ASSESSMENT OF AUDIT COMMITTEE ROLES IN CONTROL ANND
MANAGEMENT OF RISK IN PUBLIC SECTOR ENTERPRISES.
THE CASE OF NATIONAL HOUSING CORPORATION(NHC).
DAR ES SALAAM-TANZANIA
By
Loyce K Kitoboi
2022
CHAPTER ONE
BACKGROUNG AND PROBLEM SETTING
1.1 Introduction
This study will aim on addressing on how Audit committee roles on control and management of
Risk at national housing corporation. The chapter will be covered with study background,
statement of the problem, research questions, research objectives, scope, and the significance of
the study plus organization of the study.
1.2 Background to the study
The recent corporate accounting and auditing scandals of early years of 21 century reported in
the press outraged the financial community and clearly showed that the US corporate governance
system contains some important flaws that cannot be ignored. Of course, the board of directors,
considered as an important part in a corporate governance system, took the largest part of the
blame and directors were accused of failure in the ir watchdog role. For example, in the Enron’s
case, the Powers report concluded that Enron’s board “failed to monitor …to safeguard Enron’s
shareholders”. Those scandals have served as catalysts for legislative and regulatory changes.
New rules were adopted in order to avoid the apparition of other disasters
similar to the Enron or WorldCom’s cases. In this context, the Sarbanes-Oxley act (SOX
hereafter) enacted in 2002 tried to restore the credibility of the US corporate governance
system by setting stricter rules on the functioning and the independence of the external
auditor, enabling the board of directors to acquire higher levels of fiduciary and statutory
responsibilities and also by proposing new rules aimed to enhance the quality of financial
disclosures by firms (off-balance operations, insider trading, securities holding). More
recently, the NYSE adopted a new set of rules aimed to complement the SOX
requirements in the matter of corporate governance.
Interestingly, the SOX does not require any particular condition for the board as a whole
entity but requires the audit committee to be entirely constituted of independent directors
with at least one financially knowledgeable member3. The new rules set by the NYSE put
additional conditions concerning the independence of the board of directors and the
composition of the audit, compensation and governance committees. Overall, this new
regulation on corporate governance mainly focuses on the audit committee and the
independence of the board of directors.
We are aware that stricter rules for the audit committee and the independence of the
board will help avoid financial scandals and ensure a better monitoring but one might ask
whether the independence of the board as a whole entity is sufficient to avoid additional
problems related to the US corporate governance system.
Risk manifests itself in a range of ways and may have a positive and/or negative outcome for the
entity. It is vital that those responsible for the stewardship and management of an entity are aware
such of the best methods for identifying and subsequently managing risk.
The governance of risk requires principally the establishment and maintenance of effective
systems of internal control. Internal control comprises all the policies, processes, tasks, behavior
and other aspects of an entity that, taken together, ensure, as far as practicable, the orderly and
efficient conduct of business. This includes adherence to management policies, compliance with
applicable laws including regulations, the safeguarding of assets, the prevention and detection of
fraud and error, the accuracy and completeness of accounting records, and the timely preparation
of Internal and External Audit reports. The “Internal Control Integrated Framework” (2013) and
“Enterprise Risk Management Integrated Framework” papers published by the Committee of
Sponsoring Organizations of the Treadway Commission (COSO) establish the prerequisites for a
proper internal control set up.
In order for the public sector to deliver public services and achieve its policy objectives, it is
critical that public finances are managed well (NBAA, 2011). There is an increasing pressure for
entrusted officials to demonstrate a high level of accountability over the use of public resources.
This can only be achieved if there is a sound internal control system, good corporate finance and
sound, efficient, independent and competent audit committee. Audit committee is a corner stone
of corporate governance (Smith, 2006).
The importance of corporate governance became dramatically clear in 2002 as a result of fall down
of big corporation in the world as a result of dishonest and acts of frauds by the management and
audit firms (Smith, 2006).
This resulted into destruction of billions of dollars of shareholders’ wealth, the loss of thousands
of jobs, criminal investigations of dozens of executives and record-breaking bankruptcy filings in
the world. It was apparent that there was deliberate move within the management to confiscate the
resources entrusted to them by shareholders. Even auditors failed to give early warnings on the
bankrupt companies, Legislatures, councils and governments are accountable to the public.
Companies in the 21st century face a formidable array of risks. Driving forces like Technology
advances and the Internet, global competition, complex financial Instruments, mergers,
downsizing, deregulation and increased consumer demands all create a riskier operating
environment for organization. Interest in enterprise risk management (ERM) has continued to grow
in recent years.
1.3 Statement of the Problem
Audit committees are traditionally responsible for oversight of auditing matters relating to the
company's financial systems and risk management relating to financial reporting. While the audit
committee needs to have a full understanding of the risk management system in order to be able
to assess the overall risk profile of the company we illustrate that the complex risk and regulatory
environment high technology firms face may necessitate the creation of a separate risk
management committee to interface with and assist the board and audit committee.
1.4 Research objectives
1.4.1 General objective
The general objective of the research was to examine how Audit Committee roles control and
manage risk in public enterprises.
1.4.2 Specific objectives
Specific objectives of the study are as follows
i) To examine the relationship between Audit committee and risk management.
ii) To assess the effects of Audit committee in controlling and managing risk.
iii) To examine the challenges faced by AC in control risk management.
iv) To examine the factors hindering the effectiveness of AC in risk management.
v) To assess the independency of Audit Committee in control and managing risk.
1.5 Research questions
i) Is there any relationship between AC roles and risk management?
ii) What are effects of AC roles towards control and managing risk?
iii) Does the AC work independently in control and managing risk?
iv) What are factors hindering the effectiveness of AC roles in risk management?
v) What are challenges facing AC in controlling and managing risks?
1.6 Significance of the study
The findings of the research will benefit the National Housing Corporation itself, as well as other
company. The study also will contribute to the understanding of the AC concept and it’s critical
in the process of controlling and managing risks in public sector entities in Tanzania, the
characteristics of the effective audit committee, its roles and responsibilities.
The findings have implications to the management, policymakers, regulatory bodies to set up
effective guidelines and other stakeholders in the process of enhancing good corporate practices
in the country. It will serve as a source of knowledge to other researchers in the similar area.
Lastly, it will be used as means for the researcher of this study to accomplish its objective of
acquiring the qualification to be awarded the Bachelor degree of Accounting and Finance of the
Mzumbe University.
1.7 Scope of the study
This study will be carried out in Dares Salaam at National Housing Corporation (NHC)
headquarters. The study dealt only with issues concerning Audit committee’s roles in control and
management of risks which would shed light to effect of Audit committee on effectiveness and
efficiency of Risk management in Tanzania. Based on its main objective the study will be
confined to public entity and mainly staff of NHC in the head quarter office in Dares Salaam.
1.8 Organization of the study
The study is organized in five chapters. Chapter one covers introduction of the study, statement
of the problem and research objectives. Chapter two covers Literature review, chapter three
research methodology, chapter four results of research findings and last chapter five covers
conclusion and recommendations.
CHAPTER TWO
LITERATURE REVIEW
2.1 Introduction
This chapter incorporates reviews related to the aspect of the study by reviewing on the different
issues and various researches from authors with the aim of gaining knowledge and making the
researcher to be familiar with any relevant information about the study being undertaken. It will
be covered with literatures related to the study (empirical and theoretical), definition of the terms,
conceptual framework, relationship of the variable and a research gap.
Many authors have pointed out with great emphasis the importance of reviewing critically the
work done by other researchers in similar fields in order to grasp the knowledge and identify the
gaps that exists.
In Jankowicz (2005) quoted by Saunders et al., (2009.59) says “the work that you do is not done
in a vacuum, but builds on the ideas of other people who have studied the field before you. This
requires you describe what has been published, and to marshal the information in a relevant and
critical way”.
This chapter therefore shall review the literature related to assessment of audit committees’
efficiency in strengthening public finance management in local government authorities. This study
is expected to add knowledge and bring about awareness to the public
2.2 Theoretical aspect
2.2.1 Audit Committee
According to Tuteja and Malubi (2011) audit committee is a committee consisting of non-
executive directors which is able to view an entity’s affairs in a detached and independent way and
liaise effectively with the internal auditor, external auditors and the Board.
On the other hand Controller and Auditor General define Audit Committee to be a standing
committee of the Board of Directors whose purpose is to assist the Board in fulfilling its oversight
responsibility.
American Institute of Certified Public Accountants define an audit committee as "A committee (or
equivalent body) established by and amongst the board of directors of an issuer for the purpose of
overseeing the accounting and financial reporting process of the issuer and audits of the financial
statements of the issuer; and if no such committee exists with respect to an issuer, the entire board
of directors of the issuer.
" In defining an audit committee emphasis is usually placed on its composition and functions. For
instance, according to Al-Lehaidan (2006) citing the works of Canadian Institute of Chartered
Accountants (CICA, 1992: 20), Marrian (1988:2) and Rickard (1993) respectively define audit
committee as:
“A committee of Directors of an Organization whose specific responsibility is to review
the annual rectors. The committee generally acts as liaison between the auditor and the
board of directors and its activities may include the review of nomination of the auditor,
overall scope of the audit, results of the financial statements before submission to the
board of di audit, internal financial controls, and financial information for publication”.
Canadian Institute of Chartered Accountants (CICA, 1992: 20)
In the view of Marrian (1988: 2), it is:
“A committee of the board normally comprising three to five directors with no
operating responsibility in financial management. Its primary tasks are to review
the financial statements, the effectiveness of the company’s accounting and
internal control systems, and the findings of the auditors and to make
recommendations on the appointment and remuneration of the external auditors”.
According to Rickard (1993: 35):
“An audit committee consists of a group of senior staff, chaired by the chief executive
officer or his deputy. The committee’s responsibility is to safeguard the independence of
the internal audit function and ensure continual improvement in management
performance and accountability by seeking action on internal audit and external audit
reports”
All the above definitions agree that an audit committee is a sub-committee of the main board of
directors of a company, usually formed from non-executive directors, and charged with matters
relating to financial reporting, internal control systems and audit and to act as a link between the
board of directors, internal and external auditors. Al-Lehaidan (2006).
2.2.2 Purpose
The purpose of this tor is to outline the committee responsibilities. This includes meeting
procedures and its composition. The terms of reference are to be periodically reviewed and
modified to ensure that they are effective. The board must minute the approvals and ensure it is
distributed to all senior management, external and internal auditors.
2.2.3 Composition
The audit and risk committee must be comprised of at least three non-executive board members
who must be elected by shareholders on the recommendation of the remuneration and
nomination committee. All members of the committee must be non-executive board members
and meet all applicable independence requirements and be appropriately qualified.
The chairman of the board is not eligible to be chairman or a member of this sub-committee and
the chairman of this sub-committee must be an independent, non-executive director.
Collectively, members of this committee must have the appropriate mix of qualifications and
experience in order to fulfil their duties adequately. Such qualifications and skills will include
expertise and/or experience in the following fields; financial, legal, risk management,
sustainability and reporting, internal financial control, external and internal audit processes,
information technology („IT‟) governance, corporate governance, ethics and integrated reporting.
Members of the committee are required to ensure they are fully apprised of latest developments in
the industry and in commerce generally. Important attributes of the members are an independent
and enquiring mindset, a reasonable
2.1.5 Definition of Risk
Risk has been defined by (Robertson & Louwers, 2001), as a likelihood chance that an
action/event may occur in particular activity and adversely impact company’s
objectives/goals.
Treasury Board of Canada (2002), risks are events or outcomes that occurs in the future
that company where uncertain if those events will occur; and usually they are potential
to influence non-achievement of organization goals.
2.1.6 Types of Risks
Guides (2014), identifies the following as risks types that organizations are likely to
face;
[Link] Financial Risks
These refers to risks coming from how organization is financed, this includes the long
terms debts and equity or shareholders’ funds that are applied in financing the fixed assets of a
company. The development risks, investment risks, and business risks are also included in
financial risk. Examples of financial includes the following; Liquidity risk, which refers to all
potential risks that an organization is likely to face when it has less liquidity to offset /fulfill all
the current liabilities it has.
This means there is mismatch between the inflows and outflows which will result an
organization having insufficient cash or bank balance and organization may have illiquid asset
that cannot be converted into cash quickly; Credit risk, this is the risk that result from an
organization operate on credit basis. This risk may occur if the debtors are not pay their
obligations when they fall due and hence will affect the organization day to day operation as
organization will not obtain cash as planned and therefore laid them also delaying on other
payments and sometimes requires them to find finance from other sources which will increase
burden of debts to the organization.
[Link] Compliance Risk
This risk arises from non-compliance of applicable laws, rules and regulations. This
can be either by breaching laws, rules or obligations or not follow reporting framework.
For example there is new law, standard or regulation introduced or the existing ones
have been changed which may have impact on organization, failure to adhere to those
changes may attract fines and penalties to the organization and sometimes requires the
organization to shut down its business. Organization face these risks since they operate
within legal and regulatory parameters as responsible corporate citizens.
[Link] Operational Risk
This refer to a risk that arises when there is changes in operation of the business it can
either be due to economic changes, technology change or other change that requires the
organization to make amendment in its operation for better performance of its activities.
For instance if there is technology changes that will adversely affect the organization
then organization need to take measure to that situation, but also technological risk also
creates opportunities for business as it provide opportunity to innovate and advance its
system in line with changes in the market.
Apart from those risks, (Sawyers, 2012) identifies the following components as audit
risk or audit risk mode; Inherent risk, which refers to the vulnerability of a financial
statement to be misrepresented by either an error or omission, mainly caused by absence
of internal control policy and not by other factors like default control system. It is the
risk that intrinsic to the organization. For example, a complex assessment for income or
an allowance is more likely to contain clerical error than a simple one.
Detection risk, this includes all risks which appears as a result of failure of a responsible
auditor to detect and identify the material misstatement existing in an assertion during
auditing of financial statements. These risks most occurs when an auditor decides not
to examine 100% of the balances or transactions due to time and / or due to other uncertainties.
Control risk, these includes all risks facing an organization as a result of internal control
system failure. The content misstatements of financial statements under this category,
occurs as a failure of internal control system to detect and to prevent it from happening.
2.1.7 Definition of Risk Management
Agrawal (2009), defines risk management as an overall human approach and process
involving several activities such as risk identification and recognition, risk assessment
procedures, risk strategies development and implementation of risk mitigation activities
via the given managerial resources.
Tourism Queensland (2005), defines risk management as a procedure which consist
well-structured steps applied in identifying potential opportunities, how to exploit the
said opportunities effectively while avoiding and keeping all viable losses minimum by
applying different techniques to improve the organizational performance, quality and
productivity in their operations. Through risk management, organization are likely to
improve their strategic and operational decisions as it better improves its forecasting
abilities in risks and find out better ways to handle the potential risk impacts.
2.1.8 Risk Treatment/Mitigation.
According to Accounting and Reporting Charities (2004), organization needs to take
into account all necessary actions that can be used to reduce risks for all major risks
identified (both by reducing the probability of the risk event to occur and by minimizing
the impact of the risk if the said risk event occurs). The following are example of
possible actions that organization can undertake in mitigating risks; the risk may be
avoided by stopping to perform a certain activity (for example stop working in particular
risk area), risk can also be shifted to another entity or can be shared with others
(individuals /entities), but also organizations can plan how to counter risks (for example
by developing a reserve account to counter loss of income), nevertheless risks can be
reduced by well designing and developing internal control system that can help in
detecting and preventing the risks from happening and also risks can be insured for
instance can be insured against theft and fire.
Diafra (2002), talks about the four T’s the general tactics to consider when responding
to a risk, and the main objective will be to make sure that risks does not grow into an
issue and when possible threat should be realized. Therefore organization may choose
one of the following general tactics (4T’s);
Transfer of the risks, means the risk is passed to the third party. This can be achieved
through conventional insurance policy or by entering in a contractual agreement by third
party to be liable of handling the risks or by outsourcing the particular function or
activity that is likely to be exposed to risks, especially those risks with high impact that
cannot be accepted and terminated due to the importance of the activity that is exposed.
Toleration of the risk, this means risks are known and accepted by organization at a
certain level. Therefore, it becomes unjustifiable / meaningless to deal with such risks
since the cost involved in making and taking corrective measures may be high compared
to the importance and benefit gained from the activity. A strategic action here is to
accept the risks while observing it in a close manner to ensure the risk’s probability to
occur and impact are relatively low. Observing such risks is important as this tactic is
never permanent, in case of increasing of the probability and impact of such risk to
occur, the management has to change to other tactics such as treat and transfer.
Treating the risk, means reducing the particular risk by lowering the probability of the
risk to happen and reducing the impact of the risks by developing strong control system
and procedures such as staff training, quality control, facility maintenance and
developing contingency plans to be followed when such risks occur. Main reason
behind treating the risks isn’t really to end the risks in many cases, but to bound it to set
in train an arranged arrangement of moderating activities to cover the risks to an
acceptable or reasonable dimension;
Termination the of risk, means we stop using a certain process or activity, this happens
when there is no much time for other treat measures, or no other suitable treat measure
can be applicable while the likelihood of occurrence of the event is high and the impacts
are very high that might significantly damage the entire project. For example, the impact
of using a certain chemical in the environment the treat would be to completely ban that
chemical, but also new technology can be used to remove or solve different risks that
exist previously in the environment.
2.4 Relationship between the audit committee’s roles to risk management
The audit committee’s roles in relation in relation to risk management will differ depending upon
where the PSE’s has:
i) Separate risk management and audit committee
ii) An audit committee only and has not established a risk management committee
iii) A combined risk management and audit committee
In all circumstances, the extent and nature of the audit committee’s roles in relation to risk
should clearly documented in the audit committee’s charter.
Over the last 10 years it became almost dogmatic that risk management effectiveness has to be
disclosed at the Board level. It seems to be equally accepted that full Board is responsible for risk
management oversight, who, however can and often do, delegate this oversight responsibility to
the Audit Committee. This is in fact so common, that many organisations have expanded the Audit
Committee mandate to include risk management and renamed them Audit and Risk Committee.
Some regulators, Russia for example, even legislated the idea that r4isk management oversight as
well as other risk management matters are the responsibility of the Audit Committee.
To derive optimal benefits, risk management ought to be conducted in a systematic manner, using
proven methodologies, tools and techniques. The responsibilities of the Audit Committee with
respect to risk management should be formally defined in its charter. The Committee should
provide an independent and objective view of the PSE risk management effectiveness (Refer
Annexure 12).
The responsibilities of the Audit Committee towards control and management of risk as provided
under The Guidelines for Audit Committee in the Public Sector, Improving Transparency and
Accountability (2013);
i) Reviewing and recommending disclosures on matters of risk in the annual financial
statements;
ii) Reviewing Risk Registers and related mitigation strategies in place
iii) Reviewing and recommending disclosures on matters of risk and risk management
in the annual report;
iv) Providing regular feedback to the Board /Oversight Authority on the adequacy and
effectiveness of risk management in the Institution, including recommendations for
improvement;
v) Ensuring that the internal and external audit plans are aligned to the risk profile of
the Institution;
vi) Satisfying itself that it has appropriately addressed the following areas namely
financial reporting risks, including the risk of fraud, internal financial controls; and
IT risks as they relate to financial reporting;
vii) Gains thorough understanding of the risk management policy, risk management
strategy, risk management implementation plan, and fraud risk management policy
of the institution to enable them to add value to the risk management process when
making recommendations to improve the process;
viii) Reviews and critiques the risk appetite and risk tolerance, and recommends this for
approval by the oversight authority;
ix) Reviews the completeness of the risk assessment process implemented by
x) management to ensure that all possible categories of risks, both internal and external
to the institution, have been identified during the risk assessment process. This
includes an awareness of emerging risks pertaining to the institution;
xi) Reviews the risk profile and management action plans to mitigate the risks;
2.5 Theories of the study
2.5.1 Agency Theory and the Audit Committee
Agency theory is linked with legal relationships within the entity, defining legal relations of
principal and an agent, whose rights and responsibilities are specified by a contract of
employment, Collier and Agyei-Mpomah, (2009). The theory identifies the behavior of an agent
(the manager) whose actions the principal (shareholder) tries to uncover and get it to manipulate
and control in the course of a management control systems.
The basic intention of the theory is to influence what an agent do, however gives authority to an
agent in an unsure environment. The agents will in turn spend and use much effort in performing
their duties and tasks allotted and the outcomes are reliant on internal and external aspects and
the quantity of efforts spent in realizing goal.
The theory is applicable in accounting reports as ACs are required to play an extremely
significant roles in monitoring and changing the actions of agents. This creates the audit
committee roles in monitoring the financial outputs that measures their efforts contingent or
inferred the measures/actions that perfectly imitate and reveal their efforts spent.
McConnel & Servaes (2009) state that the agency theory is the theory of the business firm which
argues incentive with the managerial challenges arises from the separations of ownership and
decision making. In line with Jensen & Meckling (1976) describes that an agency relationship as
a contract whereby the principal (shareholders or stakeholders) engage the agent (AC) to carry
out services on their behalf by delegating a number of decision-making authorities to the agent
2.6 Empirical literature
The empirical literature review analyses previous researches related to this to establish gap. Both
published and unpublished research papers in print and electronic formats were reviewed to
provide secondary information for the current study. The subsequent part provides a review of key
studies conducted in and out of Tanzania.
The committee is constituted as a statutory committee of Royal Bafokeng Platinum (“RBP”) in
respect of its statutory duties in terms of section 94(7) of the Companies Act, 2008 and a sub-
committee of the board of directors („board‟) in respect of all other duties assigned to it by the
board. The committee should assist the board in carrying out its functions relating to the
safeguarding of assets, the operation of adequate risk management and control processes and the
preparation of financial statements in compliance with all applicable legislation and regulations,
and the oversight of the external and internal audit appointments and function. The committee
does not provide relief to board members for their joint and several responsibilities regarding
their fiduciary duties and they must continue to exercise due care and judgement in accordance
with their legal obligations.
Conceptual framework
The conceptual framework provides the structural relationships between the independent variables
with dependent variable Ndeto et al. (2016). The conceptual framework in this study based was
constructed bearing into mind about the cause effect relationship. Below is the conceptual
framework developed using both independent and dependent variables. The variables have been
identified with a cause and effect relationship (independent and dependent) variables.
CHAPTER THREE
RESEARCH METHODOLOGY
3.1 Introduction
This section concerns with the methodologies that the researcher will use in examining the study.
This part concerns with the tactics and design used in carrying out this study, it includes study,
area of study, population of the study, units of analysis, the variables and their measurements, and
sampling techniques and sample size, types and sources of data, data collection methods, validity
issues, and data analysis methods (Kothari, (2004).)
3.2 Research design
A research design is a logical and systematic plan prepared for directing a research study. It
specifies the objectives of the study, the methodology and techniques to be adopted for achieving
the objectives (Krishna Swami, 1993).
The research design is the case study design. A case study is an in-depth comprehensive study of
a person, a social group, an episode, a situation, a programme, a community, an institution or any
other social unit (Krishna Swami, 1993).
It is also defined as a strategy for doing research which involves the empirical investigations of a
particular contemporary phenomenon within its real- life context, using multiple sources of
evidence Robson (2002) in Saunders et al., (2009). Therefore, the case study was appropriate for
descriptive purposes and determination of relationships between variables.
Moreover, case study research was used by the researcher to bring out the details from the
viewpoint of the participants by using multiple sources of data which includes observation (both
participants and non- participants interview (structured and unstructured) and documentary
sources. However, case study research tends to be selective in the sense that focuses on one or two
issues that are fundamental to understand the system being examined. The case study strategy also
has considerable ability to organize a wide range of information about a case and then analyze the
contents by seeking patterns and themes in the data. Hence, case study strategy was used in this
study to generate answers to central questions which are mentioned
earlier in chapter 1.
3.4 Area of the study
The research will
and for that reason it is researcher’s confidence that the area was worth and was convenient for the
study as sufficient and
reliable information was obtained.
3.5 Types and Sources of Data
3.5.1 Primary Data
Kothari (2004) defines primary data simply as firsthand information collected from the field. This
was conducted through participatory observation, Questionnaire and interview. The researcher was
working with finance and sales department in order to make sure that all necessary queries,
comments and recommendations were well understood and clear.
3.5.2 Secondary Data
These are second hand information’s collected from some other purpose. Secondary data allows
comparison of information with primary data enabling a more generalized triangulation of
findings. The researcher grasped more about the roles of AC in risk management Tanzania from
Different articles, journals, annual reports of NHC.
3.6 Population and Sample, Sample Size and Sampling Design
3.6.1 Sample and Target Population
Sample refers to the number of items that were selected from the universe. A population is a group
of individuals, object, or items from which sample are taken for measure. It refers to the entire
group of persons or elements that have at least one thing in common. Population also refers to a
large group from which the sample is taken (Kombo& Tromp 2006). Population is all members or
individuals or other elements that a researcher hopes to be represented in the study. In this case the
targeted population was the population drawn from NHC head office staffs.
3.6.2 Sample Size
Sample size is defined as a finite part of statistical population whose properties are studied to gain
information about the whole (Webster, 1985). The total sample were respondents from NHC staff
different department from Finance, Auditing department and Risk Management Unit.
Table 3.1: Target population
S/N Name of inquiry Total
1 Risk management unit 2
2 Audit committee members
3 Internal Auditors
4 Finance department 30
Head of departments and other
4
staffs
Total
Source: Research data, 20
3.6.3 Sampling Procedures
In this study both probability and nonprobability sampling were used to determine the sampling
methods and sample size. Where there is a sampling frame, probability sampling methods and the
sample was adopted where’s in the absence of sampling Frame, on-probability was used. Under
probability sampling, questionnaires were administered randomly but in systematic manner. On
the other hand, purposive sampling used for nonprobability sampling. The researcher used both
probability and non-probability method to select sample.
3.7 Data collection methods and tools/instruments
The researcher study used Interviews, Questionnaires, Participatory observation, Documentary
review and focus group method to collect data.
3.7.1 Interviews
Kothari (1990) argues that an interview is a scheduled set of questions administered through oral-
verbal communication in a face to face relationship between a Researcher and Respondents.
Interview is one among the most important source of information of descriptive survey design as
it allows the interviewer to explore a lot of information regarding an individual’s experiences and
knowledge; his or her opinions, beliefs and feelings and demographic data (Best & Khan, 2004:
202).
The interview can be prepared in different forms including; open- ended, focused or structured.
Interview was conducted to Risk Manager, Chief Internal Auditor, NHC Director of Finance.
3.7.2 Questionnaires
In questionnaires the respondents will be supposed to feel in the answers in written form and the
researcher will collect the forms with the completed information (Kombo& Tromp, 2006). In this
study questionnaires were given to different people who were provided with a time limit so as not
to run out of time.
The researcher used simple questions logically arranged straight forward to the point regarding the
challenges faced in acquisition of Mortgage finance in Tanzania. In that case both open and closed
ended questions were used in order to explore enough information for the study.
There were two types of questionnaires, open and closed questionnaires. The questionnaires were
filled by few NHC Staff from different department includes RMD
3.7.3 Observation
Since the researcher is an employee at the NHC Finance department unit, it was easier for the
researcher to observe Mortgage financing for NHC clients and for the corporation in general. Also
through observation the researcher will be in a position to give recommendations that are useful
for the organization and public at large.
3.7.4 Review of documents
The researcher used various documents available at NHC Concerning subject matter
to extract required information required concerning Mortgage finance. These documents include
NHC Journal and different papers available at NHC. These reports provided a clear insight on how
AC control and management of risk in the organization.
3.7.5 Focus Group
Another tool of collecting information is the focus group. Focus groups are useful in obtaining a
particular kind of information that would be difficult to obtain using other methodologies. A focus
group typically can be defined as a group of people who possess certain characteristics and provide
information of a qualitative nature in a focused discussion. In this research the focus group was
conducted in Risk management department, Auditing department, Finance department at NCH.
3.8 Data Management and Analysis
Data analysis refers to examining what has been collected in a survey or experiment
and making deductions and inferences (Kombo& Tromp, 2006). It involves scrutinizing the
acquired information and making inferences. The methods used in data analysis are influenced by
whether the research is qualitative or quantitative. In this case the data for this study will analyse
both quantitatively and qualitatively. Data processing is any process that a chosen program does
to enter data and summarize, analyse or otherwise convert data into usable information.
The process may be automated and run on a computer. It involves recording, analysing, sorting,
summarizing, calculating, disseminating and storing data. Because data are most useful when well-
presented and actually informative, data-processing systems are often referred to as information
systems; data-processing systems typically manipulate raw data into information, and likewise
information systems typically take raw data as input to produce information as output. The
researcher in this case used statistical package for social science (SPSS) software to analyse data,
graphs, tables, pie charts, tables, frequencies and percentage where necessary.
3.10 Ethical Considerations
In any kind of a research conducted, ethical consideration issues are to be analyses effectively as
they guarantee protection to the information provided. From that point the study will take the
following ethical matters into consideration: firstly, right to choose whether or not to participate
in the proposed research. Secondly Right to be informed in all aspects of the research to be
undertaken, knowing what is involved, how long it will take, and what will be done with the
data, last but not least will be Right to Privacy for their information provided and other related
issues concerning their participation. The information provided will be treated confidentially
unless there is a permission not to do so.
REFERENCES
Guidelines for Audit Committee in Public Sector Improving Transparency and Accountability
(2013)
Report of investigation by the special investigation committee of the board of directors of Enron
Corp,
William C Powers Jr et al, 2002, at
[Link]