internal Audit Roles (Consulting Role – with safeguards)

These may be undertaken with care to preserve independence:

● Facilitating risk identification and assessment.

● Coaching management on risk response.

● Coordinating ERM activities and reporting.

● Helping develop and maintain the ERM framework.

C. Roles Internal Audit Should Avoid (Management Responsibility)

To maintain objectivity, internal audit should not:

● Set the organization’s risk appetite.

● Make or implement risk decisions.

● Impose risk management processes.

● Provide management assurance or take accountability for risks.

VIII. Tools Used in Risk Management

A. Risk Matrix

A graph plotting likelihood vs. impact of risks to visualize their severity:

● Inherent (or gross) risk = risk without controls.

● Residual (or net) risk = risk after applying controls.

● Helps determine if residual risk is within the organization’s risk appetite.

B. Risk Register

IX. Approaches to Risk Response by Quadrants (Figure 5.6)


Quadrant Risk Recommended Action
Characteristics

A (High Impact, High Catastrophic, likely Board oversight and constant


Likelihood) mitigation.

B (High Impact, Low Rare but severe Contingency planning or termination of


Likelihood) risk.

C (Low Impact, High Frequent but minor Focus on control activities.


Likelihood)

D (Low Impact, Low Inconsequential Monitor periodically.


Likelihood)

X. Risk Categorization

It’s often necessary to categorize risks (e.g., strategic, operational, financial, compliance, HR,
IT) and use separate risk matrices for each to avoid confusion and ensure focus.

XI. Judgement and Subjectivity in Risk Management

● Risk scoring involves subjective judgment, especially in assessing likelihood and


impact.

● Risk appetite varies by organization (and within departments).

● Scoring tools like the numerical risk matrix (e.g., Figure 5.8) help but also simplify
complex uncertainties.

XII. Advanced Techniques

A. Colour-Coded Risk Matrix

● Uses numeric scores (Impact × Likelihood) to classify risks:

○ Red = Critical

○ Orange = High

○ Yellow = Medium

○ White = Low

B. Ranges Instead of Points


● Recognizes that risk levels often exist on a spectrum (not a single point).

● Visualized as lines or curves to represent variability in likelihood and impact.

RISK REGISTERS

Graphical tools are useful for brainstorming threats during workshops. The risk register is less
visual but widely used to track and manage risks across the organization.

It provides a detailed record of threats and the actions being taken to address them. The risk
register helps maintain accountability and clarity on risk management roles.

Some organizations define two roles:

● Risk Sponsor – the senior person or committee responsible for overseeing the risk
response.
● Risk Owner – the staff member handling the day-to-day management of the risk.

RISK MANAGEMENT CHALLENGES

Concealed Risks
- Major risks may be hidden deep within the organization, like woodworms silently
causing damage.
- Some employees, including those in management, may notice problems but feel
it's not their responsibility to act.
A risk-based audit approach should not focus only on areas labeled as high-risk.
- Internal audit should also cover low-risk areas, as these may hide unseen or
underestimated risks.
- Concealed risks in overlooked areas can pose serious threats if left unchecked.

The Extra Risks of Less Democratic Organisations


- Hierarchical or command-style organizations are more prone to hidden risks
- Employees may avoid speaking up about problems if they fear punishment.
- Lack of openness makes it harder to detect issues early.
- The organizational culture itself becomes a risk when it discourages honesty and
feedback.
- A participative culture helps surface problems before they become serious.

Multiple Simultaneous Risks Materialising


- Organizational failure often results from several risks occurring at the same time.
- These risks may be interconnected or completely separate.
- Most risk management systems are not equipped to handle multiple risks
simultaneously.
- Adapting current techniques to manage such risks would make them too complex
to use effectively.
- The human mind can intuitively understand and assess complex risk scenarios
better than rigid systems.
- Organizations should identify potential simultaneous risks they may face.
- It is essential to have crisis plans in place to manage multiple risk events if they
occur together.

Opportunities as well as Threats


- Risk management is often focused on identifying and responding to threats.
- However, it should also be used to identify and prepare for opportunities.
- Organizations should look ahead to future events that could present
opportunities.
- These opportunities might not be in the current business plan, but still worth
preparing for.
- Companies should consider developing the capability in advance to seize these
opportunities.
- A missed opportunity can also be seen as a risk not avoided.

Too Risk Averse?


- Being too risk-averse can limit business growth and innovation.
- Profit is the reward for taking well-calculated risks.
- According to Drucker (1977), the goal of management is to enable smart
risk-taking, not eliminate risk.
- Management must learn to understand, prepare for, and correct risks, not avoid
them completely.
- Focusing only on risk minimization can create resistance to necessary
risk-taking.
- COSO (2004) emphasizes that no business operates in a risk-free environment.
Enterprise Risk Management helps businesses function effectively despite risks,
not eliminate them.

CONTROL ISSUES FOR RISK MANAGEMENT PROCESSES


A. Organisational objectives support and align with the organisation’s mission
B. Significant risks are identified and assessed
C. Appropriate risk responses are selected that align risks with the organization’s risk
appetite
D. Relevant risk information, enabling staff, management, and the board to carry out their
responsibilities, is captured and communicated in a timely manner across the
organisation, enabling staff, management, and the board to carry out their
responsibilities.

You might also like