0% found this document useful (0 votes)
71 views64 pages

Tax Risk Management Strategies Guide

The document outlines the importance of tax risk management, detailing its evolution and the need for organizations to establish effective policies and frameworks. It defines tax risk, categorizes it into specific and generic areas, and emphasizes the necessity of understanding and managing uncertainties related to tax obligations. The guide aims to assist tax directors, CFOs, and other stakeholders in navigating the complexities of tax risk management in a rapidly changing corporate environment.

Uploaded by

Namjaa Enkhbat
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
71 views64 pages

Tax Risk Management Strategies Guide

The document outlines the importance of tax risk management, detailing its evolution and the need for organizations to establish effective policies and frameworks. It defines tax risk, categorizes it into specific and generic areas, and emphasizes the necessity of understanding and managing uncertainties related to tax obligations. The guide aims to assist tax directors, CFOs, and other stakeholders in navigating the complexities of tax risk management in a rapidly changing corporate environment.

Uploaded by

Namjaa Enkhbat
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Tax Risk Management

Tony Elgood Ian Paroissien Larry Quimby


Tax Partner Tax Partner Tax Partner
United Kingdom Australia United States

Tony Elgood is the author of The ‘Best Practice’ Ian Paroissien is the leader of PwC’s Global Larry Quimby, is a US based tax engagement
tax function guide. He is based in the UK and is Compliance Services for Australia and the Asia partner working with a number of our Philadelphia
part of PwC’s Global Compliance Services team. Pacific theatre. Ian advises many leading based clients. He is currently the national lead for
He works regularly with leading tax functions in companies on best practices and developments an initiative addressing the application of the
helping them set their strategies and manage in tax management and compliance systems. Sarbanes Oxley Act to the tax function.
their tax functions.
For further information: For further information:
For further information: [Link]@[Link] [Link]@[Link]
[Link]@[Link]

Acknowledgments:
We are very grateful for the help and comments given to us by a number of people during the preparation of this guide. In
particular we would like to thank Pat Ellingsworth (head of group taxation at Royal Dutch/Shell) and Alan Davidson from the
PricewaterhouseCoopers London office for their input. For more information on strategic thinking for a tax function see the
PricewaterhouseCoopers ‘Best Practice’ tax function guide.
Contents Page

1. Introduction 2

2. What is tax risk? 3

3. Why is tax risk management important and who to? 11

4. Where does managing tax risk fit into the overall tax strategy? 18

5. The risk management framework for tax 20

6. The tax risk management framework in practice 30


a. Risk control environment 32
b. Risk assessment 34
c. Control activities 41
d. Information and communication 46
e. Monitoring 47

7. Managing global tax risk 48

8. Summary 53

Appendix 1 Best practice checklist 54

Appendix 2 Risk assessment templates 56

Tax Risk Management 1


1 INTRODUCTION

In early 2002 we published a guide entitled the ‘Best Practice’


tax function. In that guide there was one chapter (seven pages)
on Tax Risk Management. Since that guide was published the
corporate world has changed dramatically and risk management
has shot up the agenda of most organisations.

We have seen the Enron scandal in the US, and more recently the Parmalat scandal in Italy. The US has
responded with the introduction of the Sarbanes-Oxley legislation, and with an ongoing increase in
globalisation, similar legislation and practices are springing up in a number of different countries. Inside
organisations there is an increasing awareness that risk management, and in particular, good internal control
procedures is becoming more and more important.

Historically tax risk management and tax internal controls were a bit of a black art, not necessarily
understood even by those in the tax function, let alone those outside. Whilst recognising that the tax area
has its own unique profile, tax risk management is now increasingly being discussed inside both commercial
organisations and revenue authorities. Companies are starting to document their tax risk management
policies and to do this they are having to assess the different types of tax risk in their business. Some
organisations have also recently appointed internal tax risk managers.

The purpose of this guide is to pull together the current thinking on tax risk management. It is aimed not
only at tax directors and their teams, but also at CFOs, audit committees, chief risk officers and internal
audit functions. These stakeholders, including those sitting outside the tax function, need to be comfortable
that there is a tax risk management policy in their organisation, that tax, as one of the key costs in the
business, is being properly managed and that the inherent risks in the tax position of the organisation are
being both understood and properly controlled.

Tax risk management has come a long way over the last couple of years and will continue to evolve. This is
not a manual about how to manage tax risk – different businesses will address their issues in different ways.
What we have tried to do is to set out firstly the issues that need to be discussed when a company is
deciding on its policy and addressing its approach to tax risk management, secondly a framework for
managing the risks and finally some specific tools and techniques that can be used in doing so.

We look forward to being part of the debate as this area of tax management continues to develop in the fast
changing commercial world in which we find ourselves.

2 Tax Risk Management


2 WHAT IS TAX RISK?

The term tax risk means different things to different people and
we need to start with a common understanding of what it is we
are talking about. Only then can we address how tax risk can
be managed.

The decisions, activities and operations under the umbrella of tax risk management, that can arise from business transactions,
undertaken by an organisation give rise to irrespective of whether they are taxes the downside hazard which can arise
various areas of uncertainty – business managed by the tax function or not. from the compliance process and the fact
risks. Some of these uncertainties will be in They all give rise to uncertainty and hence that the operational part of the business
respect of tax. These tax uncertainties may to tax risk. can give rise to both opportunities and
be in relation to the application of tax law hazards. Ensuring that the opportunities
and practice to particular facts, it may be For any type of risk, you not only need to are maximised can be as important as
uncertainty over the facts themselves or it understand what it is but you also need to managing the hazards.
may be uncertainty as to how well systems decide how much risk you are willing and
operate to arrive at the tax results of the prepared to take. To our mind tax risk A company’s policy on tax risk
business activities and operations. These management is not necessarily therefore management will therefore determine:
uncertainties give rise to tax risk. about minimising risk. Businesses make • The value that can be achieved by
profits by taking risks and a no-risk taking risks,
Managing tax risk is therefore about strategy is probably neither cost effective • The costs that can be saved by
managing these uncertainties. Due to the nor right for any business. By setting a reducing risks, and
very nature of these uncertainties, there is framework scale (or a score out of 10), • The resources needed to manage
often no one right answer. Tax risk against where you either want to be or are both the upside opportunities and
management is about understanding where prepared to be for each type of tax risk, the downside risks
these risks arise and making judgement you give yourself some criteria against
calls as to how they are dealt with. which to decide what actions need to be Before we proceed, we should make it
taken, what risks you are prepared to take clear that we believe each business has a
We have sought in this chapter to provide and how any particular type of tax risk is to responsibility and duty to pay the
an explanation of where we see the main be managed. For each area of tax risk this appropriate taxes on its business
areas of tax uncertainty arising. This has chapter provides such a framework scale. transactions. We also feel strongly that it is
led us to define seven main areas of tax important for organisations to manage and
risk. We have quite intentionally not tried The tax risk spectrum below shows plan their tax affairs. However we do not
to do any analysis by type of tax – suffice where the major tax uncertainties can believe it is right for a business to play the
it to say that we include all types of tax arise. It shows the upside opportunity ‘tax audit lottery’ with the revenue
authorities. This chapter and, indeed, the
whole guide, are based on the fundamental
Opportunity Transactions Operations Compliance premise that non disclosure to authorities
is not an acceptable approach and that the
‘risk of getting caught’ is therefore not a
consideration or risk to be ‘managed’.

Uncertainty/
Variance

Hazard

Tax Risk Management 3


Types of Tax Risk
In our view there are seven broad categories of risk associated
with taxes, four that are specific risk areas and three that are
rather broader and more generic.

These are:
Specific risk areas
1 Transactional risk
2 Operational risk
3 Compliance risk
4 Financial accounting risk

Generic risk areas


5 Portfolio risk
6 Management risk, and
7 Reputational risk

Specific risk areas transactions. From a tax point of view the risks have been properly assessed and are
highest risk transactions are often those appropriate. In doing so the Commissioner
Transactional risk that are happening specifically for tax has provided boards with 10 questions
This concerns the risks and exposures purposes e.g. a tax driven reorganisation. or criteria against which to judge this.
associated with specific transactions (For more details on the Australian
undertaken by a company. In any In any transaction there will be views Commissioner’s position see Chapter 3.)
transaction there may be uncertainty taken during the process as to what is The appropriateness of this and the issues
as to how the relevant tax law will apply acceptable and what is not – risks will it raises are a major discussion point in
and uncertainty arising from specific undoubtedly be taken. This is in the very themselves but it does highlight the
judgement calls – particularly in the more nature of the way transactions and growing profile and importance of tax risk
complex areas. negotiations are carried out. Some parts management in this area.
of a transaction may be carried out to
The more unusual and less routine a achieve a particular tax result (for example
particular transaction is, then generally, to preserve tax losses). The steps taken Additionally tax risks can arise from
the greater the tax risks associated with to achieve the hoped for tax result may be failures, such as:
the transaction are likely to be. One-off, low risk or they may be more aggressive
non-routine transactions, such as with more chance of being challenged by • The tax department is not involved in
acquisitions/disposals of businesses or a revenue authority. the transaction or are brought in only
parts of a business, or significant at the last minute;
restructuring projects and reorganisations, Major transactions have for some time • There is no organisational agreed
will generally bear greater tax risks than the been a key focus for tax authorities but framework against which to judge
routine every day business such as selling the signs are that this is increasing. In acceptable risk; and/or
products and services. In addition there are Australia for example, the Commissioner
of Taxation has just written to the boards • There is a failure to properly document
likely to be well-designed procedures and and implement a transaction.
systems in place for the processing of of all public companies indicating that as
routine transactions, which would usually part of their governance responsibilities
not apply to non-routine, one-off they should be signing-off that the tax

4 Tax Risk Management


In our view this last point often carries the greatest risk in the transactional area. Failure
to implement and document properly what has been planned and agreed is in our
experience the cause of more tax authority challenges in this area than any other. Where
the tax result depends on a particular sequence of events, board meeting or wording in
a documentation there is often the risk that the ‘i’s are not dotted and the ‘t’s are not
crossed – and all the best planning falls down due to inadequate implementation and
monitoring over the life of the issue to ensure nothing is done to prejudice the tax result.
Revenue authorities are increasingly asking to see the full documentation relating to a
particular transaction to test out whether the implementation has achieved the result the
company is claiming.

The question then arises as to how much tax risk are you prepared to take in particular
transactions and how much risk are you actually taking over the correct implementation
of the transactions? What is your profile in relation to transactional risk?

Low Medium High

0 5 10
Conservative Aggressive
No risk
Proud of the tax we pay Minimum amount possible

It is important in considering this scale to indicate where you want to end up as distinct
from the inherent risk in the transaction or planning idea. Risks identified can in many
cases be managed, such that a risk initially identified as above an acceptable level may
be capable of being brought within it by a tax ruling or some other approach. This
recognises that risks can be managed so that the potential upside benefit is not lost.

Operational risk
Operational risk concerns the underlying risks of applying the tax laws, regulations and
decisions to the routine every day business operations of a company. Different types
of operation will have different levels of tax risk associated with them. For example,
compare normal third party product sales with intra-group cross-border products sales;
there are greater tax risks associated with connected party cross-border transactions
(primarily transfer pricing issues). With increasing globalisation of trade there is an
ever increasing risk of operational people inadvertently creating a taxable presence in
a country in which they are operating. These are just two examples of tax risks that
can occur from the normal ongoing business of a company.

In our experience the closer the tax function is to the business operations the better
these types of risks are managed. Communication between the various parties is key.
The standing of the tax function in the organisation will be an important point here;
if the people are well respected, then they are more likely to be contacted at the
appropriate time. Where are you today on the operational risk scale – and where would
you like to be?

Low Medium High

0 5 10

Tax heavily involved in operations Tax seldom consulted


Formal sign off procedures in place No formal procedures

Tax Risk Management 5


Compliance risk Low Medium High
Compliance risk concerns the risks 0 5 10
associated with meeting an organisation’s
tax compliance obligations. (As we noted Zero tolerance – no error rate Large acceptable error rate
earlier, we do not believe risk of discovery
by tax authorities is a factor. One must
assume full disclosure and that the Tax compliance risk also includes the At this point one should note that in most
authorities are aware of and will review risks arising from agreement of tax jurisdictions the figures included in the tax
your activities.) From a tax perspective returns and from enquiries on, or the accounts, at the time the financial
compliance risk would primarily relate to audit of, submitted tax returns by fiscal statements are issued, are ‘estimates’.
the preparation, completion and review of authorities. In a number of countries the In fact, deferred tax accounting generally
an organisation’s tax returns (of whatever final agreement of a tax return often calls for the estimation of future taxes to
type and not only corporate tax returns) ends in a ‘horse trade’ between the be paid under tax regimes on transactions
and the risks within those processes. taxpayer and the relevant revenue that are recorded in the accounts in the
authority; it may make sense to have a current year. Avoiding negative prior year
Compliance risk addresses the risks number of aggressive positions in the adjustments to the tax accounts has
implicit in the systems, processes and return so that there is something to give always been high on most tax directors’
procedures adopted by a company to as part of any negotiations. agendas. We have lost count of the
prepare and submit its tax returns and in number of times we have been told by tax
responding to any enquiries/issues raised Additionally, and we will come back to this directors that what the CFO and board are
in the process of reaching an agreed point later on, how many of the group’s looking for is ‘no surprises’. This has
position with the authorities. tax returns is the tax function actively probably led tax directors to be more risk
involved with? What about payroll tax averse than they might have been (and to
What we are talking about here is: returns, indirect tax returns, and customs miss upside opportunities?) This
and duty returns? If it is not the tax conservative view as to what should be
• the integrity of the underlying accounting function, who is managing the risks provided for in the accounts may lead to
systems and information, associated with these returns? a debate with the auditors as to whether
• the processes of extracting tax sensitive a provision is justified or is perhaps a
information from the accounting system, There is also an interaction between touch over prudent.
• ensuring the tax compliance analysis compliance risk and reputational risk (see
processes are based on up to date below). How do the revenue authorities As well as looking at the processes in
rate you on a risk scale? Do they see you arriving at the accounts figures, and the
knowledge of the latest tax law and
internal controls around these processes,
practice, and as an aggressive tax planning group and
the following questions need to be asked:
• the proper and efficient use of have ‘marked your card’ as one where
technology in the processes. they have to do a lot of work – or are you • How much uncertainty is there in the
seen as a more conservative group where interpretation or application of the tax
There are clearly cost implications in where they have little to go for? law(s) used to compute the tax
you position yourself on the scale below figures?
and there will be a trade off between costs • What is the quality of the data received
Financial accounting risk
spent and risks taken. To achieve no errors from or used in the transactional,
in any tax return will undoubtedly be cost The Sarbanes-Oxley Act of 2002 has operational and compliance areas?
prohibitive. Alternatively, are you over brought the risks in the financial • Are there issues or questions as to the
engineering the process and could you accounting area into sharper focus. application of the tax law to the data?
reduce the cost with little or no impact on A particular challenge for many tax
• What provisions are needed to cover
your risk position? What is your attitude to departments is the requirement in
these uncertainties and what level of
tax penalties? Where do you want to be on Sarbanes-Oxley Section 404 requiring materiality is acceptable?
the scale above – and what changes need documented and tested internal controls
to happen in the way you operate to get over financial reporting.
you there?

6 Tax Risk Management


Low Medium High

0 5 10
Good internal controls Unquantified risk
High degree of certainty Low degree of certainty

It will be interesting to see how Portfolio risk Have you given each key tax risk in your
companies apply Section 404 to the tax organisation a percentage chance of
accounts. The ‘spirit’ of the law would Portfolio risk concerns the overall going wrong and aggregated the result?
suggest that better information and more aggregate level of risk when looking at Have you considered the worst-case
timely consideration of risk will evolve. transactional, operational and compliance scenario and the impact of this on the
Some have suggested a mechanical risks as a whole and considers the profit and loss account and the balance
‘check the box approach’ to the adoption interaction of these three different specific sheet? Is this acceptable?
of the requirements of Section 404. We risk areas. This is of particular concern to
believe that the mechanical approach those organisations that are involved in a We look later, in Chapter 6 and
may cause a number of tax functions to number of transactions, whether tax driven Appendix 2, at how you might measure
focus too heavily on the processes in or business driven. One might argue that portfolio risk by considering both the
arriving at the tax figures in the financial the financial reporting is the measure of impact and the probability of particular
accounts – at the expense of the the portfolio risk and well it might be. risks actually happening.
processes of managing the other tax risks However, we believe that a conscious
considered in this chapter. These other consideration of the aggregation of the
tax risks are potentially the ones that three risks should be considered.
have been less well managed and are
where there are both larger opportunities Each particular transaction may be below
and greater risks. the ‘risk threshold’, but when combined
together with positions taken with various
Clearly it is not only the statutory financial revenue authorities the cumulative risk
accounts where financial accounting risk profile becomes unacceptable.
arises. Tax figures appear in cash flow
planning, forecasting, and in managing What would be the impact if all the areas
investor expectations of the future. of tax risk went wrong at the same time?
What would be the financial implications
and what would be the resourcing
Generic risk areas
implications to deal with the issues?
You could argue that the four specific tax
risks set out above are the only ones that
really exist, and the risks we set out
below are more about managing these Low Medium High
risks than risks themselves. However we
0 5 10
believe them to be sufficiently important
to be treated as separate risks in their Low aggregate risk High aggregate risk
own right and to be reviewed as part of
the tax risk management process. If you
disagree with us then some of the tools
introduced later in this guide will need
adapting to show four risk areas, not
seven. However whichever way we go on
this point, the general principles of tax
risk management will not change. The
three areas of tax risk that we are calling
the generic tax risks are explained below.

Tax Risk Management 7


Management risk

The second generic area of tax risk is one In this new world, with tax risk management
of not properly managing the various risks becoming increasingly important, it is clear
set out above. In our experience, few tax that organisations need to put some time
functions actually have a documented tax and resources behind this issue. They also
risk management policy, though we are need to ensure that those charged with
starting to see tax risk managers being managing tax risks have the skills and the
appointed. Risk management is ability to do so. ‘Under-managing’ these
something that historically has not issues, either through a lack of skill,
specifically been on the agenda for many resource or time can lead to unexpected
tax functions. While some of the risks ‘surprises’ or possibly worse, missed
above will have been managed, we opportunities. Tax risk management will
suspect few people will claim that all their need to become a higher management
tax risks have been managed in a priority for many organisations.
systematic way. Even where it has, a lot
of the information about tax issues is
carried around in people’s heads and if
these people leave the organisation then
the information leaves with them.

Low Medium High

0 5 10
Tax risk management taken seriously Lack of risk management skills
High on management agenda Lack of budget/resources
Resources available to do this Quality resources not available

Reputational risk

We have collected a file of press cuttings issue through a public arena such as the
relating to the tax affairs of companies – courts, information about the company’s
and this file is becoming increasingly activities or practices result in changes to
bulky. How will your CEO or the board the perception of the company by its
react to seeing your tax affairs splashed customers, suppliers, or employees.
all over the front page of a national
newspaper (or even on the inside pages)? Consider also the impact of being seen
to pursue considerably more aggressive
Reputational risk concerns the wider tax planning and ideas than the norm –
impact on the organisation that might does this matter to you?
arise from an organisation’s actions if
they become a matter of public
knowledge. By their very nature such
risks will impact wider business interests.
For example, consider the impact on a
company if, as a result of pursuing a tax

Low Medium High

0 5 10

Not important Very important

8 Tax Risk Management


More than one tax strategy we have seen have included policies
such as “We will not undertake any tax planning transaction
which would reflect adversely on the group if details of it were
to be published in the business pages of [Daily Newspaper Title].”
By way of an example, in the US it is External risks
proposed that failure to disclose certain
‘listed transactions’ under the Reportable The comments so far have focused on
Transaction Regulations will result in a the risks that are manageable inside an
fine. For an SEC listed company, the fact organisation. There will also be risks that
that a fine has been levied may have to are external and by their very nature are

St m
es
d do
unmanageable – but are very real and

U K re
be disclosed in the published accounts.

In ny

Corporate income taxes


at
lg ia
Br m

te g
te po
er l
Be ral

S ia
G zi

ni in
iu

a
equally important nevertheless. Examples

d
a
The potential disclosure of the failure to

ni a
st

U ing
d
Au
report properly certain transactions to the under this heading are a change of
Inland Revenue Service could however legislation, an unexpected court decision

Sales taxes
be more concerning than the fine itself. on a particular point, or even a change Transactional risk

Excise duties
of government. The rest of this guide

Payroll taxes
Withholding taxes
Operational risk
For MNCs (multi national corporations) focuses on those risks that a business
this issue may also go to the heart of has some control over – but perhaps Compliance risk
good corporate citizenship, particularly in portfolio risk should be deemed to Financial accounting risk
foreign jurisdictions where reputational risks include this extra layer of external risk.
may be more important in some countries Portfolio risk
that at home. It is also where cultural Use of the scale frameworks Management risk
differences and policy clashes can occur.
In our discussions so far, there is an Reputational risk
Identifying and managing issues such as
assumption that there is one point on the
the impact of aggressive tax planning,
scale for each of the different types of risk.
reputational issues just from major tax It is likely that the mere exercise of
However we recognise that this
authority challenges, and policy and compiling the information and considering
assumption may not be valid when you
practices around corruption, are all look across the spectrum of different taxes the areas of tax risk that we have discussed
elements of reputational tax risk management. and different countries. For example you in this chapter will significantly enhance a
may well decide that the compliance risk company’s management of tax risks.
This leads on to the question of tax ‘ethics’ you are prepared to take for one particular
and whether companies have an obligation tax in country A is very different from that
to pay their ‘fair share’ of tax – whatever for another type of tax in country B.
that might mean. There is a debate taking
place in many countries around this point – You may wish to put the different taxes
and whether companies should pay the tax and countries at different points on the
that is in accordance with the letter of the scales. This leads us to a three
law, the spirit of the law or both (if that is dimensional matrix, covering the types
possible). To be seen to be doing anything of risk, the types of tax and the different
different can impact on a company’s wider countries in which you operate.
reputation. Is transparency of your tax
position an important part of managing
your reputational risk?

Tax Risk Management 9


Other activities
In our experience tax functions often have The purpose of this guide is to focus on
a wider remit than just tax. Tax and treasury tax risk management and we have not
are sometimes the same department; tax sought to stray into the other activities that
functions are often responsible for the may be carried out by the tax function.
preparation of statutory accounts as they That is not to say that the risks in these
are the people who need them most – to areas do not need managing.
enable them to file the tax returns.

Summary
We have set out the seven areas of tax risk, together with a scale of one to ten for each one. By reviewing all
seven scales, it should be possible to produce one overall scale summarising your organisation’s attitude to tax
risk management. You should be able to consider where you want to be on the scale – and where you are today.
This will give you a template to consider further what actions you need to take going forward.

Low Medium High

0 5 10

Conservative Aggressive
Low appetite for risk Risk taker

Very few organisations will be positioned at either The organisations that position themselves on the
end of this scale. right hand side of the scale:
The organisations on the left hand side might be • Are more aggressive
the ones who: • Accept that they will have more compliance risks
• Are inherently cautious • Have a higher materiality level
• Spend more time managing risk • Are less concerned about upsetting revenue
• Are more concerned about compliance risk authorities
• Are concerned about their reputation • Spend less time managing tax risk

We look in more detail in Chapter 4 as to how tax risk management fits into the bigger picture both in terms of managing
tax and managing risk in the organisation as a whole. However before doing so can you answer the question below
specifically in terms of tax risk management.

Where are you today – and, more importantly, are you


where you want to be?

10 Tax Risk Management


3 WHY IS TAX RISK MANAGEMENT IMPORTANT – AND WHO TO?

We have set out in the previous chapter our view of the different
types of tax risk. This chapter seeks to identify the different
parties who have an interest in an organisation’s tax risk
management. We will explore why they are, or should be,
interested in this subject. We are also presenting a view as to
who should focus on (or take ownership for) each of the various
risks outlined in Chapter 2. Our analysis of this latter point is
undoubtedly open to challenge – but if it gets the reader thinking
through their role and responsibilities with respect to tax risk
management then our objective will have been achieved.

There are (or should be) many stakeholders, point therefore is to consider who, in
both inside and outside the organisation, addition to the tax function, are the
involved in managing risk, and in stakeholders in a business’s tax risk
particular managing tax risk. The first management?

Head of tax/
tax function
CEO/CFO

Business units
The board Tax Risk and functional
Management areas
Stakeholders

Investors
Auditors
Revenue
authorities

The board risk management policy. This, we


believe, is the starting point for effective
There is a tendency to equate the tax risk management.
board’s view on tax risk management
closely with their view on corporate (We recognise that the role and
governance. However a board’s role is responsibilities of the board of directors
first and foremost to give direction to the may vary by country. While the level of
overall running of the business so let us involvement of the board in day-to-day
look at this aspect first. operations may be different, it is clear
that the board is and must be the key
We would suggest that until now there stakeholder in the management of risk.
has been little or no engagement or As noted below, the board could be the
understanding around tax risk entire board of directors or if applicable
management at board level – with such the audit committee of the board. The
matters normally being delegated to the key point is involvement by persons not
CFO and the head of tax. We question responsible for ‘day-to-day’
how many boards of companies have management.)
seen and considered a documented tax

Tax Risk Management 11


The templates in Chapter 2 might be The rules, regulations and commentary
used as a starting point for engaging the generated by Sarbanes-Oxley have been
board in the debate as to what is the driving most of the current thinking in this
group’s tax risk management policy. Have area, even where a group is not SEC
they properly considered both the listed. The Sarbanes-Oxley rules require
benefits and the costs of the various detailed documentation of the design and
approaches to tax risk management – operational effectiveness of internal
how aggressive or conservative do they controls to be in place – and
want the group to be? How does this fit documentation of tax risk management
in with the risk management policy for the policies and controls is not something we
group as a whole? How does this fit in have seen in many organisations. Best
with the group’s overall tax strategy? practice would suggest that whatever the
tax function (or others) produces in this
Historically, we have found that, when area should be acknowledged and
asked, boards may have perceived that embraced by the board.
the tax function was one where there was
‘low risk’. In fact, the board may have In some countries revenue authorities
perceived (and expected) the company to have also been driving thinking in this
be taking a more aggressive approach to area. In Australia for example, the
tax risk management than the tax function Commissioner of Taxation has written
was actually adopting. The process of to public company boards stating, “It is
discussing a tax strategy with the board important that the board identify the
is, in our recent experience, changing and taxation risks associated with their
adding direction to and support for what organisation’s operations, which risks are
the tax function is expected to do. acceptable and appropriate, and which
Whatever the view of the board, getting are not, and put in place a process for
the tax strategy in front of them is good the management of those risks.”
for the profile of the tax function.
The view expressed was that in respect
Perhaps the two key tax risks the board of major transactions and arrangements
should focus on are portfolio risk and it was not sufficient for boards to rely
reputational risk. The board should have a simply on tax functions and external
general understanding of the organisations advice but should focus beyond tax
‘risk profile’. The portfolio risk addresses outcomes to questions of probability,
this ‘profile’ for tax. Of equal or possibly level of aggressiveness, likely tax office
of greater importance is a view on response and the implications of
reputational risk. It is important that the alternative outcomes.
board understands the impact on
reputation that the organisation’s tax
positions (or lack thereof) may have within
the business community or the community
at large. A consistent position, along with
board support for the resources needed
to manage reputational risk, are key to
successfully addressing this area.

A documented tax risk policy that is


embraced by the board is also crucial for
good corporate governance. The board
not only sets the tax risk/reward
philosophy of the business, it also sets
the tax risk management framework and
the whole ethos as to how risk is
assessed, how management controls
operate within the business and how
they are monitored.

12 Tax Risk Management


This of course raises a whole series of The points discussed above concerning
issues and questions to be addressed. the board’s involvement in tax risk
In this context the Australian These range from whether these are the management obviously apply to the CEO
Commissioner posed 10 right questions and whether this is in fact and CFO as members of the board.
questions boards should be the right level to be asking these questions. However their interest in tax risk
(Should it be the audit committee, CEO, management will go further. The CEO and
asking in this area:
CFO or the tax director?) Issues range CFO, having had high level input into the
1. What level of confidence do you have from the capacity of the board to make strategy design, should be using it as a
in the correctness of your advice? appropriate judgements to content and framework for participating in significant
tax office access to board papers. In our tax related decisions both on the
2. How likely is it that the tax office will
view many of the matters raised in these transactional side and possibly also on
take a different view of the application
questions can be dealt with by appropriate the operational side.
of the law and assess the company
policies that the board has signed off on,
accordingly?
and controls to ensure those policies are They clearly have an interest in the
3. If the Australian Tax Office takes a adhered to. figures in the accounts and hence in
different view and the matter proceeds financial accounting risk. They may
to litigation, what is the risk of the Just how far the board should go is an even be personally at risk if major
Federal Court or the High Court deciding open question, the discussion on which restatements or prior year adjustments
the matter in favour of the tax office? has only just begun. We would say that, in arise in the accounts.
this new world of greater governance and
4. What is the potential downside if the responsibility of boards, greater
company is unsuccessful in litigation They are also responsible for monitoring
involvement than we currently have seen how tax risk is being managed and how
with the tax office? does seem appropriate. In this regard, the tax department is performing (tax
5. If there is a dispute, what is the likelihood involvement in ensuring there is an
management risk). We come back to the
of the tax office being prepared to settle appropriate risk management framework
point that in today’s environment it is
the dispute and, if so, on what terms? and policy in place, that it fits in with the
important that the leadership view of the
organisation’s overall attitude to risk
6. How likely is it that the tax office will tax function’s risk profile is consistent with
identify the tax issues that arise from management and that a process for
practice. Where there is a disconnect
the proposed course of action? Allied ensuring that this is functioning as
there can be surprises for the CEO and
with that, to what extent will embarking intended, would be an important place
CFO from adjustments to the accounts or
on the proposed course of action to start.
missed tax savings, and frustrations on
increase the tax risk profile of the
company and increase the possibility the part of the tax function when
of audit scrutiny? information provided or resources
The CEO and CFO
allocated are not sufficient to achieve the
7. In light of the potential risk, would it Historically it has been the CFO who risk management targets established.
be desirable to approach the tax represents tax at board level and to whom
office for guidance in the form of a
most heads of tax report. However we are
private binding ruling
seeing pressure in some countries for Tax risk Tax risks
8. Where a position has been taken on a CEOs to become more actively engaged identified and high on
tax issue, would it be desirable, in the in the tax area – whether because of the communicated management
interests of appropriately managing any need to sign off on accounts or from agenda
risk, to be up front with the tax office in Virtuous
external pressures (e.g. the above debate circle
identifying the issues before or when
lodging the tax return and endeavouring being initiated at CEO level by the
to constructively handle any Australian Tax Office). We have therefore
disagreements which may ensue? combined these two positions in terms
of stakeholder consideration – whilst
9. Is the advice based on the actual Appropriate
recognising that more of the responsibility tax resource
transaction or on an expectation of
how the transaction will be
for tax risk management will likely fall on
implemented? the shoulders of the CFO than the CEO.

10. Are you satisfied that the factual basis


for your opinion to the board has been
properly checked?

Tax Risk Management 13


The head of tax and his/her team management risk – ensuring that the right business planning team may well be
people are in place to manage tax, dealing with forecasting, both of tax
Obviously the tax function is responsible ensuring these people have the right charges in the accounts and cash going
for managing the majority of tax outcomes, skills, and ensuring that the appropriate out of the business.
and the actions and activities that create processes and procedures are in place.
tax risk. It is also the first point of contact
The finance department will nearly always
in tax risk management. What therefore are
But however good the tax risk play a key role because it is impacted by
the head of tax’s objectives in relation to
management policy of an organisation is tax in many ways. Its own responsibilities
tax risk management? Do they buy in to
and however much leadership and can vary from managing expectations
the concept that tax risk can be managed?
discussion there is at board level, the around the effective tax rate through
How do their objectives on risk
head of tax and his/her team will deliver processing the results of operational
management fit in with those set out by
what they are being measured on. This activities to full responsibility for tax in
the chief risk officer? What framework is
begs the question as to what are they foreign jurisdictions. The finance
used to measure risk and does the tax
measured on – and what are the department is nearly always involved in the
function participate in developing the
consequences for them personally if, implementation of significant transactions
scores? Is the head of tax trying to make a
having taken a risk, revenue authorities and will also often be involved in producing
name for themselves by taking risk – or do
take different positions or impose detailed information for the tax returns –
they come from the ‘no surprises’ school
arbitrary adjustments. how much detail does it need to go into,
where tax risk management is about
what level of materiality is appropriate for
avoiding potentially contentious or
We would encourage those setting different tax returns? In all these areas it
aggressive positions? How secure do they
objectives for tax functions to build tax will need to understand the full range of
feel in their jobs? Will they now be signing
risk management into such objectives – the tax risk profile of the business.
off, to the CEO or CFO, that the tax figures
and to identify acceptable levels of risk
in the accounts are acceptable – and if the
(whatever that might be for that To do their job properly internal auditors
group is SEC listed, also on the internal
organisation) in order to add value to the will need to understand the group’s
controls over tax?
business. Once risks have been taken, tax position on tax risk. This is applicable to
functions will need support if things go any role they may have in monitoring
Whilst the board will agree the strategy, in
wrong – and praise when things go well. controls or in reviewing the tax function.
practice it is the head of tax who will set
We will look at how tax risk management Historically we believe that internal
the whole tone on tax risk management
can be monitored in a later chapter. auditors may have found reviewing the tax
for the rest of the organisation – whether
function as one of those items that goes in
it is the tax team doing the tax returns or
Business units and functional areas the ‘too specialised’ basket. Perhaps this
the advice and support provided to
will have to change. Indeed where internal
operational and other teams doing their The interest in the management of tax
audit functions undertake broader reviews
jobs. It is therefore vitally important that risks by the other business units and
of the tax function, which we have seen
the head of tax, CEO and CFO, and the functional areas of the organisation will
in a small number of cases, they can
board are in agreement on the group’s tax vary based on the broader management
help raise the profile of the tax function
risk management policy. and risk profile of the organisation.
by highlighting where the tax function is
For example, the level of interest by
adding value to the business.
The one area where we see some gaps is management of a business unit will be
with MNC’s foreign subsidiaries. In many closely aligned with whether the unit is
Moving away from the functional areas of
cases tax is the responsibility of the local measured on a pre-tax or after-tax basis.
a business to the operational people we
CFO in the foreign subsidiary with indirect The business unit’s accountability for
come to people who are responsible for
line responsibility to the head of tax. In information provided to the tax function (or
making decisions with potentially
these circumstances there is a real risk that responsibility for transaction taxes within
significant tax implications. This is the
tax risk management is falling between the the unit) will also drive the level of interest.
operational tax risk area, and the question
cracks and it is important that clear In a similar manner the legal department
arises as to whether operational people
responsibilities are established. This point will need to understand where the
understand what risks they are taking,
is explored in more detail in a later chapter. business sits on transactional risk. The
when they need to consult, when they can
treasury department will want to know
act without consulting – and what
The head of tax will, or should, be what tax is payable – and what tax might
happens when something goes wrong? In
involved in all areas of tax risk be payable if some of the risks taken do
businesses that are measured on a profit
management. However they will usually actually crystallise. This may include both
before tax basis, operational people will
have prime responsibility for the transactional risk and compliance risk. The

14 Tax Risk Management


often be more focused on sales taxes auditors will require more time and effort External advisors, who may or may not be
and payroll taxes and will often ignore to understand where the risks lie and your auditors, need to understand your
corporate income taxes. This in itself is the implications for them in reaching appetite for tax risk. This will help them to
a risk – tax management risk. their opinion on the financial statements deliver more appropriate advice and filter
– with corresponding additional costs out unsuitable ideas they might be thinking
This brief list skims the surface of the for the group concerned. of bringing to you. They will also need to
understand the accounting implications of
many potential interactions between tax
This leads on to the point as to the board’s what they are advising on – this is perhaps
and the different areas of your
and the audit committee’s view of using more of an issue for lawyers than
organisation – which other functional their audit firm for tax work. Different accountants, but still a point to be
areas are making decisions that have a businesses have taken different views here. considered if the advisor is not the auditor.
tax impact and hence carry tax risk? If Our view is that the audit firm is generally
these people are to take responsibility for the best placed provider of both tax The understanding of the corporate
the tax impact of their actions they need planning and tax compliance services. appetite for risk is particularly important
to understand both where the risk areas There is a strong linkage between a for tax advisors in foreign jurisdictions
are and how they are expected to manage company’s accounts and its tax affairs that where tax in these jurisdictions is often the
their tax risks. You need to be able to has led to the audit firm generally also responsibility of the finance functions. In
answer the question below. providing tax services to its audit clients. these circumstances local risks and issues
The audit firm will have a deep need to be understood and tax risk
understanding of the company’s business policies adapted to local circumstances.
Who are the tax risk and therefore generally be best placed to
provide related tax services. Additionally,
In some cases policies that do not have to
be enunciated at home may need to be
management internal the tax charge will generally be a material
component of the company’s profit and loss
overseas, to ensure that different cultural
circumstances and local practices do not
stakeholders in your account and therefore needs to be carefully
considered by the auditor. This process is
inadvertently breach corporate policy.

business? made easier where the audit firm provides


tax services on an ongoing basis; with its
deep involvement with the company this
External auditors and other external leads to a better quality audit. It therefore
advisors follows that we believe that the company’s
management of its tax risk is improved by
Let us now consider the stakeholders the involvement of its auditors in the
outside your organisation. The external provision of tax services as opposed to the
auditors clearly have an interest in a provision of such services by others.
group’s tax risk policy. They need to
understand both the policy and where In addition to issuing an opinion on the
risks are being taken so they can plan financial statements, there are specific
their audit of the financial accounts. We requirements for auditor attestation of
would suggest the auditors have an internal control procedures over financial
interest in all seven of the areas of tax risk. reporting for SEC registered clients (as
required by Section 404 of Sarbanes-Oxley
One of the effects of the current Act of 2002). As with the necessity to
corporate governance concerns is that consider the impact of the tax accounts on
some groups are not using the tax the financial statements, the internal controls
departments of their auditors as much applicable to the tax accounts will need to
as they used to for tax planning advice. be considered in the attestation on a
Where the auditors are not the tax company’s internal controls over financial
advisors to the company, they will have reporting. These requirements will first apply,
less familiarity with the client’s tax broadly, for accounting periods ending on or
affairs. This is likely to be particularly after 15 November 2004 for US registrants
significant where the group has, for and 15 July 2005 for non-US registrants.
example, made large acquisitions or The Public Company Accounting Oversight
disposals, undertaken new financing Board (PCAOB) rules, which govern the
arrangements, implemented a group audits of internal controls over financial
reorganisation, or implemented tax reporting, will also have a significant impact
mitigation strategies. As a result the on both auditors and registrants.

Tax Risk Management 15


Revenue and other regulatory authorities Additionally a number of revenue Investors and analysts
Tax authorities are taking an increasingly authorities are keen to discuss a group’s
One of the prime sources of information
sophisticated approach to tax risk risk assessment with that organisation
for investors and analysts is the accounts
management. If they can be clear where and discuss with them which areas will
and other quarterly/half yearly
the tax risks are in any organisation they come under particular scrutiny this year or
statements. The element of uncertainty
will know where to focus their resources. next. The US authorities have moved to a
in the financial accounts is therefore of
very specific series of regulations requiring
interest to them – and as such they are
The Australian Tax Office has, for example, specific identification and disclosure of
interested in financial accounting tax risk.
published a list of seven criteria they use transactions that they (the authorities) view
To the extent that the tax charge tends
when assessing an organisation’s tax risk as giving an indication of aggressive or
to fluctuate they will wish to understand
profile and listed the six key areas they are inappropriate tax positions. The UK Inland
why this is so and how it might fluctuate
going to focus on. The seven criteria for Revenue instigated a specific initiative
in the future. Portfolio tax risk may also
risk assessment are: entitled ‘Spend to Save’ that particularly
be of interest to them – is there a high
focused on where their resources should
portfolio of tax risk that could cause
• Business and transactions best be concentrated to achieve maximum
significant fluctuations in the tax figures
revenue raising benefit. They have now
• Globalisation or is there a small portfolio of risk and a
announced a crackdown on tax avoidance
• Attitude steady tax charge is to be expected?
by introducing a package of measures
• Systems of compliance targeted at perceived loopholes, in addition
There seems to be an increasing focus
• Perceptions of stakeholders to specific anti-avoidance legislation.
on cash tax as opposed to the
• Materiality accounting tax charge – the comments
The issue here is not to be unduly
above are equally relevant to cash tax as
• Application of the law influenced by either aggressive or dormant
they are to the accounting charge. Finally
revenue activity but rather to build the
reputational tax risk is something
For each category they rate the business, revenue authorities’ approach and
investors will be interested in – what is
and from this they can build up a picture information requirements into your risk
the effect on the share price if, for
of the organisation they are looking at. assessment, strategy and policies. We are
example, a major revenue investigation
With this analysis they are focusing on the aware of some businesses that have
becomes public knowledge?
following questions to decide how shared their tax strategy with tax
detailed a review they need to do. authorities in order to help demonstrate
‘lower risks’ than may have otherwise have
• Whether the group’s financial or tax been perceived; however this is not a
performance varies substantially from common approach.
industry norms?
• Are there significant variations in the As well as revenue authorities there are a
amounts or patterns of tax payments? number of other regulatory authorities in
• Are there unexplained variations different industries (e.g. financial services)
between economic performance, and countries (e.g. in the US, the SEC)
productivity and tax performance? that will be interested in the tax risk profile
of a business. We have not attempted to
• Are there unexplained losses, low list these out – but are you aware of which
effective tax rates, and cases where other authorities are looking at your
part or all of the group consistently figures and possibly also your risk
pays low tax?
management systems?
• Is there a history of aggressive tax
planning?
• Are there weaknesses in the group’s
structure, processes and approaches
to tax compliance?

16 Tax Risk Management


Documentation and communication
A theme that has been running through Summary
the above discussion is the width of
impact that taxes and tax risk We have attempted to summarise
management has in the organisation and which tax risks will be important to
therefore the importance of documenting the various different stakeholders in
policies and disseminating them through tax risk management. The summary
an appropriate communication strategy. below will not be right for all
Word of mouth and informal businesses; however a discussion
communications are unlikely to be around the grid below will help
appropriate for such a wide range of people focus on who should be
different stakeholders. We will explore this considering and is responsible for
in more detail in later chapters. the various areas of tax risk.

Types of tax risk

Financial
Transactional Operational Compliance Portfolio Management Reputational
accounting
Stakeholders

Board ✔ ✔ ✔

CEO/CFO ✔ ? ✔ ✔ ✔ ✔

Tax function ✔ ✔ ✔ ✔ ✔ ✔ ✔

Legal & treasury ✔ ✔

Business units ✔ ?

Auditors &
tax advisors ✔ ✔ ✔ ✔ ✔ ✔ ✔

Revenue & other


regulatory bodies ✔ ✔ ✔ ✔

Investors & analysts ✔ ✔ ✔

Tax Risk Management 17


4 WHERE DOES MANAGING TAX RISK FIT INTO THE
OVERALL TAX STRATEGY?
Tax risk cannot be looked at in isolation. Tax risk management
needs to be part of a business’ overall risk management policy
as well as being part of an overall tax strategy. It is not the
purpose of this guide to stray outside of the tax arena and we
will therefore leave others to consider how their tax risk policy
and management fit in with what the business is doing by way
of risk management in other, non tax, areas.

However we can consider how tax risk There is clearly a trade off between these prepared to spend time fighting a case
management fits within an overall tax three. One cannot have a very aggressive in the senior law courts. As noted above
strategy. Indeed it is the overall tax approach to managing the tax charge we believe that, broadly, the three
strategy that should drive the approach to without incurring some (legitimate) tax risk scales are correlated.
tax risk management – and not the other and some extra costs. In our earlier guide
way around. ‘The ‘Best Practice’ Tax Function’ we
introduced the Tax Strategy Template to
It is our view that there are only three stimulate debate in this area.
basic areas of tax that can be managed
and controlled. These are: For each of the three areas there is a
scale, which runs from nought to ten.
• The tax charge (some groups may
Nought represents a very reactive
segregate the total charge and current approach to tax management, probably
cash taxes) little more than completing and
• Tax risk submitting tax returns. Ten represents
• The cost of running and managing the a very proactive (aggressive?) approach,
tax affairs of the group where the head of tax would be

<Reactive Proactive>
Tax charge Not Minimum legally
managed achievable
0 1 2 3 4 5 6 7 8 9 10

Tax risk Basic Aggressive


tax planning schemes
0 1 2 3 4 5 6 7 8 9 10

Unaware Maximum awareness


of issues of issues

Tax management Minimum Cost not the


costs main issue
0 1 2 3 4 5 6 7 8 9 10

Completed Next to be
by date reviewed

18 Tax Risk Management


To get an overall view of someone’s This is an overview tool. It’s not meant to
approach to their tax strategy, and be a ‘scientifically perfect’ model of a tax
because of the correlation noted above, function’s strategy. It’s a tool that helps
we ask people to draw a vertical line clarify opinions as to overall approach
down the template giving a single and start discussions that draws out
overall ‘score’ between nought and ten. some of the underlying issues.
The more conservative and reactive
groups would have a lower score than The overall score above should bear
those who manage their tax more some correlation to the summary score
aggressively and proactively – and are arrived at in the last section of the
prepared to take greater tax risks. second chapter of this guide. (This was
the scale that summarised your
Tax charge
<Reactive
Not
Proactive>
Minimum legally
organisation’s overall attitude to tax risk
managed
0 1 2 3 4 5 6 7 8
achievable
9 10
management.) If the two scores are not
close together one of them needs
Tax risk Basic Aggressive
tax planning schemes revisiting. As both scales are part of
0 1 2 3 4 5 6 7 8 9 10

Unaware Maximum awareness


your overall group tax strategy, in terms
of issues of issues
of best practice, both should be agreed
Tax management Minimum Cost not the
costs
0 1 2 3 4 5 6 7 8
main issue
9 10
with the board and getting the two
Completed Next to be
scores the same should be achievable.
by date reviewed

Tax Risk Management 19


5 THE RISK MANAGEMENT CONTROL FRAMEWORK FOR TAX

The early chapters of this guide have focused on what is tax risk
and who should be interested in it. We have looked, at a high
level, at how a tax risk policy fits into the overall strategy of a
business. It is time to look in a bit more detail as to how tax risk
can actually be managed and what processes might be put in
place to achieve this – and introduce an internal control
framework for tax risk management. This chapter focuses on
designing a systematic approach to tax risk management, and
the following chapter then looks at how to make the systematic
approach work in practice.

INTERNAL CONTROL The COSO Internal Control • Effectiveness and efficiency of


Integrated Framework operations;
INTEGRATED
FRAMEWORK • Reliability of financial reporting; and
In the early 1990s the Committee of • Compliance with applicable laws and
Sponsoring Organisations of the regulations.”
Treadway Commission (COSO), set up
in the US, called for a study to develop The commentary around the COSO
COMMITTEE OF a framework for internal control and in Framework explains that whilst internal
SPONSORING 1992 the Internal Control – Integrated control is a process that will change and
ORGANISATIONS OF Framework was published. Today the develop over time, the effectiveness of
THE TREADWAY most widely recognised international an organisation’s internal control is a
COMMISSION standard for an integrated framework of statement of the condition of that
internal control is the COSO Framework. process at one or more points in time.
We have sought in this chapter firstly The purpose of internal control is to help
to explain how the COSO Framework an organisation achieve its performance
operates and more importantly how it and profitability objectives, and
might be used to manage tax risk. safeguard assets. It can also help to
ensure reliable financial reporting,
What is internal control? compliance with laws and regulations
and therefore avoid damage to its
The COSO Framework defines internal reputation and other consequences.
control as: As the COSO Framework is the leading
model for internal control, and is being
“A process, effected by an entity’s board used on a global basis, it seems an
of directors, management and other appropriate model to consider for tax risk
personnel, designed to provide reasonable management.
assurance regarding the achievement of
objectives in the following categories:

20 Tax Risk Management


Components of internal control Control activities
Control activities are the policies and
The current COSO Framework sets out procedures that are designed and
five interrelated components in an operate in order to manage and address
integrated system of internal control that the risks to the achievement of an
applies to organisations of all types and organisation’s objectives. These control
sizes – and hence should equally apply activities need to be effective in their
to tax risk management. The five operation in order to manage and mitigate
components are: the risks consistent with the overall
objectives of the organisation.
• Control environment
• Risk assessment Information and communication
• Control activities Information and communication systems
are required to support the other four
• Information and communication components in order to ensure the
• Monitoring people in an organisation understand,
capture, exchange and record the
Let us look at these in a generic sense information needed to manage and
before going on to look at them specifically control risk in an organisation.
in terms of tax risk management. Information and communication is also
needed to assess how the organisation
Control environment is performing and whether its goals and
The control environment is the overall objectives are being achieved.
tone of an organisation – the culture and
atmosphere of the organisation in which Monitoring
people conduct their activities and carry The entire process, but particularly
out their responsibilities, and the controls and processes, must be
seriousness with which risk and monitored to assess their effectiveness
compliance with controls and processes and to identify where modifications or
is taken. The control environment is remedial actions are necessary. Monitoring
based on the individual attributes and allows early identification of deficiencies
attitudes of the senior management of so that the internal control system can be
the organisation – and will reflect their responsive to changing conditions both
within and from outside the organisation.
integrity, ethical values, competence and
authority. The control environment is a
Each of these components can and will
foundation for all the other components
impact and influence each of the other
of internal control and is the nature of the components. The extent to which an
platform on which the whole organisation organisation implements these components
is built. If risk management is not will vary from business to business and will
important in an organisation and people be influenced by many different factors.
do not take processes and controls However, these five components should be
seriously then introducing specific risk identifiable in any integrated system of
policies, procedures and controls in an internal control for tax risk management
area like tax, may have little chance of and should be embedded throughout the
being effective. organisation in order to be effective.

Risk assessment There is a direct relationship between


these five components and the three
This is the awareness and response of an
categories of objective set out earlier in
organisation to the risks that it faces.
the definition of internal control. The five
Processes and procedures will need to be components are what an organisation
established to identify, evaluate and needs to have in place and be operating
manage those risks. Risk objectives must effectively, in order to achieve each of the
be set that are integrated with the rest of three objectives throughout all activities
the organisation. and business units in the organisation.

Tax Risk Management 21


The COSO Framework can therefore be component in the internal control
represented generically as follows: framework into three separate
components – event identification, risk
assessment and risk response.

g
tin

e
ns

or

nc
tio

ep
In addition, the proposed new Enterprise

ia
ra

pl
lr
Risk Management Framework separately

ia

om
pe

nc
O

C
distinguishes objective setting as a

na

Activity 2
Fi
component separate from the control

Activity 1
Monitoring environment. The underlying philosophy
itself – that senior management has a

Unit B
Information &
process in place to both set and align
communication

Unit A
objectives within the organisation’s overall
Control activities strategy consistent with their risk appetite
- is not something new. This would
Risk assessment previously have been considered to be
included in the control environment
Control environment component in the earlier model.

We have based this chapter on the


established internal control framework
because the new Enterprise Risk
COSO Enterprise Risk Management Framework is still in draft
Management Framework and may change as it goes through its
public consultation process. That said it
During the summer of 2003 COSO issued could be a very useful source of further
an exposure draft for public comment information for readers wanting a more
entitled ‘Enterprise Risk Management detailed analysis of risk management.
Framework’. This framework broadly What this all reinforces is that this is an
follows the framework outlined above for area which is changing rapidly and
internal controls, with the main difference receiving plenty of public attention.
being to expand the risk assessment

So how does the COSO Framework apply to tax risk management?

Let us now move on to consider how tax risk management can be considered in terms
of the COSO Framework. We should firstly consider the three internal control objectives
set out above and what they mean in the context of taxes and tax risk management.
The effectiveness and efficiency of the
organisation’s management of taxes. This would
Effectiveness and include the financial and operational objectives
efficiency of operations over taxes throughout the organisation.

Relates to the preparation of reliable financial


information on taxes for inclusion in financial
Reliability of financial reporting statements and selected financial data derived
from such statements, such as earnings
releases, reported publicly.

Relates to complying with those tax laws and


Compliance with laws regulations (and other related laws and
and regulations regulations such as accounting standards
relating to taxes) to which the entity is subject.

22 Tax Risk Management


An organisation’s objectives for the specific tax risk areas set out in Chapter 2
(Transactional, Operational, Compliance and Financial Accounting risks), broadly
speaking, each correlate with one of the three objectives in the general
COSO Framework:

Effectiveness and efficiency of operations Transactional and operational risk


Reliability of financial reporting Financial accounting risk
Compliance with laws and regulations Compliance risk

For tax purposes we are therefore We accept that there is no right answer; it included business units. We accept
proposing that we replace the three broad the whole of tax risk management is an this is also a debatable point. In
objective categories of internal control area where the thinking is still developing. organisations where the internal
across the top of the COSO cube, with However the conclusion we reached in structure is very centrally oriented, the
our four different types of specific tax risk. Chapter 2 is that the three generic risks consideration of the tax risk objectives
should be treated as tax risks in their own and the internal control components for
right. Notwithstanding that the each of objective needs to be
g
ks

organisation’s objectives in the generic considered for each separate tax within
tin
ks
ks
is

ks un
ris
is
lr

Corporate income taxes

risk areas will, to varying degrees, impact the organisation (as shown in the
lr

ris co
na

e
na

nc

c
io

on all three of the framework objectives diagram above).


la
tio

ia
ct

ia
pl
ra
sa

set out above, we believe it is appropriate


nc
om
pe
an

na
O

C
Tr

also to add the objectives for the three


Fi

Sales taxes

generic risks to the top of the cube giving


Excise duties

Monitoring
us a tax risk management equivalent of
Withholding taxes
Payroll taxes

Information & the COSO model that looks like this:


communication
Objectives
Control activities
pl al sks

ag ri isks

ks
na s
M rtfo nting s
ce ks

tio isk
Po co risk

is

Risk assessment
r

Re em sks
ris
om on ri

Corporate income taxes


lr
ta t r
C ati al

pu en
n

u
pe ctio

an lio
nc an

c
i
la
a

Control environment
ia
r
a ns

na
O
Tr

Fi

Sales taxes
Excise duties

Monitoring
Withholding taxes
Payroll taxes

However where does this leave us in Information &


respect of the three generic tax risk areas communication
Components

(portfolio, management and reputational


Control activities
risks)? We raised in Chapter 2 the
question as to whether these three
Risk assessment
generic tax risk areas are tax risks or
whether they are really ways of managing Control environment
the specific types of tax risk. These
Depth of
generic tax risks are, by their nature,
Organisation
wider than any one of the individual
objectives of the generic integrated
internal control framework – the purists (The various tools in Chapter 6 and the
will therefore argue that they should not appendices are based on the COSO cube
be included in the COSO framework having all seven tax risks across the top;
when applying it directly to taxes. if you believe that there should only be
(Whether the top of the COSO cube the four specific risks then the tools will
should have four or seven risks is need adapting accordingly.)
perhaps the area that has caused the
most debate when writing and producing You will note that on the right hand side
this guide.) of the cube we have put the different
taxes – whereas in the main COSO cube

Tax Risk Management 23


However where an organisation is more devolved and tax operates along geographical,
divisional or business unit or other lines (and where these sectors have responsibility
for all the different taxes within that sector, division, etc.) it would probably be more
appropriate to consider the internal control processes at the different locations,
divisions or operating units level rather than through the different taxes as shown
above. In fact, the current PCAOB pronouncements on auditing internal controls over
financial reporting suggest that each of the taxes should be considered in each of the
significant business units (at least for financial reporting).

In a best practice model, the five internal control components should be in place for
each of the different types of risk objectives and each of these should apply across the
whole organisation (in whichever way the organisation operates). An alternative model,
on a geographic basis, would be:

Objectives

Re em sks s
ag ri risk

ks
na s
M rtfo untin s
cia c ks
Fin pl al s

tio isk
Po acc risk

is
om on sk

an lio g
an ian ris

lr
ta t r
C rati l ri

pu en
a

o
pe n
O itio

l
s
an

Australia
Tr

Brazil

Monitoring
United Kingdom
India
United States

Information &
communication
Components

Control activities

Risk assessment

Control environment
Depth of
organisation

We now have an integrated model for managing tax risk management which picks up
each of the COSO components, each of the seven different tax risk areas and covers
the whole business – whether it be by type of tax or the different business units. We
now need to look in a bit more detail at what each of the COSO components means
in terms of tax risk management.

What does each COSO component mean in terms of tax risk


management?
Below we have summarised, from a tax risk management perspective, what each of the
five internal controls components might try and address. We then set out a series of
questions that you might ask of yourself under each of the five headings. The answers
to the questions will enable you to start judging whether your tax risk management
procedures are acceptable and fit within the COSO Framework – which as noted earlier
is recognised globally as the best practice for internal control procedures.

24 Tax Risk Management


1 Control environment

Control This is the attitude and culture of the board and senior management towards tax risk
environment and their overall strategy and objectives for tax risk. This will include their commitment
to tax risk management, the degree to which tax risk policies are set and communicated
and the level of accountability for achieving and monitoring the performance of those
policies. This also includes consideration of the compensation ‘driver’ for the tax
function and their overall position within the organisation.

The types of questions that need considering under this heading are:

• What influence does tax risk have when the organisation’s overall strategy and
objectives are being established?
- Is tax risk considered side-by-side with other business risks in evaluating proposals
and making decisions about achieving the organisation’s goals?

• What is the organisation’s tax risk appetite/tolerance - where on the tax risk spectrum
is it and where does it want to be?
- What is the organisation’s approach, management style and attitude to tax risk –
what is its risk culture?

• How does the board of directors manage tax risk?


- Is there a written and agreed tax risk policy and methodology?
- How are the board’s strategy and objectives with regard to tax risk and tax risk
management delegated, communicated and embedded with the people throughout
the organisation?
- Is the board’s policy understood throughout the organisation?
- How do senior management ensure their policies and objectives are met – how do
they assess to whom responsibility is delegated and that responsibility is passed to
sufficiently competent and experienced personnel?

• How do senior management assess whether the organisation is in compliance with


their strategy and objectives on tax risk management?
- Is information on tax risk management and measurement of achievement against
objectives gathered and regularly reviewed by senior management?
- How do senior management respond to new tax risks and weaknesses or
deficiencies over tax risk management?
- Do senior management demonstrate their commitment to their tax risk management
philosophy and strategy in their everyday activities?

• How do the compensation policies and organisation structure of the tax department
support or conflict with the fundamental goals of the organisation?

Tax Risk Management 25


2 Risk assessment
This is the awareness and response of the organisation to the different types of tax risk
Risk facing the organisation (as set out in Chapter 2). This will include the organisation’s
assessment processes and procedures for identifying and evaluating the tax risks and how those
risks are managed and mitigated consistent with the overall objectives of the
organisation on tax risk.

The types of questions that need considering under the risk assessment heading are:

• How are tax risks identified, evaluated, and recorded?


- How are the consequences of external factors such as economic, environmental,
political, technological and social factors considered within the assessment and
evaluation of tax risk?
- What policies and procedures are there in place to ensure tax
risks/issues/exposures are identified?
- What risk assessment techniques are used and do they consider past and future
events?
- Who assesses the risk, what tax skills are brought to bear to ensure risks are
properly assessed and is there an escalation process for predetermined large
amounts?
- How is information obtained/gathered on operations and other internal activities to
ensure tax risks are identified?
- Although certain tax risks may be risks to one organisation there can be instances
where those risks fall on a different organisation in certain circumstances. Are such
secondary risks included in the risk assessment?

• How is the effectiveness of judgements assessed?


- How are the likelihood of events and the impact of events estimated/modelled?
- o Is scenario planning used?
- Are appropriate individuals with relevant experience and seniority involved?

• Are risks aggregated to enable a portfolio view to be considered?

• How are responses to identified risks designed and implemented?


- How are the risk avoidance/risk reduction responses to mitigating tax risks
assessed and evaluated – how is residual risk quantified?

• How is the tax risk assessment documented?

26 Tax Risk Management


3 Control activities
These are the detailed procedures and processes that have been designed and
Control established to manage the tax risks identified in the risk assessment. The design and
activities operation of control activities should ensure that the tax risks are managed in order to
achieve the organisation’s tax risk objectives. The detailed control activities can take
many forms but will include the detailed policies, reviews, approvals, and use of
external tax opinions that are used to mange the tax risks.

The types of questions that need considering under the control activities heading are:

• What are the control activities policies of the organisation?


- How are these policies communicated throughout and embedded in the
organisation?
- Are both preventative and detective control activities used?
- How might control activities be circumvented?
- Are there appropriate levels of review?
- When are external opinions sought?
- What controls and processes are in place to ensure tax planning, transactional
issues and tax change generally is properly implemented?
- Who is responsible for the control activities?
- If the group is SEC listed, has consideration been given as to their adequacy
against the requirements of Section 404 of the Sarbanes-Oxley Act?

• Where are the detailed control activity procedures recorded?


- What general controls (controls over information technology and information
systems) are used to mitigate risks to information technology and changes to
electronic systems?
- What application controls (controls over the completeness, accuracy, authorisation
and validity of data and transaction processing) are used?
- How is the actual operation of control activities documented/demonstrated?

• Are the activities identified for each type of tax that would address controls to assure:
- Timely identification of changes in tax laws, regulations and decisions?
- Timeliness and accuracy of the data to which tax law applies?
- Accurate application of the tax laws to the data?
- Timely and accurate reporting and payment of taxes?

Tax Risk Management 27


4 Information and communication
This is the information and communication necessary to ensure the organisation’s
Information & objectives in respect of tax risk are documented and communicated to the relevant
communication people. It will include the operating policies and procedures within the organisation that
are necessary to ensure all tax risks are identified and quantified and that the controls
designed to manage those risks are documented. It will also cover the findings of the
monitoring process so that the effectiveness of the controls over tax risk can be
assessed, allowing appropriate development of controls and remedial action where
new risks are identified or existing controls are not operating effectively.

The types of questions that need considering under information and communication are:

• How is pertinent information on tax policies, tax risk and tax control activities,
identified, captured and communicated to relevant personnel?
- Is there clear information about roles and responsibilities for provision of information
on tax risk management and the operation of controls over tax risks?
- What procedures/processes are there to ensure information is provided on a
timely basis?
- What procedures are there to communicate information requirements and provide
feedback on information sources?
- What procedures are there to ensure that when people change there is
communication and a proper handover?

• How does relevant information flow up and down the organisation from board level
down to relevant individuals in the organisation and vice-versa?

• How does relevant information pass around the business – so that the tax function
is aware of what is happening in the rest of the organisation and so the rest of the
organisation can access relevant tax information?

• How is data/information managed, controlled, aggregated and refined without


losing relevance?
- How is information stored, protected and accessed?
- What back-up/retrieval procedures are there for valuable/critical information?

• What information is gathered from external/independent sources and how is it used


to support tax risk assessment and development of internal controls over taxes?

28 Tax Risk Management


5 Monitoring tax risk
These are the procedures put in place to review the effectiveness of the operating of
the internal controls over tax risks, and to enable conclusions on the effectiveness of
Monitoring
the controls over taxes to be reached. Monitoring will identify where controls are not
operating effectively and where the organisations objectives are not being met. This
allows remedial action to be taken where controls are not operating effectively and
may identify where new risks are not being properly managed

The questions which need considering under this heading are:


• How is the effectiveness of the operation of internal controls over tax risks assessed?
- How is tax risk assessment monitored on an ongoing basis?
- What review/testing procedures are there in place that can be used as a basis for
reaching conclusions as to the effectiveness of the risk assessment process and the
design of controls to mitigate identified risks?
- How are conclusions reached?

• Who receives the results of the monitoring process and what action do they take
with them?
- What remedial actions are taken if internal control procedures are found not to be
operating effectively?
- How do the findings of the monitoring process impact the control environment, risk
assessment, and control activity functions?

• Is there any independent review of the monitoring process?

• How is the monitoring process documented?

It should now be apparent how closely the various components of an integrated system of
internal control are interrelated. Designing and operating a tax risk management internal
control system is an iterative process and not a linear task. Continual evaluation and
development of each of the components is necessary to maintain a responsive up-to-date
internal control system, which can deal with the uncertainties in a continually changing world.

Summary
Many features of the components of an integrated system of internal control over taxes are
likely to have been considered, at some point in time, in the vast majority of organisations.
However, it is our experience that this tends to have taken place in a somewhat unstructured,
ad-hoc and haphazard way. It is a relatively rare occurrence to find a systematic, well planned
approach to designing and documenting internal control systems over a business’ tax affairs.
Addressing tax risk has not been high on the agenda of most tax departments. Whilst most
organisations can probably cite controls that they have in place such controls tend to be
informal, somewhat lacking in design and unlikely to be documented in any level of detail.
In the current risk environment, including the Sarbanes-Oxley Act with its requirements for
senior management to attest on the adequacy of design and the operational effectiveness of
their internal controls over financial reporting, many organisations face a significant challenge
to move to a best practice compliant regime. Documenting and monitoring internal controls
over financial reporting of taxes, within a regime of standardised controls, designed by
reference to a recognised framework which are periodically tested to assess their
effectiveness, is likely to be a large leap forward for many organisations. The gap to be
bridged in respect of internal controls over taxes is a significant one that should be focussing
the minds of senior management responsible for this area in the foreseeable future.
Appendix 1 introduces a tax risk management best practice checklist to help you
address where you are today in putting a best practice framework into your organisation.

Tax Risk Management 29


6 THE TAX RISK MANAGEMENT FRAMEWORK IN PRACTICE

In Chapter 2 we highlighted that managing tax risk is about


managing uncertainty. By the very nature of uncertainty, there
can often be no one right or wrong answer. Managing
uncertainty is about making judgement calls and the quality of
your tax risk management will depend to a large extent on the
quality of those judgement calls. However having a framework
and system within which those judgement calls can be made is,
in our opinion, vitally important to proper tax risk management.

In the last chapter we considered what Risk framework maturity spectrum


makes up an integrated tax risk
management system, building on the Before looking in detail at how the
COSO internal controls. We then went on components of an integrated system of
to look at how the various objectives and internal control can be applied in practice
components of the COSO Framework let us consider, at an overview level,
might apply to tax risk management. This where you are now, or in other words the
chapter now focuses on how we use that maturity of your existing internal control
framework in a practical way in managing systems over tax risk management. By
tax risk and uncertainty and, in reviewing where you are now on the
conjunction with Appendix 2, puts maturity spectrum below it will help you
forward some tools that can be used in think about where you want to be.
the process.

It is also worth mentioning at the outset


that the practice of using internal controls
to manage tax risk is not a simple linear
process where you complete one stage
and move on to the next. You will need to
be able to respond to the rapidly
changing environment in which your
business finds itself. The control
environment practices of deciding on a
tax risk management policy and setting
tax risk objectives, carrying out a risk
assessment to identifying tax risk and
developing mitigating control activities to
manage those risks is therefore an
ongoing, evolving process – and it will
need to evolve and develop in line with
what is happening in the rest of the
organisation. It is perhaps more of a
circular process – it is certainly
something that needs to be kept under
constant review and should become an
integral part of the day-to-day operation
of the organisation.

30 Tax Risk Management


Unreliable Informal Standardised Monitored Optimised
Level 1 level 2 Level 3 Level 4 Level 5

Level 1 – Unreliable
• Unpredictable environment where controls are not designed or in place

Level 2 – Informal
• Controls are designed and in place but are not adequately documented
• Controls mostly dependent on people
• No formal training or communication of controls

Level 3 – Standardised
• Controls are designed and in place
• Controls have been documented and communicated to employees
• Deviations from controls may not be detected

Level 4 – Monitored
• Standardised controls with periodic testing for effective design and operation with
reporting to management
• Automation and tools may be used in a limited way to support controls

Level 5 – Optimized
• An integrated internal control framework with real time monitoring by management
with continuous improvement
• Automation and tools are used to support controls and allow the organisation to
make rapid changes to the control activities if needed

At the time of writing our experience is that most businesses are at levels 1 or 2 – i.e.
in the unreliable/informal stage with respect to tax risk management. However the
steps being taken to implement the provisions of the Sarbanes-Oxley Act, dealing with
internal controls, have organisations, both in the US and elsewhere, focused on rapidly
moving up the ‘maturity’ line. We would suggest that effective tax risk management is a
minimum of level 3 and probably looking towards being at level 4. This involves having
standardised controls over tax risk management that are periodically tested to ensure
they have been adequately designed and are operating effectively. It is important to
note that to be in compliance with COSO there should also be some monitoring of
controls as discussed below.

Where on the scale do you want to be?


Let us now look at each of the five COSO framework components and consider how
they can be used in practice to help manage tax risk.

Tax Risk Management 31


a) Risk control environment

Control It is primarily through the policy and objectives, together with the
environment general culture and approach of the organisation to risks and
controls, that the risk culture and tone of an organisation is set.
The control environment over taxes therefore manifests itself in
the setting of the tax risk management policy and tax risk
objectives, and the involvement of senior management in both
this and the ongoing monitoring.

Building a tax risk management practice it is likely to be CFO (or possibly


policy the CEO) as the key stakeholder who
would take ownership of it. It is likely that
In our view the starting point for the control the head of tax will have drafted it. The
environment is a documented tax risk policy should have the buy-in of the key
management policy. What does this mean interested parties such as the audit
in a large and diverse group, particularly committee and the chief risk officer.
one operating in a multi territory
environment? The answer, we believe, lies It follows that one of the key points the
in the development of two layers of policy, board should focus on is the quality, skills
namely one directed, at the strategic level, and attitude to risk of the head of tax (and
on the overall organisational appetite and possibly others in the tax function). Are
framework and the second focused on they naturally conservative people or are
operational controls. they more aggressive risk takers – and how
does this marry up with the board’s
The strategic framework or policies should attitude to risk? How do they rate the head
set the tone for how tax risk should be of tax’s judgement and management skills
managed in the organisation and therefore in relation to putting in place a structured
reflect the following: risk management framework? Historically
boards have put a lot of trust in heads of
• High level corporate policies about the tax to ‘get it right’; we are moving to an era
level of risk across the various types of where the board will be taking less on trust
risk discussed above, outlining the and expecting more evidence to show that
position the group wants to adopt as it is right.
a whole.
Beyond this, detailed operational tax risk
• Country and/or business unit policies policies, e.g. policies around sign off on
that further develop this in the individual matters such as transactions, tax review of
circumstances of that country or unit. new product development, external advisor
These policies could reflect the different opinions, and rulings from fiscal authorities
positions that the company may want to will be important components of a control
take on different types of taxes. environment to manage tax risk.
The scales for each type of tax risk as set When agreed, the tax risk management
out in Chapter 2 might be used as part of policy should be formally documented,
the policy. The policy should cover the approved by the board and communicated
entire organisation. It should be sufficiently to those responsible for the
flexible both to avoid it having to be implementation of the policy and to other
changed too frequently and to encompass interested stakeholders.
routine, day-to-day, changes in the
organisation and its environment.
Key board objective: We will have a formal documented tax risk management
The formal approval of the policy is the framework and policy that will be agreed by the board and monitored by the audit
responsibility of the board although in committee. This will be in place by [date].

32 Tax Risk Management


Setting specific tax risk objectives
The next stage in tax risk management, As with the policy set out above, there
after the setting of the high level tax risk are two layers of risk objectives – those
management policy, is the setting of at the strategic level and those that are
specific tax risk objectives. The setting of operational. The strategic objectives will
tax risk objectives is effectively the relate to the high level goals set out in
development of a plan to deliver the tax the policy; the operational objectives will
risk management policy. The test of the be around what happens on a day-to-
objectives is that if these tax risk day basis.
objectives are achieved the organisation
should be delivering against its tax risk
management policy.

Tax risk objective Examples

Strategic objectives • The group head of tax will take responsibility for tax risk management for all taxes
on a global basis
• We will implement tax planning strategies that will impact positively on our day-to-
day business
• We aim to avoid having anything to do with our tax affairs being aired in the public
domain
• We will file the appropriate returns in all relevant jurisdictions in accordance with
tax laws and regulations regardless of local custom

• We will not implement more than five significant tax planning ideas in any one year
Operational objectives • The tax function must be involved in all transactions over $/£5m
• No new subsidiaries may be set up without tax function input into the
structuring/financing
• External opinions will be taken on any issue where the tax at stake is greater than
$/£1m
• The financial accounts tax figure needs to be accurate to within 3% (or a financial
amount)
• Our total portfolio risk should at no time exceed more than 10% of our annual tax
charge in the accounts
• The cost of any revenue authority investigation/adjustments should not exceed
1% of the tax payable
• Penalties, including tax related penalties, for late filings of tax returns will not
exceed $/£20,000 in any one year

These objectives will also, to a large extent, to the individuals in the organisation who will
determine where resources are focused and be involved in delivering them, and built into
directed. Certain of the objectives will be their own individual performance objectives.
more easily achieved than others – They effectively become the target in
especially those objectives entirely within the designing suitable tax risk management
organisation’s control. However just because controls. It is also useful to develop a
an objective is difficult to achieve does not common means of documenting and
mean it should be left off the list! When the communicating the tax risk objectives in
objectives have been established they order to create familiarity with such
should be documented and communicated information throughout the organisation.

Tax Risk Management 33


b) Risk assessment

Risk Risk assessment is the awareness and response of the organisation


assessment to the different types of tax risk facing the organisation (as set out in
Chapter 2). This will include the organisation’s processes and
procedures for identifying and evaluating the tax risks and how
those risks are managed and mitigated consistent with the overall
objectives of the organisation on tax risk.

The board and management will make should cover all significant transactional they are in your organisation. To identify
decisions around events and activities that risks. A way of ensuring tax functions tax risks, the tax function will need to be
an organisation will undertake in order to know what is going on might be to copy in close contact with these people on an
meet its overall objectives and increase them in on minutes of meetings, capital ongoing basis.
shareholder value. In virtually all cases expenditure approvals, public
these events will have tax implications for announcements, etc. These can be For those risks associated with change,
the organisation, or parts of it. Such events forward looking or historic and carried out the objective is to identify all future events
can be internally or externally generated, on either a top-down or bottom-up basis. that could potentially impact the tax risk
such as a decision to re-organise part of position of the organisation. The table
the organisation or dispose of certain Focussing on current business processes below sets out, at a high level, some of
assets, or, having to comply with some will be a useful source to identify key tax the typical events that need to be
new laws or regulations. risks from the ongoing, day-to-day, considered in the risk identification
business where no major changes are process.
It is important to establish at the outset expected. For the risk identification to be
that ‘events’ in the context of risk complete it is important to consider those
assessment means both active events risks (which will largely be operational and
where some proactive course of action is compliance risks) arising from following a
undertaken and non-active events, where no change/business as usual approach.
a risk arises because of the failure These risks will arise both from not
(whether inadvertently or by design) to properly carrying out a process through to
undertake a particular action. the failure to do something at all.

Risk identification On the compliance side you might also like


to consider your ‘compliance footprint’.
The first step of tax risk assessment is This involves creating a map of the various
therefore to identify the tax risks – both regulatory regimes that the organisation
upside and downside risk. Looking at the has to deal with and the regulatory returns
causes of risk, firstly there are risks arising that have to be submitted.
from changes in the business and
secondly there are those arising from the On the external side, changes in tax laws
on going day-to-day activities. and regulations – over which the
organisation has no control – can give risk
For those risks associated with change to significant tax costs, especially in
you might start by considering the organisations which have been more
organisation’s overall strategy and its aggressive in active tax planning and
objectives for achieving that strategy, exploiting loopholes. Here the likelihood
together with the planned and potential and potential impact of anti-avoidance
events, both in the business and measures might have a significant impact.
externally. Board and management
meetings, where decisions about the Another approach to risk identification is
direction and key events are taken are to focus on the people. In any
probably the key source of identifying the organisation there will be people who
items likely to have the greatest impact on create risks and those who mitigate risk.
tax risk assessment. Being aware of what The risk creators will include the decision
is happening at such meetings should makers, those developing new parts of the
identify the key risks arising where there is business and those driving acquisitions
pro-active change in the business and and disposals – you probably know who

34 Tax Risk Management


Type of tax risk Typical events giving rise to tax risk
Transactional Acquisitions
Disposals
Mergers
Financing transactions
Tax driven cross border transactions
Internal reorganisations

Operational New business ventures


New operating models
Operating in new locations
New operating structures (e.g. JVs/partnerships)
Impact of technological developments (e.g.
Internet trading)

Compliance Lack of proper management


Weak accounting records or controls
Data integrity issues
Insufficient resources
Systems changes
Legislative changes
Revenue investigations
Specific local in country customs, approaches
and focuses in compliance

Financial accounting Changes in legislation


Changes in accounting systems
Changes in accounting policies and GAAP

Portfolio A combination of any of these events

Management Changes in personnel – both in tax and in the


business
Experienced tax people leaving – and information
being in their heads and not properly
documented
New/inexperienced resources

Reputational Revenue authority raid/investigation


Press comment
Court hearings/legal actions
Political developments

Tax Risk Management 35


How are those managing tax risk informed of such changes in
your organisation?

Whichever route you follow for Similar judgements are also needed in to ensure that they provide meaningful
risk identification, the key here estimating the tax consequence of the information required to manage tax risk.
type of risk identified. You will need to You need to bear in mind that the key
is communication. Those take account of past experience, current objective here is to assess tax risk so
responsible for managing tax knowledge about the future, and the that the organisation’s resources can be
risk need to know what is impact that other events and decisions directed to address those risks.
happening in the business and will have. The overall aim is to reach a
view as to the likely tax outcome of the The first example of a tax risk
there needs to be a mechanism
event, if the event giving rise to the tax assessment template is the risk priority
for this to take place. Whatever risk were to take place. It is the inter- template. This is based on the chance of
techniques are used it is relationship of the event, the likelihood of an event happening and the impact if it
important that the whole of the its occurrence and its tax consequence does. By grading both the chance and
organisation is considered both that is important in assessing the tax risk the impact high (H), medium (M) or low
inherent within any event. (L), a risk priority can be arrived at which
at the entity and activity level
will help focus where action needs to be
and that internal and external The events of particular importance are taken. For example where the chance of
factors, as well as the risks those which have both significant or an event happening is high and the
associated with there being no material consequences and which have impact if it does happen is high, then this
change, are taken into account. a high risk of happening, since, in the risk is clearly priority 1 and it needs
absence of any measure taken to attention. An example is set out below
What is needed is a thorough mitigate those particular risks, the based on the particular events in the
and disciplined approach to consequences are likely to be significant previous table.
ensure that all areas are to the organisation. However it is not only
considered and nothing falls the one off events that can give rise to
between the cracks. large tax risks. A large volume of small
risks can build up into large overall risk.
An example might be the regular
misposting of disallowable expenditure to
Risk quantification
an allowable code.
Having identified the tax risks the
second part of the risk assessment It should be possible to build a risk
phase is to consider the potential tax assessment table outlining the various
impact of these risks and the likelihood events, their consequence and their
of the underlying event occurring likelihood. This could be done for each
(especially where the events are not type of tax risk and for each different
wholly within the control of the location, operating unit, or along
organisation). Once the various risks whichever primary organisational and
have been quantified then decisions can reporting lines the organisation operates.
be made as to which ones need the However what is important is that the key
most attention. events are collated and aggregated to
give an overall risk assessment table for
Risk quantification is an area where the organisation as a whole.
judgement and experience play a major
role. Various qualitative and quantitative Appendix 2 contains two sets of risk
techniques can be used ranging from the assessment templates which have the
broad (e.g. quantification of risk of flexibility to be used in any organisation
occurrence being high, medium or low and can be structured to follow the
risk) to more detailed approaches to operational and reporting structure of any
assess the likelihood of occurrence of an organisation. It is important to give some
event (such as benchmarking and thought to the structure and content of
sophisticated probability analysis). such risk assessment tools before
adopting them in your own organisation

36 Tax Risk Management


Chance of event
Impact Risk priority
Event happening
High, Medium, Low
High, Medium, Low 1 = High, 5 = Low

Acquisitions H H 1
Disposals H M 2
Mergers H L 3
Financing transactions H H 1
Tax driven transactions L H 3
Internal Reorganisations M H 2

New business ventures M H 2


New operating models M M 3
Operating in new locations M L 4
New operating systems H M 2
Impact of technological M H 2
developments (e.g. Internet trading)

Lack of proper management L H 3


Weak accounting records or controls L M 4
Data integrity issues H L 3
Insufficient resources L L 5
Systems changes M H 2
Legislative changes H M 2
Revenue investigations H M 2
Specific local in country H L 3
approaches

Changes in legislation
Changes in accounting systems
Changes in accounting
policy & GAAP

Changes in personnel –
both in tax and in the business
Experienced people leaving
Inexperience resources

Revenue authority raid or


investigation
Press comment
Court hearing/legal action
Political developments

Alternatively, the position could be looked at by type of tax risk or by country or by type of tax.
A table using type of risk might look like this:

Chance of risk arising Impact Risk priority


Type of tax risk High, Medium, Low High, Medium, Low High, Medium, Low

Transactional H H 1
Operational H M 2
Compliance L L 5
Financial accounting M M 3
Portfolio M M 3
Management M L 4
Reputational L H 3

The above templates give a priority rating, but do not actually spell out the financial implications of
the risks in question. The two templates below address the same points, but do put financial figures
on the results, which gives an alternative way of prioritising which risks need to be addressed.

Tax Risk Management 37


Chance of event
Impact Potential cost
Event happening
$’m B $’m AxB
% A

Acquisitions 75 10 7.5
Disposals 25 40 10.0
Mergers 10 20 2.0
Financing transactions 60 5 3.0
Tax driven transactions 20 5 1.0
Internal Reorganisations 5 10 0.5

New business ventures 20 5 1.0


New operating models 50 8 4.0
Operating in new locations 25 2 0.5
New operating structures 20 3 0.6
Impact of technological 80 5 4.0
developments (e.g. Internet trading)

Lack of proper management


Weak accounting records or controls
Data integrity issues
Insufficient resources
Systems changes
Legislative changes
Revenue investigations
Specific local in country approaches

Changes in legislation
Changes in accounting systems
Changes in accounting
policy & GAAP

Changes in personnel – both in tax


and in the business
Experienced people leaving
Inexperienced resources

Revenue authority raid or


investigation
Press comment
Court hearing/legal action
Political developments

Portfolio risk – total – – 34.1

Using the same financial approach, but looking at the risks on a country by country basis would give
the following template.

The use of scenario


Chance of risk arising Impact Risk weighted cost
Country or Entity % A $m B $m AxB
planning might be
appropriate here.
Scenario planning is too
Australia big a subject to go into
Belgium in this guide but we
Brazil have used it at a
conference of European
Germany tax directors and would
India suggest that more
Singapore sophisticated methods
of risk assessment
United Kingdom should include its use.
United States
Total

38 Tax Risk Management


Organisations should be able to identify and
quantify their key tax risks. Can you?

Response to tax risk


Taking alternative action such that the risk no longer arises, for
The risk assessment example by operating using a different model such as:
process, and the tables
above, will have highlighted – using arms length transfer price to avoid a transfer pricing tax risk; or
the key tax risks that need Avoidance – restructuring an asset disposal to be a sale of a shareholding in a
to be managed. The specific company owning those same assets; or
response to each identified
risk will vary depending on – to operate through a legal entity with a different taxable status in
factors such as: a particular location

• The ease and cost of Taking action to reduce the likelihood or impact of the risk by transferring
mitigating the risk, or sharing the risk in some way. This generally achieved through the
• Its potential impact on the Sharing techniques such as the obtaining of warranties or indemnities, obtaining
business, and professional opinions, or outsourcing of tax functions
• The availability of
alternative mitigating
techniques. Taking action to reduce the likelihood of the occurrence and/or the
impact of the risk, for example by:
– carrying out appropriate tax planning; or
The response might be any
one or a combination of the – obtaining documentary evidence or opinions in support of the
following three options: proposed tax treatment such as a tax valuation, or
Reduction – restructuring the event to give a more favourable tax treatment e.g.
by leasing rather than buying a capital asset; or
– carrying out a detailed review of potentially disallowable expenditure
to ensure all potentially allowable amounts have been identified
and claimed

The cost/benefit analysis of responding to a Whilst mitigating responses are generally


particular risk needs to be taken into account. considered on a risk-by-risk basis and need to
For example, you may decide to have a very be thought about for each tax risk identified, it
low acceptance of errors in your compliance, is important to bear in mind the overall portfolio
but for a particular disallowable expense risk. This ensures the impact of any low
searching through all the various account outcome/low consequence risks, which may,
headings is prohibitively expensive and time on their own, have been considered immaterial
consuming and the better answer is to accept or within the organisation’s tolerance threshold,
the risk and live with it. are considered. If, on a portfolio basis, the
overall level of risk does not meet the
It should also be borne in mind that the most organisation’s tax risk objectives, then it will be
effective means of mitigating the risk may be a necessary to consider mitigating responses to
combination of several reduction or sharing more of the risks in order to bring the overall
techniques and that the residual risk, (i.e. the tax risk level consistent with the objectives.
risk remaining after mitigating action has been
taken) should then be evaluated. If none of the In order to document the responses to tax
above techniques can be or are used to risks identified, it should be a fairly
mitigate or respond to the tax risk then, by straightforward exercise to expand the risk
default, the organisation bears the risk and assessment and risk priority templates referred
accepts the consequences. These residual to both in Appendix 2 and the risk
risks should be compared with the quantification section above, in order to record
organisation’s tax risk tolerance level and, if the various responses that have been designed
necessary communicated up the line. to respond to the risks identified.

Tax Risk Management 39


An outline example of a tax controls template for corporate tax transfer pricing risks for a specific location (although it could equally
be a for a subsidiary, division or an operating unit) is shown below:

Transfer pricing Mitigating control


Inherent tax risk Residual risk Responsibility
activity

Goods - acquired No direct third party Comparables transfer Potential challenge Group tax manager
comparables available pricing study carried to comparables
out/up-dated to being used.
confirm arm’s length
price being used.

Goods – sold
Services – acquired
Services – sold
Royalties – acquired
Royalties – sold
Interest – payable
Interest – receivable
Documentation

40 Tax Risk Management


C) Control activities In the earlier control environment
section we set out both the strategic
Control Control activities are the individual policies and the operational objectives for
activities and procedures that are put in place to managing tax risk. From the risk
respond to the identified tax risks. Control assessment section we have highlighted
activities also include the policies and where the key risk areas are in the
procedures put in place over the entire tax organisation. We now come to our
risk management process to ensure that the control activities which need both to
process is complete and that all relevant tax link in with these objectives and to
risks are identified and considered. Control focus on the high risk areas – being
activities include a broad range of actions areas of known risk as well as areas
such as approvals, authorisations, where the tax function is not closely
reconciliations, reviews and policies on involved and which may give rise to
areas such as segregation of duties. risks which have yet to be identified.

Taking the results of some of our earlier templates we might build up a picture that
looks like this:

Objective / Risk Who is What do they need How do they


When?
responsible? to do? do it?

Ensure there is a group Chairman of Agree broad Delegate detail to Immediate


tax risk management Audit committee parameters with rest head of tax
policy of the Board

The group head of tax Head of Tax Full group tax risk Seek external Next three months
will take responsibility for assessment advice on best
all tax risk management Design control practice procedures
activities around all for this exercise
major risks

The tax function must be Legal Involve the tax Formal notification At the start of any
involved in all department function when any required negotiations
transactions over $/£5m such transaction
arises

Revenue investigations Head of Monitor all Overview role, but Ongoing


Compliance involvement with involved in detail for
revenue authorities major issues
where tax at risk is >
$/£25,000

Tax Risk Management 41


So in considering the tax risk management control activities we need to look at:
• Who is responsible for the operation of the control activities?
• What do they need to do?
• How do they do it?
• When do they need to do it?
people are the ‘risk mitigators’ and you
Who policy and involvement in setting and
monitoring achievement of the tax risk need to think through what support and
objectives. The CFO would also be help they will need to do their job
Various people through an organisation will
expected to be involved with particularly properly. For example if you have junior
be responsible for the operation of control
significant tax risk management issues account clerks coding expenses between
activities over tax risks. We call these
and reporting to the board or the audit tax allowable and tax disallowable codes,
people the ‘risk mitigators’ (as opposed to
committee on tax risk management. what training and/or manuals do they
the risk creators mentioned earlier). Who
need to help them do this.
these people are in your organisation will
The head of tax would have increasingly
depend on your own management
more involvement and would be the key There is nothing new in this type of
structure. The extent of these people’s
point for overseeing tax risk management hierarchical structure. The precise roles,
responsibility will depend on their role in the
procedures and policies with local CFOs responsibilities and detail of it will depend
organisation. The table at the end of this
or country tax managers. The head of tax on the organisation’s overall management
section gives an indication of the hierarchy
would be expected to have significant and reporting structure. There will also
of responsibility for control activities over
involvement in (and may have primary inevitably be additional roles which should
taxes and tax risk in a typical organisation
responsibility for setting) the tax risk be reflected in the list above such as
and what those individuals might be
objectives and notifying the CFO on tax internal audit and risk management
expected to have responsibility for.
risk management matters. In addition the personnel. What is important is that the
head of tax may also be responsible for responsibility for operation of the controls is
The important point is that there are
specific individual control activities (such as clearly set out and understood, especially
people at appropriate levels throughout
giving input to potential major transactions, in large organisations operating in different
the organisation who have responsibility
tax negotiations with fiscal authorities and locations, where operational, reporting and
for both the operation of control activities
in matters such as legal actions). legal structures may vary considerably.
and for the operation of tax risk
management procedures and policies.
Local CFOs and tax managers would be The roles listed above are all internal roles
They also need to be clear what is
expected to have a supervisory role over in an organisation. Businesses also use
expected of them.
the operation of detailed control activities external advisors in managing tax risk,
in their territory, and responsibility for both in helping set up procedures and,
What reviewing and reporting up the group to
the head of tax the results of the risk
perhaps more commonly, in performing
mock revenue authority reviews. In the
The answer to what those various assessment process for their territory. latter case they often use people who
individuals need to be doing will depend They would also be responsible for the used to work for the revenue authority in
on their position and their role in the design and establishment of control question who are well placed to see things
organisation. Some thoughts on this are activities in response to identified tax from the ‘other side’. External advisors
set out below. risks and for operating some of the more can therefore also play an important role
important control activities (such as in the area of control activities.
At the board level the ‘what’ would be authorising and reviewing certain
expected to include high level oversight transactions). The local CFO/tax manager
and review of the tax risk management would also be expected to have How
policy, and consideration and involvement in the monitoring phase,
especially where detailed control activities Control activities should be in place to
development of the tax risk management
are found not to have been operating cover the risks arising from:
policy and objectives.
effectively in their particular location.
• What is done in the tax function
The audit committee might take a slightly
The individual members of the tax team • What is done in the rest of the business,
more detailed interest in not only the
or shadow tax departments will have and
policy, but also in ensuring that the
ongoing responsibility for the operation of • What is carried out externally
appropriate control framework is in place,
is being operated and is being monitored. the detailed control activities. These
individuals will be responsible for the Control activities should be built into to
They should keep an oversight of the
performance of the various reviews, the day-to-day operations of the business
policy; they might also want to keep a
approvals, reconciliations etc, as well as with responsibility for the activity being
close eye on reputational risk.
the first level of risk assessment, since assigned to appropriate members of the
these individuals are also likely to have organisation’s staff. The tax risk
At the CFO level it would be expected
the closest ongoing relationships with management policy should spell out
there would be more regular review of the
operational people in their locality. These levels of authority and who has to review
operation of the tax risk management

42 Tax Risk Management


what, and the ground rules for people the relevant parts of the organisation and A review to ensure that either the
performing tasks where there are no all its activities are considered irrespective transaction was implemented as proposed
review procedures. Each organisation will of where in the organisation they reside. by the lawyers, or, if not, to consider the
have its own way of setting up its control Unless it is clearly established who in the tax risks inherent in the actual
activities and it is beyond the scope of organisation has responsibility for the implementation become important in
this guide to try and set out all the controls in these areas there is the ensuring all relevant tax risks are identified
potential controls that could be used to potential for either duplication of work and dealt with.
mitigate individual tax risks. However between both the tax function and the
identifying where risks are or might be, other department involved, or worse, that In outsourcing situations, where an
and then considering how these risks can each assumes the other is managing the organisation uses a third party service
be managed should give a framework in tax risk in that area when in fact neither is provider to carry out transaction
which control activities can be developed. doing so. This is particularly important in processing it may not be possible to
those organisations where all the financial directly manage the controls in the third
IT and tax knowledge management targets are based on the profits before tax party organisation. In such situations, the
systems are in themselves controls. – with the result that tax management can area that is often overlooked is the
This is particularly important where such be very low on some people’s agendas development of controls to ensure that
systems are used in identifying exceptions (assuming it is there at all). the output given to the third party is
such as significant volume changes that whole and complete and that the input
may indicate tax risks, or alternatively Similar duplication or omission issues can received back is fully assimilated back
providing information that is key to be found within the tax function especially into the organisation. The use of a third
decision making on tax matters. Therefore in large organisations where there is party itself may well be a control against
as well as including manual procedures, insufficient dialogue between local tax an identified tax risk in itself – in that the
control activities should also include people and the head office team. Processes use of specialist third party resources is
application controls within IT systems. and procedures are needed to ensure that how the organisation achieves the
Additionally these need to be designed to all these different areas are working accuracy of, say, its tax computations,
ensure the completeness, accuracy and together and effectively. The people but this is dependent on full relevant
validity of data capture. Such controls involved are often the risk mitigators and information being provided to the third
within, and over, IT systems are important they need support and help in their roles. party and the organisation fully
activities since they impact on the processing the information received back.
systematic processing of transactions for,
for example, VAT/GST tax returns. Control activities over tax risks
where using external
Control activities over tax risks advisors/outsourcing
outside the tax function Another area that needs managing is the
use of external advisors and the
There are many examples where outsourcing of certain activities. Some
responsibility for tax matters sits outside examples on this point might be helpful.
the tax function. Payroll taxes may be dealt
with in the payroll/HR function, sales taxes Where external advisors are used to
may sit within the finance department, and provide advice on a proposed transaction
treasury may deal with withholding taxes. it is important that there are processes in
One of our examples of a strategic tax risk place to ensure not only that the tax risks
management objective, under the control are captured, but that there are
environment section earlier in this chapter, appropriate related controls to ensure
was that ‘the group head of tax will take that the background and information on
responsibility for tax risk management for which the advice has been based is
all taxes on a global basis’. Even if this is accurate and reflects the actual position
not the case in your organisation it is likely of the organisation. In a fast moving
that the tax function will be called in if and transaction these basic procedures can
when issues arise in respect of taxes not often be overlooked.
directly under their control.
Similarly, when proposed transactions are
It is therefore important to ensure when implemented there are inherent tax risks
considering tax risk management that all based on the transaction that took place.

Tax Risk Management 43


When n
The regularity and frequency of involvement For effective tax risk management, the
of the various individuals mentioned above control activities noted above do however
will depend on the issues and the need to be linked to a time period. For
organisation involved. For those groups example, tax reconciliations may need to
who are SEC registrants then initially there be carried out monthly (VAT or GST), and a
is likely to be great deal of activity to tax analysis of a proposed transaction
ensure that such organisations are up to should be carried out before the proposed
speed and in compliance with the transaction is put forward for approval.
Sarbanes-Oxley rules.

The timeframes listed in the table below, ranging from annually for the board, down to
ongoing involvement for the individual staff members of the tax team, are purely indicative.
The point is that there should be an agreed timetable for the control activities to take place,
and progress should be monitored against this timetable.

Outline timetable for tax risk management activities

Feedback to Board
Risk management on tax risk
Preparation of
policy agreed management
risk policy
by board objectives

Tax risk objectives


agreed and
communicated

Year 1 Year 2

Risk assessment Risk assessment Risk assessment


update update

Development and Remedial


design of control development of
activities control activities

Monitoring of Monitoring
control activities control

One of the purposes of having a detailed timetable is to ensure that the control activities are put in place and implemented in a timely
and disciplined way.

44 Tax Risk Management


Summary
In summary an overview of the control activities position might look like this:

Who is responsible? What for? Review cycle

The board The overall control activities of the entire organisation Annually

Review of tax risk management policy and


The audit committee confirmation that the internal control framework is Half yearly
being operated and monitored

All control activities relating to the finance function


CFO Quarterly
including all control activities over taxes and tax risks

Control activities over tax risk and tax risk


Head of tax Monthly
management

Control activities over the finance function including


Local CFOs/ taxes (in the case of CFOs) or all control activities
tax managers over taxes (in the case of tax managers) for the Monthly
country/subsidiary/business unit for which the
CFO/tax manager has responsibility

Responsibility for the control activities over taxes and


Individual staff
tax risk within their area of responsibility. For example,
members of the tax Ongoing/
control activities over VAT and sales taxes are likely to
team or shadow Continual
be the responsibility of the local VAT/sales tax manager
tax dept.
and their team

Internal audit Review of application of controls and procedures Bi annually

Tax Risk Management 45


d) Information and communication
We have touched in the earlier parts of this chapter
Information & on the importance of communication and information.
communication
Information and communication are effectively the oil
that lubricates the whole internal control system and
ensures it operates smoothly.

Information needs to flow up, down and In practice many different forms of Some types of information such as the
across the organisation to ensure that: communication will be used, both formal overall tax policy and the risk objectives
and informal, manual and computerised. will probably be relevant across the entire
• the tax risk management policy forms It is important that the information is tax function and to people responsible for
the basis for the development of the appropriate for the purpose for which it taxes within other parts of the business.
risk objectives; is needed and therefore it needs to be at At the more detailed level, the results of
• the tax risk objectives underpin the risk the right level of detail, timely, up-to-date tax risk assessments and control matrices
assessment and risk quantification; and accurate. identifying the nature of individual risks,
• control activities are developed to cover controls and who has responsibility for
the risks identified in the risk The distribution method and the nature of them, probably need to be made known
assessment consistent with the risk the information will need to be considered. on a more localised basis.
objectives; Some of the information such as the
• the detailed control policies and detailed control activities and the Finally you might like to consider what
procedures are communicated and responsibilities of individuals will need to sort of training is needed for the tax risk
known to those responsible for be widely communicated and may well be mitigators, those people from accounting
operating them; stored and managed in some central staff through to the audit committee, who
• knowledge about what is happening, repository such as an organisation’s are responsible for managing tax risk.
and is proposed to happen, on the intranet site or in documents such as a tax For example do the people who code
operational side of the organisation is controls and policies manual. Where such incoming invoices understand why the
considered in order to identify tax risk; central repositories of information are correct coding is so important and the
• knowledge about what is happening in used it is important to ensure that they are potential tax risks that arise if they do not
the external environment feeds into the kept up-to-date, consulted and followed if do their jobs properly?
risk assessment and into the they are to become an integral part the
development of mitigating control organisation’s tax risk management There can, of course, be no standard
activities; processes. We are probably all aware of list of what information and forms of
• some general knowledge and organisations where significant time and communication should or should not be
understanding of the impact of taxes money has been spent developing tax used. As each organisation is different
on the organisation are communicated policy and tax procedure manuals; only then the relevance, format and types of
to the wider organisation so that these for them to gather dust on the top shelves communication that best meets each
can at least be considered at a high of an office somewhere! Other less formal organisation’s individual needs will
level when developing the wider means of communicating will include be different.
business policy; e-mails, memoranda, training materials,
• support is given to those in shadow tax databases, and notice boards. Generally, however, the following comments
function roles to enable them to be are likely to apply in all organisations:
effective, and To be most effective, these tools should
• feedback as to the effectiveness of the become an integral operating tool for • the tax risk policy and tax risk objectives
whole internal control system can be anyone involved in tax management. The should be known by all involved in any
passed up the organisation to enable information used and key communication tax risk management role;
management to assess the overall methods should form part of the training • individuals should know how their own
effectiveness of their tax risk for new and existing staff and when staff roles and responsibilities align with the
management activities change roles and take on new policy and objectives and fit with the
responsibilities. This helps individuals work of others in their area;
understand how their own role and • the results of the risk assessment process
responsibilities align with the goals of the linking the risks to any mitigating controls
wider organisation. Tax risk management that have been developed in response to
should become part of the culture. them should be documented.

46 Tax Risk Management


e) Monitoring
In order to consider the effectiveness of the operation of the
control activities that have been designed and implemented in
Monitoring
an organisation to mitigate identified tax risks, it is necessary
to monitor their operation. Following the monitoring process
an organisation will be able to reach a conclusion on the
effectiveness of its controls over tax risks.

It is an established principle of effective In the Sarbanes-Oxley regime, the CEO


review procedures that the monitoring and CFO will be required to attest on the
process should be carried out by different effectiveness of design and operation of
individuals to those responsible for the an organisation’s internal controls over
design and operation of the internal financial reporting (which will include the
controls themselves. financial reporting of taxes). The
monitoring process is likely to be the
In many organisations this type of activity key means by which senior management
is carried out by the organisation’s internal will be able to reach such a conclusion.
audit function. However, it is our In addition, since an SEC registrant’s
experience that internal audit departments auditors will be required to give an
have tended to shy away from reviewing opinion, a properly structured and
tax risks and controls and therefore tend documented monitoring process is likely
to lack experience in the specific area of to be the major area that auditors will
assessing the design and effectiveness of want to consider in reaching their opinion.
internal controls over tax risks. Maybe this
has to change?

To be fully effective there will need to be Summary


procedures in place to ensure that the
results of the monitoring activity are fed Different organisations will implement
back into the whole tax risk management internal controls in different ways.
process in order to ensure that: Those businesses directly impacted by
the Sarbanes-Oxley Act of 2002 will be
• remedial or corrective action can be driven both by what is best practice
taken where the results of monitoring and by the requirements of their
activity reveal that controls are not auditors. Other organisations will need
operating effectively or as designed; to decide what levels of internal
• there is a process to consider the controls are appropriate for their
impact of controls not operating business. What is clear to us is that,
effectively on whatever route you follow, a well
- the achievement of the tax risk defined process is needed for effective
objectives, and tax risk management.
- risk assessment
• the results of failures and non-compliance
are communicated to the relevant people
in the organisation so that appropriate
effective action can be taken.

Documentation of the risk assessment


and the operation of control activities is
essential to enable independent testing of
the operation and effectiveness of those
controls. Therefore, documenting the
control procedures and processes needs
to be embedded into the day-to-day
operations in order to be effective.

Tax Risk Management 47


7 MANAGING GLOBAL TAX RISK

In this chapter we want to focus specifically at how a group can


manage the tax risk arising in countries other than the head
office country.
These are the risks that are perhaps not as risks that arise in local territories? Let us go expect the head office tax function to
visible as those arising at head office level – back to the seven main areas of tax risk as be involved.
and they are often more difficult to manage set out in Chapter 2 and consider them in
by virtue of them arising in different relation to what is happening in your 5. Reputational risk - how much damage to
countries, different time zones, different overseas subsidiaries. the group’s reputation can a local subsidiary
cultures and sometimes in a different do? This needs to be reviewed on a country
language. Additionally in some of the less We would suggest that the three most by country (or subsidiary by subsidiary)
developed countries there may be a lack of important types of local tax risk areas are: basis. You also need to consider the impact
sophistication within both the tax law and your local reputation has on your ability to
the tax authorities with the result that a very 1. Operational risk – with local subsidiaries do business in that local country.
different approach to tax management is carrying out their business with little or no
needed in these countries. tax involvement. You might also include The types of risk that are likely to be
transfer pricing under this heading even if managed at head office level, and hence are
The points made in earlier chapters are of there is a group transfer pricing policy set unlikely to be local country risks, are:
course as relevant to a multinational as they at head office level. Having a policy is one
are to a domestic group. However thing, ensuring that it is being properly 6. Portfolio risk – whilst the head office team
managing tax risk for a multinational group implemented is quite another. needs to understand what is happening
brings with it a number of specific issues at a subsidiary level, portfolio risk is by is
and solutions that need to be addressed. 2. Compliance risk – in respect of the very nature something which is managed
We are therefore now going to consider, for various local tax returns that need to be across the totality of the group and hence
a multinational group: submitted. It is important here to needs managing at head office level. (A
recognise the wide range of tax returns regional tax manager might disagree with
• What are the main local tax risks? that are needed and that withholding this statement and argue that they are
• Who owns the different tax risks around taxes and sales taxes/VAT may be more running a portfolio of countries and that
the world? important and higher risk than corporate this risk is also a high priority.)
• How these risks might be managed, and income taxes.
• The specific risks arising from the use of 7. Management risk – our view is that the
shared service centres. 3. Financial accounting risk – which may be management of tax risk is a head office
a risk if the subsidiary in question is function and it is the head of tax who
What are the tax risks? material to the group as a whole or where needs to ensure that proper management
there is a lack of familiarity with group of tax risk is in place across the group.
This chapter is about managing risk arising policies and non-local GAAP (especially in
in local territories. It is not about managing the context of group reporting). So let us focus on the three key local tax
the international tax position of a group and risk areas, namely operational, compliance
the risks which go with that; it is about what The types of risk less likely to give issues are: and financial accounting risks. Before going
is happening in local territories, what tax any further you might like to list out what
risks might arise and how these risks can 4. Transactional risk – on the grounds that you believe are the five most significant
best be managed. So what are the main tax for any significant transaction you would local overseas tax risks for your group.

Key overseas Country in which this risk


Type of tax risk Type of tax
tax risks is an issue

1
2
3
4
5
If you are struggling to complete this table, you might like to consider how good your risk assessment procedures are. Adopting a structured
bottom-up approach to using the tax risk template tools referred to in Chapter 6 could be a useful tool for identifying the tax risks in your significant
overseas locations. If you have completed the table, how aware is your CFO or your board that these are the group’s key areas of overseas tax risk?

48 Tax Risk Management


Ownership of tax risk
Let us now consider who is responsible for the management of the following taxes:

People responsible for tax


Head office country Country A Country B
management of:

Corporate income taxes


Sales taxes / VAT
Excise duties
Payroll taxes
Withholding taxes
Other taxes

If you are a head of tax the chances are above are equally relevant in such
that you and your team (even if you have The first question therefore that we situations – even if the answers may be
tax people present in some of your major believe needs addressing for a slightly different.
territories) have little or no responsibility multinational group is who has ownership
for the operation of some of these taxes of which taxes and where – and hence The final point on ownership of tax risk is
in other countries. However when issues ownership of the relevant tax risk to consider the reporting structure so that
arise on the tax audits, the management management issues. If, as we suspect, the head of tax can sign off, if required to
of this inevitably shifts to the tax function. some of the ownership will fall to local do so by the board or CFO, that the
On the principle that it is better to get CFOs then the second question is how group’s tax risk position is being
things right at the outset, we are seeing well equipped they are to perform a tax adequately managed. We would suspect
a trend towards more centralised control risk management role. Do they that there are very few local CFOs who
of tax matters, but most groups are still understand the risks in what they are report or sign off on tax risk management
some way away from the tax function responsible for and do they understand to the group head of tax. How is the
having ownership of all tax matters the group’s attitude to, and policy on, tax group head of tax going to get
wherever they happen to be. For example risk? Does it matter to them – particularly himself/herself in a position where he/she
how many head office Heads of Tax are if they are measured on a profit before tax can sign off?
responsible for the operation of payroll basis? The third question is who is
or withholding taxes in other countries? accountable if something goes badly You will by now appreciate the great
Probably none. But what about VAT or wrong – e.g. a large VAT penalty arises importance of information and
sales taxes? Still not that many. And for in an overseas territory? communication in considering many of the
corporate income taxes? questions raised here as it is the strength
Notwithstanding that ownership may lie of the information and communication
However if you are a CFO reading this with a local CFO, what accountability will processes which forms the foundation for
you may well be saying that you expect lie at the door of the head of tax if managing global tax risk.
your head of tax to be responsible for all something dramatic goes wrong? The
taxes and all tax risk – whatever tax that answers to these questions will provide Before addressing some of the questions
may be and wherever the tax happens to some initial thoughts as what structure raised above, let us take a slight
arise. We are aware of CFOs, particularly needs to be put in place in relation to digression to look at an operating model
in the US, who are expecting their heads managing the group’s global tax risk. which is increasingly common in an
of tax to sign off on the totality of the tax international group – the Shared Service
position for their group. So how do we There will be some subsidiary companies Centre – which brings with it their own set
manage the expectations of the group that have their own tax teams, either of tax risks which need managing.
CFO (and the board) against the reality reporting to the group head of tax or to
of what is happening on the ground? the local CFO (or both). The questions

Tax Risk Management 49


A number of international groups have set up Shared Services
Centres (SSCs) – often with a focus on bringing the accounting
and processing for a number of countries into one central location.
The rationale behind these SSCs has been to create greater
efficiencies and greater consistency across a group with often little
or no accounting expertise left in the individual countries.
Tax risks associated with Shared At the other end of the spectrum, we have legislation in a particular country, which
Service Centres yet to come across an SSC that has the required a specific election to be made –
ability to complete local corporate income and this election was missed. If VAT is to
The question arises as to how the various tax returns. In our opinion, it would be very be dealt with by an SSC then tax risk
tax returns, for the particular countries high risk to try and deal with such returns management procedures need to be in
covered by the SCC, are dealt with – and for another country in an SSC. Such returns place to ensure that local changes are
how, in particular, compliance tax risk is require significant local expertise and picked up and such risks are identified and
managed within an SSC environment. What invariably have to be dealt with in local managed. Alternatively, VAT can be
local tax returns should an SSC deal with, territories – and they are usually outsourced outsourced to a local, or trans-national,
what might they deal with and what should to a local service provider. The SSC does service provider who will be closer to
they not deal with? We have worked with a however continue to have a key role in changes in the countries concerned.
number of groups who operate out of SSCs providing the data to complete the returns.
and our comments below reflect the The main point here is that there are a
experience we have gained in this area. The However the position on some other tax number of different ways of dealing with tax
key point is to analyse the risks inherent in returns is not so clear-cut. Let us, for returns when the underlying information is
the various alternative ways of dealing with example, consider VAT or sales taxes. Prima being processed in an SSC. If we go back
tax returns and decide, on a cost/benefit facie, these are transaction taxes, and thus to our COSO model, we need a proper risk
basis, which is the most appropriate way should follow the withholding tax model and assessment of the issues and proper
forward for your SSC. be dealt with in the SSC. But the in-country control activities in place for whatever
rules for these taxes are different in each course of action is decided upon. The
There are some tax returns where the country, even across Europe where there is, control activities need to cover not only the
position is reasonably clear-cut. For in theory, a common approach to VAT. processing of the information, but also the
example, local withholding taxes on interest Methodologies can be set up so that the application of local tax law, both present
generally arise when the interest is paid. The information coming out of the SSC’s and changes in the future.
SSC will often be the only party who knows accounting systems feeds through to the
when the interest is being paid and it makes appropriate boxes on the return; the We have set out in the table below our
a lot of sense for the SSC to be responsible question is how these methodologies are experience of the different types of tax
for dealing with the withholding taxes. From kept up to date when there are changes in activity and where they are commonly
a risk management point of view a system legislation in particular countries. carried out when there is an SSC in
needs to be put in place to ensure the SSC existence. The driver here is the amount
knows what taxes to withhold, what forms to We are aware of a recent example that of local knowledge that is required to deal
complete and where to make the payments. cost a group a lot of money. Their with the tax return – and how you ensure
Of course in some countries this is not a processes were fine and produced the this local knowledge is brought to bear on
simple matter as there are a range of right VAT information from their SSC the tax return before it is submitted to the
different withholding rates depending on the accounting system. What they were relevant authority.
nature of the payments. unaware of was a change in local

Where is it dealt with? Type of activity

Usually dealt with in the SSC Withholding taxes


Tax packs/tax provision
Data extraction for corporate income tax returns

VAT and sales taxes


Sometimes dealt with in the SSC European Intrastat and sales listing returns

Property taxes
Municipal taxes
Usually dealt with locally Stamp duty
Employee taxes

Always dealt with locally Corporate income tax returns

50 Tax Risk Management


Managing these risks and of their tax position for use in new issues such an approach may indeed
planning and completion of home be the best way forward so all the issues
The framework spelt out in earlier chapters territory tax returns? can be thoroughly aired and discussed.
is, of course, equally valid in managing the However in a large group a more systematic
local overseas tax risks as it was in 3. Once information is collected from the approach may be required.
managing domestic tax risks irrespective of overseas territories how is it stored so
whether an SSC is part of your operating that it is always up to date, and readily 2 Use of technology
model. However, in our experience, the accessible to all those who need to use
biggest single issue in managing overseas it wherever they happen to be, Database and web technology lends itself
tax risks is communication and that is whenever they need it? very well to managing information across
where we want to focus the discussions in disparate locations. A good technology tool
the rest of this chapter. Of the three tax risk 4. The more service providers you have will help communicate what information is
areas highlighted above as being most around the world the more difficult it required (and when), standardise information
relevant to managing global tax risk, the becomes to manage the global process. formats, provide the repository for storing
best communication is probably seen in the There is unlikely to be much consistency and sharing information and (potentially)
area of financial accounting, as this has to as to the way work is carried out or highlight and/or chase for missing
happen annually and often quarterly. information is reported if you use multiple information. One caution: our experience is
Communication on compliance risk is service providers around the world. that provision of a good technology tool is
probably next best, but on the operational unlikely to bring about any significant
side, tax functions are often struggling to 5. Managing the position around the world, improvement in itself. It will only deliver
find out what is happening at a local in particular for financial reporting and results if the discipline surrounding its use
subsidiary level. compliance, can be a time consuming can be instilled/enforced. It is the information
and frustrating exercise – with numerous content that ultimately matters, not the
Communication is relevant to all five emails and phone calls, not necessarily technology that is used to manage it.
components in the COSO framework. at sensible times of the day.
Local subsidiaries need to have some 3 Basic discipline
understanding of the group’s tax risk policy 6. A lot of the time spent on managing the
and the control environment within which global issues could probably be spent Easing the gathering of the appropriate
the group is working. The head of tax on more value added activities – to the information requires investment in scoping
needs to understand where the local risks benefit of both the business and the out responsibilities and ensuring all
lie so that they can help put control individuals concerned. concerned take them seriously. If people in
activities in place and also find some way local subsidiaries are given responsibility
of monitoring these activities. In summary we would suggest that the for and clear guidance as to the information
following would be high on the agenda required, the format in which it is to be
We have worked with many global Heads of your head of tax: supplied, the timetable for provision and
of Tax and there are common themes the reasons why the information is needed,
around their communication issues with • Getting good quality information from they are more likely to provide what is
their overseas subsidiaries both on the subsidiaries needed without further chasing.
managing the tax position and managing • On a timely basis
the tax risk. These include: • On a consistent basis In large organisations, this discipline will
• Ensuring it is up to date need to be continually reinforced as the
1. How does the head of tax manage and • Without spending hours doing so group structure and the tax function’s
control what is happening in other contacts change. Inevitably not all
territories? For example how do you know To achieve this you clearly need to have information needed will be provided to
what activities the overseas subsidiary is some form of system in place. How do timetable, but if the requirements and
undertaking? How do you ensure that you do this – and are there better ways of timetable are properly defined and
local tax planning is for the benefit of the achieving the desired result? documented and responsibility for the
group as a whole and not just for the local provision of the information has been given
subsidiary? How do you know where 1. Direct communication then a junior (administrative) member of
compliance is falling behind or where the staff can be charged with following up
major compliance risks areas are? Face to face meetings, a lot of travel and missing information, rather than having to
numerous emails and telephone calls are have experienced tax staff spend time
2. How do you obtain good quality and one way for the group head of tax to keep chasing it up.
timely information from overseas on top of the tax risk management issues in
territories of both what they are doing other countries. Where there are significant

Tax Risk Management 51


4 Use of external service providers Compliance information:
• Status of filings by legal entity
To have an effective global tax risk • Due dates by legal entity
management system in place it is • Tax payment by legal entity
necessary to instil the appropriate • Compliance process task summary –
discipline into one’s team in other milestones (who, when)
territories. However this system and the • Work paper store – ability to attach
investment in both managing and documents
producing it does not necessarily need • Document store – statutory accounts,
to be made in-house. provisions, notices, completed returns
• Tax reconciliations
Certainly on the compliance side an
outsourcing service provider will Revenue authority audits:
probably already have put similar • Queries from taxing authorities and
solutions in place for other clients and status of responses
will be used to liaising with local territory
contacts to ensure the right information Other matters:
is gathered at the appropriate time. It is • Documented planning ideas and
certainly worth considering leveraging implementation status
off a service provider’s investment in • Global fees by jurisdiction
people, processes and technology • Foreign tax attributes to facilitate head
rather than try and secure internal office tax planning
investment in something that is non-
core to your business? Whilst the technology tool provides rather
more than is required from a pure risk
For example, we in management perspective, it does provide
PricewaterhouseCoopers have designed a mechanism or system for the group
a global compliance technology tool head of tax to manage better, in particular,
which is used to help a number of our the compliance risk within their group.
clients control their compliance
processes and compliance risks. The
sort of information which our clients are
able to track using this tool include:
Summary
There is an increasing requirement from
CFOs for their group’s Head of Tax to
Reference information: have ownership of the tax risks and tax
• Territory listing – it is perhaps surprising internal controls on a global basis.
how many head offices are not clear in Whilst it is not only financial risk, this is
which territories they have subsidiaries particularly so in relation to internal
• Legal entity listing – names of all the controls over the financial reporting of
companies in the group taxes in SEC registrants. The Sarbanes-
• Status of their legal entity – dormant, Oxley Act requires CEO’s and CFO’s to
operations or holding. attest on the adequacy of the design
• Legal entity type – corporation, GmbH, and operation of internal controls over
SA, etc. financial reporting.
• Identification number – VAT, corporate
income tax, other For some groups this will require a
• Address, date of formation, ownership fundamental shift, and perhaps an
• Global contact information – both the increase, in what they need to do to meet
client team and the these requirements. A systematic
PricewaterhouseCoopers team, to approach with strong information and
include email addresses, telephone communication procedures will
numbers and fax numbers undoubtedly be needed
and we see this as one of the bigger
challenges for the global tax function over
the next few years.

52 Tax Risk Management


8 Summary

What is clear is that Pandora’s box has What we have set out to do in this guide
been opened and tax risk management is is to stimulate the debate around tax risk
on many more people’s agendas. Whilst management and perhaps throw out one
assessing and managing tax risk is what or two challenges for people to pick up
tax functions have been doing for many and run with. Best practice in this area
years, there is now a need for a systematic will develop and we look forward to
organisational approach that ensures that ongoing discussions around the world
all significant tax risks are identified and with those in commerce and industry
managed. Communication is key and at no who have to address these issues in
time has ‘no surprises’ been more on the their own businesses.
agendas of senior management, boards
and the external market. Where this will By way of conclusion we would like to
take us over the next few years is open to leave you with the diagram we used in
speculation. However no leading tax Chapter 2 that reminds us that tax risk
function, and certainly no leading head of has an upside as well as a downside.
tax, can afford to ignore the issues we Businesses make money by taking risks.
have raised in this guide. Tax risk management is about a
considered approach to your tax risks – it
We have analysed the various types of tax is not about trying to reduce them to zero.
risk and we have set out how a
recognised internal control framework can
be applied to manage these risks. We do
not pretend that we have all the answers,
but we are investing in this area and
working through these issues with our
clients to develop practical and
appropriate risk systems.

Opportunity Transactions Operations Compliance

Uncertainty/
Variance

Hazard

Tax Risk Management 53


Appendix 1

TAX RISK MANAGEMENT


BEST PRACTICE CHECKLIST

Internal control
Question Yes No
component

Control environment Do you have a documented tax risk management policy?


Are there specific tax risk management objectives?
Have all relevant stakeholders had input to the policy?
Have all tax risk areas been included?
Has the tax risk management policy been discussed and
agreed at board level?
Has the policy and objectives been communicated to
all stakeholders?
Is there an appetite in the business to implement the policy?
Does the board review the position at least once a year?
Is the tax risk management policy aligned with the wider
objectives of the business?

Risk assessment Are there procedures in place to assess the tax risks
in the business?
Do they cover all areas of tax risk?
Do they cover all taxes?
Do they cover all significant countries in the group?
Do you know who are the key creators of tax risk in
your organisation?
Do you have processes in place to manage these people?
Do you know what the five key tax risks are in the business?
Do you use scenario planning to assess risk?
Are tax risks considered in aggregate to allow an overall
portfolio view of risks to be considered?
Is the tax risk assessment documented?

Control activities Are risk control procedures in place?


Are the five key tax risks in the business being
properly managed?

54 Tax Risk Management


Internal control
Question Yes No
component
(continued) Is it clear to the business when they need to consult the
tax function
Is it clear when the tax function needs to consult with
the board?
Are control activities communicated and embedded
throughout the organisation?
Is it clear who in the organisation has responsibility for
individual control activities?
Are the detailed control activities documented
agreed at board level?
Are you properly supporting those who have a risk
mitigation role (e.g. the shadow tax function)?

Information & Is the board kept aware of the key tax risks
Communication in the business?
Is the board consulted on major tax risk matters?
Is there a central place people can find out
about the business’ tax risk policy?
Is there a list of people (or roles) who need
to understand their role within tax risk management?
Are people new to roles within tax risk
management briefed on tax risk management
as it affects them?
Is the shadow tax department briefed on tax
risk management?
Is there training in place to ensure key
individuals understand their role in tax risk management?
Are processes in place to ensure the tax function is
kept aware of operational changes to the business?

Monitoring Is there a process in place to ensure that tax


risk management control activities are operating effectively?
Are internal audit involved?
Are the results of monitoring activities reported back to
senior management?
Is the monitoring process documented?
Is remedial action taken where risk assessment and
control activities are not found to be operating effectively?

Tax Risk Management 55


Appendix 2

1.1 Risk priority template by the type of underlying event.


TAX RISK ASSESSMENT Chance of event
TEMPLATES Impact Risk priority
Event happening
High, Medium, Low 1 = High, 5 = Low
High, Medium, Low
There are a selection of different tax risk
Acquisitions
assessment templates set out below.
Disposals
Individual people or businesses will
Mergers
choose the ones that best suit their Financing transactions
organisation. The templates below are Tax driven transactions
not the definitive tool to use in Internal Reorganisations
assessing tax risks in a business, but as
New business ventures
a starter that can be adapted to suit
New operating models
different circumstances and different
Operating in new locations
organisational structures. New operating structures
Impact of technological
1. Risk priority templates developments (e.g. Internet
trading)
Where such risk priority templates are
used as the top level summary for the Lack of proper management
Weak accounting records or
entire organisation, each line in the table
controls
would be supported by further tables Data integrity issues
analysing the risk assessment in greater Insufficient resources
levels of detail. For example in template Systems changes
1.1 below, the risk summary for Legislative changes
acquisitions could then be analysed either Revenue investigations
by location, type of tax or type of tax risk. Specific local in country
approaches
The aggregation of the risk assessment
Changes in legislation
should follow the entity’s organisational Changes in accounting systems
structure. So, if for example, an Changes in accounting policy &
organisation primarily follows a GAAP
geographic reporting structure, which
then operates within a country using tax Changes in personnel – both
type as its primary reporting structure, in tax and in the business
that organisation would be expected to Experienced people leaving
produce its highest level tax priority Inexperienced resources
template on a country-by country
Revenue authority raid or
analysis. This would then be supported investigation
by a tax type analysis for that particular Press comment
country, with the most detailed level of Court hearing/legal action
analysis for each separate tax type Political developments
analysed by event or type of tax risk.

The risk priority assessment reported is 1.2 Risk priority template by type of tax.
based on the high (H), medium (M) or low Impact Risk priority
Chance of risk
(L) outcomes reported in the chance of Type of tax arising
event happening and the impact columns High, Medium, Low High, Medium, Low 1 = High, 5 = Low
on the following basis.
Corporate income

Sales
HH priority 1
HM and MH priority 2 Excise
HL, MM and LH priority 3
ML and LM priority 4 Payroll
LL priority 5 Withholding

Others

56 Tax Risk Management


1.3 Risk priority template by location.
Chance of risk Impact Risk priority
Country or Entity arising
High, Medium, Low High, Medium, Low 1 = High, 5 = Low

Australia

Belgium

Brazil

Germany

India

United Kingdom

United States

This template could equally be used to analyse the risk priority by


entity/division/business unit etc.

1.4 Example risk priority template analysing risk by the type of tax risk.

Chance of risk Impact Risk priority


Type of tax risk arising
High, Medium, Low High, Medium, Low 1 = High, 5 = Low

Transactional

Operational

Compliance

Financial accounting

Portfolio

Management

Reputational

Tax Risk Management 57


2.1 Risk weighted cost template by the type of underlying event.
2. Risk weighted cost templates Chance of event
Event Impact Risk weighted cost
happening
A more detailed risk assessment $m B $m AxB
% A
approach, which allows resources to be
directed towards areas where they will Acquisitions
have greatest impact, is to use a Disposals
probability based approach to Mergers
evaluating the potential cost of tax risks. Financing transactions
Tax driven transactions
Internal Reorganisations
The following templates consider the
likelihood of an event happening and the New business ventures
potential impact of the event should it, New operating models
in fact, occur. Multiplying these two Operating in new locations
factors together gives a risk weighted New operating structures
outcome for each event. Impact of technological
developments (e.g. Internet
The flexibility mentioned when trading)
considering the risk priority templates
above apply equally to this type of risk Lack of proper management
assessment so that the risk weighted Weak accounting records
costs outcome can be built up for an or controls
entire organisation. This is potentially a Data integrity issues
more valuable tool in directing resources Insufficient resources
Systems changes
to address tax risks. However, it must
Legislative changes
be borne in mind that this tool is only as
Revenue investigations
strong as the accuracy of the underlying Specific local in country
likelihood and impact assessment – and approaches
judgement calls are needed to arrive at
these figures.
Changes in legislation
Changes in accounting
systems
Changes in accounting
policy & GAAP

Changes in personnel –
both in tax and in the
business
Experienced people leaving
Inexperienced resources

Revenue authority raid or


investigation
Press comment
Court hearing/legal action
Political developments

Total

2.2 Risk weighted cost template by type of tax

Chance of risk Impact Risk weighted cost


Type of tax arising
% A $m B $m AxB

Corporate income

Sales

Excise

Payroll

Withholding

Others

Total
58 Tax Risk Management
2.3 Risk weighted cost template risk by location

Chance of risk Impact Risk weighted cost


Country or Entity arising
% A $m B $m AxB

Australia

Belgium

Brazil

Germany

India

United Kingdom

United States

Total

2.4 Risk weighted cost template risk by type of tax risk

Chance of risk Impact Risk weighted cost


Type of tax risk arising
% A $m B $m AxB

Transactional

Operational

Compliance

Financial accounting

Management

Reputational

Total/Portfolio

Tax Risk Management 59


3. Specific tax risk templates component parts so you are clear where
the largest risks arise and hence where the
A series of templates can now be built up focus needs to be in managing these risks.
either around a type of tax risk, or a type
of tax, or the impact of a specific event, Let us, for example, look at compliance
or for a particular country or entity. The risk in country A – which has been
options are almost infinite and we do not recognised as one where there are
intend to produce all the different potential significant risks from the
permutations and combinations. What is corporate income tax returns being
however important is that you take the reviewed by the local revenue
items above which are either the priority authorities. The corporate income tax
risks or the highest risk weighted tax cost templates may look something like this:
and break them down into their

3.1 Example tax risk template for compliance risks for country A

Chance of risk Impact Risk priority


Compliance tax risk arising
High, Medium, Low High, Medium, Low 1 = High, 5 = Low

Income recognition

Disallowable expenditure:
• Entertaining
• Provisions
• Legal

Interest deductions

Capital v revenue

Allocation of capital
expenditure to tax
categories

R&D deductions

Transfer pricing

The aggregate assessment for Country other countries to give the organisation’s
A’s tax compliance risks could then be overall tax risk priority assessment for tax
summarised along with the other types of compliance risks.
tax risk area (such as operations,
transactions, etc) to give an overall tax The detailed templates will take time to
risk priority assessment for Country A. complete and the way forward may well
Alternatively it could be aggregated with be a rolling programme with the focus
the tax compliance risk assessment for being on different areas at different times.

60 Tax Risk Management


Copyright ©2004 PricewaterhouseCoopers LLP. All rights reserved. “PricewaterhouseCoopers” refers to PricewaterhouseCoopers LLP (a limited liability partnership,
registered in England under registration no. OC303525) or, as the context requires, other member firms of PricewaterhouseCoopers International Limited, each of which
is a separate and independent legal entity. The registered address of PricewaterhouseCoopers LLP is 1 Embankment Place London WC2N 6RH.
Designed by studio ec4 16471 (04/04).

Common questions

Powered by AI

Organizations can ensure continuous improvement in tax risk management by implementing regular training programs, conducting periodic audits, and adopting feedback mechanisms from both internal and external stakeholders. Utilizing technological tools for real-time monitoring, actively engaging with changes in tax legislation, and fostering a culture of openness to change and innovation also contribute to this continuous improvement. Additionally, conducting post-implementation reviews of control activities can identify areas for refinement .

Using a risk priority template can enhance tax risk management by systematically assessing the potential risk of different tax-related events based on both their likelihood and impact. By categorizing risks into priority levels, such as 'high', 'medium', and 'low', organizations can allocate resources more effectively, addressing higher priority risks first. This method helps ensure that significant risks are not overlooked and resources are not wasted on low-impact issues .

The hierarchical structure in tax risk management roles ensures effective control by distributing responsibilities across different levels of the organization, ensuring issues are identified and addressed promptly. Local CFOs/tax managers are closest to operational changes and can react quickly, while the head of tax oversees consistency and policy adherence globally. This tiered approach enables efficient risk identification, assessment, and response, critical in multinational organizations with diverse operations and regulatory environments across countries .

Changes in operational systems can pose tax risks by disrupting established processes that ensure compliance with tax regulations, potentially leading to inaccuracies in tax calculations and reporting. Control activities such as implementing robust data management systems, conducting thorough system testing, and maintaining comprehensive documentation can mitigate these risks. Additionally, involving IT professionals in risk assessments and ensuring that changes adhere to tax-related governance frameworks are crucial steps in managing these risks .

Aligning tax risk management activities with an organization's management and reporting structure ensures that tax risks are identified, assessed, and managed within the context of the organization's operations. This alignment helps streamline communication and decision-making processes, integrating tax risk management into routine business activities and ensuring that tax considerations are factored into all relevant business decisions. Additionally, it prevents duplication of efforts and ensures responsibility for tax risks is clearly defined and communicated, which enhances accountability and effectiveness .

Typical roles in a tax risk management framework include local CFOs or tax managers, tax team members, and external advisors. The local CFO/tax manager reviews and reports tax risks up the group hierarchy. Tax team members operate control activities and perform assessments, while external advisors offer expertise and conduct reviews from a regulatory perspective. Collectively, these roles help identify, assess, and manage tax risks, integrating tax risk management into the organization’s operational framework .

External advisors bring specialized knowledge and objectivity to the tax risk management process, offering insights into best practices and potential pitfalls. They can conduct mock audits and help set up control procedures, often leveraging their experience from working within tax authorities. The potential benefits include enhanced compliance and the identification of overlooked risks. However, limitations include dependency on external expertise and potential conflicts of interest. Advisors' recommendations may require adaptation to fit the specific context of the organization .

Internal audit functions contribute by reviewing the design and effectiveness of tax risk management controls, ensuring they function as intended. Despite their hesitance to engage deeply with tax-specific issues, internal audit teams can offer independent evaluations and aid in verifying compliance with tax policies. Their involvement is crucial in identifying weaknesses in control activities and facilitating remediation efforts. However, in practice, internal audits often lack tax-specific expertise, suggesting a potential area for improvement .

A risk-weighted cost template involves evaluating the potential financial impact of tax risks by multiplying the likelihood of an event occurring by its estimated financial impact. This provides a quantifiable risk cost, allowing organizations to prioritize resources based on financial criteria. In contrast, a risk priority template categorizes risks by priority level based on qualitative assessments of likelihood and impact. The risk-weighted cost template offers a more detailed financial perspective, whereas the risk priority template provides a broader, qualitative view .

Clear communication of tax risk management policies throughout an organization is important to ensure that all employees understand their roles in managing tax risks and align their actions with organizational tax objectives. Strategies to facilitate this include comprehensive training programs, clearly documented policies, and the use of communication tools that ensure consistent messaging. Effective communication enhances compliance and ensures that tax risk management becomes an integral part of the organizational culture .

You might also like