internal audit corporate risk management

Internal Audit & Corporate Risk Management  Risk management has come to be regarded as an essential element of good governance, and as an integral part of internal control.

Upload: laura-dabija

Post on 07-Apr-2018




0 download


Page 1: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 1/14

Internal Audit & Corporate

Risk Management 

Risk management has come to beregarded as an essential element

of good governance, and as anintegral part of internal control.

Page 2: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 2/14

Definition of risk

Risk can be defined as either:

a threat to achieving corporate objectives oroutcomes, or

an opportunity to enhance or accelerate theachievement of corporate objectives.

"The chance of something happening that willhave an impact on business objectives."

"Risk arises as much from failing to capturebusiness opportunities as it does from a threat thatsomething bad will happen."

Page 3: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 3/14

Definition of risk management

it is about making the most ofopportunities and about achievingobjectives once those decisions are


Controlling Risks

Transferring Risks

Living with Risks.

Page 4: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 4/14

The Turnbull report 

Turnbull stated that a sound system of internalcontrol:

Includes both financial and operational controls;

Helps to safeguard stakeholder and company

assets;Contributes to the management of risks whichimpact on the achievement of business objectives;

Helps to ensure reliability of reports to

stakeholders;Is dependent on a regular evaluation of the risks towhich a company is exposed.

Page 5: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 5/14

General Principles of Risk

Management & Internal Audit

In some organisations internal audit isdirectly involved in the riskmanagement function of the business.

In other organisations internal audit isinvolved in reviewing this function.

Page 6: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 6/14

Risk Management Cycle 

establish a business framework

identify all risks

measure risksdeal with risks

monitor arrangements.

Page 7: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 7/14

Risks may be identified from aseries of risk categories



health and safety


corporate issues




Page 8: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 8/14

two key aspects of risk:

cause - who or what causes the exposureto happen. This can be a type of person(e.g. staff or public); an event (e.g. fire,

flood); or it can be the absence ofappropriate action;

effect - the logical outcome of the potentialrisk turning into an actual exposure. This

should be described qualitatively (e.g.additional cost, loss of income).

Page 9: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 9/14

Measuring Risk 

Impact  Likelihood  Probability 

The organisation would notsurvive

Certain More than 80%

Major impact on theachievement of theorganisation’s business

plan and the quality of its overall services

Probable (likely tohappen eachyear)

50% - 80%

Significant impact on thesuccess of the businessand quality of its services

Possible (couldhappen in thenext three years)

25% - 50%

Some impact on theorganisation’s staff andminor effect on its clients

Unlikely (mayhappen in thenext five years)

5% - 25%

Insignificant impact on theorganisation or its staff 

Remote Less than 5%

Page 10: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 10/14

Deal with risks




Page 11: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 11/14

Example Format for Risk Matrix





dealingwith risk

Action Monitoringactivity & 


Page 12: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 12/14

Role of Internal Audit

It is fundamental that internal auditaddresses the organisation's mostsignificant risks. Internal audit will be

more effective if its view of theorganisation's most significant riskexposures is aligned with that of the

organisation's senior managers.

Page 13: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 13/14

Risk management is a vital aspect or dimension of

management and business planning 

bottom up risk identification of significantissues at departmental level to ensure thatstaff are extensively involved in the

process and risk management becomes anaccepted dimension of planning

top down strategic review of risks from theBoard's perspective to ensure that all risks

to achievement of corporate objectives areidentified and action on most significantrisks is prioritised.

Page 14: Internal Audit Corporate Risk Management

8/3/2019 Internal Audit Corporate Risk Management 14/14

benefits of adopting a formal approach to

corporate risk management 

clearly identifying all the significant risks that theorganisation faces

setting the evaluation of these risks in the contextof the organisation's corporate objectives

prioritising risks to ensure that management andresources are focused on the critical areas

developing a suitable level of risk awareness bymanagers and staff

ensuring a positive attitude to risk managementand knowledge of the organisation's policytowards risk.