CHAPTER 3 Risk and Control Faz
CHAPTER 3 Risk and Control Faz
CHAPTER 3 Risk and Control Faz
2
Definition of Risk Management
Risk management is a process for identifying, assessing, and
prioritising risks of different kinds. Once the risks are identified, the
risk manager will create a plan to minimise or eliminate the impact
of negative events.
4
4
Enterprise Risk Management (ERM)
ERM – is a structured process, effected by an entity’
board of directors, management and other personnel
that is applied in strategy-setting and across the
enterprise. Its goal is to provide reasonable
assurance regarding the achievement of
organisational objectives by identifying events that
may affect the entity and managing risk to be within
the entity’s risk appetite.
5
5
COSO ERM Framework
6
6
COSO ERM Framework
7
7
Risk Assessment
8
Risk Response
9
Role of Internal Auditor
Test check the adequacy of risk management processes, models
and systems.
Educate and create awareness among the management and staff
concerning the risk issues.
Assist the management in developing risk management
framework and its implementation.
Provide feedback on the appropriateness of risk management
infrastructure.
Review risk management processes, both their design and how
well they work.
Review management of those risks classified as ‘key’, including
the effectiveness of the controls and other responses to them.
Ensure reliable and appropriate assessment of risks and reporting
of risk and control status.
10
10
However, auditor should NOT involve in:
Setting the risk appetite
Imposing risk management processes
Managing assurance on risks
Taking decisions on risk responses
Implementing risk responses on management‘s behalf
Being accountable for risk management
11
11
Responsibility of Board and Management
• Board
• Knowing the extent to which management has established effective
ERM in an organisation.
• Being aware of the organisation’s risk appetite.
• Reviewing the organisation’s risk portfolio to match its risk appetite.
• Being apprised of the most significant risk and management’s response
to the risk.
• Management/Risk Officers
• Ensure that activities conducted are within the organisation’s risk
appetite through proper risk management procedures
• Provide necessary information to risk officers to enable them to
effectively identify and assess the significant risks faced by the
organisation.
• Establish risk management policies
• Frame authority and accountability for managing risk
• Promote competency in risk management
12
Other Risk Management Framework
• Risk Management Standards AS/NZS 4360:2004
13
Other Risk Management Framework
• ISO 31000:2009 Risk Management
14
Internal Control
• COSO’s definition of internal control –
A process, effected by an entity’s board of directors,
management and other personnel, designed to provide
reasonable assurance regarding the achievement of
objectives in the following categories:
• Effectiveness and efficiency of operations
• Reliability of financial reporting
• Compliance with applicable laws and regulations
15
COSO Internal Control Framework
16
16
Components of Internal Control
17
Components of Internal Control (cont.)
Control Environment
• Set the tone of organization and influence the control consciousness of its
people.
• Foundation of all components of internal control, provide discipline &
structure.
Risk Assessment
• Identification and analyze of relevant risk to achieve the objective, & how to
manage other risks.
Control Activities
• Include arrange of activities as diverse as approval authorization, verification,
review of operating performance, security of asset and segregation of duties.
Information & Communication
• Information must be identified, capture and communicated in a form & time
frame that enable to carry out their responsibilities.
Monitoring Activities
• Internal control system need to be monitored- a process that access the
18 quality of the systems performance over time.
Types of Control Activities
Preventive controls: proactive controls that deter undesirable events
from occurring. An example of preventive control is an alarm system.
21
END CHAPTER 3