Ministry of Finance
Internal Audit Department
Good Practice Guide:
Risk Management & Risk Based
Internal Audit
November 2018
FUNDED BY
SUPPORTED BY
1|Page
Contents
Introduction by Director IAD
Section 1 Risk Management within MDAs.
Section 2 What is Risk Based Internal Auditing (RBIA)?
Section 3 Implementing RBIA
Section 4 Assessing Risk Maturity
Section 5 Production of a Periodic Audit Plan
Section 6 Carrying out a risk based internal audit assignment
Section 7 Benefits and Drawbacks of RBIA
2|Page
Introduction
Over the last few years, the need to manage risks has become recognised as an essential
part of good corporate governance practice. This has put organisations, both private and
public sector, under increasing pressure to identify all the risks they face and to explain how
they manage them. In fact, the activities involved in managing risks have been recognised as
playing a central and essential role in maintaining a sound system of internal control.
While the responsibility for identifying and managing risks belongs to management, one of
the key roles of internal audit is to provide assurance that those risks have been properly
managed. A professional internal audit activity can best achieve its mission as a cornerstone
of governance by positioning its work in the context of the organisation’s own risk
management framework. This approach is generally known as Risk Based Internal Auditing
(RBIA).
However, IAD MOF management recognise that, in the short to medium term, this will be a
challenge to introduce RBIA within most MDA IAUs. This is because within most MDAs the
maturity level and understanding around risk management is extremely low, and as a result
risks to the operations of MDAs are either not recognised, not understood and/or not
managed effectively, the result is likely to be a poor control environment within an MDA.
Although there is this challenge, internal audit within an MDA can move forward to a risk
based internal audit approach and apply same to internal audit assignments and fulfil its
consultancy role by being a catalyst in assisting MDA management with their understanding
and implementation of risk management.
This Good Practice Guide explains:
Risk management within MDAs;
What RBIA is and why IAUs should introduce RBIA;
How RBIA can be implemented; and
The advantages and drawbacks of RBIA.
RBIA is at the cutting edge of internal audit practice. This Guide provides advice and ideas
only as a starting point. Experienced HIAUs and internal auditors within MDAs will need to
consider these ideas, and perhaps adapt, in order to implement RBIA.
The guidance also assumes that readers have an understanding of risk management, risks
and internal controls which affect their MDA, and have an appropriate knowledge of both
the Sierra Leone Public Sector Internal Audit Standards 2017, and the Good Practice Guide
‘Developing an Internal Audit Strategy’.
3|Page
SECTION 1 Risk Management and MDAs
Risk Management
Risk is the effect of uncertainty on objectives. Risk management refers to the architecture
framework for managing risks effectively. Establishing an appropriate and effective risk
framework within an MDA requires a project approach, it requires a plan, takes time,
involves change, requires top management support and takes several years to embed.
Generally, a comprehensive risk management requires seven core building blocks:
1 A strategy that defines the function, role, objectives and establishes a going forward
strategic roadmap
2 Governance – a risk management oversight structure with well-defined roles and
responsibilities to manage risks.
3 Policies, standards and procedures – defining risk management methodology and
activities, risk tolerance levels and integration across the organisation to ensure
consistency and quality in risk management activities
4 Risk management processes – due diligence and ongoing oversight that an
organisation must exercise throughout the risk management lifecycle.
5 Tools and technology – that drive cohesion in risk management process, and support
data accuracy, availability and timeliness.
6 Reporting – that provide a comprehensive view of risks to the relevant stakeholders
across the organisation.
7 Communication, training and awareness – coordinated communication and
programmes to educate those with risk management responsibilities at all stages of
the risk management life cycle
4|Page
Risk management within MDAs
Although there was an attempt to introduce risk management within MDAs in 2015, this did
not really get off the ground thus risk management within most, if not all, MDAs is at the
lowest levels of risk management maturity – either initial or inconsistent.
INITIAL There is no or minimal awareness of the importance of risk management
and there are no processes in place across the entity. Risk management
is usually left to the individual and performed on an ad hoc basis. Risk
management is more reactive than proactive.
INCONSISTEN There is organisational awareness of the importance of risk
T management. There are some formal processes in place for a few risks.
There is limited standardisation of risk management processes and risk
management is conducted inconsistently across each risk and across
each business unit.
For the interest of the reader the other maturity levels are as follows.
CONSISTENT – DESIGNED An enterprise risk management framework exists covering
all major risks. Standardised risk management principles
are defined and documented, basic training conducted.
Consistent risk management processes with
communication and accountability exist throughout the
business but not all processes have been fully implemented
Note: For GoSL a draft Action Plan for implementation of
5|Page
the ERM framework and policy is awaiting approval, as is a
draft ERM flier for sensitization purposes is also available.
CONSISTENT – IMPLEMENTED Organisational risk management is fully implemented
across the organisation, consistently applied and used in
decision making and day to day management. Risk
management processes are measured, evaluated and fed
back into continuous improvement. Principles and policies
are implemented, and aggregated reports are prepared
and reported to those charged with governance. Risk
management is proactive. Key Risk indicators are collected
and monitored consistently
OPTIMISED Risk management is fully addressed and embedded into
day to day management. Sophisticated and advanced risk
management processes are used for all major risk types.
Risk management is used as a key value driver supporting
decision making and pursuit of opportunities. Risks,
including emerging risks are proactively identified and
monitored through key risk indicators and predictive risk
analytics
Notes: (a) For each level of maturity mentioned, there are specific assessment criteria, the
above provides a summary of each maturity level.
(b) There a number of risk maturity models but the above fits a public sector environment.
6|Page
SECTION 2 What is Risk Based Internal auditing?
The Institute of Internal Auditors defines Risk Based Internal Auditing (RBIA) as a
methodology that links internal auditing to an organisation’s overall risk management
framework. RBIA allows internal audit to provide assurance to the board that risk
management processes are managing risks effectively, in relation to the risk appetite.
RBIA is based on an organisation’s own risk management framework and seeks at every
stage to reinforce the responsibilities of management for managing risk.
NOTE: As mentioned in the previous section within MDAs, it is likely that the risk
management framework is at a low maturity level - not very strong or does not exist, if
this is so then it means that the MDA’s system of internal control is probably poor.
IAUs in MDAs in such a scenario should promote good risk management practice to
improve the system of internal control.
Where RBIA is new to the MDA, the HIAU will need to market the concept to MDA
management and win their support, particularly since it may mean a change for them in the
way that they think about risk.
The guidance includes in Section 7 the benefits of RBIA to help with that process. RBIA also
provides challenges to the internal audit activity itself because it is a dynamic process. It is
more difficult to manage than traditional audit methodologies.
But the advantages are much greater. By following RBIA, internal audit should be able to
conclude that:
• Management has identified, assessed and responded to risks;
• The responses to risks are effective but not excessive in managing risks;
• Risk management processes, including the effectiveness of responses and the completion
of actions, are being monitored by management to ensure they continue to operate
effectively; and
• Risks, responses and actions are being properly classified and reported.
This enables internal audit to provide the Vote Controller and Audit Committee with
assurance that it needs on three areas:
• Risk management processes, both their design and how well they are working;
• Management of those risks classified as ‘key’, including the effectiveness of the controls
and other responses to them; and
• Complete, accurate and appropriate reporting and classification of risks.
7|Page
SECTION 3 IMPLEMENTING RBIA
The implementation and ongoing operation of RBIA has three stages:
Stage 1 Assessing risk maturity – obtaining an overview of the extent to which MDA
management determine, assess, manage and monitor risks. This provides an indication of
the reliability of the risk register for audit planning purposes. As indicated in the preface at
this point in time there will be few, if any, MDAs that are risk mature.
Stage 2 Periodic audit planning – identifying the assurance and consulting assignments for a
specific period, usually 1 to 3 years, by identifying and prioritising all those areas on which
the Vote Controller and the Audit Committee requires objective assurance, including the risk
management processes, the management of key risks, and the recording and reporting of
risks.
Stage 3 Individual audit assignments – carrying out individual risk-based assignments to
provide assurance on part of the risk management framework, including on the mitigation
of individual or groups of risks.
OVERVIEW OF THE STAGES:
8|Page
The Sections 4 to 6 detail each stage but because of the low level of risk maturity within the
MDAs, this Guide has recognised that the detail may not relate nor be appropriate to the
MDA / IAU. However, as mentioned RBIA is at the cutting edge of internal audit practice and
each HIAU should incrementally move forward to risk based strategic planning and a risk-
based approach to audit assignments. It should be possible to adopt a risk based internal
audit approach to assignments using the information within this Good Practice Guide.
9|Page
SECTION 4 ASSESSING RISK MATURITY
The first stage of RBIA is to review the level of risk maturity within the MDA. There are
three objectives to this stage, which are to:
• Assess the risk maturity of the MDA
• Report to Vote Controller and to the audit committee on that assessment
• To agree an audit strategy
Step1
Discuss the understanding of risk maturity with the senior managers. Determine what has
already been done to improve the risk maturity within the MDA such as training, risk
workshops, questionnaires about risks and interviews on risks with managers. Where there
are risk registers, determine whether managers feel that the risk register is comprehensive.
Discuss whether an understanding of risk management is embedded so that managers feel
responsible not only for identifying, assessing and mitigating risks but also for monitoring
the framework and the responses to risks.
Step 2
Obtain documents, where they are available, which detail:
– The objectives of the MDA.
– How risks are analysed, for example by scoring their impact and likelihood.
– An approved definition which defines its risk appetite in terms of the scoring system used
for inherent and residual risks.
– The processes followed to identify risks which threaten the MDA’s objectives.
– How management considers risks as part of their decision making. For example, including
risks and the response to them, in project approval documents.
– The processes followed to report risks at different levels of management.
– The sources of information used by management to assure themselves that the
framework is working effectively to manage risks within the risk appetite.
– The risk register of the MDA, including the types of information described in the previous
section.
– Any existing assessment by management of the risk maturity of the organisation.
– Any other documents which indicate the commitment to risk management.
10 | P a g e
Step 3
Conclude on the risk maturity. Using the documents and information gathered assess the
organisation’s risk maturity – See Section 1. Again because of MDAs situation, a simpler
assessment should be possible using only the descriptions in Section 1.
Step 4
Report your conclusion on risk maturity to management and to the audit committee. This
stage will provide a first, high level, assurance on the risk management processes, the
management of key risks and on the recording and reporting of risks.
In reporting your conclusions and their implications, you should note that a risk maturity of
“initial” or “inconsistent” implies that the MDA’s system of internal control and the ability to
assess it may be ineffective.
Step 5
Work with management to identify any actions they propose to take as a result of this
assessment. Management may suggest consulting assignments for internal audit such as, for
example, facilitating management’s efforts to improve their risk management processes.
Step 6
Decide on the audit strategy that follows from your assessment and obtain approval from
management and audit committee.
The audit strategy selected depends upon the MDA’s risk maturity.
Range of audit strategies
An MDA with “initial” or “inconsistent” risk management maturity levels will be unable to
implement RBIA straight away. However, such MDAs can benefit from some aspects of the
audit strategies described below. For example:
internal audit can help improve risk management and governance processes by
reporting its assessment of the risk maturity of the MDA to management and to the
audit committee,
by championing risk management throughout the internal audit activity’s work,
the IAU may also conduct consulting assignments supporting management in
improving the organisation’s risk maturity. Below is a theoretical diagram of range
of audit strategies:
11 | P a g e
12 | P a g e
SECTION 5 Production of a periodic audit plan
NOTE: If risk maturity is assessed as ‘initial’ or ‘inconsistent’ then the development of the
Internal Audit Strategy should follow the guidance in the Good Practice Guide: Developing
an Internal Audit Strategy
Introduction
The objectives of this stage are:
• To agree all the risk management responses and risk management processes on which
objective assurance from internal audit is required.
• To produce an audit plan which lists all audits to be carried out over a specified period –
usually from 1 to 3 years.
The steps to complete Stage 2 are shown as follows.
Step 1
Identify the responses and risk management processes on which objective assurance is
required.
Internal audit should review the risk register and list all the responses on which objective
assurance is required, together with information on the risks to which they are related.
Internal audit should provide assurance on parts of the risk management framework itself –
i.e. on the processes used to identify and assess risks and to decide on the appropriate
responses; processes for reporting risks throughout the organisation; and monitoring
controls over those processes.
The audit committee may prioritise the risks on the management of which it would like
objective assurance, favouring higher inherent risks. It may not, therefore, require objective
assurance on all risks every year.
Internal audit may wish to review thoroughly the audit committee’s assurance requirements
to ensure that they do not leave a gap in assurance. It is important to recognise that the
internal audit activity does not have to provide assurance on every aspect of the risk
management framework in order for it to be effective.
Step 2
Categorise and prioritise the risks.
a. If there is a large number of risks, they should be categorised. This should result in
grouping the risks into a logical order, which will help in compiling the audit plan. Useful
categorisations include:
– By business unit. This is useful where the MDA has a number of physically independent
operation units, the procedures and systems of which are self-contained. It may be
necessary to duplicate common responses, for example, those arising from computers,
across all units.
13 | P a g e
– By function or system, such as revenue, purchases, or stock control. This is useful in a large
central organisation with integrated systems.
– By objectives. This is useful when assessing the audit plan for its relevance to the MDA
because it links audits directly to the objectives affected by the risks, the management of
which is being checked by the audit.
b. Internal audit should also prioritise the responses which are to be audited. An
important characteristic of RBIA is that prioritisation is always by reference to the size of the
risks and to the contribution that the response makes to managing the risks. Useful
prioritisations include:
– The size of the inherent risks managed by the response: the bigger the risk, the higher the
priority.
– The contribution that the response makes in managing risks so that the more the response
reduces the risk, the higher the priority.
– Those categories of risks on which the audit committee requires objective assurance each
period.
Step 3
Link risks to audit assignments.
Two methods can be used to link risks to audit assignments:
a. Group the risks, for example by operational unit, objective, function or system, and
decide the audits which will provide assurance on the related responses. This
method has the advantage that the management of all risks will be covered.
b. Set up an audit universe (see Good Practice Guide ‘Developing an Internal Audit
Strategy’). This allocates each audit to an operational unit or system and assigns the
risks, on which assurance is to be provided to these audits. This method has the
advantage of covering one physical location in one visit and of allowing the definition
of suitably sized audit units. It requires an additional check to ensure that the
management of all risks is being audited.
This step will produce a list of potential audit assignments. The priority of each audit is
derived from the size of the risk management process on which it provides assurance. This
information should link to the categorised listing of risks, which in turn links to the risks in
the MDA’s risk register.
Step 4
Draw up the periodic audit plan.
Estimate the number of days required for each audit and identify which audits can be
completed with the available resources, while providing scope for consulting support.
RBIA generates a defined amount of work and, therefore, highlights whether resources are
sufficient to complete the planned work. Internal audit can propose an increase in staff, or a
14 | P a g e
reduction in the number of audits if there are insufficient resources. Management and the
audit committee should be informed of any risks on which assurance will not be provided.
All the audits to be included in the plan should have now been determined. However, many
organisations add audits based on criteria other than risk. Such criteria might include areas
subject to change, mandatory audits or audits requested by management. This is a reason to
‘sense check’ the RBIA work so far because any topic worthy of audit should have surfaced
through the risk management framework. For example, considerable change happening in
an area could result in increases in the likelihood of a risk event materialising and this
should be visible in the risk register. If an audit has to be included by management request,
then it is displacing an audit included on the basis of risk scores and management should
justify this substitution.
Step 5
Reporting to management and the audit committee.
a The periodic audit plan should be discussed with management and be presented to
the audit committee for approval. It should provide:
– Details of those risks where assurance is provided by carrying out the audits of the risk
management processes and responses in the plan.
– Details of those risks where assurance is provided but based on audit work from previous
years, if applicable.
– Details of those risks where consultancy work is carried out to assist management in
reducing the risks to below the risk appetite, or, at least, an indication of the resources
available for consultancy work.
– The impact of any constraints on resources.
– Any risks not covered due to policy constraints.
– Confirmation that the plan is in accordance with the internal audit activity ‘s terms of
reference.
b. Internal audit should report to MDA management any information that has come to
light about the quality of the risk register. If extra topics for audit have been identified at the
end of Stage 2, these should be discussed with management so that management can revise
the risk register.
For those MDAs or parts of the MDA without a risk register, internal audit should follow the
guidance in the Good Practice Guide ‘Developing an Internal Audit Strategy’
15 | P a g e
SECTION 6 CARRYING OUT AN INDIVUAL RISK BASED AUDIT
ASSIGNMENT
Introduction
Since RBIA is not about auditing risks but about auditing the management of risk, it focuses
on the actions taken by the management team to respond to risks. Internal auditors need to
spend time with managers, discussing and observing the monitoring controls they apply,
rather than re-performing controls or other responses, or analysing data for themselves.
Internal auditors should behave in a way that reinforces the fundamental principle that
management is responsible for managing risks. Procedures should exist to enable internal
auditors to report issues to management and agree with them the action they will take to
update the risk register.
Objectives at this stage
To provide assurance that, in relation to the operation, activity, or system under review and
for the processes identified in the audit plan:
• Management has identified, assessed and responded to risks above and below the risk
appetite.
• The responses to risks are effective but not excessive in managing inherent risks within the
risk appetite.
• Where residual risks are not in line with the risk appetite, action is being taken to remedy
that.
• Risk management processes, including the effectiveness of responses and the completion
of actions, are being monitored by management to ensure they continue to operate
effectively.
• Risks, responses and actions are being properly classified and reported.
The steps to complete Stage 3 are:
Step 1
Establishing the planned scope of the assignment. This involves the internal auditors
understanding the results of Stages 1 and 2 in order to draw up the draft scope. Relevant
information includes the conclusion on the risk maturity and the resulting audit strategy, the
title of the assignment and information that links the audit to the responses on which it
should provide assurance and then to the risks managed by the responses.
Step 2
Assessing the risk maturity of the unit being audited. This allows internal audit to take its
assessment to a more detailed level than was possible at Stage 1. The criteria used to assess
risk maturity should be consistent with those used in Stage 1 and in other assignments. The
16 | P a g e
assignment may include scrutiny of the risks identified by management, which may need
additional or expert resources.
Step 3
Assignment-level conclusions on risk maturity. Conclusions from individual audits should
either confirm or cast doubt on the original organisation-level assessment. This initial
assessment may need to be changed.
Step 4
Confirming the scope of the assignment. Under RBIA, internal auditors need more of
management’s time than they would in other approaches to internal audit. HIAUs may wish
to support the audit team by marketing the approach and gaining buy-in from the
management prior to conducting audit work.
Step 5
Discussion and observation of monitoring controls. This is the first stage of the audit testing.
The aim is to determine that the controls used by management to ensure that the risk
management framework is working are designed to achieve this objective and to show that
they are working as designed.
Step 6
Verification of evidence, walkthroughs, re-performance, etc. These activities may also be
required to provide extra evidence that responses to key risks are working effectively and to
support a conclusion that the monitoring controls are also working.
Step 7
Documenting the results of the audit work. This differs in RBIA from standard practices
mainly in that the link between risks, responses to risks, assurances given and work done to
support those assurances has to be made clear.
Step 8
Assessing management’s evaluation of residual risks. This produces a conclusion about
specific scores in the risk register and should lead to findings about how management
determine residual risks in general. If there is a systemic failing failure, internal audit should
ensure that it is reflected in the organisation-level conclusions on risk maturity.
Step 9
Conclusions on responses and risk management processes covered by the assignment. This
covers both their design and how well they are working.
Step 10
Reporting and feedback. This should be in accordance with the Sierra Leone Internal Audit
Manual (Version 2) including whatever levels of review are required by audit management.
17 | P a g e
This step is critical to your aim of reinforcing management’s responsibility for managing
risks. Findings should be discussed with management in such a way that they take
responsibility for deciding on appropriate remedial actions, including all and any changes to
the risk register. If this is a big change in the style of the internal audit activity, the effort
required to implement it properly should not be underestimated. Internal audit may need to
play a bigger role in drafting and delivering reports for the first months of implementing
RBIA.
To complete the RBIA steps and stages, the findings from individual assignments are fed
back into the overview of the organisation begun in Stage 1 because:
– The findings may change the conclusions on risk maturity and may need to be reflected
throughout the audit plan the next time it is updated.
– The findings need to be reflected in the reporting of risks so that management and the
audit committee understand where objective assurance has been provided.
Step 11
Summarising the audit conclusions for the audit committee. This summary should:
– Support the requirement of any regulations which apply to the organisation.
– Fulfil the requirements of the audit charter.
– If not part of the charter, provide an opinion on whether risks are being managed
sufficiently to ensure the MDA’s objectives are being achieved and, within reasonable limits,
will be achieved in the future.
18 | P a g e
SECTION 7 BENEFITS & DRAWBACKS OF RBIA
The following information has been taken from the Institute of Internal Auditors (UK)
resources.
Clear and unambiguous conclusions on risk management
RBIA is inextricably linked to the risk management framework. During Stage 1, it allows a
conclusion on the risk maturity of the organisation. If this is not high, it provides internal
audit with an opportunity to report that fact promptly to management and the audit
committee so that they can take immediate action.
While this allows the internal audit activity to provide value to its organisation, RBIA is a
challenging prospect. Organisations with a poor level of risk maturity may be that way
because the managers and directors do not accept that a good risk management framework
is an essential element of a sound system of internal control. Internal audit may need to
undertake a longer-term programme of activity to champion risk management.
Direct contribution to the organisation’s objectives
An effective risk management framework will improve an organisation’s governance and its
chances of achieving its objectives over the long term. The RBIA methodology makes a clear
and valuable contribution to the risk management framework by providing objective
assurance and by facilitating management’s efforts to improve the framework. It ensures
that internal audit resources are directed towards assessing the management of the most
significant risks.
Relationship with management
The RBIA approach requires increased management involvement.
Since the processes to be covered in audits exist in all parts of the organisation, audits may
involve managers in departments never before visited.
In order to discuss the responses deployed to manage risks and how management knows
these are working properly, the internal auditor may need to involve a greater number of
more senior managers than might be involved in traditional audits.
RBIA emphasises management’s responsibility for managing risks. This must be stressed
during all meetings with managers.
The close-down meeting is less about management accepting internal audit’s
recommendations and more about management agreeing that an issue exists and
determining what action it is going to take and what reporting it needs to provide to the
next level of management.
As a result, the head of internal audit may be required to market the benefits and the need
for internal audit. A much higher profile may be necessary in non-financial areas in order to
pave the way for audits that managers can understand and support. The implications for
staff expertise are discussed later.
19 | P a g e
Management responsibility for risk management
RBIA can be implemented fully only in risk enabled and risk managed organisations. One
characteristic of this level of risk maturity is that managers have to take responsibility for
managing risks. In taking responsibility for risks, managers understand that controls, like
other responses to risks, are not the responsibility of internal audit, imposed by internal
audit, but are their own responsibility.
Implementing RBIA means that the internal audit activity behaves in a way that reinforces
this management responsibility and thus contributes to a stronger risk management culture.
Achieving targets
RBIA is an effective way to achieve targets set for the internal audit activity, such as:
• The compilation of an audit plan which ensures the internal audit activity fulfils its charter
• Gaining acceptance from management that it takes appropriate action to manage risks
within the risk appetite;
• Provision of objective assurance in the three areas of risk management normally required;
and
• Keeping within the budget set for the activity.
Audit Resources
RBIA justifies the number of auditors required. The audit plan, including the resources
required, is driven by the proportion of processes and risks on which the audit committee
requires objective assurance. This differs from alternative approaches, where the resources
available determine the audits which can be carried out.
Staff Expertise
Internal auditors engaged in RBIA require more people and business skills, such as
interviewing, influencing, facilitating and problem solving.
The expansion of the audit universe to cover all risks threatening the organisation’s
objectives requires the internal auditor to conclude on the design and operation of
responses to risks in areas that may be new. This may require specialist knowledge that may
be acquired as follows:
• Use specialist skills already available within the internal audit activity, e.g. computer
auditors.
• Provide specialist training to auditors with general expertise, e.g. provide training on the
regulations and practices related to stress management to an auditor who already hold an
Advanced Diploma in Internal Auditing and Management.
• Recruit temporary or permanent specialists from inside the organisation, e.g. a warehouse
manager from one overseas subsidiary could audit warehouse processes in another.
• Use specialists from outside the organisation, e.g. treasury specialists.
20 | P a g e