1/50
Topics that I need extra study time for
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Process owner, internal auditor, user
The participants of an assurance service
Scope of assurance services
Determined by the internal auditor.
Operational efficiency
Reliability of reporting
Compliance
Safeguarding assets
Ethical culture
Control Self Assessment (CSA)
Evaluation of organization’s risk management and control systems
facilitated by internal auditors
participation by employees of all levels
results in: sense of ownership, awareness of risks, improved effectiveness of controls
Workshop-Facilitation; Survey (questionnaire); Self-certification
The three primary approaches of CSA programs:
Workshop Facilitation Approach
CSA that is structured, documented, and repetitive.
Objective-based format: best way to accomplish business objective? identifies controls.
Risk-based format: risks to achieving adjective? identifies risks.
Control-based format: how well controls in place are working? risks & controls preidentified. gap analysis.
Process-based format: activities in chain of processes. evaluate & better entire process.
Self-Certification Approach
CSA through management produced analysis of selected business processes, risk management activities, and control procedures.
Assumes managers and members of work team understand risk and control concepts and use them in communications.
Survey Approach
CSA though question based format - mostly “yes or no”, “have or have not”.
Preferred if the culture in the organization limits open, candid discussions in workshop settings or there is a need to minimize time spent & costs of information gathering.
External Business Relationships
Service providers, supply-side partners, demand-side partners, strategic alliances & Joint Ventures, Intellectual property partners
Benefits of: lower costs, operational efficiency, special expertise, new tech, known brand, and/or economies of scale
Mgmt ensures that benefits > costs; IA assists in validating those efforts
Lump Sum Contracts
Used when requirements are well-defined, uncertainties can be identified and costs estimated, and competition is adequate
Consider:
Progress payments
Incentives
Escalator clause
Adjustments for labor costs
Change orders
Cost-Plus Contracts
Contract which copes with uncertainties about costs by setting a price equal to project expenditures in addition to a determined amount.
Balance in getting contractor to have incentive for economy and efficiency
Look for:
maximum cost provisions
incentives for early completion
Unit Price Contracts
Contracts used when convenient measure of work is available [i.e. person-hours logged, acres of land cleared, cubic yards of earth moved, etc.]
key issue of accurate measurement of work performed
Total Quality Management
Focuses on the customer. Continuous pursuit of quality throughout the organization.
do it right the first time
empower employees
promote teamwork
continuous improvement
satisfy the customer (internal and external)
Balanced Scorecard
Tool relating Critical Success Factors determined by a strategic analysis with financial and non-financial measures. Prioritize both long- and short-term considerations.
Perspectives:
Financial (sales, fair value of stock, profits, liquidity)
Customer (retention rate, relationships, marketing, delivery, response time, quality, market share)
Internal (quality, productivity, adaptability, lead-time, safety)
Learning, Growth, and Innovation (R&D, HR development, morale, competence)
Process (functional) Engagements
Engagement following process-crossing organizational lines, service units, and geographical locations.
Emphasis on operations and effectiveness and efficiency of the cooperation of the area under review.
i.e. Purchasing and receiving; Safety; Marketing; Scrap handling and disposal; etc.
Program-Results Engagement
Obtain information about the costs, outputs, benefits, and effects of a program
[Program - funded activity not part of the continuing operations of the organization i.e. new information system implementation]
Productivity Ratio
[Program-Results Eng: assessing tool]
Output / Input
Productivity Index
[Program-Results Eng: assessing tool]
Production potential - (Output / Input) tracked overtime
Resource Usage Rate
[Program-Results Eng: assessing tool]
Resource use / Available Resources
Operating Ratio
[Program-Results Eng: assessing tool]
Operating Costs (C.O.G.S + OpEx) / Revenue
(COGS + OpEx) / Revenue
Operating Ratio
Integrity
Adherence to ethical principles; honesty and professional courage; tell the truth and do the right things.
The foundation of trust and other principles within the code of ethics.
Disclose all material facts that could affect org’s ability to make informed decision
Observe all applicable laws and make all disclosures expected by the profession
Objectivity
Unbiased mental attitude that allows auditors to make professional judgments, fulfill responsibilities, and achieve objectives without compromise.
Avoid conflict of interests - either in fact or appearance [must be disclosed]
Avoid bias - self-review bias; familiarity bias; prejudice/unconscious bias
Competency
Must use their knowledge, skills, and abilities to effectively perform their duties.
Only provide services for which required skills are possessed or will soon be developed.
Due Professional Care
Auditors should take great care when planning and performing IA services.
Conformance with IPPF standards
Consideration of nature, circumstances, and requirements of work to be performed
Application of professional skepticism
Professional Skepticism
Maintaining an attitude of inquisitiveness;
Critically assessing reliability of information;
Straightforwardness and honesty in questioning;
Seeking additional evidence to make judgments of information
Confidentiality
Internal Auditors use and protect information appropriately.
Following policies, procedures, laws, and regulations when using information.
Not to be used for personal gain
Internal Governance Mechanisms
Corporate charters & bylaws, boards of directors, internal audit functions.
External Governance Mechanisms
Laws, regulations, and government regulators (enforcement)
Strategic Direction
Governance component which determines the:
Business Model
Overall Objectives
Approach to risk taking (including risk appetite)
Limits of organizational conduct
Oversight
Governance component which include the following elements:
Risk management activities performed by Senior Management & Risk Owners
Internal & External assurance activities
This component is which internal audit is most concerned; where risk management & control processes are most likely to be applied.
Risk Owners
Determined by Senior Management. They are Managers responsible for specific day-to-day risks.
Responsible for:
Evaluating adequacy of RM activities
Determining if activities are operating as designed
Establishing monitoring activities
Ensuring accurate, timely, and available information is to be reported
Identification of context; Risk identification; Risk assessment and prioritization; Risk response; Risk monitoring
The steps of the Risk Management Process
Controls
Actions by management to manage risk and ensure risk responses are carried out
Control Risk
Risk that controls fail to effectively manage controllable risks
Enterprise Risk Management
The culture, capabilities, and practices, integrated with strategy-setting and performance, that organizations rely on to manage risk in creating, preserving, and realizing value.
Risk Profile
Composite view of the types, severity, and independence of risks related to a specific strategy or business objective and their effect on performance.
Any level (entity, division, operating unit, or function) or aspect (product, service) of the org
Portfolio View
Composite view of risks related to entity-wide strategy and business objectives and their effects on entity performance.
Acceptance (Retention)
Risk response where no action is taken to alter severity of the risk. “Self-Insurance”.
Appropriate when risk is within the risk appetite.
Avoidance
Risk Response where action is taken to remove the risk.
Suggests that no response would reduce the risk to an appropriate level.
Ex. risk of pipeline sabotage is mitigated by selling the pipeline.
Pursuit (exploitation)
Risk response where action is taken to accept increased risk to improve performance without exceeding acceptable tolerance.
Reduction (mitigation)
Risk response where action is taken to reduce the severity of the risk so that it becomes within the target residual risk profile and risk appetite.
Ex. risk of system penetration is mitigated by maintaining an effective cybersecurity team
Sharing (transfer)
Risk response where action is taken to reduce the severity of risk by transferring a portion of the risk to another party.
Ex. Insurance, hedging, joint ventures, outsourcing, and contracts
COSO ERM
ERM Framework. Prescriptive.
5 Components
Governance and Culture
Strategy and Objective Setting
Performance
Review and Revision
Information, Communication, and Reporting
20 Sub Principles across the components.
Reasonably expected to manage risks effectively and to help create, preserve, and realize value when the components, principles, and controls are present and functioning.
ISO 31000
ERM framework. Flexible, integrated.
8 Principles
6 Framework components
6 RM Process Elements
3 RM Assurance Approaches
P.P.M. - Principles, Process, Maturity
ISO 31000 Principles
Each inducive to Value Creation & Protection:
Integrated
Structured and Comprehensive
Customized
Inclusive
Dynamic
Best Available Information
Human and Cultural Factors
Continual Improvement
Risk Treatment
Element of ISO 31000 RM process.
Repetitive process of:
1) selecting a risk response (accept, avoid, reduce, share, pursue),
2) implementing it
3) assessing effectiveness & determining acceptability of residual risk
4) repeat if attempt was unacceptable
Authorization, Recordkeeping, Custody
Segregation of Duties: for any given transactions the following functions should be performed by separate individuals in different parts of the organization
COSO Internal Control Framework
3 Objectives to achieve
O.R.C - Operations, Reporting, Compliance
4 Entities affect it
5 Components
C.R.I.M.E. - Control activities, Risk assessment, Information & communication, Monitoring, control Environment
COBIT 2019
IT Control & Governance Framework.
6 Governance System Principles
3 Governance Framework Principle
Pressure, Opportunity, Rationalization
The fraud triangle
Independence
Freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner.
“Am I free from influence?”
Organizational position & relationships