0% found this document useful (0 votes)
5 views27 pages

Chamaka Ranasinghe on Strategic Risk Management

The document outlines the principles and processes of Strategic Risk Management, emphasizing the importance of strategic planning and the identification of risks in achieving competitive advantage. It discusses various strategic choices, including competitive strategies, growth directions, and the risks associated with formal planning and alternative strategies. Additionally, it addresses ethical considerations, reputational risks, and the impact of corporate social responsibility on organizational strategy.

Uploaded by

aashirahamed3121
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views27 pages

Chamaka Ranasinghe on Strategic Risk Management

The document outlines the principles and processes of Strategic Risk Management, emphasizing the importance of strategic planning and the identification of risks in achieving competitive advantage. It discusses various strategic choices, including competitive strategies, growth directions, and the risks associated with formal planning and alternative strategies. Additionally, it addresses ethical considerations, reputational risks, and the impact of corporate social responsibility on organizational strategy.

Uploaded by

aashirahamed3121
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Strategic Risk Management

Strategic Risk Management


Strategy Risk

Strategy - ‘A course of action, including the specification of resources required, to achieve a


specific objective - CIMA Official Terminology

Strategy is about where to compete and how to compete, achieving sustainable competitive
advantage.

Levels of Strategy

Strategic Planning Process – RPM

Chamaka Ranasinghe 1
Strategic Risk Management

Strategic Choice

Strategies are required to close the gap.

[Link] strategy for each business unit

[Link] for Growth

[Link] – Organic or Inorganic, other methods

→ Benefits of long term/ formal planning

[Link] to look ahead

[Link] key risks

[Link] controls

[Link] creativity

→ Risks in formal planning


● Stakeholder conflicts when setting objectives.
● Short term pressures
● Forecasting difficulties
● Bounded rationality
● Rigidity
● Cost
● Management Distrust

→ Alternative Strategies
● Logical Incrementalism
● Emergent Strategies
→ Issues when formal planning is not conducted.

[Link] to identify threats

[Link] drift

[Link] difficulties

Chamaka Ranasinghe 2
Strategic Risk Management

[Link] skills

● Which approach is suitable?

RPM → Stable industries, managers less experienced

Informal approaches → Dynamic environments


3Es - Economy, efficiency & effectiveness
Strategic Planning for NFP Not for profit

The party which receives the benefits is not the party which funds these organizations.
Therefore, setting a strategic plan can be problematic. Their performance should be
measured using 3Es and this also can be considered when setting the strategy.

● Risks of using 3Es

[Link] measures

[Link] between measures giving contradictory result

[Link] measure to prioritize

[Link] measures can be easier to measure, and some are not

● Approaches to strategic planning and associated risks

[Link] – Risk of objectives not capturing market considerations

[Link] lead - Risk of incorrect future estimates

[Link] based – Risk of making the products complicated

Strategic Analysis and Choice


How to compete? – Competitive Advantage

Porter’s generic strategies

• Cost leadership

• Differentiation

• Focus

Chamaka Ranasinghe 3
Strategic Risk Management

Strategy Benefits Value chain impact Risks


Cost leadership Higher profits with same Cost reduction – no No fall back if
price as frills Economies of the position is
competitors/Undercutting scale Locate in lost Continual
advantageous areas adaptation to
Defense against price Learning curve ensure prices are
war. benefits low.

Allows penetration
strategy.

Barrier to entry
Differentiation Higher margins Demand Differentiation Need for
is less elastic using technology, continuous
Strengthening barriers to design, innovation.
entry performance. Smaller volumes
Superior after Marketing costs
sales service are higher
Brand strength performance in a
Augmenting the recession can be
product packaging poor.
Focus Smaller investment in Reliable segment Cost leaders and
marketing identification. other will get
Specialization Identification of attracted
Less competition consumer needs Low volumes
Entry is easier Segment to be
sufficiently large
Competition
analysis

Risks to generic strategies;

Chamaka Ranasinghe 4
Strategic Risk Management

Stuck in the middle – certain businesses have adopted hybrid strategies.

Cost leadership may not be a competitive advantage.

Differentiation may not always lead to a business being able to command higher
prices.

Where to compete? – Products, Markets

Ansoff’s matrix

Method Risks
Market penetration Lowest risk option
Product development Higher risk
Market development Higher risk
Diversification Highest risk Related – Less risky.
Unrelated - Riskier

Which mode? Organic or Inorganic

Mode Risks Controls


Acquisition Costly than internal Key control – Due
inorganic growth
growth Cultural mismatch Diligence – Financials,
Asset disposal Strategic fit, Employee
Lack of Issues, Property,
knowledge Competition commission,
Reduction in Intellectual property,
ROI Contract, Pending
litigations, Tax,
Insurance

Chamaka Ranasinghe 5
Strategic Risk Management

Joint Development – JV, Strategic


Strategic fit Cost
Alliance, sharing
inorganic growth
Franchising, Knowledge
Licenses, Outsourcing sharing Profit
sharing
Loss of control
Loss of development
opportunities
International Growth Political risk
organic growth Foreign exchange risk
Capital investment
Customer relationships
Supply chain risks Ethical
risk
Cultural risk

Other strategic risks

Disruption - New development creates a new market while destroying another

Factors influence disruption;

• Simplicity

• Resources

• Cost Accessibility

• Quality

Measures on strategic risk


Scenario Planning

Steps

[Link] high impact and high uncertain factors

[Link] possible scenarios for each factor

[Link] different factors to identify scenarios

Chamaka Ranasinghe 6
Strategic Risk Management

[Link] the scenario

[Link] courses of action for each scenario

[Link] – see which scenario is unfolding

[Link]

Stress testing – A variation of scenario planning

Scenarios under difficult situations

7 Questions

[Link] customer

[Link] do your core values prioritise shareholders employees and customers

[Link] performance variables

[Link] boundaries

[Link] to generate creative tension

[Link] commitment

[Link] uncertainties

Sources of business stress

• Changes in consumer preferences

• Cyber attacks

• Workforce strikes

• Advances in technology making products obsolete

• Economic cycles – Recession

• Rivals offering better products or services

• Failure in production systems

Ethics

Chamaka Ranasinghe 7
Strategic Risk Management

Fundamental Principles
(a) Integrity - A professional accountant should be straightforward and honest in all
professional and business relationships.

(b) Objectivity - A professional accountant should not allow bias, conflict of interest or undue
influence of others to override professional or business judgments.

(c) Professional Competence and Due Care - A professional accountant has a continuing
duty to maintain professional knowledge and skill at the level required.

There are two main considerations.

● Accountants are required to have the necessary professional knowledge


and skill to carry out work for clients.
● Accountants must follow applicable technical and professional standards
when providing professional services.

(d) Confidentiality - A professional accountant should respect the confidentiality of


information acquired

There are two key considerations here.

1. Information is not disclosed outside the firm unless there is proper authority, right
or duty to disclose.

2. Confidential information is not used for personal advantage.

There must be reasons for disclosure before confidential information is provided to a 3rd
party.

1. Permitted by law and authorized by the client

2. Required by law

3. There is a professional duty or right to disclose

(e) Professional Behaviour - A professional accountant should comply with relevant laws
and regulations and should avoid any action that discredits the profession.

Threats
(a) Self-interest threats -may occur as a result of the financial or other interests of a
professional accountant or of an immediate or close family member.

Chamaka Ranasinghe 8
Strategic Risk Management

(b) Self-review threats - may occur when a previous judgment needs to be re-evaluated by
the professional accountant responsible for that judgment.

(c) Advocacy threats - may occur when a professional accountant promotes a position or
opinion to the point that subsequent objectivity may be compromised.

(d) Familiarity threats - may occur when, because of a close relationship, a professional
accountant becomes too sympathetic to the interests of others.

(e) Intimidation threats - may occur when a professional accountant may be deterred from
acting objectively by threats, actual or perceived.

Safeguards to these threats include:

● Educational, training and experience requirements for entry into the


profession.
● Continuing professional development requirements.
● Corporate governance regulations.
● Professional standards.
● Professional or regulatory monitoring and disciplinary procedures.
● External review by a legally empowered third party of the information
produced by a professional accountant.
● Effective, well publicised complaints systems operated by the employing
organisation, the profession or a regulator, which enable colleagues,
employers and members of the public to draw attention to unprofessional
or unethical behaviour.
● An explicitly stated duty to report breaches of ethical requirements.

Ethical dilemma and conflict resolution


A dilemma will only occur if there are 2 or more interests at stake, even if it is only an ethical
duty to oneself or 1 or more principles of the code are threatened.

CIMA recommends following process for addressing ethical conflicts.

1. Gather all facts

2. Ascertain ethical issues involved and identify the fundamental principles related

3. Escalate concern internally

4. Escalate the issue to your manager’s boss

Chamaka Ranasinghe 9
Strategic Risk Management

5. Seek advice from CIMA

6. Report externally to auditors or relevant trade/regulatory body

7. Remove yourself from the situation

Conflicts within employing organisations


There may be times when an accountant’s responsibilities to an employer and their
professional obligations to comply with fundamental principles are in conflict.

Pressures that may be faced

1. Act contrary to law or regulation

2. Act contrary to professional standards

3. Facilitate unethical or illegal earnings management strategies

4. Lie to, or otherwise intentionally mislead auditors, regulators

5. Issue or associated with financial/ non-financial report that materially


misrepresents the facts

Safeguards

1. Obtaining advice where appropriate

2. Formal dispute resolution process

3. Seeking legal advice

Reputational Risk

Reputational risk is the likelihood of losses occurring due to deterioration in the belief or
opinion held about someone or something.

Sources of reputational risk


● Accounting deficiencies – E.g. Tesco overstating profits in 2014
● Poor customer service
● Poor IT security

PESTEL is one tool that can be used to identify sources.

Chamaka Ranasinghe 10
Strategic Risk Management

Social and environmental considerations

→ Environmental considerations and reputational risks


● Level of fines
● Number of environmental prosecutions
● Number of environmental enforcement actions
● Number of ‘notifiable’ incidents
● Percentage of employees working within an ISO 14001 compliant environmental
management system.
● The firm’s rating in independent benchmarking such as the ‘Business in the
environment’ index.

Ethics – Another source

→ Corporate social responsibility

Corporate social responsibility (CSR) refers to the idea that a company should be sensitive to
the needs of all stakeholders in its business operations and not just shareholders.

Benefits of a CSR strategy;

● Differentiation – the firm’s CSR strategy can act as a method of differentiation.


● High calibre staff will be attracted and retained due to the firm’s CSR policies.
● Brand strengthening- due to the firm’s honest approach.
● Lower costs- can be achieved in a number of ways. E.g. due to the use of less
packing or energy.
● The identification of new market opportunities and of changing social
expectations.
● A resultant overall increase in profitability.
● NPVs will also increase due to increased sales, lower costs, an extended project life
and a lower level
● of risk.

Impact of Strategy on brand and reputation

● Brand – is something that the organization can control to a certain extent. It’s
about what the organisation does and how it approaches its products, services and
interactions.

Chamaka Ranasinghe 11
Strategic Risk Management

● Reputation – is what people think about an organisation, and crucially what they
communicate about an organization. This is much harder to control.

Strategic alignment

Strategic alignment starts at the very top of an organisation and is about the board making
sure that the strategic goals, the company and business processes align for the reason the
organisation exists, achievement of the mission.

Transfer Pricing – source of reputational risk


International transfer pricing

Transfers within an international group will often be cross-border, between divisions in the
different countries. With international transfers and international transfer pricing, the issues
already described still apply. In addition, other factors need to be considered.

→ Different tax rates


● A multinational company will seek to minimise the group’s total tax liability. One
way of doing this might be to use transfer pricing to:
● Reduce the profitability of its subsidiaries in high-tax countries, and
● Increase the profitability of its subsidiaries in low-tax countries.

Changes in transfer price can redistribute the pre-tax profit between subsidiaries, but the total
pretax profit will be the same. However, if more pre-tax profit is earned in low-tax countries
and less profit is earned in high-tax countries, the total tax bill will be reduced.

There are factors that need to be considered when setting international transfer prices

1. Different tax rates

Reduce the profitability of high tax countries can be done through transfer pricing

2. Government actions on transfer pricing

Multinationals could be required to apply “arm’s length” prices to transfer prices, they
might be required by tax laws to use market based transfer prices, to remove
opportunities for tax avoidance.

A country with the status of a tax heaven will offer:

● Low tax rate on profits


● Low withholding tax on dividends paid to foreign holding companies

Chamaka Ranasinghe 12
Strategic Risk Management

● Tax treaties with other countries


● No exchange controls
● Stable economy
● Good communications with the rest of the world
● Well-developed legal framework

Ways of managing the reputational risk


● Governance
● Employee relations
● Environmental awareness
● External relations
● Risk professionals
● A policy framework
● Risk sensing tools

→ How to respond in a crisis?


● Setting up a crisis response team
● Scenario planning

Source of Reputation Risk : Fraud


→ Pyramid Schemes

A pyramid scheme is a business model that recruits’ members via a promise of payments or

services for enrolling others into the scheme, rather than supplying investments or sale of

products or services.

Advance Fee Fraud: When fraudsters target victims to make advance or upfront payments for
goods, services and/or financial gains that do not materialise. Types of advance fee fraud
include : Career opportunity scams. Clairvoyant or psychic scams.

3 pre-requisits :
dishonesty
→ Prerequisites for fraud opportunity
motive
As for most property-related crimes, there are three prerequisites for fraud to occur:
dishonesty on the part of the perpetrator; the opportunity for fraud to occur and a motive for
the fraud. Each can be dealt with through fraud prevention techniques:

Chamaka Ranasinghe 13
Strategic Risk Management

1. Dishonesty
● Pre-employment checks on all new staff (especially references)
● Careful scrutiny of staff by supervision and lifestyles that are not supported by
salaries.
● Severe discipline for offenders
● Effective moral leadership.

2. Opportunity
● Separation of duties where possible
● Controls over inputs (especially cash)
● Controls over processing
● Controls over outputs
● Physical security of assets.
● Motive
● Good employment condition
● Instant dismissals where necessary
● Sympathetic complaints procedure

→ Indicators of Fraud Risk

The following warning signs may indicate the presence of fraud risk.

● Absence of an anti-fraud culture


● Failure of management to implement a sound system of internal controls
● Lack of financial management expertise and professionalism in key accounting
principles, the review of management reports and the review of significant cost
estimates
● A history of legal or regulatory violations or claims alleging violations
● Strained relationships between management and internal or external auditors
● Lack of supervision of staff
● Inadequate recruitment processes
● Redundancies
● Dissatisfied employees with access to desirable assets
● Unusual staff behaviour
● Personal financial pressures on key staff
● Discrepancy between earnings and lifestyle

Chamaka Ranasinghe 14
Strategic Risk Management

● Low salary levels of key staff


● Employees working unsocial hours unsupervised
● Employees not taking annual leave entitlements
● Lack of job segregation and independent checking of key transactions
● Lack of identification of assets
● Poor management accountability and reporting
● Alteration of documents and records
● Photocopies of documents replacing originals
● Missing authorisations
● Poor physical security of assets
● Poor access controls to physical assets and IT security systems
● Inadequacy of internal controls
● Poor documentation of internal control
● Poor documentary support for transactions, especially credit notes
● Large cash transactions
● Management compensation highly dependent on meeting aggressive performance
targets
● Significant pressure on management to obtain additional finance.
● Extensive use of tax havens without clear business justification
● Complex transactions
● Complex legal ownership and/or organisational structure
● Rapid changes in profitability
● Existence of personal or corporate guarantees
● Highly competitive market conditions and decreasing profitability levels within the
organization.
● The organisation operating in a declining business sector and facing possible
business failure.
● Rapid technological change may increase potential for product obsolescence.
● New accounting or regulatory requirements which could significantly alter
reported results.

→ Examples of indicators of procurement fraud include


● Disqualification of suitable tenderers
● Unchanging list of preferred suppliers
● Constant use of single source contracts

Chamaka Ranasinghe 15
Strategic Risk Management

● Contracts that include specifications that only one supplier can satisfy.
● Personal relationships between staff and suppliers
● Withdrawal of a lower bid without explanation
● Acceptance of late bids
● Changes to specifications after bids have been opened.
● Poor documentation of contract award process
● Consistent favouring of one firm over another
● Unexplained changes to contract after its award
● Contract awarded to supplier with poor performance record.
● Split contracts to circumvent controls.

→ Example of indicators of fraud in the selling process


● Overcharging from an approved price list
● Short-changing by not delivering the correct quantity or quality
● Diversion of orders to a competitor or associate
● Bribery of a customer by sales representative
● Bribery of customer by a competitor
● Insider information by knowing competitor’s prices
● Warranty claims that are false
● Over-selling of goods or services that are not necessary
● Free samples that are not necessary

→ Fraud Risk management Strategy


● Fraud prevention
● Fraud detection
● Fraud response

1. Fraud Prevention

The existence of a fraud strategy is itself a deterrent. This can be achieved through:

● Anti-fraud culture
● Risk awareness
● Whistle blowing
● Sound internal control systems

Anti-fraud culture - where minor unethical practices are overlooked.

Chamaka Ranasinghe 16
Strategic Risk Management

Guiding principles could include:

● Not acting in a way that could bring the organisation into disrepute.
● Acting with integrity towards colleagues, customers, suppliers and the
public
● Ensuring that business objectives are clearly stated and communicated.
● Ensuring that benefits (whether to shareholders, customers or employees)
are distributed fairly and impartially.
● Safeguarding the confidentiality of personal data
● Complying with legal requirements.

Risk awareness - Fraud should never be discounted, and there should be awareness
among all staff that there is always the possibility that fraud is taking place.

Whistle blowing - Fraud may be suspected by those who are not personally involved.
People must be encouraged to raise the alarm about fraud.

Sound internal control systems - Sound systems of internal control should monitor
fraud by identifying risks and then putting into place procedures to monitor and report
on those risks.

2. Fraud Detection

Some methods of discovering fraud are:

● Performing regular checks


● Warning signals:
● Whistleblowers

Qualifying disclosures

1. Criminal offences
2. Failure to comply with legal obligation
3. Miscarriage of justice
4. Threats to health and safety
5. Damage to environment

Protected disclosure

For a disclosure to a prescribed person to be protected, you must

Chamaka Ranasinghe 17
Strategic Risk Management

1. Make disclose in good faith


2. Reasonably believe that the information is substantially true
3. Reasonable believe that you are making the disclosure to the right prescribed
person

In certain circumstances, disclosures can be made to others

1. To legal advisory
2. To a government minister if you are a public sector worker
3. To a professional body or in extreme circumstance the media

3. Fraud Response

The fraud response plan sets down the arrangements for dealing with suspected cases of
fraud, theft or corruption.

The organisation’s response to fraud may include:

● Internal disciplinary action, in accordance with personnel policies


● Civil litigation for recovery of the loss
● Criminal prosecution through the police.

Individual responsibilities should be allocated to:

● Managers, to whom employees should report their suspicions.


● Director of Finance, who has overall responsibility for the organisational
response to fraud including the investigation.
● Personnel, who will have responsibility for disciplinary procedures and
issues of employment law and practice.
● Audit committee, who should review the details of all frauds, and to whom
notice of any significant fraud needs to be reported.
● Internal auditors, who will most likely have the task of investigating the
fraud.
● External auditors, to obtain expertise.
● Legal advisers, in relation to internal disciplinary, civil or criminal
responses.
● Public relations, if the fraud is sufficiently large that it will come to public
attention.

Chamaka Ranasinghe 18
Strategic Risk Management

● Police, where it is policy to prosecute all those suspected of fraud.


● Insurers, where there is likely to be a claim.

Elements of a fraud response plan

1. Purpose of the fraud response plan


2. Corporate policy
3. Definition of fraud
4. Roles and responsibilities
5. The response – Reporting suspicions, establishing an investigation team,
formulating response.
6. The investigation – Preservation of evidence, physical evidence, electronic
7. evidence, interviews, statements from witness and suspects
8. Organisation’s objectives with respect to fraud – Internal report, Civil response,
9. Criminal response
10. Follow up action – Lessons learned, Management response.

Corporate Governance

→ Importance of Corporate governance


● Listed companies are required to practice CG either by statute or by professional
organisations.
● CG requirements are given support of the stock exchanges.
● CG is a major help to reduce company failures and companies with proper CG tend
to achieve their objectives in a less risky way.
→ Features of poor corporate governance
● Dominance by an Individual or a small Group.
● Lack of Involvement of the Board.
● Lack of adequate internal controls.
● Lack of Supervision.
● Lack of Independent Scrutiny.
● Lack of contact with Shareholder.
● Emphasis on Short Term Goals.
● Misleading Accounting Information

Chamaka Ranasinghe 19
Strategic Risk Management

Division of Responsibilities

→ Roles of Chairman and CEO

Chairman

● Should be independent.
● Provide leadership to the board.
● Leading role in determining the composition and structure of the board which
will include a regular assessment on the size of the board, balance between
executive and non-executive directors and interaction, harmony, effectiveness
of the directors.
● Set board’s agenda and plan board meetings.
● Chair all board meetings, directing debate towards consensus.
● Ensure the board receives appropriate, accurate, timely and clear information.
● Facilitate effective contribution from NEDs.
● Hold meetings with NEDs, without executive directors’ presence.
● Chair the AGM and other shareholder meetings, using these to provide effective
dialog with shareholders.
● Discuss governance and major strategy with major shareholders.
● Ensure views of shareholders are communicated to the board as a whole.

CEO

● Develop and implement policies to execute the strategy established by the


board.
● Assume full accountability to the board for all aspects of company operations,
controls and performance.
● Manage financial and physical resources.
● Build and maintain an effective management team.
● Put adequate operational, financial, planning risk and internal control systems
in place.
● Closely monitor operations and financial results in accordance with plans and
budgets
● Interface between board and employees
● Assist in selection and evaluation of board members.

Chamaka Ranasinghe 20
Strategic Risk Management

● Represent the company to major suppliers, customers, professional


associations etc

The role of chairman and CEO should not be held by the same individual.

→ Non-Executive Directors
● Strategy Role - Contribute to strategy development.
● Scrutinizing Role - Review performance of management in meeting objectives
● Risk Role - Ensure the risk management process is robust and financial systems
are accurate.
● People Role- Decide fair remuneration of BOD and succession planning.

They should be presented in remuneration, nominations and audit committees.

Independence

● The code states the board should include a balance of NEDs and executive
directors. The board should consist of half of NEDs excluding the chair.
● One NED should be the senior independent director who is directly
available to shareholders if they have concerns.
● The primary fiduciary duty of NEDs is that they owe to the company’s
shareholders.
● They should not allow themselves to be captured or unduly influenced by
the vested interests of other members of the company such as executive
directors, trade unions or middle management.
● There are also concerns over the recruitment of NEDs and the challenge
that this may bring to independence.
● Recruiting NEDs with prior industry knowledge is good, but it can make
them less independent as it may reduce their ability to be objective, so it is
sometimes easy to be independent when they are from outside the
industry.

Reasons for NED independence

● To provide detached and objective view of the board decisions


● To provide expertise and communicate effectively.
● To provide shareholders with an independent voice on the board
● To provide confidence in corporate governance
● To reduce accusations of self – interest in the behavior of executives

Chamaka Ranasinghe 21
Strategic Risk Management

Composition, Succession and Evaluation


Audit, Risk and Internal Control
Accountability

The board should establish a transparent arrangement for considering how they should apply
the corporate reporting and risk management and internal control principles and for
maintaining an appropriate relationship with the company’s auditor.

→ Audit committee

Audit committees were first required under the Cadbury Code in response to criticisms of the
relationship between the directors and auditors

Particular criticisms of the relationship were about;

● Remuneration of the auditors – Decided by directors


● Appointment of the auditors – Discretion of directors
● Reports of auditors – Received by directors
● The director had power to give other lucrative work to auditors

Audit committees were established to address these issues.

The board should establish an audit committee of at least 3 (for small companies 2)
independent NEDs. In smaller companies the chairman may be a member, but will not chair in
addition to the independent NEDs provided he or she was considered independent on
appointment as chairman. The board should satisfy itself that at least one member should
have recent financial experience.

Role of the audit committee in general

● Monitor integrity of financial statements, formal announcements related to


financial performance, reviewing significant financial reporting judgments
contained in them
● Review financial statements, internal financial controls, internal controls, risk
management systems

Chamaka Ranasinghe 22
Strategic Risk Management

● Monitor and review internal audit function


● Recommendations on appointing, deciding remuneration, terms of engagement
with external auditors
● Review and monitor external auditor’s independence
● Develop and implement policy on getting non audit services from external auditor
● Discussion with external auditors regarding significant matters that arose in audit
and review of audit report and management letter
● Ensure that a system is in place for whistleblowing (they will not implement)

Audit committee and financial reporting

They should consider;

1. Significant accounting policies that have been used, and whether these are
appropriate
2. Any significant estimates or judgments that have been made and whether these
are reasonable
3. The methods used to account for any significant or unusual transactions, where
alternative accounting treatments are possible
4. The clarity and completeness of the disclosures in financial statements

Audit committee and internal control

● Review internal financial controls


● Review all internal controls and risk management systems (unless task is taken by
a separate risk committee or full board)
● Give approval to the statements in the annual report related to internal control and
risk management
● Receive reports from management about the effectiveness of the control system it
operates
● Receive reports on the conclusions of any tests carried out on the controls by
internal or external auditors

Audit committee and internal audit

● Approve appointment and termination of head of internal audit


● Ensure that the internal auditor has direct access to the board chairman and is
accountable to the audit committee
● Review and assess the annual internal audit work plan

Chamaka Ranasinghe 23
Strategic Risk Management

● Receive a report periodically about the work of the internal auditor


● Review and monitor the response of management to the findings of the internal
auditor
● Monitor and assess the role and effectiveness of the internal audit function within
the company’s overall risk management system

Audit committee and external auditors

● Recommendation to the board on appointment, re appointment or removal of


eternal auditors
● Oversee the selection process when new auditors are being considered
● Approve term of engagement with external auditors and their remuneration
● Have annual procedures for ensuring the independence and objectivity of external
auditors
● Review the scope and the audit with the auditor
● Make sure appropriate plans are in place for audit at the start of each annual audit
● Carry out post completion audit review

Remuneration
→ Remuneration committee
● Judge where to position the company relative to other companies
● Sensitive to pay and employment conditions elsewhere in the group, specially
when determining annual salary increments
● Decide what compensation commitments the director would entail in early
termination, should avoid rewarding poor performance

Executive Share Options – ESOP

● Part of manager’s remuneration package


● No of options decided by remuneration committee
● Options will have a strike price
● Vesting period – period that should pass before the options can be exercised

Board Leadership and Company Purpose - Relations with shareholders


Board should use AGM to communicate with investors and to encourage their participation.

Chamaka Ranasinghe 24
Strategic Risk Management

Chairman should arrange for the chairmen of audit, remuneration and nomination
committees to be available to answer the questions at the AGM and for all directors to attend.

→ Summary on Committees

Nominations Audit Remuneration

Composition Majority Independent NEDs NEDs


independent
NEDs

Special Conditions Chairman can be Chairman should not Chairman can be a


a member, should be a member, should member, should not
not chair the meet at least 3 times chair the committee,
committee a year (one should before being
be with external chairman of REMCO
auditors) member should be in
the committee for 12
months at least

No of members - Min 3 3 3

Additional 1 member with


Requirements recent financial
experience

Small companies - No 2 2 2
of members - Min

International Developments
→ Sarbanes Oxley Act – US
● Came into being after financial scandals of Enron & WorldCom
● SOX is extremely detailed and carries the full force of Law
● Includes requirements for the SEC to issue certain rules on CG
● Relevant to US companies, directors of subsidiaries of US listed businesses and
auditors who are working on US listed businesses

SOX vs UK code

Chamaka Ranasinghe 25
Strategic Risk Management

● Enforcement
● UK Code is “Principles-based” (a series of voluntary codes)
● SOX is “Rules-based”

● Documentation
● SOX includes rigorous provisions for evidencing IC and having them audited

Key points in SOX

● Auditors are restricted in the additional services they can provide to an audit
client
● Company MUST have audit committee-if not it will be disallowed from trading
● Senior partner of Audit partners must be changed every five years
● Directors are prohibited from dealing in shares at “sensitive times”
● Financial reports to detail off balance sheet financing
● Annual reports must include statements concerning the IC system
● Accuracy of financial statements must be vouched for by CEO & CFO

→ UK Code vs SOX

UK Code SOX

Certification of accuracy in financial More disclosures required in SOX Eg: Details on off
statements balance sheet transactions

Increased financial disclosures More disclosures required in SOX Eg: Details on off
balance sheet transactions

Internal controls report Both codes are similar

Both codes are similar SOX has more restrictions on auditors providing
non audit services

Compulsory rotation of lead audit partner working


on a client

Chamaka Ranasinghe 26
Strategic Risk Management

→ CSR Report

CSR report address issues of important stakeholders such as Shareholders, Employees,


Customers, Suppliers, General Public and Government

Chamaka Ranasinghe 27

You might also like