Showing posts with label Risk. Show all posts
Showing posts with label Risk. Show all posts

Wednesday, June 1, 2011

The GRC Approach - for Small Internal Audit Departments

Governance, Risk and Compliance (Part 2)

First identify all of the functions and/or groups that interact with the area subject to assessment. Then through interviews and evaluation determine the following:
  • Governance: the goal, mission and objective of the program.
  • Risk: the risks that are being managed by each of the functions and groups involved.
  • Compliance: the rules, regulations, internal policies, the operating procedures that influence the operating activities. In this space it is also necessary to identify all of the tools, people, and resources available in support of the compliance efforts.
Once determined, you can assess whether the various functions are aligned as to the Governance mission and objective, you can determine if they are operating against a common set of Risk factors and you can evaluate whether the Compliance efforts are operating cohesively across all groups and whether resources are being deployed to effectively address each of the compliance requirements.

This evaluation is then used as the springboard to development of a high level summary regarding the cohesiveness of the company’s GRC activities across the multiple disciplines subject to review.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.

Tuesday, May 24, 2011

When does GRC Fit within a Small Audit Shop?

Governance, Risk and Compliance (Part 1)

Governance, Risk and Compliance (GRC) is the latest and greatest hot topic being thrown at Internal Audit functions. But what really is the place for GRC in the profession today? Having been bombarded with Risk Management literature and programs for many years and those programs appearing to still be in their embryonic state, what confidence is there to be had in the GRC initiative?

As it turns out, there is a practical application for GRC in the world of Internal Audit. Certain cross-functional audit projects can greatly benefit from a GRC perspective. When faced with a large project across multiple disciplines, divisions, regions or operating groups the GRC model can provide a structure for evaluating the control environment in a manner and perspective that should appeal to senior management’s vision of the organization.

Stay tuned for Pat 2 of the GRC for Small Internal Audit Departments.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.

Wednesday, May 18, 2011

Internal Audit Departments and Building a Definition of Risk

Internal Audit Departments today are constantly told to be "risk based" and to assist their companies in the management of risk. While this sounds great in concept, the execution is a different manner as many companies today do not have a formal risk management program with which to align. When tasked with developing such programs Internal Audit should not fall into the trap of developing a population of risks before first arriving at a common definition of risk.

Understanding how your company views risk is a good place to start. Is risk viewed as good or bad? Remember, risk is not just a negative; the presence of risk presents the possibility of reward as well as loss. In looking at risk as both a positive and negative, Internal Audit Departments will better align their risk activities with the thoughts and strategies of management.

This definition, once developed, can then allow Internal Audit Departments to evaluate risks and risk management activities to determine if the potential for success warrants the risk being taken; to assess whether the risks being taken are aligned with corporate values, goals, objectives, policies and management capabilities; and to determine whether the culture of your organization is strong enough to allow for a legitimate discussion about risk events that haven’t yet happened.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.

Monday, November 1, 2010

Data Analytics: Identifying and Responding to Business Risks Efficiently

Every time a company processes a transaction there is risk. Be it accidental errors such as duplicate entry, incorrect posting, and transposing numbers or intentional misconduct, all might be difficult to spot. As technology has advanced, so has the speed and volume of transaction processing. More is done in less time, which potentially increases the likelihood of error.

What can be done to prevent or mitigate these risks? Internal Controls. When designed properly, Internal Controls can detect a risk once it happens, or better yet, prevent a risk from happening in the first place.


Under the COSO Internal Control-Integrated Framework, internal control is broadly defined as a process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories: a) Effectiveness and efficiency of operations; b) Reliability of financial reporting; and c) Compliance with laws and regulations.*

An example of an internal control is the three way match between a Purchase Order, a receipt of the goods and the related invoice. The control is that the match ensures that the invoice has the authorized price from the Purchase Order and that the quantity agrees to what has been received.

Designing an effective system of Internal Controls is just the beginning. Once designed, it is important to test the Internal Controls to make sure they are operating effectively. The traditional method for testing would investigate a sample size of roughly 25 invoices. If there are exceptions, the sample size will be increased. If there are no exceptions in the first 25, the Internal Controls were deemed effective. Without automation, this is the typical way to test the transactions and make assumptions on the entire population by extrapolation since there are too many transactions to manually test each one.

But what if there were errors, just not represented within the sample? Using CAATTs is the answer.

Computer Assisted Audit Tools and Techniques (CAATTs), is the practice of using software such as Excel or Access, or specialized Audit software such as ACL or IDEA, or ERP specific tools built into SAP or Oracle to automate or simplify the audit process. CAATTs are an efficient way to test all transactions, providing 100% assurance on the effectiveness of Internal Controls.*

What are the benefits?
  • Large amount of data can be examined efficiently
  • Timely identification of business risks and exceptions
  • Business days are not interrupted with information requests to pull paper samples
  • Once established, running the tests is simple and very cost-effective
What are the drawbacks?
  • Setup time requires IT resource knowledge and availability
  • Knowledge of the software to create the tests accurately
  • Different system applications at different locations requires different tests to be created
To learn more about using CAATTS to identify and respond to business risks more efficiently visit www.vonyaglobal.com or contact Vonya Global for a free consultation.

* Excerpts taken from www.wikipedia.com

Wednesday, May 12, 2010

Social Media - is it Friend or Foe?

Social media is rapidly becoming a critical tool for communication not only bringing benefits, but also risks. For many organizations, social media is a vital channel for communication to customers, partners and stakeholders. However, some organizations see it as a distraction to their employees and a potential security threat and reputation risks. The key, of course, is to maximize the opportunities it presents and minimize the risks.

As an alternative to simply banning or limiting employees from using social media, organizations should understand the role that these innovative services have in today’s world. With the appropriate amount of governance, organizations can leverage social media to help reach their objectives.

In order to develop, implement, monitor and improve social media activities within an organization, an effective governance framework is imperative. A social media strategy and policy should be established followed by a risk assessment. Based on the outcome of the risk assessment, embed key controls, including an acceptable use agreement, corporate image rules and branding guidelines. Implementation of operational best practice guidelines should cover blogging and usage of popular sites such as LinkedIn, Twitter, Facebook, and YouTube.

Finally, ensure that roles and responsibilities are defined, metrics and monitoring procedures are established, and training and communication organization-wide takes place to help provide awareness and conformity.

Whether your objectives are to generate exposure for your business, increase traffic to your site, build new business partnerships or bring in new, qualified leads, benefits from social media can be realized as long as there is an effective governance structure in place to mitigate the associated risks.