The 3 IA model is:
- In-house or employees – which including recruiting staff / talent and conducting all audits, planning and maintenance of technology and methodology
- Cosourced function – blend of employees and supplemented 3rd-party providers to address gap in skill or resources while taking advantage of 3rd-party investment in technology, methodology and knowledge
- Fully outsourced – where providers are held responsible from planning to execution / audits with the direction of the audit committee and executive IA management
No one solution fits all, and really depends on various constituents and their expectations, according to Crowe Horwath: Audit Committee (plan / risk management), Executive Management (plan / financial risk / business value), External Auditors (emerging market growth / changing regulations), Internal Auditors (skills/training), and Functional Management (understanding business / major program assistance)
IA maturity categories: Basic, Evolving, Established, Advance, and Leading. The spectrum from basic to Leading involve, for example, Basic solely focusing on compliance risk and auditors skills not aligned with organizational audit needs, risk assessments not aligned with other risk functions or does not reflect company profiles, and use of technology is fairly limited. Conversely an Advance focuses on compliance risk, cost reduction, and risk that affect business objectives.
An IA transformation is founded on the 3 practices:
- Using others’ work to leverage other compliance, financial, and operating reports which will allow focus on other problems and reduce costly audits
- Hold process owners accountable is key to being most effective and when IA is evaluating the controls, monitoring performance, and providing recommendation
- Providing continuous coverage based the 4 principles below to ensure resources/time is focused on the key items while maintaining demand.
4 IA Principles:
- Compliance – implementation of periodic checks (of managers, employees, 3rd-parties) and implementing risk indicators for actionable results/reports
- Assurance – increased focus on nonfinancial areas including IT Security, customer data, and intellectual property
- Performance Improvement – shift of audit plans to expectations and more tangible value to organization to provide and recommend best practices through mixture of internal controls, automated processing and value-add activities within processes
- Risk Identification – leveraging enterprisewide perspective that identify emerging risk and vulnerabilities while linking to strategic objectives, and through integrated risk assessments
Article source: Crowe Horwath
No more paperwork, works both online and offline. No need to duplicate or lost forms. Available to anyone, everywhere and any time. In addition makes the inspection process itself super easy. Download this software https://form.com/risk-management/ risk management. Create forms for personnel, property, equipment, and vehicle inspections with fully customizable criteria to ensure that all regulations are met. You will see how easily it could be, enjoy the procces with forms!
ReplyDelete