The Three Roles Of Internal Auditing And Risk Management

Improved Essays
As we already learned in chapter 4 concerning in risk management, the key component of internal auditing is evaluating and improving the effectiveness of governance, risk management and control process. The connection between internal auditing and risk management are fairly straight-forward. Internal auditor would not achieve their objectives without risk assessment and management.

In order to achieve the objectives, one must to analyze the risk via enterprise-wide risk management. According to the Institute of Internal Auditor or the IIA, enterprise-wide risk management refers to the process conducted by management to understand and deal with risks and opportunities (uncertainties) that could affect the organization’s ability to achieve its objectives (IIA Chapter 4).

Due to complexity of business nature, risk also evolves into five types, which are strategic, compliance, operational, financial, and reputational
…show more content…
According to IIA position paper, the three categories of roles internal audit in enterprise-wide risk management are the foundation part of internal auditing in concern to ERM, legitimate internal audit roles with safeguards, and roles internal audit should not undertake (IIA 4). Each category has at least five assurance activities that support organization’s risk management and governance processes. The foundation part of internal auditing in concern to ERM is crucial part to accommodate objective assurance to the board and management level on the performance to maintain risk. After the three categories have been explained, question may rise up, what are the ramifications if internal audit assumes roles it is being advised against taking? It simple said the company or organization will not achieve their objectives. The consequences are ranging between small and large impact to the company that could lead to loss profit or even

Related Documents

  • Superior Essays

    There is no way to be sure how the investment will turn out and there is always a risk of experiencing loss in profit and not achieving as much as expected. The good part of this risk is that it can be statistically predicated in many cases. For instance, businesses can calculate the risks that are involved and whether or not they will be able to absorb the negative effects if need be and can then make their decisions based on that prediction. However risks and uncertainty are always present for businesses and as a result management must be prepared for anything at anytime.…

    • 1274 Words
    • 6 Pages
    Superior Essays
  • Great Essays

    The risk that would be identified are: A review of cash flow statements and a recommendation of implementing new short-term working capital strategies on long-term cash flow, an explanation of corporate risk mitigation techniques…

    • 1313 Words
    • 6 Pages
    Great Essays
  • Decent Essays

    Australian Unity Board is responsible for Group governance: approval of strategies, operating plans, budgets; setting and monitoring Group risk management framework; control and accountability policies/systems. Committees include: • Audit and Compliance: approves annual internal audit plan; main objective is to oversee the credibility and objectivity of financial reporting and the compliance with obligations; oversees and appraises the quality of audits conducted by both internal/external auditors (e.g. EY financial auditors); determines adequacy of controls and evaluates adherence. • Risk: oversees risk management framework for identifying, assessing, mitigating and monitoring material risks arising from the business activities; promotes…

    • 221 Words
    • 1 Pages
    Decent Essays
  • Decent Essays

    Therefore, it is important for the company to increase internal control on accounting estimate and fair value measurement. Based on the audit risk model, the planned detection risk will be low-level (Arens et al. 2013, p.234). Because the higher inherent risk related to the lower planned detection risk (Arens et al. 2013, p.234). Thus, this will impact on the evidence mix for the audit planning.…

    • 896 Words
    • 4 Pages
    Decent Essays
  • Improved Essays

    The Sarbanes-Oxley Act

    • 884 Words
    • 4 Pages

    It is the most contentious aspect of the bill, where it requires management and the external auditor to report on the adequacy of the company’s internal control on financial reporting (Wang, 2008). One of the issues Chowdhury (2007) raised, about the cost-effectiveness of the bill, is posed in this section as this is the most costly aspect of the legislation for companies to implement. To help ease the high costs of compliance, practice and guidance have evolved to accommodate some of the expensive costs of the Act. The Public Company Accounting Oversight Board approved a couple standards for public accounting firms in the year 2007 to help alleviate these problems. Some of the things that the two standards together would require management to do is to assess both the design and operating effectiveness of selected internal control related to significant accounts and relevant assertions, perform a fraud risk assessment, scale the assessment based on the size and complexity of the company, as well as other steps in this process to conclude on the adequacy of internal control over financial reporting (Virag,…

    • 884 Words
    • 4 Pages
    Improved Essays
  • Decent Essays

    The auditor gain an understanding on the company’s transactions, events and information could influence the auditor’s judgment and may refrain from significant defect on the financial…

    • 206 Words
    • 1 Pages
    Decent Essays
  • Improved Essays

    Both parties feel differently regarding what internal control measures should be taken. As an example, often, accountants are not allowed to get close to, or become involved in assessments of the companies’ assessment of risks. This sis done to keep the accountants from becoming…

    • 553 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    This is something that is showing very positively. The new challenges for the auditors are to access and respond to risks during a financial statement audit, and have a main goal not to zero out this risk, but to limit the risk to a low level, to provide truth and ethics in each statement (The Finance Pig, 2013). Audits should be done continuously, one right after the other, in step by step form for accuracy, to the best of a companies’ ability. This keeps all eyes on the process at which is being performed, and if it is being done correctly. Internal ways of handling a company to ensure minimal risks for any major or further audit are being strictly enforced.…

    • 652 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    The IT Audit Director should have to report her findings back to management before taking action against a change that management has already approved (see: ISACA S7). I think this control gives the IT Audit Director too much power over operational changes. According to…

    • 355 Words
    • 2 Pages
    Improved Essays
  • Improved Essays

    This dialogue structure creates different layouts for stakeholders that can implement different situation that can arise within the corporation. Their task is to see all the possible negative consequence, alongside with the likelihood that the situation can occur. This gives them the chance to see the consequence effect with an estimated price on the misconduct. Then “the risk manager askes the stakeholder to consider the alternative enterprise responses—avoid the risk, accept it, reduce it, or share it…

    • 1533 Words
    • 7 Pages
    Improved Essays
  • Improved Essays

    Introduction Financial reporting has changed a great deal over the past fourteen years. Many companies have went out of business for the most significant reason; unethical behavior in the work place. The Sarbanes-Oxley Act of 2002 was created to enforce financial reporting regulations and the punishments for non-cooperation. Before 2002, the regulations for financial reporting were less severe than they are presently. Companies weren't as worried about being under the radar if they decided to engage in fraudulent financial practices.…

    • 929 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    B1A: Discuss the role that Paradigm’s leadership can play in fostering an ethical culture. The Paradigm’s leadership is very vital within the organization and whatever they do really matter a lot to its employee. One way to promote ethical culture is by rewarding ethical activities that the company expect in different situation. These reward will be based on individual behaviors and decision they make.…

    • 1953 Words
    • 8 Pages
    Improved Essays
  • Improved Essays

    1). The requirement of section 301.4 of the Sarbanes-Oxley Act of 2002, the audit committee of a public company needs to establish procedures for the receipt, retention, and handling of complaints received by the company regarding accounting, internal controls, or auditing matters. They are also required to establish procedures for those complaints to be treated confidentially, and for the submission process, the employees can submit anonymous their complaints about the accounting or auditing matters. This procedure is usually known as “whistleblower procedures.”…

    • 823 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    Running head: SARBANES- OXLEY ACT ATICLE ANALYSIS Sarbanes- Oxley Act Article Analysis University of Phoenix Sarbanes- Oxley Act Article Analysis Internal controls mandated by the Sarbanes – Oxley act have proven to be a difficult hurdle for publicly held companies to comply with. (Barnes & Thornburg, 2004) The internal control requirements of the Sarbanes – Oxley act have laid the responsibility of internal audits, effectiveness and efficiency of internal auditing controls squarely on the shoulders of senior management, audit committees they employ and external auditors. The compliance responsibility includes certification and consent forms to be filed by all involved parties.…

    • 664 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Introduction In the first two chapters of Resilient Leaders, U.S. Army Major General (Retired) Robert Dees describes many situations that molded his resilient leadership style. Those who serve in the military have many opportunities to sharpen their leadership skills, especially for commanding officers.…

    • 970 Words
    • 4 Pages
    Improved Essays