RISK: IT S MORE THAN JUST COMPLIANCE. Rhode Island Annual General Meeting May 15,

Similar documents
Adam Travis, CPA, CISA

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector

WELCOME. 1

ISACA. The recognized global leader in IT governance, control, security and assurance

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance

The Business Transformation Playbook

CGEIT Certification Job Practice

Getting Started with Risk in ISO 9001:2015

More than 2000 organizations use our ERM solution

ENTERPRISE RISK MANAGEMENT USING DATA ANALYTICS. Dan Julevich and Chris Dawes April 17, 2015

Benchmarking 101: Shaping your E&C Program for Maximum Value

Feature. Internal Audit s Contribution to the Effectiveness of Information Security (Part 2) Perceptions of Internal Auditors

Enterprise Risk Management: Developing a Model for Organizational Success. White Paper

The Board s Role in Fundraising: A Strategic Approach

Rick Willson s new book, Parking Management for Smart Growth, is a how-to

ERM vs. Internal Audit

IT Audit at Brown. A collaboration between the Information Technology and Internal Audit Teams

People Are Not Afraid of Change, They Are Afraid of Uncertainty

STOP ACTING LIKE AUDITORS!

Creating a safety culture:

The UBS Client Experience Focused on you and your needs

Replacing Risk with Knowledge to Deliver Better Acquisition Outcomes

Leveraging ISO Certification Standards to Drive Performance

Developing an Integrated Anti-Fraud, Compliance, and Ethics Program

Results. Actions. Beliefs. Experiences

7 Key Trends in Enterprise Risk Management

Creating the Aligned Organization

IMPLEMENT A PIPELINE SMS

Institute of Internal Auditors 2018

2013 COSO Internal Control Framework Update. September 5, 2013

Writing an Audit Finding. Danny M. Goldberg Professional Development Practice Director

Good Practices of the Audit Committee

Leadership and Rising Stakeholder Expectations

6 SAFETY CULTURE ESSENTIALS

Practice Guide. Developing the Internal Audit Strategic Plan

What We Will Cover Today

Enterprise Risk Management: Aligning Risk with Strategy & Performance June 26, :45 p.m. 4:45 p.m.

11/16/2015. Marketing the Internal Audit Function Internal Audit Management Training November 19 20, 2015

BUS 280f Operational Risk Management Fall 2017

What Every Internal Auditor Should Know Perspectives of a Chief Compliance Officer

What to Expect from Your Auditor and What Your Auditor Expects from You

8. XBRL and the Financial Reporting Supply Chain

Converging Ethics, Governance, and Culture

Linda Carrington, Wessex Commercial Solutions

In Control: Getting Familiar with the New COSO Guidelines. CSMFO Monterey, California February 18, 2015

Keys to Meaningful Measurement Systems

12/28/2017. ERM and Audit 2. ERM Agenda. Definitions and Processes. Risks. Audit & ERM. Key Strategies. Conclusions. ERM and Audit

The Practices of Transformational Leaders

STRATEGIC PERSONAL BRANDING TAKING YOUR BRAND TO THE NEXT LEVEL

How To Win Business with the Government

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it?

Building an HR Model for the Future Agenda

Enterprise Risk Management 2016

DCAA Finds New Ways to Reduce its Audit Backlog. Written by Nick Sanders

Internal controls over financial reporting

Simple Strategies, Big Results: Driving Internal Audit Value. October 28 th, 2016

Make money, save money and manage risk

Who is in our audience today?

Measuring Corporate Culture: Enhancing the Board s Understanding

Purposing the entirety of COBIT5 for the Assurance Professional. Ross E. Wescott MA CISA CIA CCP CUERME Wescott & Associates

ASSURANCE FRAMEWORK. A framework to assure the Board that it is delivering the best possible service for its citizens SEPTEMBER 2010.

At This Education Nonprofit, A Is for Analytics Social services agencies are turning to data to find the practices that get the best results.

CLAconnect.com/creditunions. Impact the Future of Credit Unions

Investment Management Financial Planning Client Education

Format and organization of GAGAS Auditor preparation of financials is a significant threat to independence 3 party arrangements in government State

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010

How Do We Start a Project? Ensuring the Right Sponsorship, Stakeholder Alignment and Thoughtful Preparation for a Project

Implementing a Compliance Monitoring Program. January 29, 2014

Miles CPA Review: BEC Q Updates for 2017 Edition

MARKETING INTERNAL AUDIT

FRAMEWORK FOR ACTION. Driving impact and inspiring change. A guide for bold leaders.

TYPES OF RETREATS PURPOSES

SUPPLY CHAIN SUSTAINABILITY UNCOVERING THE TRIPLE BOTTOM LINE

Employee Engagement Leadership Workshop

GATU Webinar Part 1 March 2017 Presented by Carol Kraus, CPA

Lesson 5: Monitoring Performance

Quality Management System Guidance. ISO 9001:2015 Clause-by-clause Interpretation

Maneuvering the Politics of Internal Auditing to Make Positive Change. Richard F. Chambers, CIA, QIAL, CGAP, CCSA, CRMA IIA President and CEO

Organizational Governance: Guidance for Internal Auditors. - July

This is all echoed in our Māori identity Hikina Whakatutuki which broadly means lifting to make successful.

HOW YOUR CAREER BACKGROUND CAN HELP YOU BECOME A BUSINESS ANALYST

Frequently Asked Questions about Industry-led Sector Partnerships

INTRODUCTION TO ISO 14001

Council on Financial Assistance Reform s Uniform Guidance Training

Internal Quality Assurance Report. Internal Audit/Inspector General Department

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE

OUR UNIVERSITY CONTRIBUTION

Guidance Note: Corporate Governance - Audit Committee. March Ce document est aussi disponible en français.

Cloud Computing Opportunities & Challenges

The Manager Foundation Job Competency Guide

Performance Management Behaviors that Matter

UCIB Consulting Seminar

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad

ISO Standards in Strengthening Organizational Resilience, Mitigating Risk & Addressing Sustainability Concerns

Management and Leadership in the Modern Appraisal Organization. Nelson Karpa MBA, AACI P.App, AMAA, AAM

COSO Internal Control Integrated Framework Public Exposure Feedback Questions, December 2011

The Agile PMP Teaching an Old Dog New Tricks

Lesson 1: Merit System Principles

Internal Audit Division FY 17 - Audit Plan Overview

Leadership Agility Profile: 360 Assessment. Prepared for J. SAMPLE DATE

Transcription:

RISK: IT S MORE THAN JUST COMPLIANCE Rhode Island Annual General Meeting May 15, 2014 1

AGENDA Thinking Beyond Compliance Expanding How We Look at Risk Assessing, Quantifying, & Accepting Risk Are We a Risk? 2

WHAT ARE WE GOOD AT? Producing detailed assessments of compliance with rules and regulations What s the criteria? What is the Auditee Doing? We use the gap to develop our recommendation 3

LANDING IN OZ There are no rules or regulations 4

HOW DO YOU IMPOSE COMPLIANCE STANDARDS ON CONGRESS? Congress not bound to follow most statutes Separation of Powers Barrier 5

HOW DO YOU IMPOSE COMPLIANCE STANDARDS ON CONGRESS? You Don t You re-craft your argument in terms they understand: RISK 6

QUESTION When doing a compliance audit, do our auditors really understand the underlying reason they are performing certain compliance steps OR Are they checking off a box on their checklist? 7

ARE WE SUFFERING FROM COMPLIANCE MYOPIA? The Risk of the Checklist 8

ARE WE GETTING TO THE ROOT CAUSE? Traditional Reasons for noncompliance with rules/regulations: Tone at the top Poor documentation Poor communication Inadequate training But are we so focused on the rules that 9

ARE WE ENFORCING COMPLIANCE WITH OUT-OF-DATE CONTROLS? Have controls kept up with changes in: Technology Process Organizational structure Management priorities Evolving risks 10

EXPANDING HOW WE LOOK AT RISK QUESTION Don t we already do Riskbased auditing? 11

Relevant Standards all Require an Understanding of Risk COSO s Internal Control Integrated Framework COBIT for Risk Statement on Auditing Standards (SAS) Nos. 104-111 Commonly referred to as the "Risk Assessment Standards". For audits of financial statements for periods beginning on or after December 15, 2006 IIA Practice Advisory 2120-2: Managing the Risk of the Internal Audit Activity (April 2009) IIA Practice Advisory 2120-3: Internal Audit Coverage of Risks to Achieving Strategic Objectives (June 2013) 12

TYPES OF RISKS Strategic Risks Operational Risks Think both broad and deep Financial Risks Regulatory Risks Reputation Risks Credit Risks Audit Risks 13

DEFINING RISK The potential that a chosen action or activity (including the choice of inaction) will lead to a loss (an undesirable outcome). ~ Wikipedia A situation involving exposure to danger ~ Oxford Dictionary Possibility of loss or injury ~ Merriam Webster Dictionary Possibility than an event will occur and adversely affect the achievement of objectives ~ COSO The chance that an investment s actual return will be different than expected. ~ Investopedia The effect of uncertainty on objectives ~ ISO 31000 14

WE DON T KNOW WHAT WE DON T KNOW Donald Rumsfeld, Secretary US Secretary Department of of Defense 15

WHAT KEEPS YOUR AUDITEE UP AT NIGHT? Talk to the people! Talk to the Board Talk to Management AND the people that do the work View yourself as the Trusted Advisor Make sure your people build relationships too 16

IMPACT ON AUDIT VALUE When we don t understand our organizational priorities, we: Provide recommendations with limited value Ultimately damage trust and relationships by: Showing lack of understanding of our stakeholders priorities and challenges Providing lack of quality assessments/value to leadership Miss the opportunity to make meaningful change 17

STRATEGIC RISK: ARE WE LOOKING AT RISKS THAT ARE AHEAD OR BEHIND US? Bayonetting the Wounded 18

HOW DO YOU (OR YOUR ORGANIZATION) VIEW RISK MANAGEMENT? Compliance Exercise? Strategic Tool? 19

STRATEGIC RISK: DO WE KNOW WHERE OUR ORGANIZATION IS GOING? To remain relevant, audit recommendations must be: Timely Proactive And reflect an understanding of: The organization s strategic vision, mission, and objectives Risks and priorities of key stakeholders Industry best practices 20

STRATEGIC RISK: WHERE CAN WE IMPROVE? Think Big Picture! Providing risk-based frameworks for management and leadership action: Systems and technology Organizational transition/change Big Picture View of risk across stakeholders 21

ASSESSING, QUANTIFYING, & ACCEPTING RISK QUESTION What is the acceptable level of Risk in your organization? If you know, does everyone else know and can it be quantified? 22

RISK TOLERANCE AND ACCEPTANCE If risk is not quantified, it is subject to interpretation What is a High, Medium, Low Risk? Use Quantitative and Qualitative measures Make sure you explain to your staff what is acceptable! Be Suspicious of the Status Quo (In a world of constant change, risk changes, too!) Relying solely upon I know a High Risk when I see it is risky! 23

KEY CONSIDERATIONS IN SETTING RISK APPETITE Risk appetite must linked to business strategy and objectives. Setting risk appetite requires extensive judgment on the part of the board (or other governing body) and executive management. One size does not fit all. Assigning clear ownership of risk at the management level is essential. Although the board sets risk appetite, its execution cascades down and is managed by all. Communication is a key enabler. Collaboration at all levels is critical. Reference:

QUANTIFYING RISK 25

WHO S ASSUMING YOUR RISK? Improper assumption of risk Ensure risk is being assumed at the right level 26

WHAT IS YOUR RISK APPETITE? Would you bet $1 at 2 to 1 odds in your favor? Would you bet $500,000 at 2 to 1 odds in your favor? Would you bet $500,000 at 1.1 to 1 odds in your favor? Risk appetite for: A particular project/initiative Your Organization How might these differ, and why?

ARE WE A RISK? Are we keeping up with change? Do we have the right people? Are our reports effective? 28

GETTING OUT OF THE RUT OF CYCLICAL AUDITING Do things change in your organization? If so, shouldn t your audits change as well? 29

CHANGE IS THE NEW NORMAL When developing your plan and audit work, consider- Changes in Regulation Changes in Technology Changes in Processes Changes in Vendors/Suppliers Changes in People 30

LEVERAGE PAST WORK - CAREFULLY Ask Why are we doing this audit? Don t just dust-off the prior plan and redo the same audit! Sometimes it is appropriate to do a follow-up audit but where does it stand based upon RISK Don t just redo an audit because it s been a while or we do this audit every couple years Re-assess the risks! 31

ARE YOU FIGHTING WITH THE TROOPS YOU HAVE OR THE TROOPS YOU NEED? If not, what are you doing to change that? Remember not having people with the right skills increases audit risk 32

AUDIT TEAMS THAT REDUCE RISK DIVERSITY OF THOUGHT Are we hiring Mini-Me s????? Extrovert vs Introvert Big Picture vs Details People vs Process Structure vs Flexibility 33

QUESTION WE NOW UNDERSTAND RISK, BUT Is anybody reading our reports?!?!? 34

ARE OUR REPORTS EFFECTIVE? Who are we writing our reports for? Reports must be audience focused Executive level - A Bigger Picture is Required (Think PowerPoint) Line Manager Technical Details (NFRs) 35

DO WE ADD VALUE? Bottom Line: If it weren't for fear of appearance, would leadership consider cutting my department during lean times? Would they be right to do so? 36

QUESTION What can I do today to (better) incorporate Risk Based auditing into my organization? 37

POINTS TO REMEMBER Understand your Organization and its operating environment - make sure your people do too! Always re-assess risk and move away from periodically doing the same audits over and over (obviously not the case if required by regulation, etc.) Quantify and communicate Risk levels and what is acceptable Risk tolerance. Make sure everyone is on the same page. 38

POINTS TO REMEMBER Assess the risks of not having the right people and skills in your organization and mitigate as necessary. Be cognizant of changes in regulation, technology, processes, and people. Let the Risks drive your strategy, planning, and execution 39

CONTACT INFORMATION: Theresa (Terry) Grafenstine CPA, CISA, CIA, CGEIT, CRISC, CGAP, CGMA Inspector General U.S. House of Representatives 202.226.1250 Theresa.Grafenstine@mail.house.gov 40