CHAPTER 4
RISK AND
CONTROL
Learning Objectives
After going through this chapter, you should be
able to:
• Define risk and risk management.
• Describe Enterprise Risk Management (ERM).
• Explain roles of internal auditors in risk
management
• Define internal control.
• Describe the components of internal control.
RISK
• Life is full of uncertainty.
• There are many day-to-day activities about
which we simply do not know what the outcome
will be in advance.
• Our success is dependent on how well we
manage the uncertainties, not by trying to
eliminate the risk.
Definition of Risk
COSO ISO
The possibility that Effect of
an event will occur uncertainty on
and adversely affect objectives
the achievement of
an objective.
Definition of Risk
• Risks are inherent (i.e. essential) in all aspects of
organizations, i.e. wherever uncertainty exists, one or more
risks exist.
• Management must be willing to take a fair amount of risk in
order to earn the expected returns for their shareholders.
• Business risk = Uncertainties regarding threats to the
achievement of business objectives.
• COSO’s Enterprise Risk Management – Integrated
Framework, a robust framework - Geared to achieving an
organization’s objectives.
• To identify risk,
• To assess risk, and
• To manage risk.
RISK MANAGEMENT
• Risk management is a fundamental responsibility in
corporate governance. MCCG 2012, Principle 6 –
Recognize and Manage Risk.
• Recommendation 6.1 – The board should establish
a sound framework to manage risk.
• Recommendation 6.2 – The board should establish
an internal audit function which report directly to the
Audit Committee
Objectives of Risk Management
• Identify the key risks today → Explore how well to prevent the risks
→ Changes to improve the efforts.
• To mitigate the exposures of the business to various types of risks.
• Improving financial performance by reducing losses.
• Improving capital management by maximizing the value of each
Ringgit.
• Building a risk-aware culture throughout the organization.
• Reducing time and compliance cost through risk consolidation
and cross-functional efficiency. (Cross-functional = Bringing
people together from different departments to improve problem
solving and lead to more thorough decision making.)
Enterprise Risk Management
• A process to effectively understand and manage risks across an
organization.
• An iterative process of continuous improvement
• The objective of providing the management and board a commonly
accepted model for discussing and evaluating an organisation’s risk
management efforts.
• ERM as defined by Committee of Sponsoring Organizations of the
Treadway Commission (COSO)
• – is a structured process, effected by an entity’ board of directors,
management and other personnel that is applied in strategy-setting and
across the enterprise. Its goal is to provide reasonable assurance
regarding the achievement of organisational objectives by identifying
events that may affect the entity and managing risk to be within the
entity’s risk appetite.
The COSO’s definition reflects
certain fundamental concepts:
• A process that is ongoing and flows throughout an organization.
• Effected by people (that is, employees) at every level of an organization.
• Applied when setting an organization’s strategy.
• Applied across the organization, at every level and unit.
• Focused on taking an entity-level portfolio view of risk.
• Designed to identify potential events that, if they occur, will affect the
organization.
• A means to enable the management of risks within an organization risk
appetite.
• Able to provide reasonable assurance to an organization’s management and
board of directors.
• Geared toward achievement of objectives in one or more separate but
overlapping categories.
COSOERM– INTEGRATED
FRAMEWORK: THE COMPONENTS
8 interrelated components of ERM that are integrated with the
management process
1. Internal Environment
2. Objective Setting
3. Event Identification
4. Risk Assessment
5. Risk Response
6. Control Activities
7. Information and Communication
8. Monitoring
1. Internal Environment
• The tone of an organization that sets the basis for
how risk and control are viewed and addressed by
the people in the organization. People = f (Individual
attributes; Environment)
• Influenced by an organization’s history and culture.
• The internal environment sets the foundation for
how risk is viewed and addressed by an entity’s
people, including risk philosophy and risk appetite,
integrity, ethical values, and the environment in
which they operate.
2. Objective Setting
• Objectives must exist before management can
identify potential events affecting their
achievement. ERM ensures that management has
in place a process to set objectives and that the
chosen objectives support and align with the
entity’s mission and are consistent with its risk
appetite.
3. Event Identification
• Internal and external events affecting the
achievement of an entity’s objectives must be
identified, distinguishing between risks and
opportunities.
4. Risk Assessment
• Risks are analyzed, considering likelihood and
impact, as a basis for determining how they
should be managed. Risks are assessed on an
inherent and a residual basis.
5. Risk Response
• Management selects risk responses—avoiding,
accepting, reducing or sharing risk—developing a
set of actions to align risks with the entity’s risk
tolerances and risk appetite.
6. Control Activities
• Policies and procedures are established and
implemented to help ensure the risk responses are
effectively carried out.
7. Information and Communication
• Relevant information is identified, captured and
communicated in a form and timeframe that enable
people to carry out their responsibilities. Effective
communication also occurs in a broader sense,
flowing down, across and up the entity.
8. Monitoring
• The entire ERM process is monitored, and
modifications made as necessary. Monitoring is
accomplished through ongoing management
activities, separate evaluations or both
COSO ERM on Roles and
Responsibilities
Board of Directors
• The internal environment component of ERM.
• To provide oversight and direction to an organization’s management.
• To set strategy, formulate high level objectives and shape the ethical
environment.
• To determine the context of ERM and advises on and approves the key risk
criteria for the organization.
• The oversight role to ERM
• Knowing the extent to which management has established effective
ERM.
• Being aware of and concurring the risk appetite.
• Reviewing the risk portfolio and matching to the risk appetite.
• Advise on the most significant risks and whether management is
responding appropriately.
COSO ERM on Roles and
Responsibilities
Management = Chief Executive Officer x Senior
Management
− Having the ultimate responsibility for the effectiveness
and success of ERM.
− To ensure that a positive internal environment exists, by
setting the tone at the top.
− To influence the composition and conduct of the board.
− To provide leadership and direction to senior managers.
− To monitor the overall risk activities in relation to risk
appetite.
COSO ERM on Roles and
Responsibilities
Senior Management
− To be responsible for managing risks related to the specific
organizational units’ objectives.
− To convert the overall strategy into ongoing operations
activities.
− To identify potential risk events.
− To assess the related risks.
− To implement treatments to manage the risks.
− To provide risk officers with information in order to effectively
identify and assess the risks.
COSO ERM on Roles and
Responsibilities
Internal Auditors
• Scope of the internal audit function encompass
governance, risk management, and control
systems.
• To evaluate the effectiveness of and
recommending improvements to ERM, that
includes evaluating the reliability of reporting,
effectiveness and efficiency of operations, and
compliance with laws and regulations.
The Elements in Risk Management
Process
Communicate and Consult
o To have common understanding between the management and
stakeholders (both internal and external) on the basis to which
decisions and actions are made.
Establish the Context
o To determine the parameters against which risks will be managed.
o The context includes the purpose of the risk management and the
internal and external environment affecting the organization.
Identify Risks
o To identify the events that could prevent or delay the achievement of
objectives.
The Elements in Risk Management
Process
Analyze Risks
o To evaluate the likelihood and impact of the identified risks.
o To determine the effectiveness of existing control and the range of
potential effect for any deficiency.
Evaluate Risks
o To compare estimated level of risk against the pre-established
criteria.
o To balance between potential benefits and adverse outcomes.
o Enable decisions to be made about the extent and nature of
responses required and the priorities to be placed on each
response.
The Elements in Risk Management
Process
Treat Risk
o To develop and implement specific cost-effective strategies.
o To develop and implement action plans to increase potential benefits and
reduce potential losses.
Monitor and Review
o Important for continuous improvement.
o To consider
• The conditions of existing business culture and systems.
• The integration and consistency of risk management across different types of
risks.
• The possible modification or extension of current practices and policies.
• The legislative or compliance requirements.
• The resource constraints
Categories of Risks
Credit Risk
Operational Risk
Operational Risk
Market Risk
Market Risk
Information System Risk
Litigation Risk
Reputation Risk
Strategic Risk
COSO INTERNAL CONTROL-
INTEGRATED FRAMEWORK
CONTROL
CONTROL OBJECTIVES
FIVE COMPONENTS OF
INTERNAL CONTROL
FIVE COMPONENTS OF
INTERNAL CONTROL
FIVE COMPONENTS OF
INTERNAL CONTROL
FIVE COMPONENTS OF INTERNAL
CONTROL – control activities cont’d
FIVE COMPONENTS OF
INTERNAL CONTROL
FIVE COMPONENTS OF INTERNAL
CONTROL
LIMITATION OF INTERNAL
CONTROL
IA as Part of Control
• IA is an integral part of the internal control system.
• Financial and operational information are
reliable and possess integrity.
• Operations are performed efficiently and
achieve effective results.
• Assets are safeguarded.
• Actions and decisions of the organization are in
compliance with laws, regulations and
contracts.
IA as Part of Control
• How can IA play their role?
• Assess on the effectiveness of the
organization’s system of internal control,
including on the adequacy of control model or
design.
• Monitor management’s compliance with the
organization’s code of conduct and ethical
policies.
• Reviewing corporate policies relating to
compliance with laws and regulations, conflict
of interests, etc.
• Analyze on the controls for critical accounting
functions.