Risk-based audit programme

Size: px
Start display at page:

Download "Risk-based audit programme"

Transcription

1 Training on Audit Systems Risk-based audit programme Madrid, February 8, 2012 Tom VANOVERSCHELDE CA-D2-P09B Federal Agency for the Safety of the Food Chain Belgium (until 8/2011) Senior auditor HJ Heinz Ltd. Co. CAD2P09B - 1

2 Concept of risk Risk is the possibility that an event will occur and adversely affect the achievement of objectives. (enterprise risk management framework - ERM) Risk is the effect of uncertainty on objectives. (ISO guide 73 on risk management) Risk in the context of official controls is the probability of failure to comply with requirements or detect non-compliance by those who are responsible for either complying with animal health, animal welfare, plant health, feed and food law or for verifying compliance. It can be divided into three components: Compliance Risk, Official Control Risk and Audit Risk. CAD2P09B - 2

3 Some other concepts Audit universe Risk universe Risk assessment Risk appetite Risk strategy Risk management Risk and control matrix (RACM)... CAD2P09B - 3

4 Risks to be considered Sanitary risk Consumer health Animal or plant health Economic risk (impact) Reputation risk Media, consumers, politicians Food / feed operators International image risk Organizational risk Compliance risk... CAD2P09B - 4

5 Different types of risk apply CAD2P09B - 5

6 Overall risk level Course A: Auditing Implementing an audit system Risk strategy Avoid Share/ transfer Example of a risk: not detecting non compliance with relevant regulatory obligations during inspections Avoid Share = Not possible, we need to do those inspections = Food operator has final responsibility, external certification... Reduce = Checklists, training, supervision... Accept = Residual risk that remains... Reduce Accept Action plan Set of measures Risk management options (depends on risk appetite) Source scheme: IIA training on financial auditing, May 2010, Brussels CAD2P09B - 6

7 inherent versus residual risk Inherent risk Total risk to an activity if no controls or other mitigating factors are in place Controls & Mitigation Residual risk The risk that remains after putting controls or other factors in place CAD2P09B - 7

8 Player Sector / food operator Different levels Inherent risks Chemical, physical, microbiological Controls / measures GHP - GMP HACCP Residual risk Accepted residual risk by sector or operator Competent Authority Chemical, physical, microbiological Relative compliance risk of sector or operator Official inspections Sampling tests HACCP audits Certification Licensing/ registration Accepted residual risk by CA or by politicians (society) Internal audit Failing controls or mitigation measures Residual risks left by CA Test effectiveness/ efficiency of controls Assess levels of residual risks Audit risk (deficiencies or too much residual risk is not detected) CAD2P09B - 8

9 Risk-based programme Decision 677/2006 : result of a planning process identifying risk-based priorities at an appropriate risk-based frequency No further guidelines non-compulsory document in preparation Possible approaches: Formally quantified risk assessment Rather qualitative approach to risk Mix between both CAD2P09B - 9

10 Role management <-> auditors Management : Risk assessment of risks in the food chain Drafting the MANCP Staffing, training, overall organization Monitoring RACM : Risk and Control Matrix Auditors: Make (a draft / proposal of) the audit programme should be risk based Do audits and report on them. Assess the risk strategy of the CA and point out where risks are not sufficiently mitigated. By carrying out an individual audit, risk is an important consideration in defining scope / testing to do CAD2P09B - 10

11 Quantified riskassessment Risk is commonly determined by the formula probability x impact Estimation of : Impact : the impact when an event occurs Probability : the likelihood that the event will occur Other possible factors : cost detectability uncertainty CAD2P09B - 11

12 Consumer risk : Scoring probability Example CAD2P09B - 12

13 Consumer risk : Scoring impact Example CAD2P09B - 13

14 Scoring risks / audit scopes Likelihood Impact CAD2P09B - 14

15 Another example CAD2P09B - 15

16 Use of risk to prioritize CAD2P09B - 16

17 Qualitative risk assessment Implicit or explicit (documented or not) By management By key stakeholders (sector and consumer organizations, political level, ) Professional judgment of the auditors Take into account results of previous audits, FVO missions, incidents, new legislation CAD2P09B - 17

18 YES Why (not) use scoring? Quantified Easier to compare scores Scores can be used to make certain scopes more or less important Less subjective Common methodology for different types of risk Time consuming Auditors don t always have the knowledge Periodic review required Giving a score is also subjective Lower scoring areas might never be audited 677 audit everything in a 5-year period (subject to change) NO CAD2P09B - 18

19 Risk <-> 5-year coverage Dilemma between risk-based and - at the same time - cover all relevant areas within a 5-year cycle? CAD2P09B - 19

20 5-year coverage All relevant areas of 882/2004 audit universe Different approaches : High level <-> detailed Structured by sectors of the food chain, legislation, processes, organizational entities Interpretation of coverage based on FVO-meetings A full coverage of a certain domain is not realistic Auditing is always based on a sample Single audit : if areas were audited by other qualified bodies, the same work does not have to be repeated. CAD2P09B - 20

21 Coverage + risk All audit areas are listed in an audit universe Full coverage : shift from all areas are audited all areas have been considered Negligible risk audit areas can be considered as being covered (need to be part of audit universe) Not every area is audited in detail Risk assessment : defines priorities Different approaches to audit areas: Low risk : horizontal scan High(er) risk : multiple audits, horizontal and vertical approach CAD2P09B - 21

22 Horizontal and vertical approach Horizontal audit approach: when an audit focuses primarily on the implementation of general requirements e.g. Regulations 178/2002, 882/2004, 852/2004 or strategic objectives from the MANCP. Some practical examples: Implementation and control of traceability systems in the meat sector Legal instruments for dealing with non compliance Risk assessment and MANCP (inspections, sampling...) Crisis prevention and control Vertical audit approach: when an audit focuses primarily on sectorspecific requirements e.g. Regulation 853/2004, ABP Regulation, Feed Hygiene Regulation, Animal Welfare or BIP requirements. Some practical examples: Sampling and testing on use of hormones in cattle meat Infrastructure and hygiene inspections in retail businesses Export certification of pigs Infrastructure and hygiene in cutting plants Plant import controls in a border post Source definitions: Planning for audits of official control systems, draft version V10 CAD2P09B - 22

23 Audit universe Possible topics to audit Author of these images: E. Sloth CAD2P09B - 23

24 Sectors in the audit universe Primary sector Meat sector Import Wholesale sector Retail sector CAD2P09B - 24

25 From audit universe to risk universe (e.g. 1 sector at the time) Primary sector Meat sector Import Wholesale sector Retail sector CAD2P09B - 25

26 Horizontal subjects in the audit universe Primary sector Meat sector Import Wholesale sector Retail sector CAD2P09B - 26

27 Objectives of risk-based planning To contribute to consumer safety, animal health and welfare, plant health and increase stakeholder confidence in effective and efficient use of resources. This is achieved by ensuring that: audit universe(s) do not overlook any relevant areas; planning processes are able to identify and categorise main risks appropriately; the whole process is subject to regular review; and audit bodies (in case there are several) coordinate their planning processes. Extract from Planning for audits of official control systems, draft version V10 CAD2P09B - 27

28 Audit universe & coverage - Example 1 Import & intra-eu trade X Food production and wholesale Distribution (retail, B2C) X X Primary production X Slaughterhouses and the meat sector X CAD2P09B - 28

29 Audit universe & coverage example 2 CAD2P09B - 29

30 Audit universe & coverage Example 3 Source: Belgian audit universe situation on 31/12/2010 CAD2P09B - 30

31 Process flow diagram for risk based planning DRAFT Input 1.1 Process Output Competent authority MANCP Others e.g. legislation Control processes Production chain Hazards Competent authority MANCP Define Audit Universe Risk assessment Audit Universe Experts Stake holders Data / information Previous audits, inspections etc. Assess the probability: Current cases Previous findings Internal events External events Assess consequences Food safety Animal welfare Animal health Misleading Uncertainty Confidence Significance 2.3 Risk Universe Audit risks Auditors Draft the audit programme Source: Planning for audits of official control systems, draft version V Audit programme CAD2P09B - 31

32 What to do? Find an approach which suits your organization. Coverage : how detailed do you want to plan / document it? Risk assessment : find a balance between cost and benefits Challenge to work risk-based and cover the relevant areas of 882/2004 CAD2P09B - 32

RISK-BASED PLANNING FOR AUDITS OF OFFICIAL CONTROL SYSTEMS

RISK-BASED PLANNING FOR AUDITS OF OFFICIAL CONTROL SYSTEMS National Audit Systems Network RISK-BASED PLANNING FOR AUDITS OF OFFICIAL CONTROL SYSTEMS The network of national audit experts have produced this non-binding reference document based on agreed good practices

More information

Foreword... 11 Introduction - The Global Food Safety Initiative (GFSI)... 11 Scope... 12 Section Overview... 12 Normative References...

Foreword... 11 Introduction - The Global Food Safety Initiative (GFSI)... 11 Scope... 12 Section Overview... 12 Normative References... Version 6.3 Overview Contents Foreword... 11 Introduction - The Global Food Safety Initiative (GFSI)... 11 Scope... 12 Section Overview... 12 Normative References... 13 9 Foreword Global Food Safety Initiative

More information

The implementation of self checking systems in Belgium

The implementation of self checking systems in Belgium Federal Agency for the Safety of the Food Chain The implementation of self checking systems in Belgium Herman Diricks Director-general Control Policy Content Context National legislation Development of

More information

FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012. Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund

FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012. Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012 Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund There are different risk assessments prepared: Annual risk assessment

More information

Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology

Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology Risk Management and Internal Audit Specialized Training Course Audit Risk Assessment Methodology May 20, 2015 Internal FR 2 Risk and Risk Assessment Defined Risk Institute of Internal Auditors (IIA) The

More information

Policy 10.105: Enterprise Risk Management Policy

Policy 10.105: Enterprise Risk Management Policy Name: Responsibility: Complements: Enterprise Risk Management Framework Coordinator, Enterprise Risk Management Policy 10.105: Enterprise Risk Management Policy Date: November 2006 Revision Date(s): January

More information

RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide

RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation

More information

An Introduction to Risk Management. For Event Holders in Western Australia. May 2014

An Introduction to Risk Management. For Event Holders in Western Australia. May 2014 An Introduction to Risk Management For Event Holders in Western Australia May 2014 Tourism Western Australia Level 9, 2 Mill Street PERTH WA 6000 GPO Box X2261 PERTH WA 6847 Tel: +61 8 9262 1700 Fax: +61

More information

EU Sanitary and Phytosanitary Standards. Ella STRICKLAND DG Health and Consumers, EU Commission Kampala, Uganda, 30 November 2010

EU Sanitary and Phytosanitary Standards. Ella STRICKLAND DG Health and Consumers, EU Commission Kampala, Uganda, 30 November 2010 EU Sanitary and Phytosanitary Standards Ella STRICKLAND DG Health and Consumers, EU Commission Kampala, Uganda, 30 November 2010 Scope of the presentation The Single Market The Multilateral Framework SPS

More information

Schweppes Australia Head Office Level 5, 111 Cecil Street South Melbourne Victoria 3205. www.schweppesaustralia.com.au

Schweppes Australia Head Office Level 5, 111 Cecil Street South Melbourne Victoria 3205. www.schweppesaustralia.com.au Schweppes Australia Head Office Level 5, 111 Cecil Street South Melbourne Victoria 3205 www.schweppesaustralia.com.au Quality Management Systems 1. Quality Management Systems develop, implement, verify

More information

FAMI-QS Certification Rules for Operators. Rules for Operators

FAMI-QS Certification Rules for Operators. Rules for Operators Rules for Operators TABLE OF CONTENTS 1. Application for certification and FAMI QS associate membership...2 2. Assessment of operators...3 2.1. Audit planning...3 2.2. Frequency of audits and re certification...5

More information

FOOD SAFETY MANAGEMENT SYSTEMS (FSMS): REQUIREMENTS FOR ANY ORGANISATION IN THE FOOD CHAIN (ISO 22000:2005)

FOOD SAFETY MANAGEMENT SYSTEMS (FSMS): REQUIREMENTS FOR ANY ORGANISATION IN THE FOOD CHAIN (ISO 22000:2005) FOOD SAFETY MANAGEMENT SYSTEMS (FSMS): REQUIREMENTS FOR ANY ORGANISATION IN THE FOOD CHAIN (ISO 22000:2005) Dr.R.MANAVALAN, M.Pharm., Ph.D. Professor and Research Director, Department of Pharmaceutics,

More information

Checklist for Operational Risk Management

Checklist for Operational Risk Management Checklist for Operational Risk Management I. Development and Establishment of Comprehensive Operational Risk Management System by Management Checkpoints - Operational risk is the risk of loss resulting

More information

ENTERPRISE RISK MANAGEMENT POLICY

ENTERPRISE RISK MANAGEMENT POLICY ENTERPRISE RISK MANAGEMENT POLICY TITLE OF POLICY POLICY OWNER POLICY CHAMPION DOCUMENT HISTORY: Policy Title Status Enterprise Risk Management Policy (current, revised, no change, redundant) Approving

More information

Certification criteria for. Food Safety Management Systems Auditor Conversion Training Course

Certification criteria for. Food Safety Management Systems Auditor Conversion Training Course Certification criteria for Food Safety Management Systems Auditor Conversion Training Course CONTENTS BACKGROUND TO THIS COURSE 1. INTRODUCTION 2. PRIOR KNOWLEDGE REQUIREMENT 3. LEARNING OBJECTIVES 4.

More information

Welcome! DeLaval Cleaning Solutions Dallas Customer Training Session (GFSI) November 2012

Welcome! DeLaval Cleaning Solutions Dallas Customer Training Session (GFSI) November 2012 Welcome! DeLaval Cleaning Solutions Dallas Customer Training Session (GFSI) November 2012 What is it? GFSI is a non-profit foundation, created under Belgium Law Mission : Continuous improvement in food

More information

EUROPEAN COMMISSION DIRECTORATE-GENERAL FOR HEALTH AND FOOD SAFETY

EUROPEAN COMMISSION DIRECTORATE-GENERAL FOR HEALTH AND FOOD SAFETY Ref. Ares(2015)2384183-08/06/2015 EUROPEAN COMMISSION DIRECTORATE-GENERAL FOR HEALTH AND FOOD SAFETY Directorate F - Food and Veterinary Office DG(SANTE) 2015-7752 - MR FINAL OVERVIEW REPORT REPORT ON

More information

Safety Regulation Group SAFETY MANAGEMENT SYSTEMS GUIDANCE TO ORGANISATIONS. April 2008 1

Safety Regulation Group SAFETY MANAGEMENT SYSTEMS GUIDANCE TO ORGANISATIONS. April 2008 1 Safety Regulation Group SAFETY MANAGEMENT SYSTEMS GUIDANCE TO ORGANISATIONS April 2008 1 Contents 1 Introduction 3 2 Management Systems 2.1 Management Systems Introduction 3 2.2 Quality Management System

More information

Abu Dhabi EHSMS Regulatory Framework (AD EHSMS RF)

Abu Dhabi EHSMS Regulatory Framework (AD EHSMS RF) Abu Dhabi EHSMS Regulatory Framework (AD EHSMS RF) Technical Guideline Audit and Inspection Version 2.0 February 2012 Table of Contents 1. Introduction... 3 2. Definitions... 3 3. Internal Audit... 3 3.1

More information

Analyzing Risks in Healthcare. February 12, 2014

Analyzing Risks in Healthcare. February 12, 2014 Analyzing s in Healthcare February 12, 2014 1 Content What is Enterprise Management (ERM) ERM Benefits ERM Standards / ISO 31000:2009 ERM Process Register ERM Governance Model s Q&A 2 What is Enterprise

More information

Project Risk Management

Project Risk Management Project Risk Management Study Notes PMI, PMP, CAPM, PMBOK, PM Network and the PMI Registered Education Provider logo are registered marks of the Project Management Institute, Inc. Points to Note Risk Management

More information

Exhibit 1: Structure of a heat map

Exhibit 1: Structure of a heat map Integrating risk and performance management processes Werner Bruggeman Geert Scheipers Valerie Decoene 1. Introduction Years ago, Kaplan & Norton interviewed managers about their time consumption and they

More information

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework

The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework The New International Standard on the Practice of Risk Management A Comparison of ISO 31000:2009 and the COSO ERM Framework Dorothy Gjerdrum, ARM-P, Chair of the ISO 31000 US TAG and Executive Director,

More information

Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization

Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization Internal Audit Quality Assessment Presented To: World Intellectual Property Organization April 2014 Table of Contents List of Acronyms 3 Page Executive Summary Opinion as to Conformance to the Standards,

More information

Global Food Safety Systems Food-Borne Pathogen Control

Global Food Safety Systems Food-Borne Pathogen Control Global Food Safety Systems Food-Borne Pathogen Control Improving Food Safety Through One Health IOM Forum on Microbial Threats December 14, 2011 Michael C. Robach Vice President, Corporate Food Safety

More information

ENTERPRISE RISK MANAGEMENT FRAMEWORK

ENTERPRISE RISK MANAGEMENT FRAMEWORK ENTERPRISE RISK MANAGEMENT FRAMEWORK COVENANT HEALTH LEGAL & RISK MANAGEMENT CONTENTS 1.0 PURPOSE OF THE DOCUMENT... 3 2.0 INTRODUCTION AND OVERVIEW... 4 3.0 GOVERNANCE STRUCTURE AND ACCOUNTABILITY...

More information

Linking Risk Management to Business Strategy, Processes, Operations and Reporting

Linking Risk Management to Business Strategy, Processes, Operations and Reporting Linking Risk Management to Business Strategy, Processes, Operations and Reporting Financial Management Institute of Canada February 17 th, 2010 KPMG LLP Agenda 1. Leading Practice Risk Management Principles

More information

IMPLEMENTING ISO 14001:2004. www.aecos.co.uk

IMPLEMENTING ISO 14001:2004. www.aecos.co.uk IMPLEMENTING ISO 14001:2004 www.aecos.co.uk What is an Environmental Management System? A systematic framework to manage the immediate and long term environmental impacts of an organisation s products,

More information

IFAD Policy on Enterprise Risk Management

IFAD Policy on Enterprise Risk Management Document: EB 2008/94/R.4 Agenda: 5 Date: 6 August 2008 Distribution: Public Original: English E IFAD Policy on Enterprise Risk Management Executive Board Ninety-fourth Session Rome, 10-11 September 2008

More information

Enterprise Risk Management Update Executive Summary December 2010

Enterprise Risk Management Update Executive Summary December 2010 Enterprise Risk Management Update Executive Summary December 2010 Risk is integral in the pursuit of improvement. Risk, in general, is seldom avoidable and cannot always be mitigated. Accordingly, risk

More information

Overview of GFSI and Accredited Certification

Overview of GFSI and Accredited Certification Overview of GFSI and Accredited Certification Overview of GFSI and Accredited Certification Introduction Global food trade is expanding and providing consumers with access to a wider variety of foods all

More information

Integration of Risk Management and Internal Audit. Chartered Institute of Management Accountants, New Zealand

Integration of Risk Management and Internal Audit. Chartered Institute of Management Accountants, New Zealand Integration of Risk Management and Internal Audit Chartered Institute of Management Accountants, New Zealand Contents Understanding the three lines of defense governance model What is Risk? Risk Management

More information

The Lowitja Institute Risk Management Plan

The Lowitja Institute Risk Management Plan The Lowitja Institute Risk Management Plan 1. PURPOSE This Plan provides instructions to management and staff for the implementation of consistent risk management practices throughout the Lowitja Institute

More information

QUALITY RISK MANAGEMENT (QRM): A REVIEW

QUALITY RISK MANAGEMENT (QRM): A REVIEW Lotlikar et al Journal of Drug Delivery & Therapeutics; 2013, 3(2), 149-154 149 Available online at http://jddtonline.info REVIEW ARTICLE QUALITY RISK MANAGEMENT (QRM): A REVIEW Lotlikar MV Head Corporate

More information

FSSC 22000. Certification scheme for food safety systems in compliance with ISO 22000: 2005 and technical specifications for sector PRPs PART II

FSSC 22000. Certification scheme for food safety systems in compliance with ISO 22000: 2005 and technical specifications for sector PRPs PART II FSSC 22000 Certification scheme for food safety systems in compliance with ISO 22000: 2005 and technical specifications for sector PRPs PART II REQUIREMENTS AND REGULATIONS FOR CERTIFICATION BODIES Foundation

More information

Jonathan Wilson. Sector Manager (Health & Safety)

Jonathan Wilson. Sector Manager (Health & Safety) Jonathan Wilson Sector Manager (Health & Safety) OHSAS 18001:2007 Making Life Easier For Health & Safety Managers Workshop Agenda 1. Introduction 2. Why Manage Health & Safety 3. OHSAS 18001 and OHSMS

More information

Food Safety Management in the Hospital

Food Safety Management in the Hospital Food Safety Management in the Hospital Richard Hannay BSc, FRSH, MCIEP, MIFST Food Safety and HACCP Consultant The Bristol Children s Hospital Introduction Preparing a Safe Food Policy and Plan The Role

More information

Internal Audit Checklist

Internal Audit Checklist Internal Audit Checklist 4.2 Policy Verify required elements Verify management commitment Verify available to the public Verify implementation by tracing links back to policy statement Check review/revisions

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page

More information

Audit of the Test of Design of Entity-Level Controls

Audit of the Test of Design of Entity-Level Controls Audit of the Test of Design of Entity-Level Controls Canadian Grain Commission Audit & Evaluation Services Final Report March 2012 Canadian Grain Commission 0 Entity Level Controls 2011 Table of Contents

More information

BRC Food Safety and Quality Management System. New Issue 7

BRC Food Safety and Quality Management System. New Issue 7 New Issue 7 This is an ideal package for Food Manufacturers looking to meet BRC Global Standard for Food Safety (Issue 7 2015) for Food Safety Quality Management Systems. Our BRC Food Safety Quality Management

More information

Business Management System Manual. Context, Scope and Responsibilities

Business Management System Manual. Context, Scope and Responsibilities Business Management System BMS Manual Page 1 of 11 Business Management System Manual Context, Scope and Responsibilities ISO 9001:2015 BMS.0100 R1 MAS Solutions LLC 29810 FM 1093 Suite C Fulshear, TX 77441

More information

B o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing

B o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing B o a r d of Governors of the Federal Reserve System Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing January 23, 2013 P U R P O S E This policy statement is being issued

More information

Improved Utilization of Self-Inspection Programs within the GMP Environment A Quality Risk Management Approach

Improved Utilization of Self-Inspection Programs within the GMP Environment A Quality Risk Management Approach Improved Utilization of Self-Inspection Programs within the GMP Environment A Quality Risk Management Approach Barbara Jeroncic Self-inspection is a well-established and vital part of the pharmaceutical

More information

CHECKLIST ISO/IEC 17021:2011 Conformity Assessment Requirements for Bodies Providing Audit and Certification of Management Systems

CHECKLIST ISO/IEC 17021:2011 Conformity Assessment Requirements for Bodies Providing Audit and Certification of Management Systems Date(s) of Evaluation: CHECKLIST ISO/IEC 17021:2011 Conformity Assessment Requirements for Bodies Providing Audit and Certification of Management Systems Assessor(s) & Observer(s): Organization: Area/Field

More information

IS Audit and Assurance Guideline 2202 Risk Assessment in Planning

IS Audit and Assurance Guideline 2202 Risk Assessment in Planning IS Audit and Assurance Guideline 2202 Risk Assessment in Planning The specialised nature of information systems (IS) audit and assurance and the skills necessary to perform such engagements require standards

More information

CONSULTATION DELIVERING LIFETIME ASSURED BEEF

CONSULTATION DELIVERING LIFETIME ASSURED BEEF CONSULTATION DELIVERING LIFETIME ASSURED BEEF January 2015 (Responses by Friday 27 th March 2015) 1 1 INTRODUCTION EXECUTIVE SUMMARY Cattle are currently considered assured under the Red Tractor scheme

More information

Safety Management Systems (SMS) guidance for organisations

Safety Management Systems (SMS) guidance for organisations Safety and Airspace Regulation Group Safety Management Systems (SMS) guidance for organisations CAP 795 Published by the Civil Aviation Authority, 2014 Civil Aviation Authority, CAA House, 45-59 Kingsway,

More information

Periodic risk assessment by internal audit

Periodic risk assessment by internal audit Periodic risk assessment by internal audit I Introduction The Good Practice Internal Audit Manual Template, developed by the Internal Audit CoP of Pempal, defines the importance and the impact that an

More information

FOOD LAW ENFORCEMENT IN SCOTLAND

FOOD LAW ENFORCEMENT IN SCOTLAND FOOD LAW ENFORCEMENT IN SCOTLAND A Report on the Administrative and Enforcement Arrangements Prepared by: The Society of Chief Officers of Environmental Health in Scotland The Royal Environmental Health

More information

Contaminated Products Insurance Application Form

Contaminated Products Insurance Application Form Contaminated Products Insurance Application Form APPLICANT S INFORMATION Name of Applicant Mailing address Contact Person Name: Email and Phone number: Website address Years in operation Business Description:

More information

Food Safety and Quality Management System

Food Safety and Quality Management System Introduction The company has planned, established, documented and implemented a food safety and quality management system for the site, which is maintained in order to continually improve its effectiveness

More information

POLICY. Number: 7311-10-005 Title: Enterprise Risk Management. Authorization

POLICY. Number: 7311-10-005 Title: Enterprise Risk Management. Authorization POLICY Number: 7311-10-005 Title: Enterprise Risk Management Authorization [ ] President and CEO [ X] Vice President, Finance and Corporate Services Source: Director, Enterprise Risk Management Cross Index:

More information

General Regulations. Part Ⅱ - Quality Management System Rules ENGLISH VERSION 5.0

General Regulations. Part Ⅱ - Quality Management System Rules ENGLISH VERSION 5.0 General Regulations Part Ⅱ - Quality Management System Rules ENGLISH VERSION 5.0 VALID FROM: 1 JULY 2015 OBLIGATORY FROM: 1 JULY 2016 TABLE OF CONTENTS 1. LEGALITY, ADMINISTRATION AND STRUCTURE... 3 1.1

More information

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND TO THE COUNCIL

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND TO THE COUNCIL EUROPEAN COMMISSION Brussels, 23.3.2012 COM(2012) 122 final REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND TO THE COUNCIL on the overall operation of official controls in the Member States on

More information

FSSC 22000. Certification scheme for food safety systems in compliance with ISO 22000: 2005 and technical specifications for sector PRPs PART I

FSSC 22000. Certification scheme for food safety systems in compliance with ISO 22000: 2005 and technical specifications for sector PRPs PART I FSSC 22000 Certification scheme for food safety systems in compliance with ISO 22000: 2005 and technical specifications for sector PRPs PART I REQUIREMENTS FOR ORGANIZATIONS THAT REQUIRE CERTIFICATION

More information

Enterprise Risk Management in Colleges and Universities

Enterprise Risk Management in Colleges and Universities Enterprise Risk Management in Colleges and Universities Cherry Bekaert & Holland, L.L.P. Neal Beggan, CISA, CRISC Shane Hester, CPA, CISA Cherry, Bekaert & Holland, L.L.P. The Firm of Choice. 1 Cherry,

More information

FASFC policy on food safety in the short supply chain

FASFC policy on food safety in the short supply chain Symposium Scientific Committee of the Belgian Food Safety Agency Food Safety of the Short Supply Chain Brussels, 9 november 2012 FASFC policy on food safety in the short supply chain Herman Diricks Director-general

More information

Title: OHS Risk Management Procedure

Title: OHS Risk Management Procedure Issue Date: July 2011 Review Date: July 2013 Page Number: 1 of 9 1. Purpose: To outline the methodology by which Department of Education and Early Childhood Development (DEECD) identifies, assesses, controls

More information

Matthew E. Breecher Breecher & Company PC November 12, 2008

Matthew E. Breecher Breecher & Company PC November 12, 2008 Applying COSO s Enterprise Risk Management Integrated Framework Matthew E. Breecher Breecher & Company PC November 12, 2008 The basic outline for this presentation was provided by: Objectives for the session:

More information

Audit of the control body through the monitoring of compliance with control plan. Measures for the irregularities

Audit of the control body through the monitoring of compliance with control plan. Measures for the irregularities Workshop on verification of compliance with product specification for PDO, PGI and TSG Audit of the control body through the monitoring of compliance with control plan Measures for the irregularities Viktorija

More information

Aberdeen City Council IT Security (Network and perimeter)

Aberdeen City Council IT Security (Network and perimeter) Aberdeen City Council IT Security (Network and perimeter) Internal Audit Report 2014/2015 for Aberdeen City Council August 2014 Internal Audit KPIs Target Dates Actual Dates Red/Amber/Green Commentary

More information

CONCEPTS OF FOOD SAFETY QUALITY MANAGEMENT SYSTEMS. Mrs. Malini Rajendran

CONCEPTS OF FOOD SAFETY QUALITY MANAGEMENT SYSTEMS. Mrs. Malini Rajendran CONCEPTS OF FOOD SAFETY AND QUALITY MANAGEMENT SYSTEMS Mrs. Malini Rajendran Brief background 1963 - The Codex Alimentarius Commission was created by FAO and WHO to develop food standards, guidelines and

More information

Contact address: Global Food Safety Initiative Foundation c/o The Consumer Goods Forum 22/24 rue du Gouverneur Général Eboué 92130 Issy-les-Moulineaux

Contact address: Global Food Safety Initiative Foundation c/o The Consumer Goods Forum 22/24 rue du Gouverneur Général Eboué 92130 Issy-les-Moulineaux Version 6.3 Contact address: Global Food Safety Initiative Foundation c/o The Consumer Goods Forum 22/24 rue du Gouverneur Général Eboué 92130 Issy-les-Moulineaux France Secretariat email: gfsinfo@theconsumergoodsforum.com

More information

Country Specific Experience with Export Certificates

Country Specific Experience with Export Certificates Country Specific Experience with Export Certificates Dr. Nanthiya Unprasert Deputy Director General Dr. Narumon Wiangwang Senior Researcher National Bureau of Agricultural Commodity and Food Standards

More information

OAC Presentation to UNESCO Member States

OAC Presentation to UNESCO Member States OAC Presentation to UNESCO Member States Scope and Purpose of Audit and Risk Committees 29 June 2016 1 Content: 1. Context 2. Audit and Risk Management in UNESCO today 3. Relationship between Entreprise

More information

FMEA and HACCP: A comparison. Steve Murphy Marc Schaeffers

FMEA and HACCP: A comparison. Steve Murphy Marc Schaeffers FMEA and HACCP: A comparison Steve Murphy Marc Schaeffers FMEA and HACCP: A comparison Introduction FMEA and Control planning is being used more and more in industry. In the food industry companies use

More information

FOOD SAFETY SYSTEM CERTIFICATION 22000 FSSC 22000

FOOD SAFETY SYSTEM CERTIFICATION 22000 FSSC 22000 FOOD SAFETY SYSTEM CERTIFICATION 22000 FSSC 22000 Certification scheme for food safety systems in compliance with ISO 22000: 2005 and technical specifications for sector PRPs Features Foundation for Food

More information

Enterprise Risk Management: Taking the First Steps

Enterprise Risk Management: Taking the First Steps Enterprise Risk Management: Taking the First Steps TN PRIMA, 2012 DOROTHY GJERDRUM, ARM, CIRM NOVEMBER 15, 2012 Agenda Goal: To understand how to begin to implement a broader approach to risk management

More information

Enterprise Risk Management

Enterprise Risk Management Cayman Islands Society of Professional Accountants Enterprise Risk Management March 19, 2015 Dr. Sandra B. Richtermeyer, CPA, CMA What is Risk Management? Risk management is a process, effected by an entity's

More information

15 Guiding Principles

15 Guiding Principles Health, Safety, Environment and Corporate Social Responsibility 15 Guiding Principles 2013 Message from President and CEO 0 New Gold has a complementary portfolio of assets in different countries and cultures

More information

DISCUSSION PAPER ON THE POSSIBLE DEVELOPMENT OF GUIDANCE ON THE USE OF SYSTEMS EQUIVALENCE/COMPARABILITY. (Paper prepared by New Zealand)

DISCUSSION PAPER ON THE POSSIBLE DEVELOPMENT OF GUIDANCE ON THE USE OF SYSTEMS EQUIVALENCE/COMPARABILITY. (Paper prepared by New Zealand) E Agenda item 8 CX/FICS 16/22/7 December 2015 JOINT FAO/WHO FOOD STANDARDS PROGRAMME CODEX COMMITTEE ON FOOD IMPORT AND EXPORT INSPECTION AND CERTIFICATION SYSTEMS Twenty-second Session Melbourne, Australia,

More information

Selection and use of ISO 9000

Selection and use of ISO 9000 Selection and use of ISO 9000 ISO in brief ISO is the International Organization for Standardization. It is made up of national standards institutes from countries large and small, industrialized and developing,

More information

RISK MANAGEMENT & ISO 9001:2015. Greg Hutchins PE CERM Quality + Engineering CERM Academy GregH@CERMAcademy.com 800.COMPETE or 503.233.

RISK MANAGEMENT & ISO 9001:2015. Greg Hutchins PE CERM Quality + Engineering CERM Academy GregH@CERMAcademy.com 800.COMPETE or 503.233. RISK MANAGEMENT & ISO 9001:2015 Greg Hutchins PE CERM Quality + Engineering CERM Academy GregH@CERMAcademy.com 800.COMPETE or 503.233.1012 2 Who is Quality + Engineering? Background: Portland Oregon based

More information

Global Food Safety Initiative. Food Safety Auditor Competencies

Global Food Safety Initiative. Food Safety Auditor Competencies Global Food Safety Initiative Food Safety Auditor Competencies Edition 1 November 2013 Contents Introduction... 3 The GFSI Competence Model... 4 GFSI Food Safety Auditor Competencies in Detail... 5 1.

More information

BRC Food Safety Management System Implementation Workbook

BRC Food Safety Management System Implementation Workbook We have written this workbook to assist in the implementation of your BRC food safety management system. The workbook is divided into 8 steps that are designed to assist you in implementing your food safety

More information

COSO Internal Control Integrated Framework (2013)

COSO Internal Control Integrated Framework (2013) COSO Internal Control Integrated Framework (2013) The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released its updated Internal Control Integrated Framework (2013 Framework)

More information

An Introduction to ISO 22000: Food Safety Management Systems

An Introduction to ISO 22000: Food Safety Management Systems : Food Safety Management Systems Stefan Nygren What is ISO 22000? ISO 22000, Food safety management systems - Requirements for any organization in the food chain, was first published in 2005. The standard

More information

Example of a food company quality

Example of a food company quality Appendix A manual Example of a food company quality Contents Date: 13/03/95 RME-QLMN-OO Page 1 of 3 Section Title ISO 9001 reference 01 In trod uction 02 Purpose 03 Scope 04 Definitions 05 Management responsibility

More information

HACCP: Hazard Analysis Critical Control Points. Dr. Angela Shaw Department of Food Science and Human Nutrition Extension and Outreach

HACCP: Hazard Analysis Critical Control Points. Dr. Angela Shaw Department of Food Science and Human Nutrition Extension and Outreach HACCP: Hazard Analysis Critical Control Points Dr. Angela Shaw Department of Food Science and Human Nutrition Extension and Outreach Information Adapted from: Hazard Analysis and Critical Control Point

More information

CHAPTER 7 PLANNING THE AUDIT: IDENTIFYING AND RESPONDING TO THE RISKS OF MATERIAL MISSTATEMENT

CHAPTER 7 PLANNING THE AUDIT: IDENTIFYING AND RESPONDING TO THE RISKS OF MATERIAL MISSTATEMENT A U D I T I N G A RISK-BASED APPROACH TO CONDUCTING A QUALITY AUDIT 9 th Edition Karla M. Johnstone Audrey A. Gramling Larry E. Rittenberg CHAPTER 7 PLANNING THE AUDIT: IDENTIFYING AND RESPONDING TO THE

More information

3 August 2012 Policy updated to reflect name changes and alignment with current Aurora Energy Group Policy standards.

3 August 2012 Policy updated to reflect name changes and alignment with current Aurora Energy Group Policy standards. Aurora Energy Risk Management Policy Version History REV NO. DATE REVISION DESCRIPTION APPROVAL 0 19/11/98 Risk Management Policy Prepared by: Manager Internal Audit 1 March 2007 Risk Management Policy

More information

PMI Risk Management Professional (PMI-RMP) Exam Content Outline

PMI Risk Management Professional (PMI-RMP) Exam Content Outline PMI Risk Management Professional (PMI-RMP) Exam Content Outline Project Management Institute PMI Risk Management Professional (PMI-RMP) Exam Content Outline Published by: Project Management Institute,

More information

A blueprint for an Enterprise Information Security Assurance System. Acuity Risk Management LLP

A blueprint for an Enterprise Information Security Assurance System. Acuity Risk Management LLP A blueprint for an Enterprise Information Security Assurance System Acuity Risk Management LLP Introduction The value of information as a business asset continues to grow and with it the need for effective

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

A Risk Management Standard

A Risk Management Standard A Risk Management Standard Introduction This Risk Management Standard is the result of work by a team drawn from the major risk management organisations in the UK, including the Institute of Risk management

More information

Developing an Effective Enterprise Risk Management Program

Developing an Effective Enterprise Risk Management Program Developing an Effective Enterprise Risk Management Program Jay Brietz, CPA and CIA Senior Manager This material was used by Elliott Davis Decosimo during an oral presentation; it is not a complete record

More information

Risk Management Strategy and Policy. The policy provides the framework for the management and control of risk within the GOC

Risk Management Strategy and Policy. The policy provides the framework for the management and control of risk within the GOC Annex 1 TITLE VERSION Version 2 Risk Management Strategy and Policy SUMMARY The policy provides the framework for the management and control of risk within the GOC DATE CREATED January 2013 REVIEW DATE

More information

Risk Management: Coordinated activities to direct and control an organisation with regard to risk.

Risk Management: Coordinated activities to direct and control an organisation with regard to risk. POLICY CG01 RISK MANAGEMENT Document Control Statement This Policy is maintained by the Governance and Organisational Strategy. Any printed copy may not be up to date and you are advised to check the electronic

More information

A Risk-Based Audit Strategy November 2006 Internal Audit Department

A Risk-Based Audit Strategy November 2006 Internal Audit Department Mental Health Mental Retardation Authority of Harris County ENTERPRISE RISK MANAGEMENT A Framework For Assessing, Evaluating And Measuring Our Agency s Risk A Risk-Based Audit Strategy November 2006 Internal

More information

Risk Management Policy Adopted by:

Risk Management Policy Adopted by: Risk Management Policy Adopted by: Infigen Energy Limited Infigen Energy (Bermuda) Limited Infigen Energy RE Limited in its capacity as Responsible Entity of Infigen Energy Trust Adopted: 17 December 2009

More information

EUROPEAN COMMISSION HEALTH AND CONSUMERS DIRECTORATE-GENERAL

EUROPEAN COMMISSION HEALTH AND CONSUMERS DIRECTORATE-GENERAL EUROPEAN COMMISSION HEALTH AND CONSUMERS DIRECTORATE-GENERAL Directorate F - Food and Veterinary Office Ares(2014)3412772 DG(SANCO) 2014-7149 - MR FINAL FINAL REPORT OF AN AUDIT CARRIED OUT IN ARGENTINA

More information

Title: Rio Tinto management system

Title: Rio Tinto management system Standard Rio Tinto management system December 2014 Group Title: Rio Tinto management system Document No: HSEC-B-01 Standard Function: Health, Safety, Environment and Communities (HSEC) No. of pages: 23

More information

V1.0 - Eurojuris ISO 9001:2008 Certified

V1.0 - Eurojuris ISO 9001:2008 Certified Risk Management Manual V1.0 - Eurojuris ISO 9001:2008 Certified Section Page No 1 An Introduction to Risk Management 1-2 2 The Framework of Risk Management 3-6 3 Identification of Risks 7-8 4 Evaluation

More information

Risk Management Policy

Risk Management Policy Risk Management Policy June 2015 1 2 Contents 1. Policy Objectives and Background... 4 1.1. Policy Background... 4 1.2. Policy Objective... 4 1.3. Policy Sponsor and Maintenance... 4 2. Risk Types and

More information

The website link is http://www.itpfoodsafety.ugent.be/index.asp

The website link is http://www.itpfoodsafety.ugent.be/index.asp ITP food safety a 3 months International Training Program on Food Safety, Quality Assurance and Risk Analysis - Ghent University / August 22 nd to December 2 nd 2011 The Department of Food Safety and Food

More information

UNICEF s Quality Assurance System for Procurement of Micronutrient Powders (MNP)

UNICEF s Quality Assurance System for Procurement of Micronutrient Powders (MNP) UNICEF s Quality Assurance System for Procurement of Micronutrient Powders (MNP) Nutrition Supplier Meeting, June 30, 2015 Dimitris Catsoulacos Quality Assurance Specialist PRESENTATION OVERVIEW Quality

More information

GUIDE TO IMPLEMENTING A REGULATORY FOOD SAFETY AUDITOR SYSTEM

GUIDE TO IMPLEMENTING A REGULATORY FOOD SAFETY AUDITOR SYSTEM GUIDE TO IMPLEMENTING A REGULATORY FOOD SAFETY AUDITOR SYSTEM FEBRUARY 2016 2 Contents Introduction... 4 Scope and objectives... 5 Scope... 5 Objectives... 5 Responsibilities... 5 The role of the licensee

More information

Enterprise Risk Management Framework 2012 2016. Strengthening our commitment to risk management

Enterprise Risk Management Framework 2012 2016. Strengthening our commitment to risk management Enterprise Risk Management Framework 2012 2016 Strengthening our commitment to risk management Contents Director-General s message... 3 Introduction... 4 Purpose... 4 What is risk management?... 4 Benefits

More information

Enterprise-Wide Risk Assessment

Enterprise-Wide Risk Assessment Enterprise-Wide Risk Assessment Agenda 1. Definition of risk. 2. Risk drivers in higher education today. 3. Implementing an enterprise-wide risk management (ERM) program to effectively assess, manage,

More information