SlideShare une entreprise Scribd logo
1  sur  54
Page 1 | Confidential and Proprietary Information
Governance, Risk Management, and
Internal Control
Vincent Tophoff, International Federation of
Accountants (IFAC)
ICMA Pakistan
Webinar, May 5, 2015
Page 2 | Confidential and Proprietary Information
International Federation of Accountants
• Global organization of the accountancy profession
• Supports professional accountants in following areas:
– Governance and ethics
– Risk management and internal control (RM/IC)
– Sustainability and corporate responsibility
– Financial and performance management
– Business reporting
– Promoting and contributing to the value of professional accountants
• All areas of critical importance to professional accountants
Page 3 | Confidential and Proprietary Information
Today’s Agenda
• IFAC Governance Guidance
• IFAC/CIPFA Public Sector Framework
• Risk Management & Internal Control
• COSO / ISO 31000 Standards
• Risk Management & Internal Control Maturity
• Professional Accountant “Call to Action”
• Q&A
IFAC Governance Guidance
Page 5 | Confidential and Proprietary Information
Relation of Governance, RM & IC
Page 6 | Confidential and Proprietary Information
Global Crisis
• Global Crisis, according to IFAC research, caused by:
 Ethical flaws
 Governance in name, but not in spirit
 Regulatory overload, leading to legalistic compliance
 Risk management & internal control too narrowly focused on only
financial reporting controls
• Conclusions from the crisis:
 Application of governance principles is often the problem
 Organizations should also take a broader approach to governance
Page 7 | Confidential and Proprietary Information
Broader Approach to Governance
• Governance is not just about protecting shareholders’ interests
…or a compliance exercise to satisfy the requirements of
regulators
• Instead, good governance supports building sustainable value in
organizations and society
Page 8 | Confidential and Proprietary Information
Conformance and Performance
• Successful organizations have a governance structure and
culture that go beyond conformance with regulations to also
support the organization’s efforts to improve its performance
Page 9 | Confidential and Proprietary Information
Governance integrated in
Drivers of Sustainable Organizational Success:
IFAC/CIPFA Public Sector Framework
Page 11 | Confidential and Proprietary Information
• What are the main challenges for good governance in
public sector organizations?
– Sovereign debt crisis
– Shortage of funding / rationalization
– Short-termism
– Internationalization, technology, complexity
– Corruption
Public Sector Governance: Analyzing the Environment
Page 12 | Confidential and Proprietary Information
• What can a governance framework accomplish?
– Establish a benchmark for good governance
– Serve as a reference point for those developing or reviewing national
codes
– Help public sector organizations continually improve governance
systems
– Where no code/guidance exists, provide:
• A shared understanding of what constitutes good governance
• A powerful stimulus for positive action
Public Sector Governance: Analyzing the Environment
Page 13 | Confidential and Proprietary Information
Good Governance in the Public Sector:
An International Framework
Page 14 | Confidential and Proprietary Information
Public Sector Governance: International Reference Group
Yoseph Asmelash United National Conference on Trade & Development (UNCTAD)
Ian Ball Formerly IFAC
Andreas Bergmann International Public Sector Accounting Standards Board (IPSASB)
Jón Blöndal Organisation for Economic Co-operation & Development (OECD)
Carlo Cottarelli International Monetary Fund (IMF)
Robert Dacey US Government Accountability Office (GAO)
Steve Freer Formerly CIPFA
Gert Jönsson International Organization of Supreme Audit Institutions (INTOSAI)
Mervyn King King Committee on Corporate Governance
Ian McPhee Australian National Audit Office
Maurice McTigue George Mason University (USA)
Roger Tabor Professional Accountants in Business Committee, IFAC
Page 15 | Confidential and Proprietary Information
Framework:
• Foreword by Mervyn King, Chair, IIRC, and King Report, South Africa
• Definitions
• Principles-based to maximize relevance, applicability
• Sub-principles and supporting guidance to provide explanation
Supplement:
• Examples
– Provide practical experience and aid understanding
• Evaluation questions to consider
• Further reading
Public Sector Governance: Framework Layout
Page 16 | Confidential and Proprietary Information
The fundamental
function of good
governance in the public
sector is to ensure that
entities achieve their
intended outcomes while
acting in the public
interest at all times.
Public Sector Governance: Fundamental Function
• Good governance
tied to:
– Achieving intended
outcomes
– Acting in the public
interest at all times
Page 17 | Confidential and Proprietary Information
Public Sector Governance: Achieving Intended Outcomes
While Acting in the Public Interest at all Times
Page 18 | Confidential and Proprietary Information
Public Sector Governance: Explicit Attention to Managing
Risk
• “Proper risk assessment assists public sector entities in
making informed decisions about the level of risk they are
prepared to take, and implementing the necessary
controls, in pursuit of the entities’ objectives.”
• “Effective risk management better enables public sector
entities to achieve their objectives, while operating
effectively, efficiently, ethically, and legally.”
• “Governing bodies should ensure that entities have
effective risk management arrangements in place.”
Page 19 | Confidential and Proprietary Information
Public Sector Governance: Explicit Attention to Internal
Control
• “Internal control supports a public sector entity in achieving
its objectives by managing its risks while complying with
rules, regulations, and organizational policies.”
• “Controls are a means to an end: the effective management
of risks enables an entity to achieve its objectives.”
• “Public sector entities should also consider the need to
remain agile, avoid over-control, and not become overly
bureaucratic.”
Risk Management & Internal Control
Page 21 | Confidential and Proprietary Information
Serious Risk Management & Internal Control Flaws
• Having a compliance-only mentality
• Treating risk as only negative and overlooking idea that
entities need to take risk in pursuit of their objectives
• Risk management & internal control that is overly focused
on external financial reporting
• Regarding risk management & internal control as a
separate function or process
• Viewing risk management & internal control as
predominantly important for operations
Page 22 | Confidential and Proprietary Information
Current Thinking About Risk
The safest place for a ship…
… is to stay in the harbor
But that’s not what ships were made for…
Page 23 | Confidential and Proprietary Information
Current Thinking About Risk
…Instead, ships were made to transport people & goods to
other destinations…
…And that involves risk…
So, what is risk?
• Risk is defined as the “effect of uncertainly on (setting and
achieving the organization’s) objectives” (ISO 31000)
• No Objectives = No Risk
• Therefore, risk should always be assessed in light of
(setting and achieving) the organization’s objectives!
Page 24 | Confidential and Proprietary Information
Current Thinking About Risk Management
Q: How does your organization address uncertainty in
achieving its strategic objectives?
A: Through our strategic management system
– Line management engaged in plan-do-check-act cycle
– Focused on achieving the organization’s objectives
Q: How does your organization address risk?
A: Through our risk management system
– (Separate) risk and control system, staff functionaries, risk register
– Focus on mitigating risk
Page 25 | Confidential and Proprietary Information
Risk Management
Rest of the organization
Current Thinking About Risk Management
What does this example tell us?
• That we, risk management professionals, have made
great progress in the area of risk management & internal
control…
• ..But that we, in the process, lost the other people in our
organization!
Page 26 | Confidential and Proprietary Information
Five lines of defense:
Current Thinking About Risk Management
Page 27 | Confidential and Proprietary Information
Five lines of defense:
Current Thinking About Risk Management
1. Players
2. Captain
3. Coach
4. Referee
5. PFF/FIFA
Page 28 | Confidential and Proprietary Information
Five lines of defense:
Current Thinking About Risk Management
1. Players (Operational Staff)
2. Captain (Supervisor /Line Manager)
3. Coach (Risk Manager)
4. Referee (Internal Auditor)
5. PFF/ FIFA (External Auditor)
Support
Line
Page 29 | Confidential and Proprietary Information
Current Thinking About Internal Control
Hindering the
organization
Enabling the
organization
Good internal control = The Invisible Hand
From To
Page 30 | Confidential and Proprietary Information
• Is not to have effective
controls…
• Is not to effectively manage
risk…
But to
• Properly set & achieve its
objectives
• Better adapt to surprises and
disruptions
• And create sustainable value
Main Objective of an Organization
Page 31 | Confidential and Proprietary Information
Risk Is Inherent to Setting Your Objectives
Page 32 | Confidential and Proprietary Information
Achieving Your Objectives Through Planning & Control
Strategic, tactical, and
operational planning & control
cycles
A
P
D
C
Page 33 | Confidential and Proprietary Information
RM/IC Integral to Achieving Your Objectives
Page 34 | Confidential and Proprietary Information
Managing Risk as an Integral Part of Managing an Organization
From Bolt-on to Built-in
COSO Frameworks
Page 36 | Confidential and Proprietary Information
2013 COSO Internal Control Cube
Page 37 | Confidential and Proprietary Information
2004 COSO ERM Cube
Will be revised
soon!
Page 38 | Confidential and Proprietary Information
COSO IC vs. COSO ERM
ISO 31000 Risk Management Standard
Page 40 | Confidential and Proprietary Information
ISO 31000 Principles, Framework & Process
Page 41 | Confidential and Proprietary Information
ISO 31000 Risk Management Principles
• Creates Value
• Integral Part of Organizational Processes
• Part of Decision Making
• Explicitly Addresses Uncertainty
• Systematic, Structured & Timely
• Based on “Best Available Information”
• Tailored
• Considers Human & Cultural Factors
• Transparent & Inclusive
• Dynamic, Iterative & Responsive to Change
• Facilitates Continuous Improvement
Page 42 | Confidential and Proprietary Information
ISO 31000 Risk Management Framework
Page 43 | Confidential and Proprietary Information
ISO 31000 Risk Management Process
To be applied in
every decision
making process
and subsequent
execution!
Page 44 | Confidential and Proprietary Information
COSO ERM vs. ISO 31000
Many organizations use both COSO ERM & ISO 31000…
… Biggest challenge is that concepts are not aligned
COSO ISO 31000
Lengthy vs. Short
Focused on ERM vs. General approach to managing risk
One cube vs. Principles, framework & process
Skewed to negative vs. Risk can be positive or negative
Risk already exists vs. Risk tied to achieving objectives
Risk & opportunities vs. Opportunities also source of risk
More sequential process vs. More iterative process
Risk Management & Internal Control Maturity
Page 46 | Confidential and Proprietary Information
RM/IC Maturity Levels
Page 47 | Confidential and Proprietary Information
• Consult and Communicate!
• Consider good practice developments
• Use the Frameworks
• Perform gap analysis
• Determine performance
• Look at audit results
• Analyze serious flaws
• …
• Continuously move to improvement!
Thoughts on Assessing RM/IC Maturity
Page 48 | Confidential and Proprietary Information
RM/IC Maturity: Continuous Improvement
From RM/IC as objective in itself to RM/IC to help achieve objectives
From Auditor / staff driven to Driven from top down
From Rules-based to Performance & principles-based
From Off-the-shelf systems to Tailored to the organization
From Focused on loss minimization to Also focused on value creation
From Mainly hard controls to Recognizing culture & attitude
From Imposed to Implemented organically
From Stand-alone / “bolt-on” to Integrated / ”built-in”
From Static, out-of-date to Dynamic, evolving
From Seen as overhead to Seen as a sound investment
From Abandoned to Integrated in governance
Professional Accountant “Call to Action”
Page 50 | Confidential and Proprietary Information
Professional Accountant “Call to Action” #1
Champion importance of good governance & RM/IC:
• Professional accountants communicate with their
organization’s leadership
• Attitude and actions of Professional accountant sets tone
for good governance and RM/IC in organizations
• Promote integrating RM/IC into overall management of
organization
• Most important element: making RM/IC part of every
decision-making process and subsequent execution!
Page 51 | Confidential and Proprietary Information
Professional Accountant “Call to Action” #2
Support line management by providing high-quality
advice, insight, and assurance:
• Decisions should only be made with explicit understanding
of related risks and their potential consequences for
achieving an organization’s objectives
• Therefore, decision makers require relevant and reliable
information for their decision-making and control
processes
Page 52 | Confidential and Proprietary Information
Key Take Aways
• There are many flaws in current governance & RM/IC
practices
• Achieving the organization’s objectives is the overall goal;
risk is an inherent part
• Risk management should, therefore, be fully integrated in
the organization’s system of management
• Professional accountants support RM/IC in various ways
in the organizations they work for
• IFAC supports professional accountants
• However, no matter the guidance provided…
Page 53 | Confidential and Proprietary Information
There will always be some …
… who do it their own way!
Page 54 | Confidential and Proprietary Information
Resources
IFAC publications free-of-charge at www.ifac.org:
 Coming in May 2015: From Bolt-on to Built-in Managing Risk as an
Integral Part of Managing an Organization
 IFAC/CIPFA International Framework: Good Governance in the Public
Sector
 Evaluating and Improving Governance in Organizations
 Integrating Governance for Sustainable Success
 Evaluating and Improving Internal Control in Organizations
 Defining and Developing an Effective Code of Conduct for
Organizations
 Also visit our new Global Knowledge Gateway

Contenu connexe

Tendances

At (07) code of ethics
At   (07) code of ethicsAt   (07) code of ethics
At (07) code of ethicsRoward Patnaan
 
Chapter 2 internal control
Chapter 2 internal controlChapter 2 internal control
Chapter 2 internal controlDr Manu H Natesh
 
Anti Money Laundering Act - Philippines
Anti Money Laundering Act - PhilippinesAnti Money Laundering Act - Philippines
Anti Money Laundering Act - PhilippinesNikki Enriquez
 
Bba 2204 fin mgt week 8 risk and return
Bba 2204 fin mgt week 8 risk and returnBba 2204 fin mgt week 8 risk and return
Bba 2204 fin mgt week 8 risk and returnStephen Ong
 
A Presentation on Risk Based Auditing
A Presentation on Risk Based AuditingA Presentation on Risk Based Auditing
A Presentation on Risk Based AuditingAmar Deep Ghimire
 
11. materiality and audit risk
11. materiality and audit risk11. materiality and audit risk
11. materiality and audit riskSyed Osama Rizvi
 
Chapter audit report
Chapter audit reportChapter audit report
Chapter audit reportEasyStudy3
 

Tendances (20)

At (07) code of ethics
At   (07) code of ethicsAt   (07) code of ethics
At (07) code of ethics
 
Audit risk model
Audit risk modelAudit risk model
Audit risk model
 
Audit Risk Assessment Chapter 9
Audit Risk Assessment Chapter 9Audit Risk Assessment Chapter 9
Audit Risk Assessment Chapter 9
 
Chapter 7
Chapter 7Chapter 7
Chapter 7
 
Chapter 2 internal control
Chapter 2 internal controlChapter 2 internal control
Chapter 2 internal control
 
Anti Money Laundering Act - Philippines
Anti Money Laundering Act - PhilippinesAnti Money Laundering Act - Philippines
Anti Money Laundering Act - Philippines
 
Chapter 3
Chapter 3Chapter 3
Chapter 3
 
Internal controls
Internal controlsInternal controls
Internal controls
 
Chapter 10
Chapter 10Chapter 10
Chapter 10
 
General principles of taxation
General principles of taxationGeneral principles of taxation
General principles of taxation
 
Tax law in the Philippines
Tax law in the PhilippinesTax law in the Philippines
Tax law in the Philippines
 
Governance, Risk Management, and Internal Control in the Public Sector
Governance, Risk Management, and Internal Control in the Public SectorGovernance, Risk Management, and Internal Control in the Public Sector
Governance, Risk Management, and Internal Control in the Public Sector
 
Bba 2204 fin mgt week 8 risk and return
Bba 2204 fin mgt week 8 risk and returnBba 2204 fin mgt week 8 risk and return
Bba 2204 fin mgt week 8 risk and return
 
Risk Management and Internal Control in the Public Sector
Risk Management and Internal Control in the Public SectorRisk Management and Internal Control in the Public Sector
Risk Management and Internal Control in the Public Sector
 
Partnership - Liquidation.ppt
Partnership - Liquidation.pptPartnership - Liquidation.ppt
Partnership - Liquidation.ppt
 
A Presentation on Risk Based Auditing
A Presentation on Risk Based AuditingA Presentation on Risk Based Auditing
A Presentation on Risk Based Auditing
 
Audit of Cash Balances
Audit of Cash BalancesAudit of Cash Balances
Audit of Cash Balances
 
Chapter 17
Chapter 17Chapter 17
Chapter 17
 
11. materiality and audit risk
11. materiality and audit risk11. materiality and audit risk
11. materiality and audit risk
 
Chapter audit report
Chapter audit reportChapter audit report
Chapter audit report
 

En vedette

Leveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationLeveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationInternational Federation of Accountants
 
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...International Federation of Accountants
 
Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...
Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...
Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...International Federation of Accountants
 
Corporate governance
Corporate governanceCorporate governance
Corporate governanceIqra Afsar
 
An Introduction To GST In Malaysia
An Introduction To GST In Malaysia An Introduction To GST In Malaysia
An Introduction To GST In Malaysia Ken Woo
 
Simone Di Castri CGAP Microfinance Regulation And Supervision Presentat...
Simone Di Castri   CGAP   Microfinance Regulation And Supervision   Presentat...Simone Di Castri   CGAP   Microfinance Regulation And Supervision   Presentat...
Simone Di Castri CGAP Microfinance Regulation And Supervision Presentat...Simone di Castri
 
External control in organization (corporate governance)
External control in organization (corporate governance)External control in organization (corporate governance)
External control in organization (corporate governance)Raja Matridi Aeksalo
 
Portifólio de patrocínio Global Risk Meeting 2011
Portifólio de patrocínio Global Risk Meeting  2011Portifólio de patrocínio Global Risk Meeting  2011
Portifólio de patrocínio Global Risk Meeting 2011Mariana Lima
 
Best Practices in Model Risk Audit
Best Practices in Model Risk AuditBest Practices in Model Risk Audit
Best Practices in Model Risk AuditJacob Kosoff
 
EY FSO Internal Audit Services_final
EY FSO Internal Audit Services_finalEY FSO Internal Audit Services_final
EY FSO Internal Audit Services_finalVincent Jorna
 
ISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final VersionISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final VersionDuncan O. Ogutu; CPA, CFE
 
Upgrade to sap ecc 6 from short overview
Upgrade to sap ecc 6 from short overviewUpgrade to sap ecc 6 from short overview
Upgrade to sap ecc 6 from short overviewH.C. Chen
 
IIA NL IAF.combining functions
IIA NL IAF.combining functionsIIA NL IAF.combining functions
IIA NL IAF.combining functionsMichel Kee
 

En vedette (20)

RMIC - It's What We Do
RMIC - It's What We DoRMIC - It's What We Do
RMIC - It's What We Do
 
Upgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your OrganizationUpgrading Risk Management and Internal Control in Your Organization
Upgrading Risk Management and Internal Control in Your Organization
 
Leveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your OrganizationLeveraging Effective Risk Management and Internal Control for Your Organization
Leveraging Effective Risk Management and Internal Control for Your Organization
 
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
The Essential Experience for CAEs: Risk Management is Dead, Long Live Risk Ma...
 
Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...
Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...
Emerging Trends in the Public Sector: Governance, Risk Management & Internal ...
 
Corporate governance
Corporate governanceCorporate governance
Corporate governance
 
CPA Canada Risk Oversight and Governance Board Role in Risk
CPA Canada Risk Oversight and Governance Board Role in RiskCPA Canada Risk Oversight and Governance Board Role in Risk
CPA Canada Risk Oversight and Governance Board Role in Risk
 
Pursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management GuidelinesPursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management Guidelines
 
Exploring Common Paths in Risk Management by Jan Mattingly
Exploring Common Paths in Risk Management by Jan MattinglyExploring Common Paths in Risk Management by Jan Mattingly
Exploring Common Paths in Risk Management by Jan Mattingly
 
What is RIMS Doing?
What is RIMS Doing?What is RIMS Doing?
What is RIMS Doing?
 
An Introduction To GST In Malaysia
An Introduction To GST In Malaysia An Introduction To GST In Malaysia
An Introduction To GST In Malaysia
 
Ifc
IfcIfc
Ifc
 
Simone Di Castri CGAP Microfinance Regulation And Supervision Presentat...
Simone Di Castri   CGAP   Microfinance Regulation And Supervision   Presentat...Simone Di Castri   CGAP   Microfinance Regulation And Supervision   Presentat...
Simone Di Castri CGAP Microfinance Regulation And Supervision Presentat...
 
External control in organization (corporate governance)
External control in organization (corporate governance)External control in organization (corporate governance)
External control in organization (corporate governance)
 
Portifólio de patrocínio Global Risk Meeting 2011
Portifólio de patrocínio Global Risk Meeting  2011Portifólio de patrocínio Global Risk Meeting  2011
Portifólio de patrocínio Global Risk Meeting 2011
 
Best Practices in Model Risk Audit
Best Practices in Model Risk AuditBest Practices in Model Risk Audit
Best Practices in Model Risk Audit
 
EY FSO Internal Audit Services_final
EY FSO Internal Audit Services_finalEY FSO Internal Audit Services_final
EY FSO Internal Audit Services_final
 
ISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final VersionISO Internal Auditors Workshop_Final Version
ISO Internal Auditors Workshop_Final Version
 
Upgrade to sap ecc 6 from short overview
Upgrade to sap ecc 6 from short overviewUpgrade to sap ecc 6 from short overview
Upgrade to sap ecc 6 from short overview
 
IIA NL IAF.combining functions
IIA NL IAF.combining functionsIIA NL IAF.combining functions
IIA NL IAF.combining functions
 

Similaire à Governance, Risk Management, and Internal Control

Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksInternational Federation of Accountants
 
Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...
Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...
Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...International Federation of Accountants
 
The Accountancy Profession – Adding Value Globally, Regionally and Locally
The Accountancy Profession – Adding Value Globally, Regionally and LocallyThe Accountancy Profession – Adding Value Globally, Regionally and Locally
The Accountancy Profession – Adding Value Globally, Regionally and LocallyInternational Federation of Accountants
 
CMA as a Game Changer in Supporting Sustainable Strategies: Risk Management
CMA as a Game Changer in Supporting Sustainable Strategies: Risk ManagementCMA as a Game Changer in Supporting Sustainable Strategies: Risk Management
CMA as a Game Changer in Supporting Sustainable Strategies: Risk ManagementInternational Federation of Accountants
 
Finding the Balance: Regulation and the Role of the Accountancy Profession
Finding the Balance: Regulation and the Role of the Accountancy ProfessionFinding the Balance: Regulation and the Role of the Accountancy Profession
Finding the Balance: Regulation and the Role of the Accountancy ProfessionInternational Federation of Accountants
 
Bcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementBcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementStephen Ong
 
Financial crime anti-money laundering - bovill briefing
Financial crime   anti-money laundering - bovill briefingFinancial crime   anti-money laundering - bovill briefing
Financial crime anti-money laundering - bovill briefingBovill
 
Professional Accountants in Business Committee supporting PAO Development
Professional Accountants in Business Committee supporting PAO DevelopmentProfessional Accountants in Business Committee supporting PAO Development
Professional Accountants in Business Committee supporting PAO DevelopmentInternational Federation of Accountants
 

Similaire à Governance, Risk Management, and Internal Control (20)

Gestión de Riesgos y Control Interno en el Sector Público
Gestión de Riesgos y Control Interno en el Sector PúblicoGestión de Riesgos y Control Interno en el Sector Público
Gestión de Riesgos y Control Interno en el Sector Público
 
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected RisksStrategic Risk Management in the Face of Uncertainty and Unexpected Risks
Strategic Risk Management in the Face of Uncertainty and Unexpected Risks
 
The Accountancy Profession and Accountants in Business
The Accountancy Profession and Accountants in BusinessThe Accountancy Profession and Accountants in Business
The Accountancy Profession and Accountants in Business
 
Good Governance in the Public Sector
Good Governance in the Public SectorGood Governance in the Public Sector
Good Governance in the Public Sector
 
Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...
Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...
Building for Sustainable Growth—(re)Defining Accountancy Profession in the Ag...
 
#corpriskforum2016 - Vincent Tophoff
#corpriskforum2016 - Vincent Tophoff#corpriskforum2016 - Vincent Tophoff
#corpriskforum2016 - Vincent Tophoff
 
The Accountancy Profession – Adding Value Globally, Regionally and Locally
The Accountancy Profession – Adding Value Globally, Regionally and LocallyThe Accountancy Profession – Adding Value Globally, Regionally and Locally
The Accountancy Profession – Adding Value Globally, Regionally and Locally
 
CMA as a Game Changer in Supporting Sustainable Strategies: Risk Management
CMA as a Game Changer in Supporting Sustainable Strategies: Risk ManagementCMA as a Game Changer in Supporting Sustainable Strategies: Risk Management
CMA as a Game Changer in Supporting Sustainable Strategies: Risk Management
 
Good Governance in the Public Sector Presentation
Good Governance in the Public Sector PresentationGood Governance in the Public Sector Presentation
Good Governance in the Public Sector Presentation
 
Finding the Balance: Regulation and the Role of the Accountancy Profession
Finding the Balance: Regulation and the Role of the Accountancy ProfessionFinding the Balance: Regulation and the Role of the Accountancy Profession
Finding the Balance: Regulation and the Role of the Accountancy Profession
 
A Relevant Accountancy Profession
A Relevant Accountancy ProfessionA Relevant Accountancy Profession
A Relevant Accountancy Profession
 
Bcu msc cg week 4 risk management
Bcu msc cg week 4 risk managementBcu msc cg week 4 risk management
Bcu msc cg week 4 risk management
 
Success through Integrated Reporting
Success through Integrated ReportingSuccess through Integrated Reporting
Success through Integrated Reporting
 
Financial crime anti-money laundering - bovill briefing
Financial crime   anti-money laundering - bovill briefingFinancial crime   anti-money laundering - bovill briefing
Financial crime anti-money laundering - bovill briefing
 
IFAC – Current Issues and Initiatives
IFAC – Current Issues and InitiativesIFAC – Current Issues and Initiatives
IFAC – Current Issues and Initiatives
 
Angela Witzany
Angela WitzanyAngela Witzany
Angela Witzany
 
Professional Accountants in Business Committee supporting PAO Development
Professional Accountants in Business Committee supporting PAO DevelopmentProfessional Accountants in Business Committee supporting PAO Development
Professional Accountants in Business Committee supporting PAO Development
 
What Are the IFAC SMOs and Why Are They Important?
What Are the IFAC SMOs and Why Are They Important?What Are the IFAC SMOs and Why Are They Important?
What Are the IFAC SMOs and Why Are They Important?
 
Mentoring: The IFAC Perspective
Mentoring: The IFAC PerspectiveMentoring: The IFAC Perspective
Mentoring: The IFAC Perspective
 
8_ICCA Meetings Association Africa Day_The importance of good ethical practic...
8_ICCA Meetings Association Africa Day_The importance of good ethical practic...8_ICCA Meetings Association Africa Day_The importance of good ethical practic...
8_ICCA Meetings Association Africa Day_The importance of good ethical practic...
 

Plus de International Federation of Accountants

Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...International Federation of Accountants
 
Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...International Federation of Accountants
 

Plus de International Federation of Accountants (20)

Closing Remarks International Women's Day 2024
Closing Remarks International Women's Day 2024Closing Remarks International Women's Day 2024
Closing Remarks International Women's Day 2024
 
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDEIFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
 
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
 
Preparing for High Quality Sustainability assurance Engagements
Preparing for High Quality Sustainability assurance EngagementsPreparing for High Quality Sustainability assurance Engagements
Preparing for High Quality Sustainability assurance Engagements
 
Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...
 
Otros pronunciamientos: Guías de Prácticas Recomendadas
Otros pronunciamientos: Guías de Prácticas RecomendadasOtros pronunciamientos: Guías de Prácticas Recomendadas
Otros pronunciamientos: Guías de Prácticas Recomendadas
 
Otros pronunciamientos: Marco conceptual
Otros pronunciamientos: Marco conceptualOtros pronunciamientos: Marco conceptual
Otros pronunciamientos: Marco conceptual
 
Adopción por primera vez de las NICSP de base de devengo
Adopción por primera vez de las NICSP de base de devengoAdopción por primera vez de las NICSP de base de devengo
Adopción por primera vez de las NICSP de base de devengo
 
Moneda Extranjera
Moneda ExtranjeraMoneda Extranjera
Moneda Extranjera
 
Presentación de la información presupuestaria
Presentación de la información presupuestariaPresentación de la información presupuestaria
Presentación de la información presupuestaria
 
Revelaciones de partes relacionadas
Revelaciones de partes relacionadasRevelaciones de partes relacionadas
Revelaciones de partes relacionadas
 
Estado de Flujos de Efectivo
Estado de Flujos de EfectivoEstado de Flujos de Efectivo
Estado de Flujos de Efectivo
 
Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...
 
Combinaciones del sector público
Combinaciones del sector públicoCombinaciones del sector público
Combinaciones del sector público
 
Consolidación
ConsolidaciónConsolidación
Consolidación
 
Instrumentos financieros – Revelaciones
Instrumentos financieros – RevelacionesInstrumentos financieros – Revelaciones
Instrumentos financieros – Revelaciones
 
Instrumentos financieros – Cobertura y derivados
Instrumentos financieros – Cobertura y derivadosInstrumentos financieros – Cobertura y derivados
Instrumentos financieros – Cobertura y derivados
 
Instrumentos financieros – Conceptos básicos
Instrumentos financieros –  Conceptos básicos Instrumentos financieros –  Conceptos básicos
Instrumentos financieros – Conceptos básicos
 
Instrumentos financieros – Revelaciones
Instrumentos financieros –  Revelaciones Instrumentos financieros –  Revelaciones
Instrumentos financieros – Revelaciones
 
Instrumentos financieros – Coberturas y derivados
Instrumentos financieros – Coberturas y derivadosInstrumentos financieros – Coberturas y derivados
Instrumentos financieros – Coberturas y derivados
 

Dernier

Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Anamaria Contreras
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
Entrepreneurship lessons in Philippines
Entrepreneurship lessons in  PhilippinesEntrepreneurship lessons in  Philippines
Entrepreneurship lessons in PhilippinesDavidSamuel525586
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environmentelijahj01012
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFChandresh Chudasama
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCRashishs7044
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCRalexsharmaa01
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Kirill Klimov
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxmbikashkanyari
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxFinancial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxsaniyaimamuddin
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Americas Got Grants
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Servicecallgirls2057
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 

Dernier (20)

Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
Entrepreneurship lessons in Philippines
Entrepreneurship lessons in  PhilippinesEntrepreneurship lessons in  Philippines
Entrepreneurship lessons in Philippines
 
Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environment
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDF
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxFinancial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
 
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 

Governance, Risk Management, and Internal Control

  • 1. Page 1 | Confidential and Proprietary Information Governance, Risk Management, and Internal Control Vincent Tophoff, International Federation of Accountants (IFAC) ICMA Pakistan Webinar, May 5, 2015
  • 2. Page 2 | Confidential and Proprietary Information International Federation of Accountants • Global organization of the accountancy profession • Supports professional accountants in following areas: – Governance and ethics – Risk management and internal control (RM/IC) – Sustainability and corporate responsibility – Financial and performance management – Business reporting – Promoting and contributing to the value of professional accountants • All areas of critical importance to professional accountants
  • 3. Page 3 | Confidential and Proprietary Information Today’s Agenda • IFAC Governance Guidance • IFAC/CIPFA Public Sector Framework • Risk Management & Internal Control • COSO / ISO 31000 Standards • Risk Management & Internal Control Maturity • Professional Accountant “Call to Action” • Q&A
  • 5. Page 5 | Confidential and Proprietary Information Relation of Governance, RM & IC
  • 6. Page 6 | Confidential and Proprietary Information Global Crisis • Global Crisis, according to IFAC research, caused by:  Ethical flaws  Governance in name, but not in spirit  Regulatory overload, leading to legalistic compliance  Risk management & internal control too narrowly focused on only financial reporting controls • Conclusions from the crisis:  Application of governance principles is often the problem  Organizations should also take a broader approach to governance
  • 7. Page 7 | Confidential and Proprietary Information Broader Approach to Governance • Governance is not just about protecting shareholders’ interests …or a compliance exercise to satisfy the requirements of regulators • Instead, good governance supports building sustainable value in organizations and society
  • 8. Page 8 | Confidential and Proprietary Information Conformance and Performance • Successful organizations have a governance structure and culture that go beyond conformance with regulations to also support the organization’s efforts to improve its performance
  • 9. Page 9 | Confidential and Proprietary Information Governance integrated in Drivers of Sustainable Organizational Success:
  • 11. Page 11 | Confidential and Proprietary Information • What are the main challenges for good governance in public sector organizations? – Sovereign debt crisis – Shortage of funding / rationalization – Short-termism – Internationalization, technology, complexity – Corruption Public Sector Governance: Analyzing the Environment
  • 12. Page 12 | Confidential and Proprietary Information • What can a governance framework accomplish? – Establish a benchmark for good governance – Serve as a reference point for those developing or reviewing national codes – Help public sector organizations continually improve governance systems – Where no code/guidance exists, provide: • A shared understanding of what constitutes good governance • A powerful stimulus for positive action Public Sector Governance: Analyzing the Environment
  • 13. Page 13 | Confidential and Proprietary Information Good Governance in the Public Sector: An International Framework
  • 14. Page 14 | Confidential and Proprietary Information Public Sector Governance: International Reference Group Yoseph Asmelash United National Conference on Trade & Development (UNCTAD) Ian Ball Formerly IFAC Andreas Bergmann International Public Sector Accounting Standards Board (IPSASB) Jón Blöndal Organisation for Economic Co-operation & Development (OECD) Carlo Cottarelli International Monetary Fund (IMF) Robert Dacey US Government Accountability Office (GAO) Steve Freer Formerly CIPFA Gert Jönsson International Organization of Supreme Audit Institutions (INTOSAI) Mervyn King King Committee on Corporate Governance Ian McPhee Australian National Audit Office Maurice McTigue George Mason University (USA) Roger Tabor Professional Accountants in Business Committee, IFAC
  • 15. Page 15 | Confidential and Proprietary Information Framework: • Foreword by Mervyn King, Chair, IIRC, and King Report, South Africa • Definitions • Principles-based to maximize relevance, applicability • Sub-principles and supporting guidance to provide explanation Supplement: • Examples – Provide practical experience and aid understanding • Evaluation questions to consider • Further reading Public Sector Governance: Framework Layout
  • 16. Page 16 | Confidential and Proprietary Information The fundamental function of good governance in the public sector is to ensure that entities achieve their intended outcomes while acting in the public interest at all times. Public Sector Governance: Fundamental Function • Good governance tied to: – Achieving intended outcomes – Acting in the public interest at all times
  • 17. Page 17 | Confidential and Proprietary Information Public Sector Governance: Achieving Intended Outcomes While Acting in the Public Interest at all Times
  • 18. Page 18 | Confidential and Proprietary Information Public Sector Governance: Explicit Attention to Managing Risk • “Proper risk assessment assists public sector entities in making informed decisions about the level of risk they are prepared to take, and implementing the necessary controls, in pursuit of the entities’ objectives.” • “Effective risk management better enables public sector entities to achieve their objectives, while operating effectively, efficiently, ethically, and legally.” • “Governing bodies should ensure that entities have effective risk management arrangements in place.”
  • 19. Page 19 | Confidential and Proprietary Information Public Sector Governance: Explicit Attention to Internal Control • “Internal control supports a public sector entity in achieving its objectives by managing its risks while complying with rules, regulations, and organizational policies.” • “Controls are a means to an end: the effective management of risks enables an entity to achieve its objectives.” • “Public sector entities should also consider the need to remain agile, avoid over-control, and not become overly bureaucratic.”
  • 20. Risk Management & Internal Control
  • 21. Page 21 | Confidential and Proprietary Information Serious Risk Management & Internal Control Flaws • Having a compliance-only mentality • Treating risk as only negative and overlooking idea that entities need to take risk in pursuit of their objectives • Risk management & internal control that is overly focused on external financial reporting • Regarding risk management & internal control as a separate function or process • Viewing risk management & internal control as predominantly important for operations
  • 22. Page 22 | Confidential and Proprietary Information Current Thinking About Risk The safest place for a ship… … is to stay in the harbor But that’s not what ships were made for…
  • 23. Page 23 | Confidential and Proprietary Information Current Thinking About Risk …Instead, ships were made to transport people & goods to other destinations… …And that involves risk… So, what is risk? • Risk is defined as the “effect of uncertainly on (setting and achieving the organization’s) objectives” (ISO 31000) • No Objectives = No Risk • Therefore, risk should always be assessed in light of (setting and achieving) the organization’s objectives!
  • 24. Page 24 | Confidential and Proprietary Information Current Thinking About Risk Management Q: How does your organization address uncertainty in achieving its strategic objectives? A: Through our strategic management system – Line management engaged in plan-do-check-act cycle – Focused on achieving the organization’s objectives Q: How does your organization address risk? A: Through our risk management system – (Separate) risk and control system, staff functionaries, risk register – Focus on mitigating risk
  • 25. Page 25 | Confidential and Proprietary Information Risk Management Rest of the organization Current Thinking About Risk Management What does this example tell us? • That we, risk management professionals, have made great progress in the area of risk management & internal control… • ..But that we, in the process, lost the other people in our organization!
  • 26. Page 26 | Confidential and Proprietary Information Five lines of defense: Current Thinking About Risk Management
  • 27. Page 27 | Confidential and Proprietary Information Five lines of defense: Current Thinking About Risk Management 1. Players 2. Captain 3. Coach 4. Referee 5. PFF/FIFA
  • 28. Page 28 | Confidential and Proprietary Information Five lines of defense: Current Thinking About Risk Management 1. Players (Operational Staff) 2. Captain (Supervisor /Line Manager) 3. Coach (Risk Manager) 4. Referee (Internal Auditor) 5. PFF/ FIFA (External Auditor) Support Line
  • 29. Page 29 | Confidential and Proprietary Information Current Thinking About Internal Control Hindering the organization Enabling the organization Good internal control = The Invisible Hand From To
  • 30. Page 30 | Confidential and Proprietary Information • Is not to have effective controls… • Is not to effectively manage risk… But to • Properly set & achieve its objectives • Better adapt to surprises and disruptions • And create sustainable value Main Objective of an Organization
  • 31. Page 31 | Confidential and Proprietary Information Risk Is Inherent to Setting Your Objectives
  • 32. Page 32 | Confidential and Proprietary Information Achieving Your Objectives Through Planning & Control Strategic, tactical, and operational planning & control cycles A P D C
  • 33. Page 33 | Confidential and Proprietary Information RM/IC Integral to Achieving Your Objectives
  • 34. Page 34 | Confidential and Proprietary Information Managing Risk as an Integral Part of Managing an Organization From Bolt-on to Built-in
  • 36. Page 36 | Confidential and Proprietary Information 2013 COSO Internal Control Cube
  • 37. Page 37 | Confidential and Proprietary Information 2004 COSO ERM Cube Will be revised soon!
  • 38. Page 38 | Confidential and Proprietary Information COSO IC vs. COSO ERM
  • 39. ISO 31000 Risk Management Standard
  • 40. Page 40 | Confidential and Proprietary Information ISO 31000 Principles, Framework & Process
  • 41. Page 41 | Confidential and Proprietary Information ISO 31000 Risk Management Principles • Creates Value • Integral Part of Organizational Processes • Part of Decision Making • Explicitly Addresses Uncertainty • Systematic, Structured & Timely • Based on “Best Available Information” • Tailored • Considers Human & Cultural Factors • Transparent & Inclusive • Dynamic, Iterative & Responsive to Change • Facilitates Continuous Improvement
  • 42. Page 42 | Confidential and Proprietary Information ISO 31000 Risk Management Framework
  • 43. Page 43 | Confidential and Proprietary Information ISO 31000 Risk Management Process To be applied in every decision making process and subsequent execution!
  • 44. Page 44 | Confidential and Proprietary Information COSO ERM vs. ISO 31000 Many organizations use both COSO ERM & ISO 31000… … Biggest challenge is that concepts are not aligned COSO ISO 31000 Lengthy vs. Short Focused on ERM vs. General approach to managing risk One cube vs. Principles, framework & process Skewed to negative vs. Risk can be positive or negative Risk already exists vs. Risk tied to achieving objectives Risk & opportunities vs. Opportunities also source of risk More sequential process vs. More iterative process
  • 45. Risk Management & Internal Control Maturity
  • 46. Page 46 | Confidential and Proprietary Information RM/IC Maturity Levels
  • 47. Page 47 | Confidential and Proprietary Information • Consult and Communicate! • Consider good practice developments • Use the Frameworks • Perform gap analysis • Determine performance • Look at audit results • Analyze serious flaws • … • Continuously move to improvement! Thoughts on Assessing RM/IC Maturity
  • 48. Page 48 | Confidential and Proprietary Information RM/IC Maturity: Continuous Improvement From RM/IC as objective in itself to RM/IC to help achieve objectives From Auditor / staff driven to Driven from top down From Rules-based to Performance & principles-based From Off-the-shelf systems to Tailored to the organization From Focused on loss minimization to Also focused on value creation From Mainly hard controls to Recognizing culture & attitude From Imposed to Implemented organically From Stand-alone / “bolt-on” to Integrated / ”built-in” From Static, out-of-date to Dynamic, evolving From Seen as overhead to Seen as a sound investment From Abandoned to Integrated in governance
  • 50. Page 50 | Confidential and Proprietary Information Professional Accountant “Call to Action” #1 Champion importance of good governance & RM/IC: • Professional accountants communicate with their organization’s leadership • Attitude and actions of Professional accountant sets tone for good governance and RM/IC in organizations • Promote integrating RM/IC into overall management of organization • Most important element: making RM/IC part of every decision-making process and subsequent execution!
  • 51. Page 51 | Confidential and Proprietary Information Professional Accountant “Call to Action” #2 Support line management by providing high-quality advice, insight, and assurance: • Decisions should only be made with explicit understanding of related risks and their potential consequences for achieving an organization’s objectives • Therefore, decision makers require relevant and reliable information for their decision-making and control processes
  • 52. Page 52 | Confidential and Proprietary Information Key Take Aways • There are many flaws in current governance & RM/IC practices • Achieving the organization’s objectives is the overall goal; risk is an inherent part • Risk management should, therefore, be fully integrated in the organization’s system of management • Professional accountants support RM/IC in various ways in the organizations they work for • IFAC supports professional accountants • However, no matter the guidance provided…
  • 53. Page 53 | Confidential and Proprietary Information There will always be some … … who do it their own way!
  • 54. Page 54 | Confidential and Proprietary Information Resources IFAC publications free-of-charge at www.ifac.org:  Coming in May 2015: From Bolt-on to Built-in Managing Risk as an Integral Part of Managing an Organization  IFAC/CIPFA International Framework: Good Governance in the Public Sector  Evaluating and Improving Governance in Organizations  Integrating Governance for Sustainable Success  Evaluating and Improving Internal Control in Organizations  Defining and Developing an Effective Code of Conduct for Organizations  Also visit our new Global Knowledge Gateway