Good practices for risk assessment and control activities

Slides:



Advertisements
Similar presentations
Auditing, Assurance and Governance in Local Government
Advertisements

RELATIONSHIP BETWEEN THE MANAGING AUTHORITIES AND THE PAYING AGENCIES IN THE MANAGEMENT OF RURAL DEVELOPMENT PROGRAMMES Felix Lozano, Head of.
Evaluating public RTD interventions: A performance audit perspective from the EU European Court of Auditors American Evaluation Society, Portland, 3 November.
Development of internal control: methodology and responsibility
Sodexo.com Group Internal Audit. page 2 helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and.
Control procedures in polish public procurement law Public Procurement Office 2007.
Institute of Municipal Finance Officers & Related Professions
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Office of Inspector General (OIG) Internal Audit
Internal Control and Internal Audit
Purpose of the Standards
Internal Audit. Session objectives Define Internal Audit To understand functions of Internal Audit To assess effectiveness of Internal Audit and reliance.
Internal Auditing and Outsourcing
Central Piedmont Community College Internal Audit.
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Chapter Three IT Risks and Controls.
How does the ECA assess Member States’ internal control systems? Workshop on Audit/Evaluation of Public Internal Financial Control Systems (PIFC) Ankara,
Romanian Court of Accounts years of existence.
Good practices from and for the EU accountability process Irena Petruškevičienė Vilnius, 17 October 2006.
© OECD A joint initiative of the OECD and the European Union, principally financed by the EU. Quality Assurance José Viegas Ribeiro IGF, Portugal SIGMA.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
The Audit as a Management Tool Vermont State Auditor’s Office – April 2009.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
DAY 1: OVERVIEW The nature of internal auditing
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
EN EUROPEAN COMMISSION Budgetary Control Committee of European Parliament Budgetary Control Committee of European Parliament Brian Gray DG BUDGET Workshop.
S6: Internal Audit. Defining Internal Audit Internal Auditing is an independent, objective assurance and consulting activity designed to add value and.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Page 1 Portfolio Committee on Water and Environmental Affairs 14 July 2009.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
An independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
Governance, Risk and Ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
Briefing to the Portfolio Committee on Department of Mineral Resources (DMR) APP 2015/16 Presenter : Margaret Seoka – Senior Manager AGSA 18 March.
INTERNAL AUDIT SERVICE of the REPUBLIC OF CYPRUS
Getting to Know Internal Auditing
An Overview on Risk Management
Internal Control Principles
Audit of predetermined objectives
Getting to Know Internal Auditing
Getting to Know Internal Auditing
Division of powers between IA, SAI and FI
A Framework for Control
Understanding the entity
PLANNING THE INTERNAL AUDIT (8 - 10%)
INTRODUCTION TO Compliance audit METHODOLGY and CAM
PEMPAL Internal Control Working Group– 45th IACOP Meeting
Internal control - the IA perspective
Management Verifications & Sampling Methods
Supervisory and control systems for national accounts purposes Viewpoint from the European Commission’s internal auditor Eurostat Seminar 8/9 December.
Revision of the Internal Control Framework in the European Commission PEMPAL Internal Audit Community of Practice (IACOP) Brussels, 27th February 2017.
Getting to Know Internal Auditing
years of existence.
Panel discussion: Organising internal audit system and performing audit engagements Ciaran SPILLANE, Principal Advisor, Internal Audit Service of the.
PEMPAL Internal Control Working Group– 45th IACOP Meeting
Management Verifications & Sampling Methods
Briefing to the Portfolio Committee on Defence on the audit outcomes for the 2013/2014 financial year.
Bulgaria – Capital Budgeting And Fiscal Institutions
Briefing to the Portfolio Committee on Police Audit outcomes of the Police portfolio for the financial year 13 October 2015.
Costanza Schivi - 9 April 2019
FIELDWORK Expectations, challenges, methods, results
The EU Model of PIC Raymond Hill Team Leader, PIC Task Force
Data Security and Protection Toolkit Assurance 2018/19
Briefing to the Portfolio Committee on Department of Correctional Services on the audit outcomes for the 2013/2014 financial year Presenter: Solly Jiyana.
ECA Quality Control Arrangements
Bangladesh Vice Chair)
Presentation transcript:

Good practices for risk assessment and control activities Costanza Schivi – 10 April 2019

“Internal Audit Service: Improving the Commission’s Performance” Our Role as defined by International Standards for the Professional Practice of Internal Auditing “The internal audit activity must evaluate the adequacy and effectiveness of controls in responding to risks within the organization’s governance, operations, and information systems regarding the: Achievement of the organization’s strategic objectives. Reliability and integrity of financial and operational information (main focus of ECA) Effectiveness and efficiency of operations and programs. Safeguarding of assets. Compliance with laws, regulations, policies, procedures, and contracts.  “Internal Audit Service: Improving the Commission’s Performance”

The Internal Audit Service of the European Commission Sets up strategic planning based on own risk analysis and coordinated with European Court of Auditors brings a systematic, disciplined approach in order to evaluate and improve the effectiveness of risk management, control and governance processes. Reports to: Audit Progress Committee the Commission on the results of its work (Internal audit Report) Has full and unlimited access to information

“Internal Audit Service: Improving the Commission’s Performance” Powers and duties of the internal auditor (art.118 Financial Regulation) The internal auditor shall advise his or her Union institution on dealing with risks, by issuing independent opinions on the quality of management and control systems and by issuing recommendations for improving the conditions of implementation of operations and promoting sound financial management. The internal auditor shall in particular be responsible for: assessing the suitability and effectiveness of internal management systems and the performance of departments in implementing policies, programmes and actions by reference to the risks associated with them assessing the efficiency and effectiveness of the internal control and audit systems applicable to each budget implementation operation.  “Internal Audit Service: Improving the Commission’s Performance”

A risk based methodology for Strategic Plan -define audit universe -assess the risks of the underlying components (using the Commission's risk management framework ) -consider issues (i) not covered for some time on a cyclical basis (ii) inherently material -financial management of each audited entity is covered at least every three years irrespective of the level of risk => annual opinion on the state of internal control (limited assurance) -requests and/or concerns from IAS, Commission and Executive Agencies senior management and/or the APC (top-down steer)  “Internal Audit Service: Improving the Commission’s Performance”

Which risks to assess? AUDITORS ASSESS INHERENT RISK risk by making abstraction of the controls in place MANAGERS ASSESS RESIDUAL RISK no time to assess controls during the risk assessment. If during the risk assessment auditors obtain information which indicates that key controls are missing or display very significant weaknesses, this information is likely to influence the likelihood aspect of the identified risk. controls are assessed during the preliminary survey of audits If the IAS identifies high inherent risks and management judge the residual risk to be lower => IAS may decide to carry out an audit in order to re-assure management of the appropriateness and well-functioning of mitigating controls.  “Internal Audit Service: Improving the Commission’s Performance”

Audit Universe of the IAS Financial processes Non-financial processes Grants Procurement Ethics Communication IAS Strategic Audit Plan Risk assessment Audit Universe of the IAS IT Accountability, including management disclosure Financial statements HR Payroll Monitoring EU law Risk factors Audit Results REPORTING Performance Indicators 3% Financial/Compliance 31% Performance (incl.IT) 59% Comprehensive (fin/compl+performance) 7% Other (consultancy, limited reviews) 233 auditable entities 406 auditable entities Pre-financing  “Internal Audit Service: Improving the Commission’s Performance”

Non-financial processes -do not belong to the financial management audit universe -may generate significant risks for the Commission's reputation e.g. handling of crises IT systems supporting policies information security ethics citizen or staff safety (e.g. handling of pandemics, natural disasters, etc.) sound financial and resource management  “Internal Audit Service: Improving the Commission’s Performance”

Non-financial processes (cont.) They also include significant policy areas with some budgetary impact such as competition policy, with resulting fines controls over trade policy anti-dumping measures controls over the respect of EU law infringement procedures  “Internal Audit Service: Improving the Commission’s Performance”

Commission’s standard risk typology  “Internal Audit Service: Improving the Commission’s Performance”

“Internal Audit Service: Improving the Commission’s Performance” Controls The internal audit work focuses on auditing those controls that are deemed by management to be effective (i.e. strong controls identified by management).  “Internal Audit Service: Improving the Commission’s Performance”

“Internal Audit Service: Improving the Commission’s Performance” The internal audit work focuses on auditing those controls that are deemed by management to be effective (i.e. strong controls identified by management). In practice At the end of the preliminary survey FINANCIAL/COMPLIANCE AUDITS Risk Control Matrix: identifies per process or activity, the main risks/control objectives and the existing controls. PERFORMANCE AUDITS Performance Audit Matrix: starts from a question tree and for each (sub)question to be answered, states the criteria to be used against which the auditors will assess the answers, the testing procedures to be used and the potential findings and recommendations that the audit may conclude.  “Internal Audit Service: Improving the Commission’s Performance”

A few key controls in the EC Control architecture Ex-ante system assessment on implementing bodies Ex-ante control of transactions (Financial Circuits « 4 eyes principles ») Beneficiaries audit reports Ex-post control of transactions/system (audit or transactions based) Monitoring missions on projects management (Results Oriented Missions) Verification missions or on-the-spot controls  “Internal Audit Service: Improving the Commission’s Performance”

Examples of objectives of an audits of control strategies: efficiency of the control coordination adequacy of the design and the effectiveness of the control strategies in force effectiveness of the controls underpinning the assurance building process (system audits, ex-ante and ex-post checks, monitoring, reporting) timeliness and adequacy of corrective measures effectiveness of anti-fraud controls  “Internal Audit Service: Improving the Commission’s Performance”

Challenges Understand the business! Complementarity with management assessment (IAS: High risks Management: Critical risks) Determine subjects and scope of work Be informed at an early stage of new systems and changes substantially affecting the Commission's internal control system

Questions?

Contact the Internal Audit Service: ias-europa@ec.europa.eu