SlideShare une entreprise Scribd logo
1  sur  30
1
Leveraging ISO 31000 for Effective Integration
of Risk Management and Internal Control
Presenter:
Vincent Tophoff
International Federation of Accountants (IFAC)
Second international ISO 31000 conference – Toronto, 28-31 May 2013
Overview
• Role and domain of IFAC
• Maturity of risk management and internal control
(RM/IC)
• Broader approach in RM/IC
• Broader approach in RM/IC standards, frameworks &
guidelines
• Remaining pitfalls in RM/IC: application failures
• IFAC supports further improvements in RM/IC
2
Second international ISO 31000 conference – Toronto, 28-31 May 2013
3
The International Federation of Accountants (IFAC)
• The global organization of the accountancy profession
• 172 member bodies and associates in 129 countries
• 2.5 million professional accountants in public practice,
commerce, industry, financial services, the public sector,
education, and the not-for-profit sector
• Public interest focused
Second international ISO 31000 conference – Toronto, 28-31 May 2013
More than half
are in this box
4
The International Federation of Accountants (IFAC)
• Supports accountants in following areas:
Auditing and accounting
Governance and ethics
Risk management and internal control
Sustainability and corporate responsibility
Financial and performance management
Business reporting
Promoting and contributing to the value of accountants
• All areas of critical importance to the organizations they
work for!
Second international ISO 31000 conference – Toronto, 28-31 May 2013
5
Second international ISO 31000 conference – Toronto, 28-31 May 2013
• Crisis
management
• Internal
control now
complemented
with risk
management
• But performed
in a silo…
• Integrating risk
management
and internal
control in the
governance &
management
of organization
Level 1:
Non-existent
or ad hoc
Level 2:
Internal
control only
Level 3:
RM/IC
as a silo
Level 4:
Integrated
RM/IC
•Formal
internal
control
•Mainly
focused on
external
financial
reporting
Integration of RM/IC
Here we are now
6
IFAC survey on risk management & internal control
• Received over 600 responses from around the globe
Main conclusions:
• More awareness of the benefits of risk management and
internal control systems should be created
• Risk management and internal control should be better
integrated into organizations’ overall governance, strategy,
and operations
• Risk management and internal control requirements and
guidelines should be further aligned internationally
Second international ISO 31000 conference – Toronto, 28-31 May 2013
7
Global Survey on Risk Management & Internal Control
> Proposed Next Steps
• Emphasizing the benefits of (more integrated) risk
management and internal control
• Bringing various risk management and internal control
standard setting organizations (such as COSO, ISO 31000
& Risk Oversight & Governance Board) and their guidelines
closer together
• Collaborating with experts on development of practical
application guidance for (integration of) risk management
and internal control
Second international ISO 31000 conference – Toronto, 28-31 May 2013
8
Global crisis
According to IFAC research caused by:
• Ethical flaws
• Governance, risk management & internal control in name but
not in spirit
• Regulatory overload, leading to legalistic compliance
• Risk & control systems too narrowly focused on only financial
reporting controls
• However, many, if not most, of the risks that affected
organizations derived from areas other than financial reporting
Second international ISO 31000 conference – Toronto, 28-31 May 2013
9
Conclusions from survey and global crisis
A. Organizations should take a broader approach in risk
management and internal control
B. Risk management and internal control standards and
principles should better enable taking a broader approach
C. Appropriate application of risk management and internal
control standards and principles is often the problem
Second international ISO 31000 conference – Toronto, 28-31 May 2013
10
A. Taking a broader approach in RM/IC
Second international ISO 31000 conference – Toronto, 28-31 May 2013
11
Broader approach in risk management (1)
• Q: “How does your organization address uncertainty in
achieving its strategic objectives?”
• A: “Through our strategic management system;”
Line management engaged in plan-do-check-act cycle
Focused on achieving the organization’s objectives
• Q: “How does your organization address risk?”
• A: “Through our risk management system;”
(separate) risk and control system, staff functionaries,
risk register
Focused on mitigating risk
Second international ISO 31000 conference – Toronto, 28-31 May 2013
12
Broader approach in risk management (2)
What does this example tell us?
• That we, finance & accounting folks, have made great
progress in the area of risk management and internal control…
• …But that we, in the process, lost the other people in our
organization!
Risk Management
Rest of the Organization
Second international ISO 31000 conference – Toronto, 28-31 May 2013
13
Broader approach in risk management (3)
Biggest risk facing an
organization:
Disconnect between those
responsible for achieving
strategic objectives vs.
those responsible for
managing risk
Solution:
Making those responsible
for achieving strategic
objectives also responsible
for managing related risks!
Second international ISO 31000 conference – Toronto, 28-31 May 2013
14
Broader approach in risk management (4)
• Line management is accountable for (achieving) the
organization’s objectives,
• This also includes responsibility for managing the effects of
risk on those objectives
Key objective for management accountants in this regard:
• Ensure that risk management and internal control are fully
integrated in the line management of an organization!
Second international ISO 31000 conference – Toronto, 28-31 May 2013
15
Broader approach in internal control (1)
• Internal control not as an objective in itself
• But as a response to modify risk
• (In order to achieve the organization’s objectives)
• And…
Second international ISO 31000 conference – Toronto, 28-31 May 2013
16
Broader approach in internal control (2)
Hindering the
organization
Enabling the
organization
• Good internal control: invisible hand
From To
Second international ISO 31000 conference – Toronto, 28-31 May 2013
17
B. Collaborating with standard setters
• IFAC collaborates with regulators and standard setters in
area of governance, risk management, and internal control
Second international ISO 31000 conference – Toronto, 28-31 May 2013
18
IFAC collaboration with Canadian ROGB
• IFAC also participates in the Canadian Risk Oversight and
Governance Board (ROGB)
• Offers guidance to directors and senior managers to fulfill
their responsibility for governance and the oversight of risk
management
• Freely available from the ROGB website
Second international ISO 31000 conference – Toronto, 28-31 May 2013
19
IFAC collaboration with COSO
• Committee of Sponsoring Organizations of the Treadway
Commission (COSO)
• Providing thought leadership through the development of
frameworks and guidance on risk management and internal
control
• Revised Framework issued in May 2013 and available at
www.coso.org
Second international ISO 31000 conference – Toronto, 28-31 May 2013
20
IFAC collaboration with ISO 31000
• International Standards Organization (ISO) developed the
standard ISO 31000:2009 Risk Management
• Can be used by any public, private or community enterprise,
association, group, or individual
• Can be applied to any type of risk, whatever its nature,
whether having positive or negative consequences (so
broader than ERM)
Second international ISO 31000 conference – Toronto, 28-31 May 2013
21
Comparison COSO ERM vs. ISO 31000
COSO ISO 31000
• Lengthy vs. Short
• Focused on ERM vs. General approach to managing risk
• One cube vs. Framework and process
• Skewed to negative vs. Risk can be positive or negative
• Risk already exists vs. Risk tied to achieving objectives
• Risk & opportunities vs. Opportunities also source of risk
• More sequential process vs. More iterative process
• However… many organizations use both COSO ERM and ISO 31000
• Biggest challenge is that concepts and terminology are not aligned!
Second international ISO 31000 conference – Toronto, 28-31 May 2013
Too short, however,
to really understand
22
Bringing together COSO, ISO, ROGB and others
• Best opportunity to further align concepts and terminology by bringing
together the various issuers of standards, guidance & frameworks
• To discuss how the terminology, various concepts & guidelines could
be better aligned
• IFAC facilitates first meeting of COSO, ISO 31000, and ROGB boards
in September 2013 in Chicago
• Including representatives from RIMS and other organizations
• Should all work together to produce globally-aligned terminology,
concepts, and guidelines that are relevant to all users.
• IFAC looks forward to continue contributing to this collaborative effort
Second international ISO 31000 conference – Toronto, 28-31 May 2013
23
C. Encouraging better application of RM/IC guidelines
Second international ISO 31000 conference – Toronto, 28-31 May 2013
24
Bad practice vs. good practice in RM/IC
Second international ISO 31000 conference – Toronto, 28-31 May 2013
Overwhelming load of bad practice:
• RM/IC as objective in itself vs. RM/IC to achieve objectives
• Auditor / staff driven vs. Board and management driven
• Rules-based vs. Principles-based
• Of the shelf systems vs. Tailor made
• Focused on threats only vs. Also focused on opportunities
• Mainly hard controls vs. Social / human aspects
• Artificially implemented vs. Organically implemented
• Stand-alone / “bolt-on” vs. Integrated / ”built-in”
• Static, out-of-date vs. Dynamic, evolving
• Creates costs vs. Creates results / value
• Abandoned vs. Supported
25
IFAC risk management & internal control publications
• Evaluating and Improving Governance in Organizations
• Evaluating and Improving Internal Control in Organizations
• Integrating Governance in for Sustainable Success
• All IFAC Publications free-of-charge at www.ifac.org
Second international ISO 31000 conference – Toronto, 28-31 May 2013
26
Evaluating and Improving IC in Organizations
• Highlighting areas where practical application of internal
control standards often fails in many organizations
• Designed to establish a benchmark for good practice in
maintaining effective internal control in response to risk
• For all types of organizations, as all organizations—whether
private or public—should have appropriate internal control
Second international ISO 31000 conference – Toronto, 28-31 May 2013
27
Guidance to avoid or overcome pitfalls
Good internal control should:
• Support the organization’s objectives
• Define clear roles and responsibilities
• Foster a motivational culture
• Link to individual performance
• Ensure sufficient competency
• Respond to risk
• Be communicated regularly
• Be monitored and evaluated regularly
• Provide for accountability and transparency
Second international ISO 31000 conference – Toronto, 28-31 May 2013
28
Next steps > guidance in integration of risk & control
• Risk management and internal control are a means to an
end: making sound (SWOT) decisions to achieve the
organization’s objectives without surprises!
• Principles on how risk managers can support their
organization integrating risk management and internal
control into the organization’s overall governance and
management system
Second international ISO 31000 conference – Toronto, 28-31 May 2013
29
Second international ISO 31000 conference – Toronto, 28-31 May 2013
Key takeaway’s
• Risk management and internal control have matured
• Still many flaws
• IFAC supports:
further integration of RM/IC
Further alignment of RM/IC standards
Better application of RM/IC principles and concepts
• However, no matter the guidance provided…
• …There will always be some who do it their own way!
30
Second international ISO 31000 conference – Toronto, 28-31 May 2013

Contenu connexe

Tendances

Implementing Enterprise Risk Management with ISO 31000:2009
Implementing Enterprise Risk Management with ISO 31000:2009Implementing Enterprise Risk Management with ISO 31000:2009
Implementing Enterprise Risk Management with ISO 31000:2009Goutama Bachtiar
 
internal control and control self assessment
internal control and control self assessmentinternal control and control self assessment
internal control and control self assessmentManoj Agarwal
 
Ppt on risk based internal audit
Ppt on risk based internal auditPpt on risk based internal audit
Ppt on risk based internal auditAmitaMistry2
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB
 
Risk and Control Self Assessment - IRM India Affiliate
Risk and Control Self  Assessment - IRM India AffiliateRisk and Control Self  Assessment - IRM India Affiliate
Risk and Control Self Assessment - IRM India AffiliateIRM India Affiliate
 
Qms kick off meeting ppt
Qms kick off meeting pptQms kick off meeting ppt
Qms kick off meeting pptANUPAM RAY
 
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...Instansi
 
ISO 31000 Risk Management
ISO 31000 Risk ManagementISO 31000 Risk Management
ISO 31000 Risk ManagementRamiro Cid
 
COSO ERM Framework
COSO ERM FrameworkCOSO ERM Framework
COSO ERM Frameworkssuser6ea258
 
Introduction to internal auditing
Introduction to internal auditingIntroduction to internal auditing
Introduction to internal auditingDavid Griffiths
 
Process Audit and ISO
Process Audit and ISOProcess Audit and ISO
Process Audit and ISOSadafhazel
 
ISO 31000 risk management process
ISO 31000 risk management processISO 31000 risk management process
ISO 31000 risk management processMuizz Anibire
 
ISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk RequirementsISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk RequirementsMasterControl
 
Operational risk & incident reporting
Operational risk &  incident reportingOperational risk &  incident reporting
Operational risk & incident reportingShivaLeela Choudary
 
Risk management: Principles, methodologies and techniques
Risk management: Principles, methodologies and techniquesRisk management: Principles, methodologies and techniques
Risk management: Principles, methodologies and techniquesILRI
 

Tendances (20)

Implementing Enterprise Risk Management with ISO 31000:2009
Implementing Enterprise Risk Management with ISO 31000:2009Implementing Enterprise Risk Management with ISO 31000:2009
Implementing Enterprise Risk Management with ISO 31000:2009
 
Recent COSO Internal Control and Risk Management Developments
Recent COSO Internal Control and Risk Management DevelopmentsRecent COSO Internal Control and Risk Management Developments
Recent COSO Internal Control and Risk Management Developments
 
internal control and control self assessment
internal control and control self assessmentinternal control and control self assessment
internal control and control self assessment
 
Ppt on risk based internal audit
Ppt on risk based internal auditPpt on risk based internal audit
Ppt on risk based internal audit
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Risk and Control Self Assessment - IRM India Affiliate
Risk and Control Self  Assessment - IRM India AffiliateRisk and Control Self  Assessment - IRM India Affiliate
Risk and Control Self Assessment - IRM India Affiliate
 
Qms kick off meeting ppt
Qms kick off meeting pptQms kick off meeting ppt
Qms kick off meeting ppt
 
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
 
ISO 31000 Risk Management
ISO 31000 Risk ManagementISO 31000 Risk Management
ISO 31000 Risk Management
 
COSO ERM Framework
COSO ERM FrameworkCOSO ERM Framework
COSO ERM Framework
 
COSO Internal Control - Integrated Framework
COSO Internal Control - Integrated FrameworkCOSO Internal Control - Integrated Framework
COSO Internal Control - Integrated Framework
 
Introduction to internal auditing
Introduction to internal auditingIntroduction to internal auditing
Introduction to internal auditing
 
Process Audit and ISO
Process Audit and ISOProcess Audit and ISO
Process Audit and ISO
 
ISO 31000 risk management process
ISO 31000 risk management processISO 31000 risk management process
ISO 31000 risk management process
 
ISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk RequirementsISO 9001-2015: New Risk Requirements
ISO 9001-2015: New Risk Requirements
 
Coso erm
Coso ermCoso erm
Coso erm
 
Risk based auditing
Risk based auditingRisk based auditing
Risk based auditing
 
Risk management & ISO 31000
Risk management & ISO 31000Risk management & ISO 31000
Risk management & ISO 31000
 
Operational risk & incident reporting
Operational risk &  incident reportingOperational risk &  incident reporting
Operational risk & incident reporting
 
Risk management: Principles, methodologies and techniques
Risk management: Principles, methodologies and techniquesRisk management: Principles, methodologies and techniques
Risk management: Principles, methodologies and techniques
 

En vedette

ISO 9001:2015 vs Enterprise Risk Management
ISO 9001:2015 vs Enterprise Risk ManagementISO 9001:2015 vs Enterprise Risk Management
ISO 9001:2015 vs Enterprise Risk ManagementPECB
 
Bombardier Integration Plan
Bombardier Integration PlanBombardier Integration Plan
Bombardier Integration PlanAjay Singh
 
Project Plan - Risk Management & Integration
Project Plan - Risk Management & IntegrationProject Plan - Risk Management & Integration
Project Plan - Risk Management & IntegrationPrachi Dikshit
 
Management of Risk and its integration within ITIL
Management of Risk and its integration within ITILManagement of Risk and its integration within ITIL
Management of Risk and its integration within ITILhdoornbos
 
Iso 31000 تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...
Iso 31000  تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...Iso 31000  تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...
Iso 31000 تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...عبدالقادر مضوي الحاج
 
Strategic Performance & Risk Integration
Strategic Performance & Risk IntegrationStrategic Performance & Risk Integration
Strategic Performance & Risk IntegrationMihai Ionescu
 
Post Acquisiton Integration Framework
Post Acquisiton Integration FrameworkPost Acquisiton Integration Framework
Post Acquisiton Integration Frameworktejasoza
 

En vedette (12)

ISO 9001:2015 vs Enterprise Risk Management
ISO 9001:2015 vs Enterprise Risk ManagementISO 9001:2015 vs Enterprise Risk Management
ISO 9001:2015 vs Enterprise Risk Management
 
Gestión de Riesgos y Control Interno en el Sector Público
Gestión de Riesgos y Control Interno en el Sector PúblicoGestión de Riesgos y Control Interno en el Sector Público
Gestión de Riesgos y Control Interno en el Sector Público
 
Erm tm 10
Erm tm 10Erm tm 10
Erm tm 10
 
Bombardier Integration Plan
Bombardier Integration PlanBombardier Integration Plan
Bombardier Integration Plan
 
Project Plan - Risk Management & Integration
Project Plan - Risk Management & IntegrationProject Plan - Risk Management & Integration
Project Plan - Risk Management & Integration
 
Pursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management GuidelinesPursuing Global Alignment of Risk Management Guidelines
Pursuing Global Alignment of Risk Management Guidelines
 
Governance, Risk Management, and Internal Control in the Public Sector
Governance, Risk Management, and Internal Control in the Public SectorGovernance, Risk Management, and Internal Control in the Public Sector
Governance, Risk Management, and Internal Control in the Public Sector
 
Management of Risk and its integration within ITIL
Management of Risk and its integration within ITILManagement of Risk and its integration within ITIL
Management of Risk and its integration within ITIL
 
Iso 31000 تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...
Iso 31000  تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...Iso 31000  تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...
Iso 31000 تبني شركات التأمين السودانية لتطبيق إطار ادارة المخاطر المؤسسية با...
 
Strategic Performance & Risk Integration
Strategic Performance & Risk IntegrationStrategic Performance & Risk Integration
Strategic Performance & Risk Integration
 
KRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & ITKRI (Key Risk Indicators) & IT
KRI (Key Risk Indicators) & IT
 
Post Acquisiton Integration Framework
Post Acquisiton Integration FrameworkPost Acquisiton Integration Framework
Post Acquisiton Integration Framework
 

Similaire à Leveraging ISO 31000 for Effective Integration of Risk Management and Internal Control

ISO 31000 principles.pdf
ISO 31000 principles.pdfISO 31000 principles.pdf
ISO 31000 principles.pdfchandrasekars29
 
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...د حاتم البيطار
 
Understandiing ISO 31000-2009
Understandiing ISO 31000-2009Understandiing ISO 31000-2009
Understandiing ISO 31000-2009Ridwan Ibrahim
 
ISO+31000+2009+Understanding
ISO+31000+2009+UnderstandingISO+31000+2009+Understanding
ISO+31000+2009+UnderstandingSetiono Winardi
 
21832 Assessment 2 description and rubric Spring 2023.pdf
21832 Assessment 2 description and rubric Spring 2023.pdf21832 Assessment 2 description and rubric Spring 2023.pdf
21832 Assessment 2 description and rubric Spring 2023.pdfHaoranWang54
 
How to apply and benefit from the new risk management guide ISO/TR 31004:2013...
How to apply and benefit from the new risk management guide ISO/TR 31004:2013...How to apply and benefit from the new risk management guide ISO/TR 31004:2013...
How to apply and benefit from the new risk management guide ISO/TR 31004:2013...Risk Management Institution of Australasia
 
COVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | DeloitteCOVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | DeloitteDeloitte Polska
 
COVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | DeloitteCOVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | DeloitteDeloitte Polska
 
What New EU Reporting Standards Mean for North America
What New EU Reporting Standards Mean for North AmericaWhat New EU Reporting Standards Mean for North America
What New EU Reporting Standards Mean for North AmericaGreenBiz Group
 
Lobbying Forum at OECD Integrity Week
Lobbying Forum at OECD Integrity WeekLobbying Forum at OECD Integrity Week
Lobbying Forum at OECD Integrity WeekOECD Governance
 
Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000Continuity and Resilience
 
International organization for standardization
International organization for standardization International organization for standardization
International organization for standardization Chirag Tewari
 
An Easy-To-Use Checklist For Small Business Are You Ready
An Easy-To-Use Checklist For Small Business Are You ReadyAn Easy-To-Use Checklist For Small Business Are You Ready
An Easy-To-Use Checklist For Small Business Are You ReadyDarian Pruitt
 

Similaire à Leveraging ISO 31000 for Effective Integration of Risk Management and Internal Control (20)

Brochure iso 31000 conference may2013-toronto-l
Brochure iso 31000 conference may2013-toronto-lBrochure iso 31000 conference may2013-toronto-l
Brochure iso 31000 conference may2013-toronto-l
 
ISO 31000
ISO 31000ISO 31000
ISO 31000
 
ISO 31000 principles.pdf
ISO 31000 principles.pdfISO 31000 principles.pdf
ISO 31000 principles.pdf
 
Maritime Pollution Risk
Maritime Pollution RiskMaritime Pollution Risk
Maritime Pollution Risk
 
#corpriskforum2016 - Alex Dali
#corpriskforum2016 - Alex Dali#corpriskforum2016 - Alex Dali
#corpriskforum2016 - Alex Dali
 
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...Dr hatem el bitar quality text (17)د حاتم البيطار  #دحاتم_البيطار   #timodent...
Dr hatem el bitar quality text (17)د حاتم البيطار #دحاتم_البيطار #timodent...
 
Understandiing ISO 31000-2009
Understandiing ISO 31000-2009Understandiing ISO 31000-2009
Understandiing ISO 31000-2009
 
ISO+31000+2009+Understanding
ISO+31000+2009+UnderstandingISO+31000+2009+Understanding
ISO+31000+2009+Understanding
 
PPT - SIGMA-GIZ Academies - Topic 3 - ISO in public sector.pdf
PPT - SIGMA-GIZ Academies - Topic 3 - ISO in public sector.pdfPPT - SIGMA-GIZ Academies - Topic 3 - ISO in public sector.pdf
PPT - SIGMA-GIZ Academies - Topic 3 - ISO in public sector.pdf
 
21832 Assessment 2 description and rubric Spring 2023.pdf
21832 Assessment 2 description and rubric Spring 2023.pdf21832 Assessment 2 description and rubric Spring 2023.pdf
21832 Assessment 2 description and rubric Spring 2023.pdf
 
How to apply and benefit from the new risk management guide ISO/TR 31004:2013...
How to apply and benefit from the new risk management guide ISO/TR 31004:2013...How to apply and benefit from the new risk management guide ISO/TR 31004:2013...
How to apply and benefit from the new risk management guide ISO/TR 31004:2013...
 
Risk management erm
Risk management ermRisk management erm
Risk management erm
 
COVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | DeloitteCOVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | Deloitte
 
COVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | DeloitteCOVID-19 Strategic Response Lab | Deloitte
COVID-19 Strategic Response Lab | Deloitte
 
What New EU Reporting Standards Mean for North America
What New EU Reporting Standards Mean for North AmericaWhat New EU Reporting Standards Mean for North America
What New EU Reporting Standards Mean for North America
 
Lobbying Forum at OECD Integrity Week
Lobbying Forum at OECD Integrity WeekLobbying Forum at OECD Integrity Week
Lobbying Forum at OECD Integrity Week
 
Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000Implementing a Risk Management System based on the ISO 31000
Implementing a Risk Management System based on the ISO 31000
 
International organization for standardization
International organization for standardization International organization for standardization
International organization for standardization
 
An Easy-To-Use Checklist For Small Business Are You Ready
An Easy-To-Use Checklist For Small Business Are You ReadyAn Easy-To-Use Checklist For Small Business Are You Ready
An Easy-To-Use Checklist For Small Business Are You Ready
 
ISO 31000.pdf
ISO 31000.pdfISO 31000.pdf
ISO 31000.pdf
 

Plus de International Federation of Accountants

Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...International Federation of Accountants
 
Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...International Federation of Accountants
 

Plus de International Federation of Accountants (20)

Closing Remarks International Women's Day 2024
Closing Remarks International Women's Day 2024Closing Remarks International Women's Day 2024
Closing Remarks International Women's Day 2024
 
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDEIFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
IFAC Principios revisados de Gobierno Corporativo del G20 y de la OCDE
 
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
IFAC Presentación IGEP sobre OCDE-G20, Febrero 2024
 
Preparing for High Quality Sustainability assurance Engagements
Preparing for High Quality Sustainability assurance EngagementsPreparing for High Quality Sustainability assurance Engagements
Preparing for High Quality Sustainability assurance Engagements
 
Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...Otros pronunciamientos: Información financiera según la base contable de efec...
Otros pronunciamientos: Información financiera según la base contable de efec...
 
Otros pronunciamientos: Guías de Prácticas Recomendadas
Otros pronunciamientos: Guías de Prácticas RecomendadasOtros pronunciamientos: Guías de Prácticas Recomendadas
Otros pronunciamientos: Guías de Prácticas Recomendadas
 
Otros pronunciamientos: Marco conceptual
Otros pronunciamientos: Marco conceptualOtros pronunciamientos: Marco conceptual
Otros pronunciamientos: Marco conceptual
 
Adopción por primera vez de las NICSP de base de devengo
Adopción por primera vez de las NICSP de base de devengoAdopción por primera vez de las NICSP de base de devengo
Adopción por primera vez de las NICSP de base de devengo
 
Moneda Extranjera
Moneda ExtranjeraMoneda Extranjera
Moneda Extranjera
 
Presentación de la información presupuestaria
Presentación de la información presupuestariaPresentación de la información presupuestaria
Presentación de la información presupuestaria
 
Revelaciones de partes relacionadas
Revelaciones de partes relacionadasRevelaciones de partes relacionadas
Revelaciones de partes relacionadas
 
Estado de Flujos de Efectivo
Estado de Flujos de EfectivoEstado de Flujos de Efectivo
Estado de Flujos de Efectivo
 
Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...Presentación de los Estados Financieros Estados de situación financiera, rend...
Presentación de los Estados Financieros Estados de situación financiera, rend...
 
Combinaciones del sector público
Combinaciones del sector públicoCombinaciones del sector público
Combinaciones del sector público
 
Consolidación
ConsolidaciónConsolidación
Consolidación
 
Instrumentos financieros – Revelaciones
Instrumentos financieros – RevelacionesInstrumentos financieros – Revelaciones
Instrumentos financieros – Revelaciones
 
Instrumentos financieros – Cobertura y derivados
Instrumentos financieros – Cobertura y derivadosInstrumentos financieros – Cobertura y derivados
Instrumentos financieros – Cobertura y derivados
 
Instrumentos financieros – Conceptos básicos
Instrumentos financieros –  Conceptos básicos Instrumentos financieros –  Conceptos básicos
Instrumentos financieros – Conceptos básicos
 
Instrumentos financieros – Revelaciones
Instrumentos financieros –  Revelaciones Instrumentos financieros –  Revelaciones
Instrumentos financieros – Revelaciones
 
Instrumentos financieros – Coberturas y derivados
Instrumentos financieros – Coberturas y derivadosInstrumentos financieros – Coberturas y derivados
Instrumentos financieros – Coberturas y derivados
 

Dernier

👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...rajveerescorts2022
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPanhandleOilandGas
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Sheetaleventcompany
 
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLJAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noidadlhescort
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptxnandhinijagan9867
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 MonthsIndeedSEO
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Anamikakaur10
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 

Dernier (20)

👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
 
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLJAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 

Leveraging ISO 31000 for Effective Integration of Risk Management and Internal Control

  • 1. 1 Leveraging ISO 31000 for Effective Integration of Risk Management and Internal Control Presenter: Vincent Tophoff International Federation of Accountants (IFAC) Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 2. Overview • Role and domain of IFAC • Maturity of risk management and internal control (RM/IC) • Broader approach in RM/IC • Broader approach in RM/IC standards, frameworks & guidelines • Remaining pitfalls in RM/IC: application failures • IFAC supports further improvements in RM/IC 2 Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 3. 3 The International Federation of Accountants (IFAC) • The global organization of the accountancy profession • 172 member bodies and associates in 129 countries • 2.5 million professional accountants in public practice, commerce, industry, financial services, the public sector, education, and the not-for-profit sector • Public interest focused Second international ISO 31000 conference – Toronto, 28-31 May 2013 More than half are in this box
  • 4. 4 The International Federation of Accountants (IFAC) • Supports accountants in following areas: Auditing and accounting Governance and ethics Risk management and internal control Sustainability and corporate responsibility Financial and performance management Business reporting Promoting and contributing to the value of accountants • All areas of critical importance to the organizations they work for! Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 5. 5 Second international ISO 31000 conference – Toronto, 28-31 May 2013 • Crisis management • Internal control now complemented with risk management • But performed in a silo… • Integrating risk management and internal control in the governance & management of organization Level 1: Non-existent or ad hoc Level 2: Internal control only Level 3: RM/IC as a silo Level 4: Integrated RM/IC •Formal internal control •Mainly focused on external financial reporting Integration of RM/IC Here we are now
  • 6. 6 IFAC survey on risk management & internal control • Received over 600 responses from around the globe Main conclusions: • More awareness of the benefits of risk management and internal control systems should be created • Risk management and internal control should be better integrated into organizations’ overall governance, strategy, and operations • Risk management and internal control requirements and guidelines should be further aligned internationally Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 7. 7 Global Survey on Risk Management & Internal Control > Proposed Next Steps • Emphasizing the benefits of (more integrated) risk management and internal control • Bringing various risk management and internal control standard setting organizations (such as COSO, ISO 31000 & Risk Oversight & Governance Board) and their guidelines closer together • Collaborating with experts on development of practical application guidance for (integration of) risk management and internal control Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 8. 8 Global crisis According to IFAC research caused by: • Ethical flaws • Governance, risk management & internal control in name but not in spirit • Regulatory overload, leading to legalistic compliance • Risk & control systems too narrowly focused on only financial reporting controls • However, many, if not most, of the risks that affected organizations derived from areas other than financial reporting Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 9. 9 Conclusions from survey and global crisis A. Organizations should take a broader approach in risk management and internal control B. Risk management and internal control standards and principles should better enable taking a broader approach C. Appropriate application of risk management and internal control standards and principles is often the problem Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 10. 10 A. Taking a broader approach in RM/IC Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 11. 11 Broader approach in risk management (1) • Q: “How does your organization address uncertainty in achieving its strategic objectives?” • A: “Through our strategic management system;” Line management engaged in plan-do-check-act cycle Focused on achieving the organization’s objectives • Q: “How does your organization address risk?” • A: “Through our risk management system;” (separate) risk and control system, staff functionaries, risk register Focused on mitigating risk Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 12. 12 Broader approach in risk management (2) What does this example tell us? • That we, finance & accounting folks, have made great progress in the area of risk management and internal control… • …But that we, in the process, lost the other people in our organization! Risk Management Rest of the Organization Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 13. 13 Broader approach in risk management (3) Biggest risk facing an organization: Disconnect between those responsible for achieving strategic objectives vs. those responsible for managing risk Solution: Making those responsible for achieving strategic objectives also responsible for managing related risks! Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 14. 14 Broader approach in risk management (4) • Line management is accountable for (achieving) the organization’s objectives, • This also includes responsibility for managing the effects of risk on those objectives Key objective for management accountants in this regard: • Ensure that risk management and internal control are fully integrated in the line management of an organization! Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 15. 15 Broader approach in internal control (1) • Internal control not as an objective in itself • But as a response to modify risk • (In order to achieve the organization’s objectives) • And… Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 16. 16 Broader approach in internal control (2) Hindering the organization Enabling the organization • Good internal control: invisible hand From To Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 17. 17 B. Collaborating with standard setters • IFAC collaborates with regulators and standard setters in area of governance, risk management, and internal control Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 18. 18 IFAC collaboration with Canadian ROGB • IFAC also participates in the Canadian Risk Oversight and Governance Board (ROGB) • Offers guidance to directors and senior managers to fulfill their responsibility for governance and the oversight of risk management • Freely available from the ROGB website Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 19. 19 IFAC collaboration with COSO • Committee of Sponsoring Organizations of the Treadway Commission (COSO) • Providing thought leadership through the development of frameworks and guidance on risk management and internal control • Revised Framework issued in May 2013 and available at www.coso.org Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 20. 20 IFAC collaboration with ISO 31000 • International Standards Organization (ISO) developed the standard ISO 31000:2009 Risk Management • Can be used by any public, private or community enterprise, association, group, or individual • Can be applied to any type of risk, whatever its nature, whether having positive or negative consequences (so broader than ERM) Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 21. 21 Comparison COSO ERM vs. ISO 31000 COSO ISO 31000 • Lengthy vs. Short • Focused on ERM vs. General approach to managing risk • One cube vs. Framework and process • Skewed to negative vs. Risk can be positive or negative • Risk already exists vs. Risk tied to achieving objectives • Risk & opportunities vs. Opportunities also source of risk • More sequential process vs. More iterative process • However… many organizations use both COSO ERM and ISO 31000 • Biggest challenge is that concepts and terminology are not aligned! Second international ISO 31000 conference – Toronto, 28-31 May 2013 Too short, however, to really understand
  • 22. 22 Bringing together COSO, ISO, ROGB and others • Best opportunity to further align concepts and terminology by bringing together the various issuers of standards, guidance & frameworks • To discuss how the terminology, various concepts & guidelines could be better aligned • IFAC facilitates first meeting of COSO, ISO 31000, and ROGB boards in September 2013 in Chicago • Including representatives from RIMS and other organizations • Should all work together to produce globally-aligned terminology, concepts, and guidelines that are relevant to all users. • IFAC looks forward to continue contributing to this collaborative effort Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 23. 23 C. Encouraging better application of RM/IC guidelines Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 24. 24 Bad practice vs. good practice in RM/IC Second international ISO 31000 conference – Toronto, 28-31 May 2013 Overwhelming load of bad practice: • RM/IC as objective in itself vs. RM/IC to achieve objectives • Auditor / staff driven vs. Board and management driven • Rules-based vs. Principles-based • Of the shelf systems vs. Tailor made • Focused on threats only vs. Also focused on opportunities • Mainly hard controls vs. Social / human aspects • Artificially implemented vs. Organically implemented • Stand-alone / “bolt-on” vs. Integrated / ”built-in” • Static, out-of-date vs. Dynamic, evolving • Creates costs vs. Creates results / value • Abandoned vs. Supported
  • 25. 25 IFAC risk management & internal control publications • Evaluating and Improving Governance in Organizations • Evaluating and Improving Internal Control in Organizations • Integrating Governance in for Sustainable Success • All IFAC Publications free-of-charge at www.ifac.org Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 26. 26 Evaluating and Improving IC in Organizations • Highlighting areas where practical application of internal control standards often fails in many organizations • Designed to establish a benchmark for good practice in maintaining effective internal control in response to risk • For all types of organizations, as all organizations—whether private or public—should have appropriate internal control Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 27. 27 Guidance to avoid or overcome pitfalls Good internal control should: • Support the organization’s objectives • Define clear roles and responsibilities • Foster a motivational culture • Link to individual performance • Ensure sufficient competency • Respond to risk • Be communicated regularly • Be monitored and evaluated regularly • Provide for accountability and transparency Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 28. 28 Next steps > guidance in integration of risk & control • Risk management and internal control are a means to an end: making sound (SWOT) decisions to achieve the organization’s objectives without surprises! • Principles on how risk managers can support their organization integrating risk management and internal control into the organization’s overall governance and management system Second international ISO 31000 conference – Toronto, 28-31 May 2013
  • 29. 29 Second international ISO 31000 conference – Toronto, 28-31 May 2013 Key takeaway’s • Risk management and internal control have matured • Still many flaws • IFAC supports: further integration of RM/IC Further alignment of RM/IC standards Better application of RM/IC principles and concepts • However, no matter the guidance provided…
  • 30. • …There will always be some who do it their own way! 30 Second international ISO 31000 conference – Toronto, 28-31 May 2013