0% found this document useful (0 votes)
5 views3 pages

Understanding Corporate Risks Management

This document discusses corporate risks that span multiple business units and do not neatly fit within any single entity. Examples of corporate risks include strategies not being communicated or updated. These risks are very significant and require oversight from the main board. Controls to mitigate corporate risks are spread across business areas, and both control self-assessments and independent internal audit testing are needed annually to ensure the controls continue working properly. Risk management helps identify corporate risks and controls, while internal audit tests the controls.

Uploaded by

Dennis Bacay
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views3 pages

Understanding Corporate Risks Management

This document discusses corporate risks that span multiple business units and do not neatly fit within any single entity. Examples of corporate risks include strategies not being communicated or updated. These risks are very significant and require oversight from the main board. Controls to mitigate corporate risks are spread across business areas, and both control self-assessments and independent internal audit testing are needed annually to ensure the controls continue working properly. Risk management helps identify corporate risks and controls, while internal audit tests the controls.

Uploaded by

Dennis Bacay
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

RiBIA

Corporate Risks

As we have seen, in order to perform Internal Audit and Risk Management work
efficiently, organizations tend to address risk and audit issues by entity; these entities can
be functions, products or processes, or a combination of all three. There are, however,
risks inherent within an organization that do not fall neatly into any of these entities; by
their nature these risks span many if not all entities. For example consider the following
risk:

A strategy either does not exist, or it has not been communicated to the relevant
staff. Even if a strategy is in place it is possible that adverse variances are not
reported to the Board and therefore remedial action cannot be taken.

Finally, since strategies are medium term documents there is the possibility that,
what was a sound strategy when it was developed becomes less relevant as time
passes; if the strategy is not updated it becomes less of a useful document.

Whereabouts in the organization would this risk sit? It is just possible that the
organization has a Strategy Department and so may accommodate it there, but in the
absence of this there is nowhere to comfortably place the risk. But this is a major problem
for the organization should the risk occur and so it needs to be included in the overall risk
and audit portfolio. This risk, and others of a similar nature, are referred to as Corporate
Risks; they are the concern of and the responsibility of the Main Board. Corporate risks
are those that are both very significant to the organization and do not fit into a specific
entity. They are usually few in number (perhaps <20) but major in impact if they occur.
The following is an example of a list of Corporate Risks taken from a major
organizations Risk Database:

Day 2
HO 3
1
RiBIA

You can see the wide-ranging scope of each risk, how it would not sit comfortably under
the responsibility of one senior manager but requires several, if not all, senior executives
to manage it; and this brings us to the next critical point, if no one entity can have a
Corporate Risk assigned to it, who is responsible for designing and enforcing the controls
that mitigate it?

The answer to this question is that, typically, the control responsibility is spread around
amongst several business areas; let us take a simple example, the risk of Significant
Corporate Fraud; if this happens it can cost the organization millions but it could happen
in one of several areas:
Finance fraudulent manipulation of the Financial Statements;
Purchasing corrupt buying practices, collusion with suppliers;
Treasury fraudulent dealing in order to achieve bonuses;
And so on.
In this example the risk would sit in one place on the Corporate Risk Profile and the
responsibility for ensuring that it was suitably mitigated would lie with the Main Board;
but they are not going to actively design controls and then regularly monitor them, they
would expect the areas in which the fraud might occur to have in place suitable
mitigating controls and to be monitoring that these controls continue to be deployed
properly. So we can see that, in a number of entities within an organization there will not
only be controls that the entity is relying upon to mitigate their own risks, there will also
be controls that they operate on behalf of the Main Board.

Now we need to address the point raised in the above paragraph about ensuring that the
controls in place to mitigate Corporate Risks continue to be correctly deployed. Testing
can be done by two areas:
Day 2
HO 3
2
RiBIA
1. the manager of the entity can periodically test that the controls continue to work;
this role is typically referred to as Control Risk Self Assessment, or CRSA;
2. Internal Audit can test that the controls continue to work.
As we have seen earlier, Internal Audit do not have the manpower to test every area in
their portfolio every year, but in the case of the controls set up to mitigate Corporate
Risks they would be expected to make an exception to this rule and ensure that each
control was independently tested every year. In addition, the Board would also expect
some form of CRSA to be applied to the controls over Corporate Risks.

The foregoing means that, to adequately manage Corporate Risks, an organization must:
Determine what such risks are;
Determine whereabouts in the organization such risks could manifest themselves;
Determine what controls the various areas of the organization that are susceptible
to such risks have in place to mitigate them, and whether such controls are
adequate;
Arrange to have such controls regularly tested and evaluated.
Risk Management have an important role to play in points 1 3, whilst Internal Audit are
heavily involved in points 3 & 4.

Day 2
HO 3
3

Common questions

Powered by AI

The Main Board holds the ultimate responsibility for managing Corporate Risks, which are significant risks that span multiple entities within an organization and do not fit neatly into any single department. While the Main Board is responsible for ensuring these risks are identified and managed, it does not design or directly enforce control measures. Instead, it expects the relevant business areas to implement and monitor suitable controls. These departments, where the risks might manifest, operate controls on behalf of the Main Board. Additionally, these controls must be regularly tested and evaluated by Internal Audit and through Control Risk Self Assessment (CRSA) to ensure proper deployment .

Corporate Risks are significant risks that impact multiple areas within an organization and do not fit neatly into a single department or function. Unlike operational or departmental risks, which are typically managed within specific entities, Corporate Risks require oversight from the Main Board because they span across various functions. They involve coordinating controls from different sectors to be effectively mitigated and are few in number but have major implications if they occur. Examples include significant corporate fraud or strategy failures .

The absence of a well-communicated strategy is a Corporate Risk because it can lead to misaligned efforts, lack of direction, and inadequate response to market changes, potentially resulting in strategic drift. If adverse variances are not reported timely to the Board, it hampers the organization's ability to take remedial actions. As strategies are medium-term frameworks, failing to update them as the business environment evolves renders them obsolete, reducing their usefulness. Consequently, these gaps can lead to missed opportunities, financial losses, and diminish competitiveness .

A Corporate Risk Profile is pivotal for centralizing and effectively managing significant risks that impact multiple organizational areas. It functions as a comprehensive repository of all identified Corporate Risks, ensuring that the Main Board maintains oversight and that these risks are not overlooked or mismanaged. The profile facilitates coordinated governance by allowing for the distribution of control responsibilities across relevant business areas. This centralized approach benefits the organization by enabling strategic alignment, ensuring that mitigating efforts are harmonious and that all critical risks are monitored and managed in a unified manner, which enhances overall organizational resilience .

Regular testing and evaluation of controls over Corporate Risks are necessary to ensure that these controls are functioning as intended to mitigate significant risks that could impact the organization. This process helps to detect any weaknesses or failures in the controls that could lead to vulnerabilities. Internal Audit is primarily responsible for this task, testing each control related to Corporate Risks annually despite their limited resources. This ensures that even infrequent but critical controls receive adequate attention. In addition, Control Risk Self Assessment (CRSA) involves managers in the evaluation of these controls, promoting continuous operational oversight .

Risk Management teams are responsible for identifying Corporate Risks, determining where these risks might manifest within the organization, and assessing the adequacy of existing controls. They play a crucial role in the first three stages of managing Corporate Risks: identifying the risks, anticipating where the risks might occur, and evaluating the controls already in place to mitigate those risks. Subsequently, these teams must collaborate with Internal Audit to ensure these controls are regularly tested and evaluated, thereby supporting a comprehensive approach to risk management .

Control Risk Self Assessment (CRSA) is a process where managers of entities periodically test whether the controls in place continue to function effectively. This is crucial for managing Corporate Risks because it ensures that controls are being actively monitored within the entities where risks might surface. It provides a layer of oversight and accountability, ensuring that the deployed controls are correctly mitigating risks. CRSA complements the independent testing conducted by Internal Audit, ensuring comprehensive risk management by involving both the risk-owning departments and independent audit verification .

Assigning responsibility for Corporate Risks is challenging because these risks typically span multiple entities within an organization and do not fit neatly into any one manager’s domain. These risks require oversight from several senior executives rather than being assigned to a single entity. This can be effectively addressed by maintaining a centralized Corporate Risk Profile managed by the Main Board, with control responsibilities distributed across relevant business areas. Each area must have suitable controls in place for risks pertinent to their operations, and these controls should be regularly tested by both internal audit processes and Control Risk Self Assessments to ensure comprehensive oversight .

Internal Audit plays a critical role in the risk management of organizations by independently testing and evaluating the controls established to mitigate Corporate Risks. This includes making exceptions to their usual audit cycle to ensure that all controls related to Corporate Risks are tested annually. This diligence helps to confirm the effectiveness and proper deployment of controls, ensuring that the organization can reliably mitigate and respond to significant risks. Internal Audit’s involvement complements the Control Risk Self Assessment processes conducted by managers, providing a thorough evaluation from both internal and independent perspectives .

Risk Management and Internal Audit collaborate closely to manage Corporate Risks effectively. Risk Management is responsible for identifying Corporate Risks, analyzing potential impact areas within the organization, and assessing existing controls' adequacy. Internal Audit complements this by providing an independent verification of these controls through regular testing and assessment, ensuring that control measures remain effective over time. This synergy ensures a robust risk management framework, as Risk Management focuses on risk identification and prevention, while Internal Audit ensures control reliability and compliance through continuous evaluation .

You might also like