PIC EU-28 Conference Paris, 26 – 27 November 2015 PIC An EU Approach Assurance Maps An Introductory workshop Nathan Paget United Kingdom.

Slides:



Advertisements
Similar presentations
Organizational Governance
Advertisements

A Joint Code of Practice Objectives and Summary Presentation
Options appraisal, the business case & procurement
Risk The chance of something happening that will have an impact on objectives. A risk is often specified in terms of an event or circumstance and the consequences.
Internal Control–Integrated Framework
Auditing, Assurance and Governance in Local Government
Child Safeguarding Standards
IMFO Audit & Risk Indaba June 2012
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Agency Risk Management and Internal Control Standards Presentation to the Board of Visitors November 14, 2014.
Development of internal control: methodology and responsibility
Introduction to Enterprise Risk Management (ERM)
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
A Framework of Quality Assurance (FQA) for Responsible Officers and Revalidation Ahead of the Curve RO conference 4 June 2014.
2011 Governance, Risk, and Compliance Conference August 29 – 31, 2011 / Orlando, FL, USA The Top Four Essential Objectives to Auditing ERM Stephen E. McBride,
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Quality evaluation and improvement for Internal Audit
Office of Inspector General (OIG) Internal Audit
Purpose of the Standards
Information Systems Controls for System Reliability -Information Security-
Session 4: Good Governance: How SAIs influence Good Governance in Public Administration Zahira Ravat 27 & 28 May 2014.
Preparing Scotland’s first Records Management Plan Ava Wieclawska Records Manager.
Corporate Governance: Beyond Compliance at a time of Recession Prof. Ashley G. Frank BA(Econ)[Magna Cum Laude], MDPA (Cum Laude], MBA, MCom [Cum Laude],
Internal Auditing and Outsourcing
Internal auditing for credit unions Nuala Comerford, Chair IIA Irish Region Committee Pamela McDonald Council Member IIA Credit Union Summer School Thursday,
WHERE WE ARE 22 member associations in 20 countries Over 4300 individual members who are responsible for risk management and/or insurance in their organisations.
Governance of the Treasury Function CIPFA Scottish Treasury Management Forum Alan George, Regional Director 23rd February 2012.

The role of internal audit in enterprise-wide risk management (ERM)
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Equity Housing Group Risk Management. 05 August 2002 © MazarsEquity Housing Group: Risk Management 2 Agenda Introduction: what is Risk Management? The.
Risk Management Report to Audit Committee 26 September 2006 Lee Harris Assistant Chief Executive.
RISK ASSESSMENT 2010/2011 M.J Ramakgolo. THE PURPOSE The aim of the risk assessment session is to develop the Strategic Risk Profile for the municipality.
IT Risk Management, Planning and Mitigation TCOM 5253 / MSIS 4253
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
Copyright T. Rowe Price. All rights reserved 1 Ms. Deborah D. Seidel of T. Rowe Price Financial Services Vice President and Manager of Compliance.
Chapter 5 Internal Control over Financial Reporting
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
YSS Conference May 2014 Worcestershire Young Carers A Safeguarding Matter?
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Risk Management For the Board of The Law Society 16 February 2005.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
FLOOD RISK MANAGEMENT The next steps. The National Technical Advisory Group On Flooding Issues An Overview and the Future.
Devon & Cornwall Police Authority Strategic Review November 2010.
Section Topics Risk and control terminology Risk elements
Applying a risk model in state internal and external audits.
DAY 1: OVERVIEW The nature of internal auditing
Risk Management and the Audit Plan abc CIPFA in the Midlands Audit Training Seminar Wednesday 24th November 2004 Tina Spiers.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Improving performance, reducing risk Dr Apostolos Noulis, Lead Assessor, Business Development Mgr Thessaloniki, 02 June 2014 ISO Energy Management.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
INTERNAL AUDIT BRIEFING Business Objectives Business Objectives: What are they and how are they used?
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
Shared Services and Third Party Assurance: Panel May 19, 2016.
AUDIT STAFF TRAINING WORKSHOP 13 TH – 14 TH NOVEMBER 2014, HILTON HOTEL NAIROBI AUDIT PLANNING 1.
Embedding the golden threads that lead to quality care every time……
An Overview on Risk Management
Solihull Review of Urgent Care Programme Approach And Governance 2013
Risk Management and the role of the Audit Committee
HUMAN RESOURCE GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE
Internal control - the IA perspective
Portfolio, Programme and Project
Good practices for risk assessment and control activities
Operational Risk Management
Presentation transcript:

PIC EU-28 Conference Paris, 26 – 27 November 2015 PIC An EU Approach Assurance Maps An Introductory workshop Nathan Paget United Kingdom

PIC An EU approach PIC – EU 28 Conference 2015 Definitions Risk - The possibility of an event occurring that will have an impact on the achievement of objectives. Risk is measured in terms of impact and likelihood. Internal Control - Any action taken by management, the board and other parties to manage risk and increase the likelihood that established objectives and goals will be achieved. Management plans, organises and directs the performance of sufficient actions to provide reasonable assurance that objectives and goals will be achieved. Assurance - The internal audit activity must assist the organisation in maintaining effective controls by evaluating their effectiveness and efficiency and by promoting continuous improvement. 2

PIC An EU approach PIC – EU 28 Conference 2015 Business objectives and the link to assurance maps Business Objectives Framework of Internal Control 3 2 nd Line Assurance 3 rd Line Assurance 1st Line Assurance Ownership & Management Monitor and review Independent Assurance Management at various levels Board / Audit Committee / Governing group

PIC An EU approach PIC – EU 28 Conference 2015 Assurance Maps 4 Assurance:Why it is important Provides:‘Confidence’ / ‘evidence’ / ‘ownership’ To:Managers / Directors / Members/ Partners / Stakeholders / Public Over:That which needs to be done is being done in an effective and proper manner to achieve the outcomes desired. That risks are effectively managed.

PIC An EU approach PIC – EU 28 Conference 2015 Assurance Map – WHY? Providing :  A complete picture of the services being delivered, the activities undertaken, the level of associated risk.  A complete picture of the types of assurance available and obtained. Enabling:  Identification of any potential areas where assurance activities are not present or are insufficient (i.e. assurance gaps).  Identification of any areas where assurance is duplicated, repeated or excessive when compared with the value of the activity being undertaken. Allowing:  Better understanding of risk exposure.  Direction of proportionate assurance provision (and efficiencies).  Evidencing of collective assurance the Annual Governance Statement.  Better focus of efforts by the Audit Committee. 5

PIC An EU approach PIC – EU 28 Conference 2015 Business objectives and the link to assurance maps Business Objectives Framework of Internal Control 6 2 nd Line Assurance 3 rd Line Assurance 1st Line Assurance Ownership & Management Monitor and review Independent Assurance Management at various levels Board / Audit Committee / Governing group

PIC An EU approach PIC – EU 28 Conference st line of Assurance Good policy and performance data, Monitoring statistics, Risk registers, Reports on the routine system controls and other management information. 7

PIC An EU approach PIC – EU 28 Conference nd Line of Assurance Compliance assessments or reviews carried out to determine that policy or quality arrangements are being met in line with expectations for specific areas of risk across the organisation; Portfolio Management Strategic planning, Investment appraisal and project and programme management. 8

PIC An EU approach PIC – EU 28 Conference rd Line of Assurance This relates to independent and more objective assurance and focuses on the role of internal audit. Internal audit will place reliance upon assurance mechanisms in the first and second lines of defence, where possible, to enable it to direct its resources most effectively, on areas of highest risk or where there are gaps or weaknesses in other assurance arrangements. It may also take assurance from other independent assurance providers operating in the third line, such as those provided by independent regulators, for example. Other sources of independent assurance available include external system accreditation reviews/certification (e.g. ISO/Risk Management Accreditation Document Sets), European Commission/European Court of Auditors and Treasury/Cabinet Office/Parliamentary scrutiny processes. 9

PIC An EU approach PIC – EU 28 Conference 2015 Assurance Map - Approaches 10 3 rd Line2 nd Line1 st LineRiskObjective Business Objectives RiskControl RiskControl

PIC An EU approach PIC – EU 28 Conference 2015 Assurance Map – Control and assurance connections 11 Control Environment Risk Assessment Control Activities Information Communication Monitoring ASSURANCE MAPS

PIC An EU approach PIC – EU 28 Conference 2015 Control Environment 1 st Line2 nd Line3 rd Line All lines of Assurance should be expected to demonstrate through their directives, actions, and behaviour the importance of integrity and ethical values.  Leads by example in implementing values, a philosophy and an operating style for the organization.  Implements ethics-related objectives, programs and activities.  Designs and implements processes to evaluate the performance of individuals and teams against expected standards of conduct.  Specific members of the 2nd Line may be requested to support compliance hotlines, investigate potential breaches, or perform other specific duties related to integrity and ethical values. Assesses the state of the organization’s ethical climate and the effectiveness of its strategies, tactics, communications, and other processes in achieving the desired level of legal and ethical compliance. Evaluates the design, implementation, and effectiveness of the organization’s ethics-related objectives, programs and activities. Provides assurance that ethics programs achieve stated objectives, key risks are effectively managed and controls continue to operate effectively. Provides consulting services to help the organization establish a robust ethics program and improve its effectiveness to the desired performance level. 12

PIC An EU approach PIC – EU 28 Conference 2015 Assurance and Risk 13 This is a direct output from the risk management process: Assurance provided that controls are effective in the case where inherently high / extreme risks are mitigated to a lower residual classification. Assurance provided that actions are progressing where risk is both inherently and residually high / extreme. Assurance over the management of risk where our appetite to the risk is low. Those business risks that, if realised, could fundamentally affect the way in which the organisation exists or conducts its business. These risks will have a detrimental effect on the organisations achievement of its key business objectives. The risk realisation will lead to material failure, loss or lost opportunity ASSURANCE RISK The main operational risks associated with the key business activities and processes that if realised would increase the likelihood of a strategic risk realising. Key business activities and processes on which the organisation is reliant for successful execution of its strategies.

PIC An EU approach PIC – EU 28 Conference 2015 DEFRA CASE STUDY 4 Strategic Priorities – supported by lower level activities. Growing the rural economy. Protecting the Environment. Protect / respond on Animal Health. Protect / respond on Plant Health. 14

PIC An EU approach PIC – EU 28 Conference 2015 Defra Example 15

PIC An EU approach PIC – EU 28 Conference 2015 Animal Health 16

PIC An EU approach PIC – EU 28 Conference 2015 Managing a disease outbreak 17

PIC An EU approach PIC – EU 28 Conference 2015 Reporting 18

PIC An EU approach PIC – EU 28 Conference 2015 Outline implementation approach 19

PIC An EU approach PIC – EU 28 Conference 2015 Further References HMT Orange Book – Assurance Maps CoSo / IIA Guidance on Assurance Maps and CoSo 20

PIC An EU approach PIC – EU 28 Conference 2015 Questions Any questions??????? 21