0% found this document useful (0 votes)
5 views5 pages

Business Process and Risk Management Guide

The document outlines the concept of business processes, detailing types such as operating processes, projects, and management/support processes, which collectively aim to achieve organizational objectives. It also discusses the importance of auditing these processes and understanding business risks, including methods for risk assessment and response strategies. Additionally, it highlights business process outsourcing as a means to enhance efficiency while maintaining management accountability for associated risks.

Uploaded by

ameyu
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views5 pages

Business Process and Risk Management Guide

The document outlines the concept of business processes, detailing types such as operating processes, projects, and management/support processes, which collectively aim to achieve organizational objectives. It also discusses the importance of auditing these processes and understanding business risks, including methods for risk assessment and response strategies. Additionally, it highlights business process outsourcing as a means to enhance efficiency while maintaining management accountability for associated risks.

Uploaded by

ameyu
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

BUSINESS PROCESS -encompasses compliance

program
-set of connected activities linked with each
other to achieve an objective -processes the org uses to
manage its external
-types:
relationships
-operating processes: core
-activities involving org
processes thru which the org
governance that sets strategic
achieves its objectives
direction of the company
-continuous

-repeated many times thru out


the business cycle

-creates value and delivers it


directly to customers

-projects: activities w/ extended


period

-complex sequencing

-unique in every activity

-not done continuously

-to structure nonroutine


activities

-ex: constructing assets,


choosing and implementing
new acc system

-management and support


processes:

-oversee and support org core


value-creation processes
(operations)

-necessary across all


industries BUSINESS MODEL
-indirectly creates value -includes the org objectives and how the
-administers human, business processes are structured to achieve
financial, info and tech, and them
physical resources -defined by org vision, mission, values
-includes high-level strategies and tactical
direction
-starts at org level
-annual goals w/ specific steps to undertake
-key process: its failure leads
next year and measures of expected
to not achieving the objective
accomplishments
-yields a manageable set of
HOW TO AUDIT BUSINESS PROCESSES
critical processes

-by a team of indivs w/ a broad


perspective of the org w/out
detailed knowledge per area

-could potentially overlook


critical processes

-bottom-up approach:

-starts at activity level


UNDERSTANDING THE BUSINESS -each area identifies and
PROCESS document business
processes

-done by people who are


actually responsible for the
activities

-aggregated across the org

-works for smaller orgs,


tiresome for big ones

-key objectives:
-first source of info: process owner (org) and
existing policy and procedures -why does the process exist?
documentation
-how does the processes support the
-discuss with people performing the activities org strategy?

-approaches: -how should people act?

-top-down approach: -what else do the processes do that is


important to mgmt.?

-understanding the business process =


understand how mgmt. determines
processes effectiveness
-key performance indicators (KPIs): BUSINESS RISKS
monitors process performance
-ability of chief audit executive (CAE) and
-must be observable, relevant, internal audit mgmt. to understand business
available on a timely basis, risks affects the extent to which the internal
communicated audit can fulfill its mission to add value

-indicates mgmts. tolerance levels to -overall risk profile: identifies critical risks to
variation achieving each strategic objective

-documentation: -usually developed by mgmt.

-business process is typically -internal auditors build risk


documented by the process owner assessment from existing risk profile

-uses:

-orientation

-defining areas of
responsibility

-evaluation of process
efficiency

-determining primary concern


areas

-identify key risks and controls

-methods:

-processes narratives

-process maps: pictorial


representations + narratives HOW TO AUDIT BUSINESS RISKS

-high level: more concise,


shows broad inputs and its
interactions with processes
and outputs

-detailed level: shows all


involved inputs, processes
and outputs

-no absolute standards on formatting


-significance: impact + likelihood
-corps strive for consistency, so they
formulate their own standards assessment
-impact: adverse effect of a risk outcome -involves daily business
decisions (implementing
-assessed on a continuum from low
control)
to high
-sharing: transfer risks (insurances,
-uses 3 or 5 categories
hedging, outsourcing)
-establish boundaries per category
-mapping out risk:
-org determines the terms used to
-create risk process matrix to link
signify impact
risks with business processes
-severity: other term for impact
-key links: process plays a direct and
-likelihood: assessing the odds/probability of key role in managing the risk
the risk occurring
-secondary links: process helps
-usually in precise categories manage the risk indirectly

-uses 3 or 5 category scale -example:

APPROACHES TO RISK RESPONSE Business risk: excessive inventories

1. Risk model approach Key links: improving inventory mgmt.


2. Risk factor approach
Secondary link: consignment sales to
RISK MODEL APPROACH indirectly manage inventory

-at least 1-3 processes are identified


to have key links

-determining engagements:

-count all key and secondary links

-number of links determine the type of


internal audit

-experience is a must
-risk responses: -audit cycles for each processes can
-acceptance: accept risks as it is be based on risk impact and
likelihood
-avoidance: exit or divesting
-consider past audit results
-pursuit: exploit the risk for its
advantages to achieve an objective RISK FACTOR APPROACH

-reduction: reduce impact, -develops basic risk factors to evaluate risks


likelihood, or both across processes
-higher level of abstraction that is applicable BUSINESS PROCESS OUTSOURCING (BPO)
to each processes
-transferring some of the org’s business
processes to an outside provider

-to reduce costs and improve service quality


and efficiency

-outsources repetitive processes using long-


term contracts

-mgmt is still accountable for the risks

-types of risk factors:

-external: w/in the business


environment and the process itself

-internal: extent that the controls


assure the achievement of objectives

-assessment scale:

-uses 3, 5, or 7-point scales

-same scale for all risk factors

-weight identification:

-importance of the risk factor relative


to other risk factors

-sum of all weights = 100

-combination of risk scores

-sum of all (assessment scale x


weight)

OVERVIEW OF RISK RESPONSE

-risk control map: plots risk significance


(impact and likelihood) against control
effectiveness

-shows where there is a balance between risk


and control

You might also like