Building Strategic Risk-Based Internal Audit Services Case Studies.

Slides:



Advertisements
Similar presentations
Board Governance: A Key to Quality Organizations
Advertisements

Organizational Governance
. . . a step-by-step guide to world-class internal auditing
Head teacher Performance Management
HR Manager – HR Business Partners Role Description
Chapter 14 Fraud Risk Assessment.
IMFO Audit & Risk Indaba June 2012
Chapter 10 Accounting Information Systems and Internal Controls
Control and Accounting Information Systems
Introduction to Enterprise Risk Management (ERM)
Meeting with IESBA CPAB Update Glenn Fagan and Kam Grewal April 7, 2014.
Presented by: Patricia “Patti” Snopkowski Chief Auditor, OUS Internal Audit Division 2011 Annual Risk Assessment.
Building a Better Business Model Start with a discussion of Risk Higher Education Policy Commission Board of Governors Summit August 2, 2014.
The Role and Value of Internal Audit Association of Credit Union Internal Auditors September 26, 2012.
Preparing for an External Quality Assessment of your Quality Assurance and Improvement Program Institute of Internal Auditors El Paso Chapter August 29,
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Institute of Municipal Finance Officers & Related Professions
PwC Role of Internal Audit in Corporate Governance September 2010 Tumin Gültekin, Partner.
IS Audit Function Knowledge
By Saurabh Sardesai October 2014.
Enterprise Risk Management in DHHS
Quality evaluation and improvement for Internal Audit
Risk Assessment Frameworks
External Quality Assessments
Report on Internal Audit and Investigation activities
Purpose of the Standards
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
PAINTING THE FULL PICTURE
Audit Committees in Local Government FinPro Professional Development Seminar Linda MacRae Local Solutions Pty Ltd 25 October
BRIEFING TO THE PORTFOLIO COMMITTEE ON THE DPSA’S RISK MANAGEMENT STRATEGY PRESENTATION TO THE PORTFOLIO COMMITTEE 12 MAY
Minnesota Adoption of the Green Book April 16, 2015 Jo Kane Internal Control & Accountability Specialist.
Internal Auditing and Outsourcing
WHERE WE ARE 22 member associations in 20 countries Over 4300 individual members who are responsible for risk management and/or insurance in their organisations.
IT Governance Steering Committee December 2, 2010.
Organization Mission Organizations That Use Evaluative Thinking Will Develop mission statements specific enough to provide a basis for goals and.
The role of internal audit in enterprise-wide risk management (ERM)
OECD Guidelines on Insurer Governance
Where Innovation Is Tradition Mason Initiatives: Efficiency & Effectiveness Enterprise Risk Management Beth Brock, Associate VP & Controller George Mason.
Audit objectives, Planning The Audit
Section Topics Establish a framework for assessing risk
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Chapter 14 Internal auditing 14-1 Copyright  2010 McGraw-Hill Australia Pty Ltd PPTs t/a Auditing and Assurance Services in Australia 4e by Grant Gay.
City of Tshwane GDS August Reputation promise/mission The Auditor-General of South Africa has a constitutional mandate and, as the Supreme.
World Bank Institute Regional Workshop for Anglophone Africa on Auditing and Financial Accountability Addis Ababa KEY ISSUES IN CREATING AN EFFECTIVE INTERNAL.
Corporate Governance Yoshi Kawai Secretary General, IAIS IAIS-ASSAL Regional Seminar Buenos Aires, Argentina, November 2011 PUBLIC.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
The views expressed in this presentation do not necessarily reflect those of the Federal Reserve Bank of New York or the Federal Reserve System Association.
RAWG.  Risk assessment guideline for strategic and annual planning ◦ Identifying auditing universe ◦ Identification of risks ◦ Categorization of possible.
Strategic Approaches to Improving Ethical Behavior
ANNOOR ISLAMIC SCHOOL AdvancEd Survey PURPOSE AND DIRECTION.
INTERNAL AUDIT 2015 ANNUAL REPORT Internal Audit Assurance Independent Objective Collaborative Compliance Controls Efficiency Accountability Transparency.
Internal Auditing Effectiveness
Developed for: ORIMS Professional Development Session October 22, 2013 Presented by: Steve Pottle, York University Michelle Williamson-Reid, TSSA Risk.
1 COSO ERM Framework Update Our Next Challenge and Opportunity September 2015.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Internal Audit Quality Assessment Guide
Business Continuity Planning 101
JMFIP Financial Management Conference
An Overview on Risk Management
IIASA Governance Review
HUMAN RESOURCE GOVERNANCE, RISK MANAGEMENT AND COMPLIANCE
Understanding the entity
PLANNING THE INTERNAL AUDIT (8 - 10%)
SAPS Audit Committee 26 October 2016.
William “Bill” McGinnis
Response to Report on Local Government new risk management and internal audit framework for NSW councils.
Good practices for risk assessment and control activities
Presentation transcript:

Building Strategic Risk-Based Internal Audit Services Case Studies

RISK BASED AUDIT SERVICES Outline Two Universities - Two Approaches –Linkages between Internal Audit & Enterprise- Wide Risk Management (ERM) –ERM’s application in audit processes Participative – encourage everyone to share successful practices

RISK BASED AUDIT SERVICES The University of Alberta In 2007: – Over 36,500 students – Over 8100 degrees granted – Staff: 3493 Academic, 6233 Support (FTE) – Over $420 million in annual research – The current capital program is valued at more than $1 billion

RISK BASED AUDIT SERVICES New Internal Audit Strategy Conducted a Current State Analysis Supported by External Audit of Internal Audit (2005) Interviewed Senior Administration (34) & Audit Committee members (3 of 5) –“What would you like to see from internal audit?”

RISK BASED AUDIT SERVICES Board Audit Committee Responsibilities Leading Practices for Post-Secondary Institutions 1 Strategy Manage the Relationship with the External Auditor Ensure the Quality of Financial Reporting Oversee Regulatory Compliance Work with the Internal Audit Function Monitor Management’s Handling of Internal Controls & Risk Management Monitor the Ethics ProgramWhistleblowing 1 The Changing Role of the Audit Committee – Leading Practices for Colleges, Universities and Other Not-for-Profit Education Institutions, PricewaterhouseCoopers 2004

RISK BASED AUDIT SERVICES Strategic Business Plan Internal Auditing (Core Business) Examining Suspected Fraud and Irregularities (Secondary Business) Related Activities: –Liaison with External Auditors –Continuous Auditing –Risk Management –Institutional Compliance

RISK BASED AUDIT SERVICES Strategic Business Plan The Strategic Plan outlines: – Strategic initiatives – Objectives – Specific IA strategies – Performance measures Clear linkage to the U of A’s strategy documents Dare to Discover & Dare to Deliver –Report progress annually

RISK BASED AUDIT SERVICES Strategic Business Plan Stakeholder Satisfaction Committee & Senior Mgt Auditee Surveys # recommendations accepted/implemented Internal Audit Processes Completed vs. planned audits Time analysis Audit Cycle Time Compliance with Standards Innovation & Capability Training Hours Certified Staff Effective Use of Good Practices. Other: Budget and Benchmarks Reporting on IA strategic initiatives

RISK BASED AUDIT SERVICES Audit Linkage to ERM Separate Functions at U of A

RISK BASED AUDIT SERVICES History of ERM 2002/03 PWC hired to develop framework Accountability and Risk Management Steering Committee established (IA ex-officio) Risk Management Policy /Appetite statements ERM reviews in 2005 and 2007 Adoption of COSO ERM Integrated Framework New Associate Vice-President (Risk Management) position created in Dec 2007 Risk Management, Budgets, Emergency Preparedness, Insurance. Environmental Health & Safety, and Compliance

RISK BASED AUDIT SERVICES ERM & Internal Audit – The Institute of Internal Auditors. “The Role of Internal Auditing in Enterprise- wide Risk Management”, September 29, 2004.

RISK BASED AUDIT SERVICES Challenges –ERM is evolving –Roles & responsibilities Where should we be on the continuum? – Board of Governors oversight requirements

RISK BASED AUDIT SERVICES A Snapshot of Queen’s 20,566 students 2,374 faculty; 2,472 staff Fiscal revenue of $733M Largest ever capital expansion program with debt requirements Fiscally conservative governance

RISK BASED AUDIT SERVICES Internal Audit –Formerly Internal Audit, now Risk Management & Audit Services (“RMAS”) –First audit completed in 1991 –Averaged two to three staff members until reorganization to RMAS in 2004 –Presently three staff members and a student auditor

RISK BASED AUDIT SERVICES Internal Audit Strategy –New VP from New Zealand with ERM experience –Department name change to RMAS in 2004 –View to outsourcing internal audit function –After first year of revised mandate, agreed on strategy to provide audit services in-house with co- sourcing where expertise required (i.e. IT)

RISK BASED AUDIT SERVICES Revised Mandates –Audit Committee mandate revised May ’05 with best practice responsibilities, including oversight of effectiveness of risk management –RMAS Charter revised –Staff complement of 3 achieved April ’07 –No departmental strategic plan to date

RISK BASED AUDIT SERVICES ERM at Queen’s –Deloitte engaged in 2005 to perform initial risk assessment and advise on framework –RMAS leader of project with executive leadership support –Initial report to the Audit Committee –Further development of framework put on hold as University Strategic Plan developed –Recent update of current strategies and action plans

RISK BASED AUDIT SERVICES ERM and Internal Audit RMAS is the ERM “Champion” Included in RMAS’ Charter : Develop and maintain the ERM framework Coordinate and report on ERM activities Promote a strong risk management culture, monitor strategies and provide advice Develop the audit plan using risk-based methodology

RISK BASED AUDIT SERVICES ERM and Internal Audit Legitimate IA role per IIA

RISK BASED AUDIT SERVICES Challenges –ERM is still in relative infancy –Difficult to champion a process while building a department and delivering on a risk based audit plan –No internal risk management committee –Audit Committee concern

RISK BASED AUDIT SERVICES Group Discussion What are the ERM linkages to Internal Audit in your institution? What are the challenges?

RISK BASED AUDIT SERVICES ERM Application in Internal Audit –Audit Planning Two year plan (updated no less frequently that annually) Projects Mapped to risks identified through ERM. Inherent Risk assessment Section of plan deals with items highlighted and not covered in plan

RISK BASED AUDIT SERVICES Internal Audit Planning process Major IT Systems Projects Description Type Priority Timing Level of Effort Project 1 Project 2 Project 3 Project 4 Scope and Objective Audit - Assurance Audit - Consulting Audit - Assurance Quarter / Year Hours Scope and Objective Risk-Based Internal Audit Plan Universe Risks Internal Audit Universe Risk Framework Unacceptable Institutional Risks (as identified through ARMSC processes) Academic Faculty Renewal Academic Reputation Enrolment Growth and Complexity HR Processes IT Infrastructure Safety and Security Research Growth, Complexity and Stewardship Leadership & Admin Structure Relationship with Key Supporters Base Funding Academic & Administrative Units, Centres Institutes Core Processes (e.g. Risk Management, Strategic Planning, Financial Reporting) Audit Universe Impa ct Inherent Risk Exposure Probability Acceptable Caution H M L HML Unacceptable

RISK BASED AUDIT SERVICES ERM Application in Internal Audit –Audit Engagements - Planning Strategic objectives – of U of A and area Potential risks – use the U of A risk appetite statements in the area to guide audit focus. Areas noted as risks are documented in Project terms of Reference

RISK BASED AUDIT SERVICES Narrow Example (Audit of Commercialization Governance) Business Objective 18: Ensure proper oversight of related party transactions and conflict of interest situations 1. Key Inherent Risks (Risks that could impact achievement of the business objective) Risk Ratings for Key In­herent Risks AuditabilitySummary of Key Considera­tions From Preliminary Survey Work Audit steps F.4 and F.5 ILE 1.Conflict of interest issues may arise due to the activities of TEC Edmonton. Possible causes:  The “conflict of interest” policy may not be followed or known. HM M H  Review how the University “Conflict of Interest” policy flows through to TEC Edmonton.  Review how conflict of interest issues are monitored and reported.  The application of the policy is unclear, however it is mentioned in both the joint venture agreement and the master secondment agreement.

RISK BASED AUDIT SERVICES ERM Application in Internal Audit –Audit Engagements – Reporting Table AttributesDescription Criteria Outlines the criteria used in the audit – what should be in place according to good practices. Current Environment and Potential Risks Highlights of what was found during the review. This includes the potential risk exposure with the current environment, as assessed based on the work conducted. Risk rating* The risk-rating framework used is that outlined below and is consistent with the University’s Risk Management policy. Opportunities for Improvement Recommendations to mitigate risks or improve operations where necessary.

RISK BASED AUDIT SERVICES ERM Application in Internal Audit –Audit Engagements – Reporting (cont.) RatingDescription High risk of significant reputation damage, financial loss or exposure, major breakdown in information system or information integrity, significant incident(s) of regulatory non-compliance, potential risk of loss of life or limb Moderate risk of significant reputation damage, financial loss or exposure, major breakdown in information system or information integrity, significant incident(s) of regulatory non-compliance, potential risk of loss of life or limb Low risk of significant reputation damage, financial loss or exposure, major breakdown in information system or information integrity, significant incident(s) of regulatory non-compliance, potential risk of loss of life or limb

RISK BASED AUDIT SERVICES Results –Fewer – “red lights” –Focussed recommendations with a clear linkage to risk and strategy –Foundation for overall assessments –Good feedback from administration (increased use of audits in governance meetings and decisions) –Budget NOT PERFECT

RISK BASED AUDIT SERVICES Challenges –Striving to ensure committee members have sufficient information to fulfill their mandate –Interpretation of risk appetite –Financial vs. Strategic, Operations Risks –Coverage – Conclusion on Internal Control –Role in Fraud Prevention/Detection: – Fraud Policy and Protected Disclosure – New IIA position – Role in Institutional Compliance

RISK BASED AUDIT SERVICES ERM and Audit Planning –Previous audit universe was academic, administrative, ancillary and research units => audits were unit based –The top 13 critical risks are very high level (e.g. Human Resources, Reputation etc.) –Review audit universe in two ways: –Traditional general ledger units –Functional/operational processes

RISK BASED AUDIT SERVICES ERM and Audit Planning –Dual annual risk assessment processes for audit plan –Units (level of expenditures; complexity; management concerns etc.) –Functions/Processes –Governance –Finance and Administration –Programs and Services –Students –Human Resources –IT –External Relations Mapped to Enterprise risks }

RISK BASED AUDIT SERVICES Mapping Enterprise Risks

RISK BASED AUDIT SERVICES ERM and Audit Planning –Professional judgement –No risk appetite or policy to refer to –Balancing “low hanging fruit” and high-level risks in audit plan –Have not specifically ruled out review of certain risks NEEDS FURTHER WORK…An evolving process

RISK BASED AUDIT SERVICES ERM and Audit Reports Example: Research Grants & Contract Audit

RISK BASED AUDIT SERVICES ERM and Audit Reports –Have avoided rating findings to date –No standard risk rating –Will rate findings not implemented during follow-up audit (High, Medium, Low risk) –Subjective

RISK BASED AUDIT SERVICES Challenges –No risk policy or risk tolerances developed –No standard risk ratings –Subjective –Not all risks are easily auditable –Some keys risks under constant management review –Coverage of issues versus the high level risks –Addressing Audit Committee concerns

RISK BASED AUDIT SERVICES Group Discussion What other challenges do you see in integrating ERM practically with IA requirements? Success stories to share? Any other comments?