Download presentation
Presentation is loading. Please wait.
Published byCecilia Palmer Modified over 9 years ago
1
Section Topics Risk and control terminology Risk elements
Control elements Part 1, Section 2
2
The Nature of Work for the Internal Audit Activity
Risk Control Governance Help manage risk by: Help maintain effective controls by: Help assess and improve governance by: Identifying and evaluating significant exposures to risk. Contributing to the improvement of risk management and control systems. Monitoring and evaluating the risk management system. Evaluating the effectiveness and efficiency of controls. Promoting the continuous improvement of the control environment. Promoting appropriate ethics and values. Ensuring effective performance management and accountability. Effectively communicating risk and control information. Effectively coordinating the activities and communicating information. Part 1, Section 2, Introduction
3
Risk and Control Risk Control
“The possibility of an event occurring that will have an impact on the achievement of objectives; it is measured in terms of impact and likelihood.” “Any action taken by management, the board, and other parties to manage risk and increase the likelihood that established objectives and goals will be achieved.” Source: Standards Glossary. Part 1, Section 2, Topic 1
4
Discussion Question Identify the following statements as true or false. Answers: True Risk begins with strategy formulation and objective setting. Risk reflects a single outcome. Risks may present threats to an organization or be the failure to achieve positive outcomes. Business risks are uncertainties related to the achievement of business objectives. False True True Part 1, Section 2, Topic 1
5
Discussion Question Identify the terms described below. Answers:
Acceptable risk The business impact that would be experienced if certain risks became realized. The risk derived from the environment without the mitigating effects of internal controls. The risk remaining after management takes action to reduce the impact and likelihood of an adverse event, including control activities. The level of risk an organization is willing to accept. Inherent risk Residual risk Risk appetite Part 1, Section 2, Topic 1
6
Terminology The list of terms provides a common language to use with the board, management, and others in all communications. Any questions about other terms? Part 1, Section 2, Topic 1
7
Risk Assessment Process
Part 1, Section 2, Topic 2
8
Discussion Question Identify the following items as likelihood or impact factors. Answers: Impact Negative press about a discriminatory employment practice Increasing complexity of environmental regulations Length of time a plant remains shut down after a fire Probability estimates for a new product launch Likelihood Impact Likelihood Part 1, Section 2, Topic 2
9
Risk Map for Likelihood and Impact
High High Impact Low Likelihood High Likelihood Low Impact Impact Low High Likelihood Part 1, Section 2, Topic 2
10
Benefits and Limitations of Internal Control
Internal control can: Achieve performance and profitability targets. Prevent loss of resources. Support reliable financial reporting. Support compliance with laws and regulations, avoiding damage to reputation or other consequences. Internal control cannot: Ensure organizational success or even survival. Ensure the reliability of financial reporting. Ensure absolute compliance with laws and regulations. Helps mitigate risk and ensure that management strategies and objectives are carried out Part 1, Section 2, Topic 3
11
Types of Controls Part 1, Section 2, Topic 3 Type of Control
Description Examples Preventive Proactive controls that deter undesirable events from occurring Ethical “tone at the top” Effective empowerment Mutual trust Performance standards Detective Reactive controls that detect undesirable events that have occurred Input controls Processing controls Output controls Directive Proactive controls that cause or encourage a desirable event to occur Guidelines Training programs Incentive plans Mitigating Controls that reduce the potential impact should an event occur Insurance Compensating Controls that compensate for the lack of an expected control Close supervision in lieu of segregation of duties Part 1, Section 2, Topic 3
12
Discussion Question Identify the following items as active or passive controls. Answers: Active Independent verification of performance Accounts payable transaction procedures Information system controls limiting transactions Plant heating, ventilation, and air conditioning system Senior and operating management status meetings Active Passive Passive Active Part 1, Section 2, Topic 3
13
The Control Loop Part 1, Section 2, Topic 3
14
Discussion Question Which of the following characterize effective controls? (Select all that apply.) Root cause identification Efficiency in achieving intended objectives Alignment to strategic objectives Redundant controls to ensure accuracy Answer: I, II, and III. Excessive and/or redundant controls can lead to confusion and frustration. Part 1, Section 2, Topic 3
15
Reinforcing Activity 1-5
Part 1, Section 2, Topics 1, 2, and 3 Risk and Control Elements Part 1, Section 2, Topics 1, 2, and 3
16
End of Section 2 Questions? Part 1, Section 2
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.