Showing posts with label Brad Zolkoske. Show all posts
Showing posts with label Brad Zolkoske. Show all posts

Wednesday, June 1, 2011

The GRC Approach - for Small Internal Audit Departments

Governance, Risk and Compliance (Part 2)

First identify all of the functions and/or groups that interact with the area subject to assessment. Then through interviews and evaluation determine the following:
  • Governance: the goal, mission and objective of the program.
  • Risk: the risks that are being managed by each of the functions and groups involved.
  • Compliance: the rules, regulations, internal policies, the operating procedures that influence the operating activities. In this space it is also necessary to identify all of the tools, people, and resources available in support of the compliance efforts.
Once determined, you can assess whether the various functions are aligned as to the Governance mission and objective, you can determine if they are operating against a common set of Risk factors and you can evaluate whether the Compliance efforts are operating cohesively across all groups and whether resources are being deployed to effectively address each of the compliance requirements.

This evaluation is then used as the springboard to development of a high level summary regarding the cohesiveness of the company’s GRC activities across the multiple disciplines subject to review.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.

Tuesday, May 24, 2011

When does GRC Fit within a Small Audit Shop?

Governance, Risk and Compliance (Part 1)

Governance, Risk and Compliance (GRC) is the latest and greatest hot topic being thrown at Internal Audit functions. But what really is the place for GRC in the profession today? Having been bombarded with Risk Management literature and programs for many years and those programs appearing to still be in their embryonic state, what confidence is there to be had in the GRC initiative?

As it turns out, there is a practical application for GRC in the world of Internal Audit. Certain cross-functional audit projects can greatly benefit from a GRC perspective. When faced with a large project across multiple disciplines, divisions, regions or operating groups the GRC model can provide a structure for evaluating the control environment in a manner and perspective that should appeal to senior management’s vision of the organization.

Stay tuned for Pat 2 of the GRC for Small Internal Audit Departments.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.

Wednesday, May 18, 2011

Internal Audit Departments and Building a Definition of Risk

Internal Audit Departments today are constantly told to be "risk based" and to assist their companies in the management of risk. While this sounds great in concept, the execution is a different manner as many companies today do not have a formal risk management program with which to align. When tasked with developing such programs Internal Audit should not fall into the trap of developing a population of risks before first arriving at a common definition of risk.

Understanding how your company views risk is a good place to start. Is risk viewed as good or bad? Remember, risk is not just a negative; the presence of risk presents the possibility of reward as well as loss. In looking at risk as both a positive and negative, Internal Audit Departments will better align their risk activities with the thoughts and strategies of management.

This definition, once developed, can then allow Internal Audit Departments to evaluate risks and risk management activities to determine if the potential for success warrants the risk being taken; to assess whether the risks being taken are aligned with corporate values, goals, objectives, policies and management capabilities; and to determine whether the culture of your organization is strong enough to allow for a legitimate discussion about risk events that haven’t yet happened.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.