295
RISK ASSURANCE
ARIZONA STATE UNIVERSITY
IEE 454 - RISK MANAGEMENT
WEEK 12
Part Eight Learning Outcomes:
•
explain the nature and purpose of internal control and the contribution that internal
control makes to risk management;
•
summarizesthe importance of controlenvironment withinan organizationand provides a
structure for evaluating the control environment (CoCo);
•
explained the importance of governance, risk and compliance (GRC) and its
relationship to the three lines of defense model;
•
summarize the importance of risk assurance and identify sources of risk assurance
available to the board/audit committee (CRSA);
•
describes the typical activities of the internal audit function and the relationship
between internal audit and risk management;
•
describes the activities involved in ERM initiatives and how these can be allocated to
internal audit, risk management, and line management;
•
discussed the importance of risk reporting and the various risk reporting obligations
imposed on companies, including Sarbanes-Oxley (SOX);
•
produces examples of risk reporting approaches adopted by different types of
organizations, including corporations, charities, and government agencies.
Case Study:
Unilever: Our appetite for risk and approach to risk management
Unilever adopts a risk profile that aligns with our vision to accelerate business growth
while reducing our environmental footprint and increasing our positive social impact. Our
available capital and other resources are applied to support our priorities. We aim to maintain
a strong single A credit rating over the long term.
The Unilever Board has overall responsibility for risk management and for reviewing
296
the effectiveness of Unilever's risk management and internal control systems. The Board has
established a clear organizational structure with well-defined accountabilities for the key risks
Unilever faces in the short, medium and long term. This organizational structure and
distribution of accountabilities and responsibilities ensures that each country in which we
operate has dedicated resources and processes for risk review and risk mitigation.
Unilever's approach to doing business is framed by our purpose. Our code of business
principles sets out the standards of behavior we expect all employees to adhere to. Day-to-day
responsibility for ensuring these principles are applied across Unilever rests with senior
management across categories, geographies and functions. Assurance of compliance with our
code of business principles and all code policies obtained annually from Unilever
management through a formal code declaration. The Board regularly reviews significant risks
and decisions that could have a material impact on Unilever. This review considers the level
of risk Unilever is prepared to take in pursuit of its business strategy and the effectiveness of
the management controls in place to reduce risk exposure.
Colgate Palmolive: Reputation damage:
Damage to our reputation can have a devastating impact on our business. Maintaining
our strong reputation with our consumers and trading partners globally is critical to selling our
branded products. Therefore, we devote significant time and resources to programs designed
to protect and preserve our reputation. Third parties sell counterfeit versions of our products,
which are inferior or may pose safety risks. As a result, consumers of our brands may confuse
our products with these counterfeit products, which may cause them to refrain from
purchasing our brands in the future.
Adverse publicity about us or our brands regarding health issues, legal or regulatory
proceedings, environmental impacts, including packaging, energy and water use and waste
management, or other sustainability issues, whether appropriate or not, can harm our
reputation. In addition, negative posts or comments about us on any social media website
could harm our reputation. Damage to our reputation or loss of consumer confidence in our
products for any of these reasons could adversely affect our business, results of operations,
cash flows and financial condition and require resources to rebuild our reputation.
If any of our products, or raw materials contained in our products, are deemed or
found to be defective or unsafe, we may need to recall some of our products. Whether or not
product liability or false marketing claims are successful, or a recall is necessary, such
statements can have a detrimental effect, and the negative publicity surrounding them can
damage our reputation and brand image. Further, if we experience loss or disclosure of
297
confidential business or stakeholder information as a result of a breach of our information
technology systems or the failure of a third-party service provider, we could suffer
reputational, competitive and/or business harm.
Sainsbury's and Tesco: Key risks and uncertainties:
The table below provides edited versions of descriptions of the three main risks faced
by two large UK-based retailers. They agree that these three risks have increased since the
previous report and accounts.
ENVIRONMENT CONTROL
33.1 NATURE OF INTERNAL CONTROL:
The internal control system in an organization is an important component in the
successful management of its risks. Internal control relates to the methods, procedures, and
checks in place to ensure that a business or organization meets its objectives. There are
several alternative definitions of internal control and some of the key definitions are presented
in Table 33.1. Internal control can be thought of as the actions taken by management to plan,
organize and direct the performance of actions sufficient to provide reasonable assurance that
objectives will be achieved. The expression 'control environment' is preferred by internal
auditors. ISO 31000 refers to the 'risk management context'. COSO refers to the 'internal
environment'. In all cases, the intention is to refer to the maturity level of the organization
with respect to internal control activities. When referring to internal control activities, it is
important to have a single definition within the organization. Table 33.1 describes some of the
most well-known definitions of internal control.
ISO Guide 73 defines control as a measure that modifies risk. It also states that
controls include procedures, policies, devices, practices, or any other action that modifies risk.
Guide 73 also makes the important point that controls may not always provide the intended or
assumed modifying effect. Internal control incorporates organizational structure and
hierarchy, as well as planning and goal setting. The scope of internal control extends to the
evaluation of controls designed to support the organization in achieving objectives and
executing strategies, but also applies to the control of actions to ensure that the organization
does not miss business opportunities.
When designing effective internal controls, organizations should look at existing
arrangements to achieve the following:
•
reliable system maintenance;
•
timely preparation of reliable information;
298
•
asset security;
•
optimal use of resources;
•
prevent and detect fraud and errors.
Effective financial controls, including the maintenance of proper accounting records, are an
important and established element of internal control. These financial controls help ensure
that the company is not exposed to unnecessary financial risks and that the financial
information used in the business and for public reporting is reliable.
33.2 INTERNAL CONTROL OBJECTIVES:
The main purpose of internal control activities is to help the organization achieve its
objectives. Typically, internal controls have the following objectives:
•
safeguard and protect the organization's assets;
•
ensure accurate record keeping;
•
promote operational effectiveness and efficiency;
•
comply with policies and procedures, including control procedures;
•
improve the reliability of internal and external reporting;
•
ensuring compliance with laws and regulations;
•
safeguard the interests of shareholders/stakeholders.
The internal control system includes internal control activities and the structures and
responsibilities associated with them. The purpose of this internal control system is to enable
the director to drive the organization forward with confidence, both in good times and bad. A
further objective of the internal control system and internal control activities is to safeguard
resources and ensure the adequacy of records and accountability systems. The purpose of the
control environment is to ensure a consistent response to the risks that materialize. A well-
developed control environment will also ensure that pre-planned responses to crisis situations
are efficiently and effectively implemented. There are a number of approaches to control
environment evaluation, including LILAC, CoCo and risk maturity models such as FOIL and
4Ns, as described in Chapter 24.
In many cases, the use of maturity models will help evaluate the status of the control
environment in terms of the application of selected structures that will be used to drive
improvements in the control environment and achieve a greater level of risk awareness within
the organization. . In summary, the LILAC or CoCo model will be selected as a means to
drive and measure improvements in the control environment. The successful implementation
299
of the chosen framework will be reflected by the level of risk maturity measured by FOIL and
4Ns that has been achieved. An enhanced level of maturity will enable the organization to
achieve more sophisticated results from its risk management efforts, as illustrated in Figure
4.2. The risk maturity model can be used as a means of benchmarking the risk management
status of an organization and targets can be set to improve risk maturity.
33.3 ENVIRONMENT CONTROL:
The Control Criteria Framework, otherwise known as CoCo, produced by the
Canadian Institute of Chartered Accountants (CICA) is a structured means of measuring the
quality of the control environment within an organization. The control environment, which
the COSO ERM framework labels as the 'internal environment', is a measure of the risk
culture within the organization. The view taken by the CoCo framework is that if the control
environment is satisfactory, risk management and internal control activities will be successful
and appropriately performed.
The structure of the CoCo framework is shown in Figure 33.1. The framework has four
components, which are represented as a continuous cycle. The components are based on a
sense of organizational direction, a sense of identity and values, a sense of competence and a
sense of evolution. A number of organizations use the CoCo framework as a means to
benchmark compliance with the internal control components of the COSO ERM framework.
Therefore, this approach will be based on a framework that is a combination of CoCo and the
other seven components of the COSO ERM framework. Table 33.2 provides more
information on the specific requirements of each of the four components of the CoCo
framework, as outlined below:
•
Objective;
•
commitment;
•
abilities;
•
monitoring and learning.
There are similarities between the CoCo approach and the LILAC measure of risk
awareness or risk culture mentioned earlier. The LILAC approach suggests that risk
management activities will be embedded when the risk culture features leadership,
engagement, learning, accountability and communication. Individual organizations must
decide how they want to measure the control environment/risk-aware culture within the
organization. Whatever method is used to measure risk culture, there is no doubt that it is
300
critical to the successful implementation of risk management.
CoCo is an internal control framework, but it is described in this chapter because it is
an established framework. There is a strong interface between risk management and internal
control activities, and therefore the CoCo framework provides a useful means of evaluating an
organization's risk culture. CoCo defines three main control objectives:
•
effectiveness and efficiency of operations;
•
reliability of internal and external reporting;
•
compliance with applicable laws and regulations and internal policies.
33.4 CONTROL ENVIRONMENT FEATURES:
There are significant differences between COSO and CoCo, as well as some key
similarities. CoCo has a broader approach to the control environment than that set out in
COSO. To give two examples of the broader approach in CoCo, it recognizes that controls are
necessary in goal setting, strategic planning and corrective action; it also recognizes that an
organization's control environment is important when making decisions. When conducting a
control environment evaluation using the CoCo structure, companies may find that good
scores are obtained for organizational objectives, commitment and capability. However, the
scores for the monitoring and learning components may not be good enough. This information
will allow the company to identify that it needs to pay more attention to the challenging areas
of objectives and the assumptions that lie behind them. Better control audits and structured
senior management reviews of risk management and internal control activities can then be
introduced.
The main difference in approach between COSO and CoCo is that CoCo is more
explicit about the following issues:
•
identification of needs to capitalize on opportunities;
•
mitigation of business resilience weaknesses;
•
the importance of individual trust in the quality of the control environment;
•
the need to periodically challenge assumptions.
There are two versions of COSO, and the COSO ERM framework (2004) is discussed in
detail in this book. COSO Internal Control was originally published in 1992, but was updated
in 2013 and the first component of the COSO Internal Control framework is called the control
environment. The characteristics of the control environment that COSO Internal Control
considers important can be summarized as follows:
•
The organization is committed to integrity and ethical values;
301
•
The board has oversight of internal control development and performance;
•
management establishes structure, reporting lines, authority and responsibility;
•
organizations strive to attract, develop, and retain competent individuals; and
•
The organization holds individuals accountable for internal control responsibilities.
Components of a good risk culture:
A good risk culture consistently supports appropriate risk awareness, behaviors and
judgments about risk taking within a strong risk governance framework. A good risk culture
supports effective risk management, encourages appropriate risk-taking, and ensures that
emerging risks or risk-taking activities outside of risk appetite are recognized, assessed,
improved and addressed.
A good risk culture should emphasize the importance of ensuring that: 1) a risk-reward
balance appropriate to risk appetite is achieved when taking risks;
2) there is an effective control system appropriate to the scale and complexity of the
organization; 3) quality
risk models, accuracy of data, ability of available tools to accurately measure risk, and
justification for risk taking can be challenged; and 4) all boundary violations, deviations from
established policies, and operational incidents are investigated with proportionate disciplinary
action when necessary.
33.5 INTERNAL CONTROL FRAMEWORK COCO:
The first component of the CoCo framework is concerned with setting and
communicating objectives, significant internal and external risks faced by the organization
and policies designed to support the achievement of the organization's objectives. Plans to
assist in the achievement of objectives and the inclusion of measurable targets and
performance indicators are also important aspects of the objectives component of CoCo.
When setting and analyzing organizational objectives, CoCo makes clear that the risks and
opportunities facing the organization should be analyzed in detail. The importance of risk
assessment and organizational resilience is emphasized, along with the importance of
recognizing the sources and origins of risks.
The commitment component of the CoCo relates to shared ethical values, including
integrity. It also relates to human resources and communication policies and practices
throughout the organization. Authority, responsibility and accountability are also including,
together with the requirement to achieve an atmosphere of mutual trust. The capability
302
component of CoCo relates to the fact that people must have the necessary knowledge and
skills to support the organization's goals, as well as its values. Sufficient relevant information
must be identified and communicated, along with the decisions and actions of the various
parts of the organization. Activities must be coordinated and designed as an integral part of
the organization.
The monitoring and learning component of the CoCo framework relates to the external
and internal environment and the fact that they must be monitored for information.
Performance should be monitored against targets and indicators and the assumptions behind
the organization's goals should be challenged periodically.
Information needs and related information systems should be assessed when objectives
change, and procedures should be established and carried out to ensure that appropriate
change actions occur in these circumstances. Finally, management should periodically assess
the effectiveness of controls within the organization and communicate the results to
appropriate stakeholders. An example of an organization evaluating its control environment is
presented in the box on the next page.
Evaluating the control environment:
Many organizations have created their own formulas to educate employees about why
controls are important and what adopting such measures means to them. A common element
among these organizations is a commitment by senior management that embraces the internal
control model. Canada Post Corporation uses eight key groupings to evaluate the control
environment, as follows:
•
leadership;
•
planning;
•
customer focus;
•
people focus;
•
process management;
•
partnership;
•
business performance;
•
continuous improvement.
During the self-assessment workshop, executives receive the final results of all audit work
performed during the year. The group then discusses the business goals for the coming year
and the risks that could interfere with achieving them. Participants rate themselves on a scale
of 1 to 10 for each criterion. Internal audit then compares the information it received directly
303
from the business process with the information the group obtained about the process during
other workshops.
Using the workshop results, internal audit develops an audit opinion on control
effectiveness and an audit plan for the coming year. In addition, internal audit provides a
summary of the results to the board of directors for consideration in its strategic planning
sessions. The report includes comments on the company's five highest risks and five weakest
controls.
33.6 GOOD SAFETY CULTURE :
Ensuring a risk-aware culture in the organization is essential. A risk-aware culture will
be achieved when all staff members and management understand and accept the importance
of adequate risk management. In addition, management and staff need to understand the role
they will play in successful risk management and have the desire to fulfill that role with
enthusiasm. There are many ways in which a risk-aware culture can be demonstrated.
Obviously, one way to demonstrate such a culture is to achieve a high score in the CoCo
analysis. COSO ERM also has an internal environment component, although this component
is not as comprehensive as the CoCo framework. Nevertheless, it is possible to evaluate the
internal environment and the level of risk awareness in an organization using the COSO ERM
framework.
Many organizations consider the combination of COSO and CoCo to be an ideal way
to combine the detailed approach to measuring culture in CoCo with the more complete
approach of COSO. ISO 31000 refers to the context of risk management. Context has three
components in ISO 31000, described as internal context, external context and risk
management context. Together, the analysis of these three contexts will provide information
about the status of the risk-aware culture in the organization. Part of a good risk-aware culture
is a strong safety culture. After the major train accident at Ladbroke Grove near London
Paddington railway station in 1999, the Ladbroke Grove Inquiry heard various definitions of
the word 'culture'. The Advisor to the Inquiry said that:
A good safety culture is the product of individual and group values, of attitudes and patterns
of behavior that lead to a commitment to organizational health and safety management.
Organizations with a positive safety culture are characterized by communication based on
mutual trust, by a shared perception of the importance of safety and by a belief in the
efficiency of preventive measures.
304
Research by the Health and Safety Executive into the components of safety culture
resulted in a detailed report and the key components of safety culture were identified as
leadership, engagement, learning, accountability and communication. This gave rise to the
acronym LILAC, which is explained in more detail in chapter
24. This is an alternative approach to the objectives, commitments, capabilities, monitoring
and learning components of the CoCo framework.
RISK ASSURANCE TECHNIQUES
34.1 COMMITTEE AUDIT:
More and more organizations have decided that it is appropriate to have an audit
committee. Almost always, the audit committee consists of non-executive directors, with
senior executive directors attending audit committee meetings. It is chaired by a non-
executive director, often referred to as the lead non-executive director, but usually not the
non-executive chair of the organization. The audit committee is generally not considered a
sub-committee of the board, but has the status and seniority that allows the audit committee to
evaluate all activities within the organization, including those of the board itself.
While the audit committee may be considered the guardian of compliance within the
organization, the terms of reference are usually much broader than just compliance. The
organization's board will be responsible for governance across the organization, including
coordinating the activities of specialist risk management functions. In this way, the board is
responsible for the first and second lines of defense. In other words, the board is responsible
for the governance and risk components of governance, risk, and compliance. The audit
committee is in a position to evaluate governance standards within the organization, ensure
that risk management receives appropriate attention, and seek assurance over the level of
compliance achieved within the organization. The role of the audit committee may be much
broader than this, and include evaluation of the board's own governance arrangements. Many
large organizations establish a separate committee to make senior appointments, including
appointments to the board. This committee is commonly referred to as the nomination
committee. Similarly, many large organizations will have a committee responsible for setting
the remuneration and benefits structure that will apply across the organization.
The existence of a separate nomination or remuneration committee does not diminish
the role and responsibilities of the audit committee. Nomination and remuneration, as well as
305
some other committees, will be sub-committees of the board and may have joint executive and
non-executive membership. In reviewing the effectiveness of the board, the audit committee
will also evaluate the effectiveness of the sub-committees. Given this role, the audit
committee will maintain its position as the primary monitor of governance, risk and
compliance across operations. The audit committee will seek assurance relating to all aspects
of the organization's strategy, tactics, operations and compliance.
The results and impact of risk management activities are often reported to the audit
committee of a large organization. The audit committee has various responsibilities, including
the obligation to obtain adequate risk assurance within the organization. Table 34.1 provides a
list of typical audit committee responsibilities. Audit committees should be non-executive
bodies that do not have executive responsibility for risk management. Similarly, they should
not have responsibility for identifying significant risks or identifying and implementing
critical controls. The function of the audit committee is to seek risk assurance and check that
procedures for identifying risks are in place significant risks are appropriate. The audit
committee should validate that significant risks have been properly identified, as well as seek
assurance that critical controls have been properly implemented.
The audit committee is concerned with internal control within the organization.
Internal control is described in the UK Corporate Governance Code guidance as the overall
system of controls, financial and otherwise, established to provide reasonable assurance of
effective and efficient internal control and compliance with laws and regulations. It is
important to consider the role of the audit committee in relation to the requirements of the UK
Corporate Governance Code. This code only applies to companies listed on the London Stock
Exchange, although the principles set out in the code appear to be gaining wider acceptance
and application. One of the requirements is that companies without an internal audit function
should review the need for such a department on a regular basis. Even if this requirement does
not apply to an organization, it is still worth the audit committee ensuring that it can fully
respond to these questions, by ensuring that the necessary information is gathered. An
important component of the governance requirement is the recognition of the limitations of
internal controls.
34.2 RISK MANAGEMENT ROLE:
The risk management policy should define roles and responsibilities for risk
management and internal control. The purpose of risk management is to fulfill statutory
obligations, provide assurance, support decision-making and help ensure the effectiveness and
efficiency of core processes (MADE2). When allocating risk management responsibilities,
306
consideration should be given with respect to each significant risk faced by the organization
on the allocation of separate responsibilities for:
•
determine the strategy;
•
designing controls;
•
audit compliance.
For example, the head office department may decide on the appropriate level of security for
an organization. The design of appropriate controls may be the responsibility of the
production department. This is appropriate as security risks may be an integral part of
production that needs to be under the ownership of the production department. In other
organizations, it may be appropriate for the security arrangements to be designed by a
specialist security advisor or head of security within the company. Auditing compliance with
security arrangements is likely to be the responsibility of the internal audit department. Even
in small organizations, it may be important for fraud risk management responsibilities to be
separated between different employees or departments.
In a small charity, for example, it may be appropriate for a non-executive board
member to conduct an internal control audit and thereby provide an objective view of the
efficiency and effectiveness of the internal financial controls in place at the organization. The
role of the risk manager in this allocation of responsibilities should be a facilitating role. The
risk manager can facilitate workshops designed to identify fraud risks within the organization
and allocate responsibility for controlling them. However, risk managers cannot be
responsible for implementing controls or auditing compliance. Risk management and internal
audit should limit their roles to evaluating the effectiveness of controls and helping identify
whether additional and/or different control measures should be implemented. Risk managers
should recognize the added value of internal audit, as outlined in the text box below.
the added value of internal audit:
While what constitutes a value-added activity will vary based on many factors, there
are some general rules that apply across the board. Four factors that can help auditors
determine what will add the most value to their organization are:
•
knowledge of the organization, including its culture, key players, and competitive
environment;
•
the courage to innovate in ways that are not expected and may not be desired by
stakeholders;
•
the ability to adapt to the organization in a way that exceeds stakeholder expectations;
307
•
knowledge of practices that are generally regarded as value-added by the profession.
Three of these factors (organizational knowledge, courage and adaptability) are competencies
and personal qualities that are largely self-explanatory. However, knowledge of practices that
are considered value-added by the profession is an ongoing professional challenge for internal
auditors.
34.3 GUARANTEE RISK:
Risk assurance is an important component of the overall risk management process.
The audit committee will seek assurance that all significant risks have been adequately
managed and that all critical controls are effective and have been implemented efficiently.
There are often discussions in the audit committee about 'how seriously a particular
department takes risk management and internal control'. Risk managers and internal auditors
will certainly be able to give an opinion. However, what the audit committee will need is an
objective evaluation of the department's performance. This objective evaluation of the risk
culture within the department will be the primary basis of assurance for the audit committee.
There are other sources of assurance available to the audit committee and these are listed in
Table 34.2. Depending on the nature of the organization, the audit committee may rely on
some or all of these sources of assurance. Risk assurance is also available from external
auditors, although this may be limited to validation of accounting processes and financial
performance.
Assurance will also be required in relation to the risk management activity itself. The
review and monitoring stage of the risk management process is usually represented as a loop
of information and experience that provides feedback to the beginning of the process. When
considering the review and monitoring activities that need to be carried out, the following
steps should be kept in mind:
•
review of the process as it operates within the organization;
•
review of applicable risk control standards;
•
review of success rate in reducing risk exposure;
•
review of the success rate of achieving business objectives;
•
an overview of why a high-risk strategy, project or operation was successful;
•
delivery of risk assurance throughout this activity.
When a company plans to borrow more money from a bank, it may be required to show how
the board obtained assurance that significant risk management is satisfactory. Available
sources of assurance may include:
308
•
evaluation of the organization's risk culture;
•
the quality of audit reports produced by internal audit;
•
quality of reports produced by various departments;
•
overall business success of each department.
Companies may decide that reports from internal audit and quality reports from departments
will form the basis of risk assurance. The company may also introduce a risk self-assessment
procedure (CRSA) which will be based on the components as set out in the 2014 risk
guidance published by the Financial Reporting Council. Areas of weakness identified in the
CRSA returns will be reported to the executive committee and remedial action will be
required. All these measures will provide greater assurance to the board and put the company
in a better position to secure additional funding from banks.
When considering risk assurance, organizations need to evaluate various
issues, depending on whether the evaluation is related to strategy, tactics, operations or
compliance. Assurance of adequate hazard risk management can be achieved by an evaluation
of the department's hazard risk performance. Depending on the organization's risk priorities,
the board or audit committee may require an annual report on specific hazard risks. Due to the
importance of health and safety in the workplace, the board usually receives an annual report
on safety performance. Likewise, the audit committee will want to receive an annual report on
fraud incidents that have been detected within the organization. This is especially true for
organizations that handle large amounts of cash.
Risks relating to uncertainty, and in particular to the successful completion of projects,
are often the subject of review by the board or audit committee. In large organizations, it is
common to have post-implementation reviews of projects. For example, if the board of a retail
company has authorized the opening of a new store, the audit committee will request a review
of the completion of the store opening project. This post-implementation review will evaluate
whether the project was completed on time, within budget, and according to Specifications. It
is also common for audit committees to request further post-implementation reviews of the
first 12 months' trading of a new shop.
Underwriting risks associated with strategies/opportunities is more difficult and
somewhat less so well developed. Nevertheless, there are more and more examples of
organizations conducting opportunity evaluations. This is becoming increasingly common in
professional consulting firms. When a new business prospect arises, many professional
consulting firms have an opportunity review committee that decides whether the organization
wants to offer its services to the prospective client. This type of opportunity evaluation can
309
initially be achieved by attaching a risk assessment to a new business proposal.
34.4 RISK MANAGEMENT OUTPUTS:
When working together, risk management and internal audit should always
concentrate on the output of the risk management process and the impact sought. The
contribution of risk management is to ensure greater opportunities to achieve organizational
objectives, and this is also the stated intention of the internal audit activity. Overall, the
outputs of risk management/internal auditing are intended to achieve improved organizational
performance in the four critical areas of strategy, tactics, operations, and compliance (STOC)
that are effective and efficient. These outputs will be achieved by ensuring minimum
disruption to routine operations from risk of harm, along with the selection of effective
processes appropriate for the organization. Effective process selection requires informed
decision-making and successful project design and execution. Risk management and internal
audit must work together to achieve this outcome.
The most important decisions made by an organization relate to strategy. Risk
management and internal audit both have a role in helping the organization reach strategic
decisions that result in effective and efficient strategy development. For example, risk
management should ensure that risk assessment workshops address strategic decisions and
internal audit should evaluate the quality of strategic decision-making procedures.
The required outputs of risk management/internal audit can be summarized as
fulfilling mandatory obligations, providing assurance, supporting decision making and
ensuring effective and efficient core processes (MADE2). Risk management and internal audit
must work together to achieve these outcomes. Attention should always be paid to internal
audit's desire to remain independent of executive management as they fulfill their activities.
This need to maintain independence is another reason why internal audit should not become
overly involved in executive roles and responsibilities related to risk management.
34.5 CONTROL SELF-ASSESSMENT RISK:
In addition to conducting physical audits, internal audit departments will often
facilitate self-certification of controls procedures. Self-certification of controls is an
arrangement where local senior management complete regular (often annual) returns
confirming details of the level of risk assurance that has been achieved in the department.
Type This self-certification is commonly known as a control risk assessment (CRSA) and is
often conducted as an electronic return or recorded on the organization's intranet. The
questionnaire for a control risk self-assessment can be based on criteria set out in COSO,
310
CoCo or another relevant internal control framework, such as the 2014 risk guidance from the
UK Financial Reporting Council (FRC).
In addition to providing confirmation of adequate levels of internal control and risk
assurance, CRSA returns can also provide details of situations where significant weaknesses
in controls have been identified. This information will enable internal auditors to identify
areas where additional controls may be required. Also, in addition to identifying significant
weaknesses, CRSA returns may require information on material failures that have occurred. A
benchmark test for identifying material failures should be provided and will be significantly
lower than the materiality test applied by external auditors. For example, an organization that
has set the materiality test at £1 million may require a CRSA return report of any failure in
control that results in an incident/loss of more than £1 million 100,000 at the department level.
Approach to Crsa:
The executive has recommended the use of an annual 'control risk self-assessment'
(CRSA) exercise, to be conducted by internal audit, as part of the annual review of corporate
governance. Each year a sample of governance policies will be selected by the governance
panel for inclusion in the CRSA exercise. Policy custodians will be asked to help formulate
the questionnaire and report back the feedback received from the service to internal audit. The
findings from the CRSA exercise, together with an assessment of compliance with each of the
supporting principles and the work carried out by internal audit in accordance with the annual
audit plan will be incorporated into the annual governance statement, for review by the
governance panel, audit committee and executive committee.
34.6 BENEFITS OF UNDERWRITING RISK:
Corporate governance is a key concern for all organizations and their stakeholders.
Therefore, risk assurance should not be an administrative exercise or a checkbox.
Organizations need to demonstrate that corporate governance is a priority for management.
Many organizations recognize the need for openness in risk reporting. This requires effective
communication activities to be conducted at all times. Once good communication activities
are in place, organizations need to ensure positive messages are communicated to
stakeholders. Conducting risk assurance activities will provide assurance to all stakeholders,
including employees, suppliers, customers, government departments, external audit and
internal audit, as described in the text box above.
Obtaining risk assurance is an important part of corporate governance arrangements
for all organizations, and benefits core strategic, tactical processes, operations, and
311
compliance (STOC), activities, and decisions of the organization. The benefits of adequate
risk assurance are:
•
build trust with stakeholders;
•
provide assurance to sponsors and financiers;
•
demonstrate good practices to regulators;
•
preventing financial and other surprises;
•
reduce the possibility of reputational damage;
•
encourages a culture of risk within the organization;
•
allows for a more secure delegation of authority.
Risk Assurance Level:
While the external auditor's work is not primarily performed for the benefit of the
organization, the audit and risk assurance committees should still be involved with this
activity. In addition to considering the results of the external audit work and the resolution of
identified weaknesses, they should inquire about and consider the external auditor's planned
audit approach.
They should also consider the ways in which external auditors work with internal audit
to maximize overall audit efficiency, capture opportunities to obtain greater levels of
assurance and minimize unnecessary duplication of work. In addition, they should review and
consider the potential implications for the organization of the broader work performed by
external auditors, for example, value for money reports and good practice findings.
INTERNAL AUDIT ACTIVITIES
35.1 INTERNAL AUDIT SCOPE:
There needs to be a close working relationship between risk management and internal
audit. The responsibilities allocated to each of these functions will vary according to the
nature, type and size of the organization. This is an important working relationship, as the
success of risk management depends on four important risk-based outputs, which can be
summarized as MADE2:
•
obligations as required by law, customers/clients, and standards;
312
•
assurance for the management team and other stakeholders;
•
decision-making based on the best available information;
•
effective and efficient core processes throughout the organization.
It is clear that if these outputs are to be successfully delivered, all stakeholders need to work
together, and that includes cooperation between risk management and internal audit. The
range of activities associated with risk assurance is explored in Chapter 34. The important
contribution made by internal audit and the various activities that internal audit departments
perform are discussed in more detail in this chapter. Internal control relates to the methods,
procedures, and checks that are in place to ensure that a business organization meets its
objectives. Since internal control is concerned with the fulfillment of objectives, there is a
clear relationship with risk management activities. Internal control activities within an
organization will most likely be evaluated by the internal audit department. In some cases, the
internal audit function may be outsourced to an external accounting firm. Despite the
differences between internal audit and risk management approaches and activities, there are
areas of common interest. It is generally accepted that risk management is an executive
function that should be performed by the executive members of the organization. This leads to
the conclusion that the risk management committee should be chaired by an executive board-
level director. Internal audit is primarily concerned with risk assurance, and this would be the
concern of a non-executive audit committee in a large organization. Given that internal audit
validates the controls and procedures in place to manage risk, it is inappropriate for internal
auditors to fulfill an executive function by assisting management in identifying, designing,
and implementing measures risk control measures.
Internal control expectations:
A good internal control system reduces, but does not eliminate, the possibility of poor
judgment in decision-making, human error, deliberate circumvention of control processes by
employees and others, controls that override management, and the occurrence of unforeseen
circumstances. Therefore, a sound system of internal control provides reasonable, but not
absolute, assurance that an enterprise will not be prevented from achieving its business
objectives, or from conducting its business in an orderly and lawful manner, by reasonably
foreseeable circumstances. However, a system of internal control cannot provide definitive
protection against a company's failure to meet its business objectives or all material errors,
losses, fraud, or violations of laws or regulations.
313
Internal financial controls in charities:
Internal financial controls are just one part of a charity's overall control framework.
The wider framework should cover all the charity's systems and activities. Executive
management, staff and volunteers are responsible for ensuring that the controls put in place by
the trustees are implemented. There should be a culture of control embedded in the operation
of the organization; this culture is created by trustees and senior management, who should
lead by example in complying with internal financial controls and good practice.
Trustees should, at least annually, ensure a review is carried out of the effectiveness of
internal financial controls. This should include an assessment of whether the controls are
relevant to, and appropriate for, the charity and are not unduly or disproportionately onerous.
A key feature of internal financial controls is to ensure that no individual has sole
responsibility for any transaction from authorization to completion and review. It is important
where trustees manage the charity personally, more likely in smaller charities, that there is
sufficient separation of duties between them, so that no trustee is overburdened or carries sole
responsibility.
35.2 INTERNAL AUDIT ROLE:
Figure 35.1 illustrates the various activities that need to be performed to fulfill a
successful ERM initiative. The diagram identifies activities that are core to the work of the
internal audit department. These activities include reviewing the management of key risks,
evaluating the reporting of those risks, and evaluating risk management processes. The
diagram also identifies activities that internal audit should not be involved in. These activities
include establishing risk appetite, implementing risk management processes, and making
decisions about risk response. In between these two sets of activities are activities in which it
is legitimate to involve internal audit, provided appropriate safeguards are in place. These
activities include facilitating risk identification, coordinating ERM activities, developing the
ERM framework and championing the establishment of ERM. The division of responsibilities
set out in Figure 35.1 not only conforms to the three lines of defense approach; it reinforces
that approach and provides considerable detail on the allocation of responsibilities. Use of the
information shown in Figure 35.1 will help organizations allocate responsibility to
management as the first line of defense, specialist risk management functions as the second
line of defense, and internal audit as the third line of defense.
Setting audit priorities is an important function of the audit department. In conjunction
with risk management activities, internal auditors need to set their priorities for control
314
testing. There is an important interface between risk management and internal controls. Risk
management professionals are excellent at assessing risk and identifying the right type of
controls that should be in place. Risk registers will often note current controls and make
recommendations for the implementation of additional controls. The internal auditor's core
work begins at this point. Having identified the controls that are critical, the auditor needs to
check that those controls are applied in practice and that they are correct and effective. The
result of testing controls is to ensure that the desired level of risk is actually achieved in
practice. In other words, the control actually moves the risk level from the inherent level to
the intended current level in the planned and often assumed way.
If controls are not effective and efficient then modifications need to be made. This is
another area where risk management and internal audit share expertise. While these
discussions about controls may be facilitated by risk management and internal audit, the final
decision about the control and its anticipated effectiveness should be made by the member of
line management responsible for the control.
35.3 CONDUCT INTERNAL AUDITS:
Conducting an internal audit involves a number of steps, as shown in Table 35.1.
Basically, the steps involved are planning an internal audit exercise, conducting fieldwork
where controls are tested, producing an audit report and, finally, ensuring that there is
adequate follow-up. As part of the audit exercise, the auditor should gather information
relevant to the audit that will be conducted. Analysis of the information that has been
collected will enable the auditor to determine and agree on the priorities and objectives of the
review. For example, a supply chain audit will require the auditor to collect information on
existing contracts with suppliers. In many instances, fieldwork is the most important part of
the audit exercise. Auditors may need to visit sites, including supplier sites if the audit relates
to the supply chain. The purpose of fieldwork is to understand the risks and the controls in
place to manage those risks. Control testing will then be performed to ensure the efficiency
and effectiveness of the controls in place. This control testing will be based on discussions
with managers and staff, as well as observations of the activities that are being performed.
done.
Based on the fieldwork performed, the auditor will produce an audit report. The audit
report will contain comments on the efficiency and effectiveness of the controls in place and
recommendations for further improvements, if deemed necessary. The internal auditor needs
to form an independent opinion on the level of control that has been achieved so that
assurance can be provided to the audit committee, as far as this is justified. Also, if the audit
315
report sets out recommendations, these should be approved by local/departmental
management. The reason for approving recommendations is that they are more likely to be
implemented, if they have been agreed upon. However, if the internal auditor feels that
controls are inadequate but local management does not accept this conclusion, escalation of
the matter will be necessary.
35.4 RISK MANAGEMENT AND INTERNAL AUDIT :
In many large organizations, the working relationship between risk management and
internal audit can be difficult. Internal audit will work with an agenda that concentrates on
effectively implementing efficient controls. Generally, the head of internal audit will have a
senior reporting line to the most senior non-executive board member, perhaps even the
chairman. Risk managers often have a less senior reporting line, usually to an executive board
member. This is likely to be the company secretary or finance director. The difference in
reporting lines can be frustrating for risk managers, but the complementary roles of risk
management and internal audit should be seen as an opportunity to ensure more effective
implementation of risk management protocols and procedures.
Both parties should look for areas where they can work together without
compromising the overall goal of their individual contributions. For example, both risk
management and internal audit should attend risk assessment workshops. Risk managers can
facilitate risk assessment workshops, but the responsibility for managing risk will always rest
with the managers of each operational department. Also, the presence of internal auditors at
risk assessment workshops should not be seen as a threat by line management.
Internal audit professionals require that control measures be identified in very precise
terms that can be audited. The focus of internal audit activities is on the impact of control
measures actually in place in practice. During an audit, internal auditors will request and be
provided with information and data. The internal auditor's approach is to test that information,
so that the facts of the situation can be established. In short, internal auditors take the rather
challenging view that information plus testing equals facts.
An approach that has grown in popularity in recent years is commonly referred to as
the three lines of defense. This approach is fully consistent with internal audit's role in
enterprise risk management, as identified in Figure 35.1. The three lines of defense model is
based on the idea that: 1) management has primary responsibility for risk management; 2) a
specialist risk management function can assist with risk management.
management in developing approaches to fulfill their responsibilities; and 3) the internal audit
function checks that the risk management process and risk management framework are
effective and efficient.
The main roles of management can be divided into three layers of top management
(directors), middle management (managers) and staff or employees. This division corresponds
to the roles and responsibilities allocated to the three levels of management in Table 1.
22.1. A specialist risk management function may operate at a corporate or group level as the
overall facilitator of the development, implementation, monitoring and improvement of the
risk management framework. The risk management function will also cover business
continuity, and health and safety. This specialist risk management function fulfills the same
role as the group risk management function, but within more specific risk areas. The specific
roles and responsibilities allocated to the risk management function are also shown in Table
22.1.
The three lines of defense approach also fits with the concept of governance, risk and
compliance (GRC), which is illustrated in Figure 35.2. The GRC approach is based on the
overall view that the board is responsible for governance issues throughout the organization.
In this role, the board will look at all three lines of defense to ensure adequate attention is paid
to risk. Non-executive directors, in particular, will look to internal audit to provide assurance
on various compliance issues within the organization.
The requirement to keep accurate financial records applies to all organizations, and
these will often be created by an external accounting firm, who will also act as external
auditors. The external auditor will be required to confirm, and in some cases prove, the
accuracy of the financial records. These external auditors can be considered the fourth line of
defense. In addition, for highly regulated organizations, there will be regulators who require
adherence to rules and regulations within the organization their scope. Under such
circumstances, regulators can be considered the fifth line of defense.
As with many areas of risk management and internal control, the terminology is
used will vary from organization to organization. The box on page 418 describes the three
lines of defense approach applied to tax and how it differs from the approach defined above.
Nevertheless, the organization in this example recognizes that responsibilities need to be
shared and that three lines of responsibility is an appropriate and robust way to ensure
adequate governance and compliance and, in the case of the example, efficient and effective
tax risk management. An area where risk management and internal control can work together
is in setting risk management/internal control priorities for the coming year.
When an organization establishes a risk-based audit program, it will seek to ensure that
internal audit activities are focused on the significant risk priorities facing the organization.
The board may seek a joint risk management/internal audit contribution that will achieve
better strategic decisions, more successful project delivery, and more efficient core processes.
The introduction of a risk-based audit program will be facilitated by ensuring that internal
audit participates in risk assessment workshops and that risk management and internal audit
produce a joint annual work program. The overall intent is to ensure that control measures
discussed at risk assessment workshops are described in the risk register as fully auditable
controls, and to ensure that managers have a greater awareness of their control responsibilities
and fulfill those responsibilities in practice.
Three lines of defense applied to taxes
Three lines of defense is a concept that seems to have quietly taken over the entire
field of risk management. It now seems ubiquitous in financial services and is finding its way,
often through public sector procurement requirements, into a variety of new areas.
But while it may be used elsewhere in an organization, it has not been widely applied
to tax risk management so far. Tax risk management is about having clear and understood
roles and responsibilities that include data management, transaction processing, information
gathering, verification and escalation. Applied to tax, the three-line concept can broadly look
like this:
•
First line: this means having a strategic understanding and the right people responsible
for the basic business processes that affect tax - complete and accurate recording of
transactions, e.g. purchases for payment, record keeping for reporting, and fixed asset
processes, and the collection and processing of related tax information.
•
Second line: this is a regular monitoring process. This requires frameworks and
guidelines, developed by the tax and finance functions together, designed to facilitate
effective monitoring of tax risks, addressing problems early and identify weaknesses
in the process. People are human and they make mistakes.
•
Third line: this is independent assurance that the tax function is doing well, whether
through internal or external audits. This requires that internal auditors get up to speed
on tax risk issues, and that the tax function welcomes the additional assurance that a
successful audit can bring. After all, it is better for your internal auditors to find errors
than to have to explain them to the tax authorities.
There are advantages and disadvantages to having a close working relationship between risk
management and internal audit. In many ways, there is a complementary fit between the two
disciplines and there are benefits in having a common focus and coordinated planning related
to risk management. Also, there are opportunities to share best practices regarding risk
management tools and techniques. However, there are also weaknesses in the common
approach. It is desirable that line management realize that the responsibility for deciding on a
particular level of risk control, the responsibility for implementing enhanced controls, and the
responsibility for auditing compliance are separate issues. Also, there will often be different
reporting relationships within an organization between risk management and internal audit.
Finally, internal audit prides itself on its independent status, and closer involvement in risk
management decision-making could jeopardize that independence.
35.5 MANAGEMENT RESPONSIBILITY:
An alternative way to allocate responsibilities set out in Fig.
35.1 is that internal audit is responsible for activities identified as core internal audit roles.
Risk management should facilitate and support activities in the center of the fan identified as
legitimate roles for internal audit (with safeguards), and line management at the appropriate
level should have responsibility for roles identified as activities that internal audit should not
perform. An alternative way to allocate these responsibilities illustrated in Figure 35.1 is
shown in Table 35.2. The working relationship between risk management and internal audit
will vary between organizations. The roles and responsibilities assigned will be a reflection of
the structure that seems most suitable for an organization. The allocation of roles and
responsibilities should consider the guidance produced by the Institute of Internal Auditors
referenced in Figure 35.1.
A clear definition of the responsibilities of risk management, internal audit and line
management is essential for clear risk ownership. In summary, risk management can assist
with risk assessment and control design activities. Internal audit can provide support by
auditing controls to ensure that they are effective and efficient and have been fully
implemented. However, ultimate responsibility for risk management remains with the
organization's executive management. It is important that the activities of risk management
and internal audit are in a way that does not in any way reduce or dilute the ownership of risk
by the organization's management. This approach is also consistent with the statement in most
risk management standards that risks should not be managed outside the context that gave rise
to the risk.
35.6 FIVE LINES GUARANTEE:
There is much discussion about the operation of the three-line defense model. For
example, an organization that has adopted this approach needs to consider where head office
functions operate within the three lines, as they will often perform activities that are first-line
and/or second-line activities and, potentially, operate as a third-line as well. -lines as well.
In particular, the treasury function at the headquarters of a large company will manage
the treasury needs of the organization as a first-line manager. In addition, the treasury function
will be the area of expertise that determines the strategies and tactics to be adopted by the
organization. In some cases, auditing the treasury function specifically falls outside the scope
of internal audit departments in large companies. Therefore, external auditors review and
audit the treasury function. Another weakness of the three lines of defense model is that it is
more relevant to hazard (or operational) risks, including internal financial controls. Three
lines of defense model also suitable for compliance risk governance. However, audit
committees generally do not audit reverse risks, or seek to identify circumstances where
opportunities have been missed. Therefore, there is likely to be a disconnect between the
scope of work of risk management and the internal audit department compared to the full
scope and scope of the company's risk management activities.
Another aspect of the three lines of defense relates to the specific role and status of the
board of directors. The board provides assurance, but the board is not usually identified as a
line of defense. In fact, the board both receives assurance as a stakeholder group and provides
assurance to other stakeholders, including external stakeholders. The board will receive
assurance from departments within the organization, as well as receive assurance from
outside, including external auditors. The three lines of defense model is well established, but
is sometimes expanded to five lines of defense by showing external audit as the fourth line
and regulators as the fifth line. However, this is not representative of the five lines of
assurance approach, as is currently being developed. To improve the effectiveness of the three
(or five) lines of defense model, an alternative approach of five lines of assurance has been
proposed. The five lines of the assurance model suggest the following sources of assurance:
1. A board of directors with overall responsibility for ensuring that an effective risk
management process is in place and that other lines manage risk as appropriate.
2. Senior executives and senior managers with overall responsibility for
establish and maintain robust risk management processes and provide reliable
information on key risks.
3. Business unit leaders with ownership or assigned responsibility for reporting on
specific risks, and ensuring resources are protected and objectives are achieved.
4. Specialist units that provide expertise on specific types of risks, such as treasury,
safety, environment, legal and insurance with responsibility for the related risk
management processes.
5. Internal audit activities, provide independent and timely information to the board on
the reliability of risk management processes within the organization and produce
consolidated reports.
Inevitably, there are variations on the format described above and different organizations will
develop a structure for the five lines of assurance that suits their specific needs. The main
improvement of the three lines of defense model, as provided by the five lines of assurance
model, is that the first line of defense is divided into the board, senior executives and business
unit leaders, each of these identified groups being responsible for providing assurance in
relation to their allocated responsibilities.
One of the benefits of the five lines of assurance model is that better communication is
required between the board of directors, executive members and business unit leaders. Also, a
close relationship is required between specialist risk units and internal audit activities. The
focus is on providing consolidated assurance across the organization, to promote a risk-aware
culture, rather than concentrating on the design and implementation of controls.
Therefore, the five lines of assurance model is more relevant to risk management
strategic and tactical (including opportunities) than the three lines of defense model. This fact
arises directly from the increased focus on assurance in the five lines of assurance model,
rather than control in the three lines of defense model. It should be noted that, in both models,
external auditors and regulators will continue to fulfill their specific responsibilities.
RISK MANAGEMENT REPORTING
36.1 RISK REPORTING:
There is a wide range of risk management documentation relevant to risk management
activities. Table 21.2 lists the types of risk management documentation that may be required
as follows:
•
risk management administration;
•
risk response and improvement plan;
•
event report and recommendations;
•
risk performance and certification reports.
The risk management manual should describe the control environment or risk culture.
Typically, it will include a variety of information, as listed in Table 21.3. The four categories
of reports mentioned above can be characterized as established procedures, action plans,
incident reports and performance reports. Chapter 21 discusses established procedures in
detail, when describing the contents of the risk management manual. Action plans, especially
those embedded in risk registers, along with recommendations derived from incident reports,
will help maintain risk management as a dynamic set of activities within the organization.
Chapter 21 describes risk management documentation in detail but the subject is
mentioned again here because of the importance of risk performance and certification reports.
In fact, the importance of these documents has increased considerably recently, due to the
introduction of the Sarbanes-Oxley Act of 2002. Enhanced reporting requirements have been
implemented for all types of organizations in most parts of the world. It is important for an
organization to ensure that the reports it submits reach the highest applicable standards, while
remaining compatible with other requirements.
For example, there may be specific requirements that apply, such as the Sarbanes-
Oxley Act when an organization is listed on the New York Stock Exchange. However, that
organization may also be listed on another stock exchange with different requirements. In
addition, the organization may have subsidiaries that are registered as charities, or operate as
(for example) insurance companies, perhaps captive insurance companies. Performance
reports and risk certifications include operational management reports as well as more formal
statements and certified reports to stakeholders. In certain cases, certification of the financial
results of the organization's operations will be done as a formal attestation by a third party.
Typically, this third-party attestation will be by an external auditor. The written attestation
will also include an evaluation of the effectiveness of control activities related to financial
reporting.
The Financial Reporting Council's (FRC) risk guidance, published in 2014, provides a
comprehensive set of responsibilities for an organization's board. Table 36.1 provides a
summary of the risk management obligations allocated to The board and Item 6 on Risk
Communication and Reporting are the most relevant to this chapter. It is important to note
that the risk management reporting and communication obligation refers to both internal and
external communication and the obligation also refers to the importance of risk management
information being communicated both to and from the board.
Reporting requirements are becoming increasingly detailed and sometimes
organizations need to produce separate reports for different regulatory authorities. Also, some
organizations may decide to issue special reports to achieve a high profile for certain aspects
of their organization. In particular, some organizations issue separate corporate social
responsibility reports to highlight their achievements in this important area. The case studies
presented at the beginning of each section of this book are all excerpts from the reports of
companies listed on the London Stock Exchange. These case studies demonstrate the range of
topics reported by listed companies in relation to the various risk management and internal
control issues covered in this book.
36.2 SARBANES-OXLEY ACT OF 2002:
The Sarbanes-Oxley Act (SOX) was passed in response to various corporate scandals
in the United States. These scandals involved misrepresentation of the financial status of
various organizations, leading to misleading financial statements. The main purpose of SOX
is to ensure that the information disclosed by companies listed on stock exchanges in the
United States is accurate. SOX requires controls to be in place to ensure the accuracy of all
information reported by the organization. Section 302 of SOX requires that all data generated
by the organization must be validated. With respect to financial statements, a detailed analysis
of the risks that could result in misstatement of the organization's financial results must be
conducted. The procedures for gathering financial information and attestation of financial
disclosures by external auditors (as required by section 404) are very detailed and considered
by many to be very onerous and costly to perform.
When complying with section 404 of SOX, the risk assessment is designed to identify
weaknesses in the financial reporting structure. This is a very detailed procedure that requires
a lot of work by the internal audit department. The organization's financial results and
evaluation of the financial reporting structure must be reviewed by external auditors, who
must provide an attestation that they consider the results to be accurate.
SOX requirements state that an approved risk management framework should be used
to evaluate the risks to accurate financial reporting. The recommended framework for
ensuring the accuracy of financial disclosures is the COSO Internal Control framework
(2013). Note that the COSO ERM (2004) framework covers all the requirements of previous
versions of COSO internal control. SOX requirements apply to subsidiaries of US companies
operating in other countries. They will also apply to organizations based in other countries if
the company has a listing on a US stock exchange. Therefore, the internal control version of
the COSO framework is used by companies in many countries around the world.
To meet the requirements of Sarbanes-Oxley, many organizations have decided to
form a disclosure committee to validate all the information disclosed by the organization. Due
to the extensive implementation of SOX, many companies based in countries other than the
United States are also required to establish disclosure committees. The risk architecture shown
in Figure 22.1 for large companies includes a disclosure committee. Compliance with the
requirements of the Sarbanes-Oxley Act of 2002 is an expensive and time-consuming
exercise. Questions have been raised about whether the Act has been effective in improving
the accuracy of reports from companies listed on a US stock exchange. This criticism is
relevant, given that SOX requirements are primarily concerned with reporting accuracy, rather
than achieving enhanced risk management standards. A summary of some of the views of the
CEOs of some US companies is presented in the box below.
Sarbanes-Oxley Not Effective:
Chief executives across the United States view the Sarbanes-Oxley law as reactionary
and overly burdensome. Yet they still cite 'improper accounting practices' as the number one
ethical issue facing businesses today. A CEO survey on business ethics by Georgia State
University surveyed nearly 300 chief executives at private and public companies. Among its
findings, most executives agreed that the Sarbanes-Oxley Act strengthened public and
investor confidence in corporate America, even though it did nothing to raise ethical standards
at their businesses. Many agreed that the act was an overreaction to the ethical failings of a
handful of executives and proved burdensome and unnecessary.
36.3 RISK REPORT BY COMPANY AS:
Companies listed on US stock exchanges are required to make extensive disclosures
about risk factors. These risk management reports are intended to be forward-looking, not
commentary on risks that have materialized in the past. The reports are contained in periodic
Form 10-K or Form 20-F filings. It is not unusual to find several pages dedicated to risk
factors. Typically, this section of the filing is between 3 and 10 pages long.
Table 36.2 provides a partial list of industry, economic and environmental risks
reported in Form 20-F for the identified companies. Extracts from other examples of risk
factors reported by US listed companies are presented in Table 36.2.
36.2. It is normal for the list to begin with a comment, such as 'important factors that may
cause future financial difficulties include, but are not limited to', and then followed by a long
list with detailed explanations. Items listed usually include:
•
regulatory developments and changes;
•
competition in our business;
•
the competition authority's decision on the proposed joint venture;
•
compliance with government regulations;
•
general economic conditions;
•
losing strategic customers;
•
higher insurance costs for terrorism, sabotage or piracy;
•
our ability to achieve cost savings;
•
fluctuations in fuel costs;
•
currency and interest rate changes;
•
disruption at key locations and facilities;
•
incidents resulting from the transportation of hazardous materials;
•
strikes, work stoppages and work slowdowns;
•
disruption due to employee illness due to pandemic influenza;
•
market acceptance of our new services and growth initiatives;
•
changes in customer demand patterns;
•
the impact of technological developments on our operations;
•
disruption to our technology infrastructure;
•
adverse weather conditions;
•
if our sub-contractors' employees are considered our employees;
•
changes in tax laws or their interpretation by the authorities;
•
higher costs associated with implementing the Sarbanes-Oxley Act;
•
changes in environmental law.
Table 36.2 is an example of a list of risk factors, but does not include all items
contained in the full list filed as part of Form 20-F. Each listed risk will typically be described
in more detail, with detailed explanations of up to half a page. In addition, the Securities and
Exchange Commission (SEC) is considering whether to require more detailed reports on the
reporting structure of risk committees at companies listed on US stock exchanges. The SEC is
the federal regulator of US stock exchanges and has a mission to protect investors, maintain
fair, orderly and efficient markets, and facilitate capital formation.
36.4 RISK REPORTING CHARITY:
Risk reporting by charities is mandatory in most countries around the world. In
general, there is an expectation that charities should have detailed risk management
procedures broadly equivalent to those required by government departments or listed
companies. The short version of the advice on risk reporting set out in the UK Charity
Commission guidance is as follows: The form and content of risk reporting should reflect the
size and complexity of individual charities. The Charity Commission does not seek to
standardize risk reporting. A narrative style report discussing key aspects would be an
acceptable reporting approach, provided the report provides:
•
recognition of the guardian's responsibility;
•
overview of the risk identification process;
•
indication that key risks have been reviewed or assessed;
•
confirmation that the control system has been created.
It is recognized that some charities, particularly larger charities or those with more complex
operations, will wish as best practice to extend this basic approach in their reporting. Where
this more detailed reporting approach is adopted, it would be desirable to discuss the
following general principles, explaining how they have been incorporated into the charity's
risk management procedures:
•
the relationship between the identification of key risks and the charity's operational and
strategic objectives;
•
procedures that go beyond financial risk to include operational, compliance, and other
identifiable risk categories;
•
linkage of risk assessment and evaluation to the likelihood of occurrence and the
impact should the event occur;
•
ensure risk assessment and monitoring activities take place and are embedded in
management and operational procedures;
•
trustee review and consideration of the key results of risk identification, evaluation
and monitoring.
Most charities already tend to consider risk in their day-to-day activities. In fact, it has been
reported that many charities now see risk management and other governance requirements as
the most significant challenge facing the organization. This seems to imply that charities are
becoming more risk-averse and spending more effort on compliance issues than fundraising.
Even if a formal risk management process has not been completed, often aspects of the risk
approach can be drawn out for comment. A typical report on risk management for a small
charity might be as follows:
•
A risk assessment process is in place to identify the priority significant risks facing the
charity.
•
Risk management policies, protocols and procedures are incorporated into routine
operations.
•
Strategy analysis is conducted to identify significant risks that could impact strategy
delivery.
•
Procedures are in place to ensure legal compliance, including regular reports on legal
issues to the supervisory board.
•
Trustees receive training on risk management and corporate governance issues
relevant to charities.
•
The Trustee receives an annual report on risk management activities and evaluation of
the control environment.
•
The Trustee also receives additional reports on significant weaknesses in controls and
details of material control failures.
36.5 PUBLIC SECTOR RISK REPORTING :
Attention to risk management in government departments and other areas of the public
sector is mandatory in most countries. Most information on risk management in government
agencies is freely available on websites and this information is very useful reference material.
However, because the information is publicly available, there is often no specific mention of
risk reporting to external stakeholders. The government in the UK has produced a set of
principles on risk reporting. Table 36.3 sets out those risk reporting principles as openness and
transparency, engagement, proportionality, evidence and responsibility. There is usually a lot
of information about how risk reporting structures will work within government bodies. The
information set out below is typical of reporting by UK local government authorities:
All risks on the strategic risk register are monitored through quarterly clinics. Reports from
these clinics are forwarded to the executive committee twice per year. The strategic risk
register is reported to the full board through its inclusion in annual strategic plan reporting.
Service-specific business risks are included in service group plans and monitored through
directorate performance management arrangements. This includes reporting, twice per year,
to the relevant board members.
36.6 GOVERNMENT REPORT ON NATIONAL SECURITY :
One of the biggest steps forward in risk communication in recent times is the
willingness of governments to be more open about security threats. Many governments
conduct national security threat analyses and publish the results. For example, the UK
government in 2011 published a document called the UK National Security Strategy. This
publication provides details of the threats to national security faced by the UK. More recently,
the UK Cabinet Office published the National Risk Register.
In this analysis, there is no mention of the UK or the UK government's key objectives
or dependencies. However, the threat analysis is robust and detailed. The main threat
categories identified in the document are as follows:
•
natural events, including weather, coastal and river flooding and human or animal
diseases;
•
major accidents, including industry and transportation;
•
malicious attacks on crowded places, infrastructure, transportation, and electronic
infrastructure (including nuclear or unconventional attacks).
The document provides a detailed analysis of various threats and measures
in place to minimize these threats. The report also discusses the drivers that are changing the
country's risk profile. These drivers include:
•
politics;
•
Climate;
•
energy competition;
•
poverty/inequality/poor governance;
•
globalization - economic, technological and demographic.
This analysis by the UK government is an interesting example of a detailed risk assessment
being conducted at a national level. It shows that risk management is now embedded at the
heart of national governments. The fact that risk management has been embraced by the
national government shows that its importance is recognized at the highest level. Figure 36.1
shows some of the significant risks to UK national security identified by the government, at
the time of the 2011 assessment.
The UK government does not classify risks in this way, but if the risk attitude structure
described in Figure 10.1 is used, then it is possible to identify key threats to which the
government feels comfortable being able to respond, such as transportation accidents, cyber-
attacks and animal diseases. If the government uses this structure, it appears to be cautious
about major industrial accidents, attacks on infrastructure and severe weather. The
government is concerned about coastal flooding and attacks on crowded places. Finally, the
risk attitude analysis seems to indicate that the government identifies the critical issue facing
national security as pandemic human diseases.
Looking back 100 years and more, the protection of national security was fairly
straightforward. The government would focus its attention on national defense using the
armed forces, with special expertise in land and sea defense. Today, however, the protection
of national security is much more complicated. The box below questions the ability of
traditional government structures to cope with this complexity.
Government structure:
Some governments are beginning to realize the complexity of national security and
have invented new language, such as the 'comprehensive approach', in the hope that this will
solve the problem. But for the most part, to the extent that the 'comprehensive approach' exists
at all, it does so in theory but not in practice on the ground where it matters.
Meanwhile, the structure and culture of government remain fixed in the past.
Ministers are judged on how well they maintain territorial integrity their departments,
maintain their budgets, and maintain their payrolls. Senior civil servants have the same
attitude. Networking with other departments is seen as a threat, not an opportunity. Vertical
hierarchies and mature minds know that they should network, but find it impossible to do so.
What is needed is a major restructuring of government along more modern lines.