BUSINESS PROCESS -encompasses compliance
program
-set of connected activities linked with each
other to achieve an objective -processes the org uses to
manage its external
-types:
relationships
-operating processes: core
-activities involving org
processes thru which the org
governance that sets strategic
achieves its objectives
direction of the company
-continuous
-repeated many times thru out
the business cycle
-creates value and delivers it
directly to customers
-projects: activities w/ extended
period
-complex sequencing
-unique in every activity
-not done continuously
-to structure nonroutine
activities
-ex: constructing assets,
choosing and implementing
new acc system
-management and support
processes:
-oversee and support org core
value-creation processes
(operations)
-necessary across all
industries BUSINESS MODEL
-indirectly creates value -includes the org objectives and how the
-administers human, business processes are structured to achieve
financial, info and tech, and them
physical resources -defined by org vision, mission, values
-includes high-level strategies and tactical
direction
-starts at org level
-annual goals w/ specific steps to undertake
-key process: its failure leads
next year and measures of expected
to not achieving the objective
accomplishments
-yields a manageable set of
HOW TO AUDIT BUSINESS PROCESSES
critical processes
-by a team of indivs w/ a broad
perspective of the org w/out
detailed knowledge per area
-could potentially overlook
critical processes
-bottom-up approach:
-starts at activity level
UNDERSTANDING THE BUSINESS -each area identifies and
PROCESS document business
processes
-done by people who are
actually responsible for the
activities
-aggregated across the org
-works for smaller orgs,
tiresome for big ones
-key objectives:
-first source of info: process owner (org) and
existing policy and procedures -why does the process exist?
documentation
-how does the processes support the
-discuss with people performing the activities org strategy?
-approaches: -how should people act?
-top-down approach: -what else do the processes do that is
important to mgmt.?
-understanding the business process =
understand how mgmt. determines
processes effectiveness
-key performance indicators (KPIs): BUSINESS RISKS
monitors process performance
-ability of chief audit executive (CAE) and
-must be observable, relevant, internal audit mgmt. to understand business
available on a timely basis, risks affects the extent to which the internal
communicated audit can fulfill its mission to add value
-indicates mgmts. tolerance levels to -overall risk profile: identifies critical risks to
variation achieving each strategic objective
-documentation: -usually developed by mgmt.
-business process is typically -internal auditors build risk
documented by the process owner assessment from existing risk profile
-uses:
-orientation
-defining areas of
responsibility
-evaluation of process
efficiency
-determining primary concern
areas
-identify key risks and controls
-methods:
-processes narratives
-process maps: pictorial
representations + narratives HOW TO AUDIT BUSINESS RISKS
-high level: more concise,
shows broad inputs and its
interactions with processes
and outputs
-detailed level: shows all
involved inputs, processes
and outputs
-no absolute standards on formatting
-significance: impact + likelihood
-corps strive for consistency, so they
formulate their own standards assessment
-impact: adverse effect of a risk outcome -involves daily business
decisions (implementing
-assessed on a continuum from low
control)
to high
-sharing: transfer risks (insurances,
-uses 3 or 5 categories
hedging, outsourcing)
-establish boundaries per category
-mapping out risk:
-org determines the terms used to
-create risk process matrix to link
signify impact
risks with business processes
-severity: other term for impact
-key links: process plays a direct and
-likelihood: assessing the odds/probability of key role in managing the risk
the risk occurring
-secondary links: process helps
-usually in precise categories manage the risk indirectly
-uses 3 or 5 category scale -example:
APPROACHES TO RISK RESPONSE Business risk: excessive inventories
1. Risk model approach Key links: improving inventory mgmt.
2. Risk factor approach
Secondary link: consignment sales to
RISK MODEL APPROACH indirectly manage inventory
-at least 1-3 processes are identified
to have key links
-determining engagements:
-count all key and secondary links
-number of links determine the type of
internal audit
-experience is a must
-risk responses: -audit cycles for each processes can
-acceptance: accept risks as it is be based on risk impact and
likelihood
-avoidance: exit or divesting
-consider past audit results
-pursuit: exploit the risk for its
advantages to achieve an objective RISK FACTOR APPROACH
-reduction: reduce impact, -develops basic risk factors to evaluate risks
likelihood, or both across processes
-higher level of abstraction that is applicable BUSINESS PROCESS OUTSOURCING (BPO)
to each processes
-transferring some of the org’s business
processes to an outside provider
-to reduce costs and improve service quality
and efficiency
-outsources repetitive processes using long-
term contracts
-mgmt is still accountable for the risks
-types of risk factors:
-external: w/in the business
environment and the process itself
-internal: extent that the controls
assure the achievement of objectives
-assessment scale:
-uses 3, 5, or 7-point scales
-same scale for all risk factors
-weight identification:
-importance of the risk factor relative
to other risk factors
-sum of all weights = 100
-combination of risk scores
-sum of all (assessment scale x
weight)
OVERVIEW OF RISK RESPONSE
-risk control map: plots risk significance
(impact and likelihood) against control
effectiveness
-shows where there is a balance between risk
and control