Tag: risk management

Risk and compliance

COSO: More Focus on Compliance Risks Needed

Companies are taking a closer look at how to effectively manage and mitigate compliance risks, especially at a time when many compliance programs are under the microscope from regulators while also dealing with the effects of a global pandemic. The Committee of Sponsoring Organizations (COSO) has released a new publication, Read More

Professional Skepticism

Professional Skepticism Essential in Avoiding and Detecting Fraud

Professional skepticism by auditors, finance professionals, and all participants in the financial reporting supply chain is crucial for the deterrence and detection of fraud, a new report from the Anti-Fraud Collaboration says. Organizations must critically assess potential fraud risks and be aware of potential biases that can lead to criminal Read More

business continuity

Protiviti Offers Business Continuity Guidance Amid Pandemic

Protiviti has updated its Guide to Business Continuity & Resilience to reflect today’s latest threats and business realities, especially in light of lessons learned from the COVID-19 pandemic. The 2020 guide includes answers to critical questions business leaders must ask to ensure they will be ready to respond when disaster Read More

digital payments

Digital Payments Prompt Review of Internal Audit Procedures in India

India’s Ministry of Finance is examining internal audit procedures and tools to implement a standard internal audit protocol for all government ministries and departments, The Tribune of India reports. The Department of Expenditure requested the update in response to the government’s increased reliance on digital financial transactions. “The Public Financial Read More

Report Clarifies Internal Audit’s Role in Fighting Fraud

As high-profile fraud cases continue to make headlines and the Coronavirus Crisis heightens concerns about fraud, a new survey could help internal auditors understand fraud risk management at their organizations. The report, “Fraud Risk Management in Internal Audit,” takes a deep look at internal audit’s role in identifying and mitigating Read More

Three lines of defense update

‘Three Lines of Defense’ Overhaul Earns Praise

The Three Lines of Defense—a popular model for guidance on how to structure risk management responsibilities at companies—is getting a long-awaited makeover, and early analysis of the result has been mostly positive. On Monday, the Institute of Internal Auditors released its Three Lines Model, an update on the Three Lines Read More

PG&E restructures internal audit

PG&E Restructures Internal Audit, Risk After Wildfire Disasters

P acific Gas and Electric Co. is establishing a chief audit officer role and making changes to the job profiles and responsibilities of those who oversee and manage risk at the San Francisco-based energy company. PG&E is expected to exit bankruptcy later this month, after a turbulent time in the Read More

Reassessing Risk: What Matters Most Now?

As companies look to reopen facilities and make accommodations for operating under the “new normal” of doing business during the coronavirus pandemic, internal audit leaders are assessing the risks and helping their organizations prepare to unlock the doors. Some are still just trying to get their bearings. “I’ve been through Read More

risk appetite

COSO Issues New Guidance on Approach to Risk Appetite

Risk appetite is a critical link between strategy and performance. In an effort to help executives and managers better understand and communication risk appetite, the Committee of Sponsoring Organizations (COSO) issued new guidance, on how organizations can promote risk appetite as an integral part of decision-making. The guidance, titled “Risk Read More

Mind the Gap

Internal Audit Study Reveals Gaps in Risk Coverage

The 2020 Pulse of Internal Audit, a report released this week by the Institute of Internal Auditors reveals serious gaps in internal audit’s coverage, with audit plans deficient in key risk areas, including: Almost one-third of respondents did not include cybersecurity and   information technology in their audit plans. More Read More