Module 3 – Risk Assessments
Learning Outcomes:
Understand the importance of risk assessments
Identify the phases of risk assessment and their risks
Understand the importance of CSAs
Identify existing business activities and related risks
Identify future challenges to the businesses
Core Value/Biblical Principles:
In life, precautions should always be in place to mitigate the harmful effects of our vulnerabilities. As auditors,
we should identify and measure the magnitude the effect of those risks to our lives. In line with this, here is a
bible verse that you can reflect on regarding this lesson:
Proverbs 22:3 – “A prudent person foresees danger and takes precautions. The simpleton goes blindly on and
suffers the consequences.”
(Stop and Think):
How are risks measured? Do all risks need to be addressed and removed? Or it is enough that controls are
in place and operating effectively? What are the existing business practices and the related risks for each?
In our current situation, what are the challenges that the businesses encounter? In this module, these
questions will be answered and will provide you a better understanding why risk assessments are
important. Even a minute risk in one department may have a significant effect to the business in its
entirety.
Introduction:
Since business risk is present in all organizations, auditors should identify risks and provide the
management awareness regarding their likelihood of happening and their impact to the business. This will help the
management to prepare for it and have action plans once the risk caused issues.
Body:
Risk Assessments
Risk assessments is the process of identifying, measuring, and analyzing risks relevant to a program or process.
This is systematic, iterative and subject to both quantitative and qualitative inputs and factors. Risk assessments can
be broken down to two phases, namely, identification and measurement of risks.
Pwedeng nasa planning phase or magre-assess ka ng risk during the execution phase
Pag may nakitang inefficient control, tapos Malaki pala yung risk nya, so dapat magrerevise tayo ng risk assessment
Likelihood (probable ba o possible lang) and impact of risk
Hindi lang audit team ang nag-aassess ng risk, dapat involved si management
Dalawang importante
Kailangan ang mga mag-aassess ng risk meron silang sufficient knowledge and experience para mag-identify ng
risk
Dapat wala silang biased, auditors dapat impartial sa gagawing risk assessment
Identification of Risks
After auditors understand the business structure, they will be able to identify various risks in each process.
However, some auditors fail to identify the risks due to lack of in-depth knowledge about the process being audited.
This is the case especially because operational audits are external engagements. Auditors may be newly assigned to
the engagement and transition from the previous auditor was not done properly. This is why some clients want the
same auditors from the previous years since they have the extensive knowledge and experience of the process that
needs to be analyzed.
Another issue encountered by auditors during identification of risks is the bias that some may have as a result of
the common training many have in accounting. If the auditor, has been educated in accountancy, has had experience
in accounting, and has focused primarily on accounting and compliance audits, the auditor is more likely to view most
matters from an accounting and compliance prism. Some firms mitigate this risk by involving other auditors with
various experience (IT auditor, Fraud auditor, Environmental auditor, etc.).
Auditors should consider internal and external constraints ‒ equipment, people and policies. In addition, internal
auditors should be concerned about the slowest operation in a process, the synchronization of activities within or
between processes, and robbing materials and other resources within or between processes or units.
Measurement of Risks
Once the risks are identified, auditors should measure their likelihood to impact to each control. This may be
subjective or quantitative, either driven by facts or not and will vary per organization.
Likelihood – probability or possibility, kung probable bakit walang control
Impact – yung effect nya malaki ba
Low, Moderate, Significant (may fraud risk – mas Malaki yung control na ginagamit)
Assessing Risks and Control Types
Auditors should look for weaknesses or vulnerabilities that would make an asset susceptible to damage or loss
from a hazard. Identifying relevant events will be driven by the scope definition of the review and can be done by
following any of the following approaches:
- Objectives based – risk ay makakaapekto sap ag-achieve ng company objectives
- Scenario based (may be external or internal) – mga what-ifs
- Common-risk checking – kung ano yung common sa industry
- Risk charting – ano yung mga resources at risk and ano pang hazard, and how to mitigate the effect of that
hazard. Not necessarily nap ag Nakita ni auditor ay iimplement na ni management, titingnan din ang cause
If the impact of the risk is significant, the business must consider a mitigation strategy. Otherwise, control
activities addressing such risk are often enough. Hazards are relevant to the extent that there are assets that can be
negatively impacted by these hazards.
Organizations must be resilient, so as much as anticipating to adverse outcomes is key to success, the lack of
flexibility to embrace new technologies, understand, and capitalize on new technologies, financial products, emerging
markets, and social dynamics can be the cause of ruin.
Controls
IT Dependent – Manual and IT involvement, output ng manual at output ng system
Manual – document inspection
Application Control – entirely system, nagbabangga ng batch controls, dapat same yung nasa system at yung output
May involvement na ng other audit teams usually may specialty ng application controls
Bawat control inaassess ng auditor kung ano yung mga control types na invlove
Importance of CSAs
As discussed in your other business courses, the management is in charge of designing and implementing
controls. However, this is not known by many executives and they have been reliant to the recommendations provided
by the auditors at the end of the engagement. This is addressed by Control Self-Assessment (CSA).
Management dapat ang incharge sa design at implementation of controls
Kung matagal ng ino-audit yung company, mas alam na yung process na mangyayari
Ito yung importance ng CSA, managers ang binibigyan ng questionnaires and sila ang mag-iidentify ng mga processes
and controls na meron sila, para hindi deumepende sa output ng auditor
CSA are answered by process owners and identify the major activities in their processes, objectives, risks and controls,
individuals that perform key tasks and controls, and the major challenges affecting these programs and processes. CSAs
require managers to think about the design and condition of their areas of responsibility, and assess the presence and
quality of the related controls. Effective CSA programs require communication, linkage to internal audit results, providing
feedback on the gap analysis, and reinforcement.
Business Activities and Their Risk Implications
The following are some of the common activities that result to various risks to the business. Note that a risk to a
business may not be a risk to another business. Always consider the applicability of each risk and its impact to the
company being audited.
- Assemble to order - Consignment
- Make to order - Cycle time
- Make to stock - Distribution center bypass or drop ship
- Bottleneck - Electronic Data Interchange
- Collaborative inventory management - Inventory
Assemble to order, may common base na
Make to order, made from scratch or raw materials,
hindi excessive ang inventory, walang added labor until demand occurs, ang risk ay pag sobrang dami na ng demand ay
mahihirapan sa pagkuha ng materials, pwedeng mawalan sila ng customers or magsuffer ang quality kasi mamadaliin
nila
Made to stock, magmamanufacture ng maramihan eg Retail. Ang risk ay Malaki ang inventory cost at isesale pag Nawala
na sa trend. Dapat alam kung hanggang saan lang ang demand, so useful ang forecasting
Bottleneck, nagppatagal sa isang process, madami ang demand konti ang capacity, nakakaapekto din sa leadtime at
delivery time
Collab Inv Management, may cooperation ang supplier at buyer, usually long term customers, may agreement na. just
like made to order meron na silang buyer, ang problema baka may magcancel. Tinitingnan ni auditor kung meron bang
kailangan iimprove klike sa contracts or kung kailangan bang mag-increase ng operations para macater yung demands
ng customers
Consignment – ginagawa to lower stock cost or warehouse cost, instead na gumastos sa additional warehouse ipadala na
sa mga resellers nila. Kung mataas ang demand sa reseller, konti na lang ang shipping cost. Isang shipment na lang
kesa order ng order. Ang risk is kung hindi mataas ang demand, or baka manakawan or madamaged yung goods. So
dapat inaassess din ng management ang mga risk na to.
Cycle time, titingnan kung may redundant processes, mga excess leadtime, kung ano yung pwede maimprove or
tanggalin
Distribution center bypass or dropship – diretso na from manufacturer to custumoer, usually large customers lang, ang
risk ay pwedeng yung customer na madami order ay scam pala so titingnan din ni company ang credentials ng mga
customers
EDI – may system na si supplier, input na lang ang purchase order at system na ang bhalang maginform sa
kanikaniayang department, ang tanong kaya ba ng system?
Inventory – ang risk ay warehouse cost, storage cost, location ng warehouse kung malapit ba sa risks
Future Challenges and Risk Implications
Due to the dynamic changes in the business environment, businesses explored various ways to improved its operations
at the following methods:
Since extensive na ang globalization, may mga katambal ng risks:
1. Increased outsourcing – nag-outsource para mapababa ang labor cost at mas malaki ang magain na profit, ang
risk ay hindi na nila controlled ang quality nung inaoursorce at di na namomonitor so pagdatng sa kanila, dadaan
sa quality controls.
2. Global Sourcing
3. Margin compression – kailangan makita ng operations auditors kung papano magiging competitive ang company,
kailangan maging value adding ang auditor sa kanila
4. Techonology – sobrang automated na, adoptive dapat ang companies, as part of competitiveness dapat mabilis
magcater sa customer demand, dpat strong ang technology na gamit natin and user friendly
5. Growth in Asia and other developing countries -
6. Improved customer analytics – eg cookies, inaanalyze ang behavior ng customers.
7. Data Capture and transfer capabilities
8. Environmental initiatives – part ng CSR, kahit competitive dapat nagaadhere pa din sa environmental
responsibilities
9. Government involvement – taxes, import fees
10. Geo-political rules
11. Corruption – kailangan makita yan by understanding the processes,
Kapag significant ang risk, kailangan ng mitigation strategies. Kapag hindi, pwede na yung control strategies.