From risk to planning Making the bridge from risks to audit plans Richard Maggs Astana September 2014.

Slides:



Advertisements
Similar presentations
1 of 21 Information Strategy Developing an Information Strategy © FAO 2005 IMARK Investing in Information for Development Information Strategy Developing.
Advertisements

FINANCIAL AUDIT METHODOLOGY PETER CARLILL UK NATIONAL AUDIT OFFICE.
Progress on Risk Assessment......continued Ms. Albana Gjinopulli, MPA Mr. Stanislav Buchkov.
Chapter 10 Accounting Information Systems and Internal Controls
Office of Operations 2009 Fall Conference Navigating Uncertain Times October 21-22, 2009 Risk Assessment and Internal Controls Internal Controls Anna Tomassacci.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
Presented by: Patricia “Patti” Snopkowski Chief Auditor, OUS Internal Audit Division 2011 Annual Risk Assessment.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
PwC Role of Internal Audit in Corporate Governance September 2010 Tumin Gültekin, Partner.
Applying COSO’s Enterprise Risk Management — Integrated Framework
Office of Inspector General (OIG) Internal Audit
Purpose of the Standards
Challenges Faced in Developing Audit Plans and Programs 21 st March, 2013.
Session 3.11 Risk Identification Presented By: RTI, JAIPUR.
Chapter 3 Internal Controls.
RISK ASSESSMENT 2010/2011 M.J Ramakgolo. THE PURPOSE The aim of the risk assessment session is to develop the Strategic Risk Profile for the municipality.
Results of Pre-event survey on Risk Assessment Ms. Edit Németh – RA WG – Budva, Montenegro.
Audit objectives, Planning The Audit
M. ANGELA JIMENEZ 1 UNIT 5. REGULATION OF EXTERNAL AUDIT IFAC AND E.C.
© OECD A joint initiative of the OECD and the European Union, principally financed by the EU Σ SIGMA risk assessment José Viegas Ribeiro IGF, Portugal.
Section Topics Establish a framework for assessing risk
1 RISK ASSESSMENT _____________________________________________________ Fort Bend Independent School District.
Internal Control in a Financial Statement Audit
Internal Control in a Financial Statement Audit
S7: Audit Planning. Session Objectives To explain the need for planning To explain the need for planning To outline the essential elements of planning.
Evaluation of Internal Control System
Commissioning Self Analysis and Planning Exercise activity sheets.
RTI, MUMBAI / CH 41 IMPLEMENTING THE PERFORMANCE AUDIT PLAN FOR THE SELECTED SUBJECT DAY 4 SESSION NO.1 (THEORY) BASED ON CHAPTER 4 PERFORMANCE AUDITING.
Audit Planning. Session Objectives To explain the need for planning To outline the essential elements of planning process To finalise the audit approach.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
1 Governance, accountability and performance reporting in the public sector Des Pearson Executive in Residence August 2013.
CC3020N Fundamentals of Security Management CC3020N Fundamentals of Security Management Lecture 2 Risk Identification and Risk Assessment.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Audit Planning and Types of Audit Tests Chapter Five.
RAWG.  Risk assessment guideline for strategic and annual planning ◦ Identifying auditing universe ◦ Identification of risks ◦ Categorization of possible.
Enterprise Risk Management Chapter One Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Internal Audit Plan and Its Alignment to Risk Strategy
©2000 Bank for International Settlements 1 F I N A N C I A L S T A B I L I T Y I N S T I T U T E BANK FOR INTERNATIONAL SETTLEMENTS On-site Examination.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
TREASURY REGULATIONS’ CHANGES AND POTENTIAL IMPACT
Revised AQTF Standards for Registered Training Organisations Strengthening our commitment to quality - COAG February August 2006.
Session 11 & 12. Auditing standard of I.A. & A.D. Prescribes: Auditor should report about weakness in Internal Control of management (Para 7.1.) Weakness.
Electronic Presentations in Microsoft ® PowerPoint ® Prepared by Brad MacDonald SIAST © 2003 McGraw-Hill Ryerson Limited.
RTI, MUMBAI / CH 81 FOLLOW UP PROCEDURES DAY 8 SESSION NO.3 (THEORY) BASED ON CHAPTER 8 PERFORMANCE AUDITING GUIDELINES.
Chapter 3 The Audit Process. Overview of Audit Process Developing an Understanding with the Client Financial statement engagements Audits Compilations.
RTI, MUMBAI / CH 81 FOLLOW-UP PROCEDURES DAY 8 SESSION NO. 1 (THEORY) BASED ON CHAPTER 8 PERFORMANCE AUDITING GUIDELINES.
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
Regional Accreditation Workshop For Asia and Eastern Europe Manila, Philippines th March, 2012.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
Writing and updating strategic and annual plans Richard Maggs Astana September 2014.
Shared Services and Third Party Assurance: Panel May 19, 2016.
USDA 2016 Financial Management Training Transforming Shared Services
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Internal Control in a Financial Statement Audit Chapter Six.
Australian National Audit Office Better Practice Guide: Implementation of Programme and Policy Initiatives Presentation to the Canberra PMI Chapter 7 March.
Successful Integration is a result of good governance – getting the wiring right Integrated care as an aspiration is simple, and simplest if one begins.
Annual Report: Additional Financial Statements
Annual Report: Additional Financial Statements
Agenda Introduction Internal Audit IIA Standard Overview COSO Overview
Internal control - the IA perspective
Edit Nemeth, Vice Chair of IACOP
Richard Maggs Bucharest December 2014.
Edit Nemeth, Vice Chair of IACOP
Annual Report: Additional Financial Statements
Good practices for risk assessment and control activities
Process and Procedure Documentation
(Audit) Expectation Management
Performance based planning and programming
Presentation transcript:

From risk to planning Making the bridge from risks to audit plans Richard Maggs Astana September 2014

Risk Audit plans must be risk based The chief audit executive must establish risk-based plans to determine the priorities of the internal audit. IIA Standard 2010 The internal audit activity’s plan of engagements must be based on a documented risk assessment, undertaken at least annually. IIA Standard 2010.A1 The last RAWG meeting considered risk assessment This meeting will focus on preparing strategic and annual plans

Key definitions for risk based planning The objective is of risk-based planning is to ensure that the Auditor examines subjects of highest risk to the achievement of the organisation’s objectives Audit plans must be developed through a process that identifies and prioritizes potential audit topics The audit universe is the entire population of potential audit topics The risks or opportunities have to be assessed and decisions taken on other risk factors that may influence the priority to be given to each element of the audit universe (audit objects).

Recap on five steps in guide Determining and categorising the audit universe. (See chapter 2 of RAAP) Identifying individual events that may give rise to risks and opportunities across the audit universe. (See chapter 3 of RAAP) Scoring events in terms of probability and impact (taking into account management actions to mitigate risk) to identify the level of residual risk. (See chapter 3 of RAAP) Building risk-based audit plans by using generic risk factors and scoring criteria for each factor to determine the audit priority of all audit objects within the audit universe. (See chapter 4 of RAAP) Presenting the results of risk-based planning by writing and updating strategic and annual work plans. (See chapter 5 of RAAP)

Audit risk assessment Audit risk assessment is part of planning and a process where auditors consider (i) individual events and the risks and opportunities these represent to the achievement of the objectives of elements of the audit universe and (ii) generic risk factors that help prioritize work to areas of highest risk. The purpose of audit risk assessment is to ensure that audit resources are addressed to the audit of areas of highest risk to the Organisation. Audit risk assessment is different from risk management undertaken by managers. See Table 1 in RAAP guide.

Why do we need a bridge from risks to plans? There may be hundreds of individual risks Risk is not the only factor that influences the decision to carry out an audit. Others include: Materiality Complexity of transactions Controls The auditor is interested in residual risk which must take into account effectiveness of controls. Inherent Risk minus controls = Residual Risk

Recap on audit Universe 1 The phrase “audit universe” is a simple way of referring to the totality of all things that an internal auditor could separately examine. The universe consists of the totality of “auditable objects” which is a way of identifying a describing discrete part of the business, system or process, which can be separately audited. Auditable objects need to be large enough to justify an audit and small enough to be manageable.

Recap on audit Universe 2 Traditionally, auditable objects were categorised by organisational structure - a “vertical” analysis. Here an auditable object equated with one or a number of organisational units. But its also important to design audit coverage from a horizontal or cross-functional view of the entity - that is ‘horizontal’ audits based on entire business processes. The top five categorisations used by IA are: Organisational structure (Departments, Divisions, Units, Stand-alone Projects); Common processes (Payments, Receipts, Asset Management, Procurement, Contracting, Inventory, Human Resource Management) Location (Headquarters, Regional offices, Local offices) Operational programmes Service lines

Selecting audits from the audit universe The objective of this stage of the process to determine what needs to be audited from within the audit universe. We build risk based audit plans by applying risk factors to each element of the audit universe. It may help to think of “risk factors” as” selection factors” Keep the number of risk factors to between 4 and 8. Too few risk factors will limit the effectiveness of the exercise; too many will increase the time it takes to and will not produce substantially better results Choose risk factors that make the most sense for the Organisation you are auditing.

Common risk (selection) factors Financial materiality Complexity of activities. Control environment Reputational sensitivity. Inherent risk Extent of change. Confidence in Management. Fraud potential. Political sensitivity. Time since last audit.

Process Develop a set of criteria to score and therefore rank the relative need to audit each of the possible audit objects within the audit universe Consider adding a weighting factor as not all risk(selection) factors are equally important Make sure that risk index scores and priorities are reasonable. (a) Calculate the theoretical maximum before setting the index priorities and (b) be prepared to change the index priorities if the results are obviously unrealistic (for example if every audit is show as high priority).

Example – scoring factors

Example – weighting factors

Final Comment The process of moving from individual risk assessment to selection subjects for audit can be confusing as there is no direct link between assessing individual risks This is a transition issue that arises because of the lack of good risk management in Government Ministries and Agencies Consider carrying out internal audits which encourage management to have more effective risk management processes