TABLE OF CONTENTS BACKGROUND AND INTRODUCTION... 5 PURPOSE... 5 SCOPE... 6 RISK ASSESSMENT PROCESS... 6
|
|
|
- Shana Dean
- 9 years ago
- Views:
Transcription
1
2
3
4
5 TABLE OF CONTENTS BACKGROUND AND INTRODUCTION... 5 PURPOSE... 5 SCOPE... 6 RISK ASSESSMENT PROCESS... 6 RISK ASSESSMENT AND EVALUATION METHODOLOGY... 6 RESULTS... 8 RISK ASSESSMENT GAPS... 9 RISK ASSESSMENT EMPLOYEE SURVEY SURVEY BACKGROUND SURVEY RESULTS CONCLUSION EXHIBIT A: CITY OF SARASOTA AUDIT UNIVERSE EXHIBIT B: RISK ASSESSMENT EVALUATION CRITERIA
6 BACKGROUND AND INTRODUCTION Enterprise risk management 1 (ERM) is a process, effected by an entity s commission, management and other personnel engaged in strategy setting across the enterprise, designed to identify potential events that may affect the entity and manage risk to within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives. The Institute of Internal Auditors emphasizes that organizations should fully understand that management remains responsible for risk management. Internal Auditors should provide advice, challenge or support management s decisions on risk, as opposed to making risk management decisions. Risk assessment is based on a set of complementary operational, financial reporting and compliance objectives linked across all levels of the organization. The process is designed to identify and analyze internal and external risks affecting achievement of objectives at both the activity and the entity level. The overall goal of the enterprise risk assessment process is to provide management with the knowledge necessary to effectively manage risk. Annual updates to the risk assessment are necessary to take into account changes in the operating environment, new personnel, new or revised information technology, increases in transaction volumes, new activities, and revised organizational structure. International Standards for the Professional Practice of Internal Auditing (Standards), require Internal Audit to develop a risk-based audit schedule which is updated annually. In 2008, Internal Audit assisted management by facilitating the City s first enterprise risk assessment. As departments have exhibited a higher level of understanding of internal controls, the process has evolved slightly. In 2009, the process was enhanced to review risks and controls on a more thorough functional/ business process level. In 2010, the process of updating risk matrices by key business process was left largely up to the departments, with some facilitation assistance by Internal Audit; new modifications introduced in 2010 included: Facilitation sessions hosted by Internal Audit were encouraged, but not required for risk/ controls identification; Departments were offered the opportunity, but were not required, to self-assess themselves on a number of risk evaluation criteria; and A Risk Assessment Employee Survey was developed and distributed to all City employees for feedback. PURPOSE The goal of Risk Assessment is to identify and prioritize areas of risk which pose a threat to the City s operations and achievement of objectives. As Internal Audit employs a risk-based approach to auditing, the auditor utilized the results of the Risk Assessment to prepare and modify the three-year Audit Schedule based on the determined areas of highest risk. 1 Enterprise risk management should not be confused with the City department called Risk Management. 5
7 SCOPE Internal Audit s review assessed risk exposure for all department-identified key business processes/ divisions in the City of Sarasota documented as of October A total of 79 business processes were examined, evaluated, and prioritized by risk level as part of the 2010 Risk Assessment (see EXHIBIT A for a full list). To the extent possible, risk was assessed at the business process level. Some departments found it easier to evaluate risks and controls on a functional basis as that is how they are structured. A business process or business method is defined as a collection of related, structured activities or tasks that produce a specific service or product (serve a particular goal) for a particular customer or customers. A business process begins with a customer s need and ends with a customer s need fulfillment. In addition, the scope of the Risk Assessment process was expanded to include an employee survey (conducted October 1, October 22, 2010) which was distributed to all City of Sarasota employees. The results of the survey allowed Internal Audit to gain a better understanding of areas where there are perceived organizational strengths and weaknesses. RISK ASSESSMENT PROCESS RISK ASSESSMENT AND EVALUATION METHODOLOGY As previously stated, the goal of risk assessment is to determine areas in the City which are exposed to the highest levels of risk and to include those areas in the Audit Schedule. The approach utilized in the Risk Assessment enables Internal Audit to review all potential audit areas, the audit universe, and rank each of the potential areas in priority order. As organizational needs and goals change, so do the areas of highest risk. To prioritize potential audit areas, Internal Audit implemented the following steps: 1) Identify Department Activities. Departments were provided risk matrix worksheets and instructions (see an example worksheet below) to assist them in recording key risks, controls, and risk probability and severity levels within each of their critical business processes. Department Directors were asked to attest that all key risks/ controls had been documented. Internal Audit assisted some departments in identifying these areas through a facilitation session with employees, managers, and department directors. 6
8 2) Select Criteria and Develop Definitions for Use in Scoring Department Risk. Internal Audit selected criteria for use in evaluating and ranking business processes on a consistent basis. Seven main Risk Categories comprised of 29 total Risk Factors were selected from over hundreds of evaluation criteria suggested by auditing best practices, professional literature, and other audit divisions/ departments reviewed. For each of the 29 Risk Factors, audit staff evaluated the 79 business processes and assigned one of five possible numerical scores which ranged from a low-risk score to a high-risk score. Please refer to EXHIBIT B for a full list of Risk Categories and Risk Factors used in the evaluation process. 3) Evaluate Activities and Apply Scoring based on Department Risk. Once the departments submitted all risk matrix worksheets cataloguing each of their key business processes/ functional areas, audit staff evaluated each of the departmental business processes using the scoring definitions for each risk factor. Departments were given the option of evaluating themselves across 12 of the 29 Risk Factors. Department-determined rankings and the rationale for each were discussed with the auditor and utilized in the evaluation process. The option of providing departmental input was extended to all departments for the Risk Factors in yellow text in EXHIBIT B. Internal Audit also applied deductions to risk scores, which served to lower the overall risk score for an area, based on successful prior audits and areas of demonstrated sufficient internal control. 4) Rank the Activities. After all business processes were assigned scores for each of the Risk Factors, audit staff calculated the total combined risk score for all Risk Factors for each business process. The total combined risk scores were sorted in order of highest value. 5) Consider Outside Input. Internal Audit provided management the opportunity to suggest areas for audit or consulting services. Once submitted, Internal Audit reviewed the suggested areas to determine a) whether they were appropriate for an audit, and; b) whether they were areas of significant risk to the organization. If both criteria were met, the areas suggested were included on the Audit Schedule. 6) Apply Adjustments and Re-Rank Activities. Adjustments to total combined risk scores were applied, as necessary, based on outside input and other insight. Total combined risk scores were re-sorted in order of highest total risk score to reflect any adjustments. 7) Update Audit Schedule. Internal Audit reviewed the final rankings of the business processes, considered available audit resources and time, and updated the Audit Schedule. For the updated threeyear Audit Schedule, please see Audit Project #11-00: Audit Schedule. 7
9 RESULTS The scoring system used in the evaluation process allowed the areas of highest risk to materialize, while also revealing those areas where risk appears to be lowest (see tables below). Of the 79 business processes/ areas reviewed during the Risk Assessment, the highest-rated risk areas were those most likely to be selected for inclusion in the Audit Schedule. Inclusion in the Audit Schedule does not necessarily mean that there is a current or specific concern associated with an area, but rather that the area may have a higher vulnerability to risk exposure at this time. Lowest-rated Risk Areas Department Business Process/ Functional Area Public Works City Auditor and Clerk Human Resources City Attorney Neighborhood and Development Services Skate Park Web Services Data Administration and Staffing Outside Counsel Public Art Highest-rated Risk Areas Department Business Process/ Functional Area All- Citywide Neighborhood and Development Services Neighborhood and Development Services All- Citywide Sarasota Police Department Financial Administration Financial Administration Sarasota Police Department Financial Administration All- Citywide Continuity of Operations Plan (COOP) Housing Grant Management Building Permits Citywide Contract Management Uniform Services Division Accounts Payable Procurement Parking Payroll Capital Improvements Program (CIP) 8
10 RISK ASSESSMENT GAPS To ensure that risk/controls were catalogued and considered for all key business processes and areas in the City, Internal Audit reviewed departmental risk matrices for completeness. Internal Audit noted that the areas outlined below were overlooked or may not have been sufficiently reviewed as part of the 2010 Risk Assessment. Areas noted below were also identified in the 2009 Risk Assessment as being overlooked by management at that time as well. For these areas, management is encouraged to review and document key risks and controls. Geographic Information System (GIS) Van Wezel Performing Arts Hall- programming, performances, contract oversight 9
11 RISK ASSESSMENT EMPLOYEE SURVEY A new component, a Risk Assessment Employee Survey, was introduced into the 2010 Risk Assessment process and was specifically designed to capture the opinions of all employees in identifying perceived areas of strength and weakness throughout the City organization. While the results of the survey were not used in the risk evaluation and prioritization process, management is encouraged to consider the outcomes and utilize them in a manner that will affect positive change. SURVEY BACKGROUND The survey was distributed to all employees (accompanied the October 1, 2010 payroll stub) to obtain information relating to the organization s control environment, risk identification processes, informational flows, monitoring, and potential for fraud/ theft. The purpose of the survey was to identify, based on responses received, where the organization s strengths and weaknesses exist according to the City s employee base. An extended series of statements were made which asked respondents to rate the extent to which they agreed with each statement (strongly agree, agree, don t know, disagree, strongly disagree). The survey also included one open-ended question. Three different versions of the survey were distributed and, while some survey statements were similar across all versions, others varied according to type of employee: 1) General Employees 2) Supervisors/ Managers 2 3) Department Directors, Charter Officials, City Commissioners The survey was conducted October 1 st through October 22 nd. Survey response rates are noted in the following table. Percentage Rate of Return General Employees 29.2% Supervisors, Managers 40.7% Department Directors, Charter Officials, City Commissioners 52.9% Overall Rate of Response: 30.7% 2 The supervisor/ manager survey version was only distributed to individuals who actually supervise employees. There are several individuals with the word supervisor or manager in their job titles who do not manage other employees. 10
12 SURVEY RESULTS Based on survey responses, Internal Audit made four key observations: 1- City employees know what actions to take to report wrongdoing, but are less confident as to whether they would be protected from retaliation or whether anything would be done to stop the wrongdoing. 11
13 2- Employees top reason for not reporting a suspected wrongdoing is the expectation that nothing will be done to the suspected individual. 3- Where similar questions were posed, responses of general employees tended to reflect different perceptions than those of supervisors. 4- Employees indicated that the City of Sarasota s biggest issues are budget/ economy/ money management and low employee morale. For further information on detailed survey results, please refer to Audit Project #11-02B: 2010 Risk Assessment Employee Survey Results. 12
14 CONCLUSION The annual Citywide Risk Assessment helps to ensure that audit staff focuses attention and resources on the highest priority areas by applying the systematic approach outlined in this report. All areas of the City were evaluated against the same criteria and ranked to determine which audits would be performed during the year; management and other input was also taken into consideration during this process. Overall, departments adapted well to the changes associated with this year s process. Of note are the following: Internal Audit was pleased to have three departments continue to request facilitation sessions to aid in identifying risks/controls: Sarasota Police Department, Public Works, and Public Utilities. Although these sessions were not required, discussion from the sessions proved to be useful in the auditor s evaluation of all departments. Several departments chose to participate in the optional self-assessment process where they evaluated themselves against a series of criteria and discussed those evaluations with the auditor. Departments included: Information Technology, Human Resources, Public Works, Public Utilities, Van Wezel Performing Arts Hall, and the City Auditor and Clerk. Internal Audit received numerous comments on the value of these sessions as departments identified current assessment levels versus levels they hope to achieve in the near future. Employee responses to the Risk Assessment Employee Survey were insightful. Varying responses by different employee groups to similar questions demonstrated opportunities for management to better align perceptions through employee education and consistency of actions by supervisors. Responses to the open-ended question provided many suggestions for change and areas for management to focus on to assist in elevating employee morale levels. Based on the results of the 2010 Risk Assessment, the Audit Schedule has been updated to reflect areas of high risk. The Audit Schedule also provides for unallocated time during which unexpected audits, consulting requests (non-audit services), investigations, or other work may be performed. It should be noted that factors including staff workload, unexpected special projects, and other unforeseen circumstances may affect the achievement of projects on the Audit Schedule where some projects may be deferred to future years and others may be added that were not originally planned. 13
15 EXHIBIT A: CITY OF SARASOTA AUDIT UNIVERSE 14
16 All Business Processes/ Functional Activities Reviewed During 2010 Risk Assessment City of Sarasota Audit Universe City Attorney Contracted Legal Services Outside Counsel City Auditor and Clerk Central Records Clerk Functions Development Review and Real Property Internal Audit Pension Plans Public Information Web Services City Manager Weekly Commission Report Top 10 Monthly Report COOP Plan (Citywide) Overall City Administration Financial Administration Accounts Payable Budget Preparation City Property Leasing General Ledger Update FMS Administration Investments Payroll Procurement Grant Management (Citywide) Human Resources Annual Benefits Enrollment Data Administration and Staffing Personnel Records Management Risk Management Information Technology Application Support Data Integrity Governance Hardware Support Infrastructure Project Management Security Server Telecommunications Contract Oversight/ Management Legal/ Regulatory Compliance Neighborhood Development Services Building Inspections Building Permits Capital Improvements Program (Citywide) Cash Handling Code Compliance Contract Management (Citywide) Department Payments Housing Grant Management Local Business Tax Receipts Neighborhood Grants Public Art Zoning Reviews Public Works Auditoriums Equipment Maintenance Solid Waste Collections Bobby Jones Golf Club Maintenance Bobby Jones Golf Club Outside Operations Bobby Jones Golf Club Pro Shop Children's Fountain Skate Park Fuel Station/ Environmental Risks Landscape Maintenance Infrastructure Maintenance Streets and Sidewalks Special Events Public Utilities Call Center Permitting for Public Works/ Utilities Facilities Water Distribution Emergency Management Cash Handling Sarasota Police Department Chief of Police Criminal Investigations Division Management Information Systems Division Uniform Services Division Support Services Division Fiscal Unit Support Services Division Training Unit Support Services Division Parking Management Sarasota Police Department COOP Van Wezel Performing Arts Hall General Administration Marketing Revenue Activities/ Financial Administration Sponsorship Negotiation Union Negotiation/ Administration 15
17 EXHIBIT B: RISK ASSESSMENT EVALUATION CRITERIA 16
18 17
Or download and view an electronic copy by visiting: www.sarasotagov.com
You can obtain copies of this report by contacting us at: Office of the City Auditor and Clerk 1565 1 st Street Sarasota, FL 34236 (941) 954-4135 Or download and view an electronic copy by visiting: www.sarasotagov.com
Annual Risk Assessment and Audit Plan Fiscal Year 2015/2016
Annual Risk Assessment and Audit Plan Fiscal Year 2015/2016 Office of the Internal Auditor May 2015 Table of Contents Introduction... 3 Risk Assessment Process... 3 Interpreting Risk Assessment Results...
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
Comprehensive Risk Assessment and Developing the Audit Plan
Comprehensive Risk Assessment and Developing the Audit Plan Laure Boyd, CIA, CGAP Internal Audit Manager Leon County Clerk of the Circuit Court and Comptroller Our Time Today Background Risk Assessment
TECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER
Page 1 of 7 A. GENERAL 1. PURPOSE The purpose of the Audit Committee (the Committee ) of the Board of Directors (the Board ) of Teck Resources Limited ( the Corporation ) is to provide an open avenue of
Internal Audit Practice Guide
Internal Audit Practice Guide Continuous Auditing Office of the Comptroller General, Internal Audit Sector May 2010 Table of Contents Purpose...1 Background...1 Definitions...2 Continuous Auditing Professional
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012. Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund
FINDING THE RISK IN RISK ASSESSMENTS NYSICA JULY 26, 2012 Presented by: Ken Shulman Internal Audit Director, New York State Insurance Fund There are different risk assessments prepared: Annual risk assessment
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE
Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE March 2012 Table of Contents Executive Summary... 1 Introduction... 1 Risk Management and Assurance (Assurance Services)... 1 Assurance Framework...
MARLIN MIDSTREAM GP, LLC AUDIT COMMITTEE CHARTER
MARLIN MIDSTREAM GP, LLC AUDIT COMMITTEE CHARTER Purpose The Audit Committee (the Committee ) is appointed by the Board of Directors ( Board ) of Marlin Midstream GP, LLC (the Company ), which is the general
IFAD Policy on Enterprise Risk Management
Document: EB 2008/94/R.4 Agenda: 5 Date: 6 August 2008 Distribution: Public Original: English E IFAD Policy on Enterprise Risk Management Executive Board Ninety-fourth Session Rome, 10-11 September 2008
RISK ASSESSMENT REPORT Internal Audit Department
RISK ASSESSMENT REPORT Internal Audit Department June 2013 Internal Audit Department Analyzes Risk and Prioritizes Audit Work About This Report Professional auditing standards require the County Auditor
Internal Auditing Guidelines
Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may
October 20, 2015. Sincerely. Anthony Chavez, CIA, CGAP, CRMA Director, Internal Audit Division
Internal Audit Annual Report Fiscal Year 2015 October 20, 2015 Honorable Greg Abbott, Governor Members of the Legislative Budget Board Members of the Sunset Advisory Commission Mr. John Keel, CPA, State
CLERK & COMPTROLLER, PALM BEACH COUNTY CLASS DESCRIPTION CLASSIFICATION TITLE: MANAGER FINANCE SERVICES GENERAL DESCRIPTION OF DUTIES
CLERK & COMPTROLLER, PALM BEACH COUNTY CLASS DESCRIPTION CLASSIFICATION TITLE: MANAGER FINANCE SERVICES GENERAL DESCRIPTION OF DUTIES Under general direction, the purpose of the position is to manage the
High Value Audits: An Update on Information Technology Auditing. Robert B. Hirth Jr., Managing Director
High Value Audits: An Update on Information Technology Auditing Robert B. Hirth Jr., Managing Director The technology landscape and its impact on internal audit Technology is playing an ever-growing role
Table of Contents: Chapter 2 Internal Control
Table of Contents: Chapter 2 Chapter 2... 2 2.1 Establishing an Effective System... 2 2.1.1 Sample Plan Elements... 5 2.1.2 Limitations of... 7 2.2 Approvals... 7 2.3 PCard... 7 2.4 Payroll... 7 2.5 Reconciliation
Executive - Salary Guide
Salary Guide Executive - Salary Guide Chief Financial Officer $138,000 to $250,000+ Highest ranking financially-oriented position within a company. Responsibilities include overall financial control and
The ADT Corporation. Audit Committee Charter. December 2014
The ADT Corporation Audit Committee Charter December 2014 1 TABLE OF CONTENTS Purpose... 3 Authority... 3 Composition... 3 Meetings... 3 Responsibilities... 4 Financial Statements... 4 External Audit...
Audit Committee Charter
Audit Committee Charter PURPOSE The Audit Committee (the Committee ) is a committee appointed by the Board of Directors (the Board ) of Tahoe Resources Inc. ( Tahoe ). The Committee is established to fulfill
FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors
Overview for Chief Executive Officers and Boards of Directors In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed
GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS
SUPERVISORY AND REGULATORY GUIDELINES Guidelines Issued: 22 December 2015 GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS 1. INTRODUCTION 1.1 The Central Bank of The Bahamas ( the Central
A Risk-Based Audit Strategy November 2006 Internal Audit Department
Mental Health Mental Retardation Authority of Harris County ENTERPRISE RISK MANAGEMENT A Framework For Assessing, Evaluating And Measuring Our Agency s Risk A Risk-Based Audit Strategy November 2006 Internal
Innovation and Technology Department
PERFORMANCE AUDIT Innovation and Technology Department IT Inventory Asset Management January 11, 2016 Office of the City Manager Internal Audit Division Cheryl Johannes, Internal Audit Manager PERFORMANCE
HEWLETT-PACKARD COMPANY BOARD OF DIRECTORS AUDIT COMMITTEE CHARTER
HEWLETT-PACKARD COMPANY BOARD OF DIRECTORS AUDIT COMMITTEE CHARTER I. Purpose and Authority The purpose of the Audit Committee (the Committee ) of the Board of Directors (the Board ) of Hewlett-Packard
The Role of Internal Audit in Risk Governance
The Role of Internal Audit in Risk Governance How Organizations Are Positioning the Internal Audit Function to Support Their Approach to Risk Management Executive summary Risk is inherent in running any
LGMA Qld Governance and Corporate Planning Village Forum
www.pwc.com.au Fraud Risk Management Fraud Risk Assessments LGMA Qld Governance and Corporate Planning Village Forum March 2015 Agenda Introductions Fraud Risk Management Fraud Statistics s Global Economic
Board of Directors and Senior Management 2. Audit Management 4. Internal IT Audit Staff 5. Operating Management 5. External Auditors 5.
Table of Contents Introduction 1 IT Audit Roles and Responsibilities 2 Board of Directors and Senior Management 2 Audit Management 4 Internal IT Audit Staff 5 Operating Management 5 External Auditors 5
NRP Training Series 2001 Financial Record Keeping
NRP Training Series 2001 Financial Record Keeping Copyright 2001 Minneapolis NRP - All Rights Reserved What is the role of the Treasurer? Generally, the treasurer is responsible for compiling and keeping
Sample Financial institution Risk Management Policy 2011
Sample Financial institution Risk Management Policy 2011 1 Contents Risk Management Program...2 Internal Control and Risk Management Diagram... 2 General Control Environment... 2 Specific Internal Control
Charter of the Audit Committee of the Board of Directors of Woodward, Inc.
AUDIT COMMITTEE CHARTER Charter of the Audit Committee of the Board of Directors of Woodward, Inc. Purpose The Audit Committee (the Committee ) is appointed by the Board of Directors to oversee the accounting
IFMIS as a driver of change. Gert van der Linde AFTFM
IFMIS as a driver of change Gert van der Linde AFTFM IFMIS as a driver of change Agenda Driver of what change? Financial Management Performance Linking Financial Management with Program Delivery Key Financial
Chapter 5. Planning the Audit Engagement
Chapter 5 Planning the Audit Engagement A. Purpose for Planning the Engagement Engagement planning is performed to provide a means for developing an understanding of the business objectives of the auditee,
CHECKLIST OF COMPLIANCE WITH THE CIPFA CODE OF PRACTICE FOR INTERNAL AUDIT
CHECKLIST OF COMPLIANCE WITH THE CIPFA CODE OF PRACTICE FOR INTERNAL AUDIT 1 Scope of Internal Audit 1.1 Terms of Reference 1.1.1 Do terms of reference: (a) establish the responsibilities and objectives
Report to the Audit Committee
Report to the Audit Committee Agenda of: JANUARY 14, 2014 From: Rahoof Wally Oyewole, Departmental Audit Manager ITEM: V SUBJECT: INTERNAL AUDIT WORKPLAN THROUGH FISCAL YEAR 2014-15 AND POSSIBLE COMMITTEE
MNsure Compliance Program Strategic Plan. December 17, 2014
MNsure Compliance Program Strategic Plan December 17, 2014 Page 2 of 12 TABLE OF CONTENTS Introduction... 3 Compliance Program Mission... 3 Compliance Department Mission... 3 Regulatory Profile... 4 Key
[RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06]
SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting
PROJECT RISK MANAGEMENT
PROJECT RISK MANAGEMENT DEFINITION OF A RISK OR RISK EVENT: A discrete occurrence that may affect the project for good or bad. DEFINITION OF A PROBLEM OR UNCERTAINTY: An uncommon state of nature, characterized
AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS:
1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF VIEWS AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN
B o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing
B o a r d of Governors of the Federal Reserve System Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing January 23, 2013 P U R P O S E This policy statement is being issued
Linking Risk Management to Business Strategy, Processes, Operations and Reporting
Linking Risk Management to Business Strategy, Processes, Operations and Reporting Financial Management Institute of Canada February 17 th, 2010 KPMG LLP Agenda 1. Leading Practice Risk Management Principles
ACCOUNTING AND FINANCIAL REPORTING REGULATION MANUAL
ACCOUNTING AND FINANCIAL REPORTING REGULATION MANUAL STATE BOARD OF ACCOUNTS 302 West Washington Street Room E418 Indianapolis, Indiana 46204-2769 Issued January 2011 Revised April 2012 TABLE OF CONTENTS
Governance Processes and Organizational Structures for Information Management
UNIVERSITY BUSINESS EXECUTIVE ROUNDTABLE Governance Processes and Organizational Structures for Information Management Custom Research Brief Research Associate Lauren Edmonds Research Manager Priya Kumar
CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS OF ARMSTRONG FLOORING, INC. ADOPTED AS OF MARCH 30, 2016
CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS OF ARMSTRONG FLOORING, INC. ADOPTED AS OF MARCH 30, 2016 I. PURPOSE OF THE COMMITTEE The purpose of the Audit Committee (the Committee ) of the
Department of Finance & Management Strategic Plan V.3.3
Department of Finance & Management Strategic Plan V.3.3 Planning Period: 2012 2015 Table of Contents Message from the Commissioner... 3 Department Overview... 4 Department Strategic Planning Process...
Audit, Risk Management and Compliance Committee Charter
Audit, Risk Management and Compliance Committee Charter Woolworths Limited Adopted by the Board on 27 August 2013 page 1 1 Introduction This Charter sets out the responsibilities, structure and composition
NOTICE REQUEST FOR PROPOSALS FOR INTERIM TOWN ACCOUNTANT SERVICES TOWN OF SCITUATE, MA
NOTICE REQUEST FOR PROPOSALS FOR INTERIM TOWN ACCOUNTANT SERVICES TOWN OF SCITUATE, MA The Town of Scituate, acting through its Chief Procurement Officer, seeks sealed proposals from qualified firms or
Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization
Internal Audit Quality Assessment Presented To: World Intellectual Property Organization April 2014 Table of Contents List of Acronyms 3 Page Executive Summary Opinion as to Conformance to the Standards,
CONTINUOUS CONTROLS MONITORING
Clarity. Certainty. Confidence. CONTINUOUS CONTROLS MONITORING Support Regulatory Compliance Improve Cost Management Drive Operational Performance Executives today are more challenged than ever to make
Antifraud program and controls assessment grid*
Advisory Services Antifraud program and * Fraud risks & controls February 2008 *connectedthinking 2008 PricewaterhouseCoopers LLP. All rights reserved. PricewaterhouseCoopers refers to PricewaterhouseCoopers
CHARTER. the performance of the Company s internal audit function and independent auditor; and
DISCOVERY COMMUNICATIONS, INC. AUDIT COMMITTEE OF THE BOARD OF DIRECTORS CHARTER I. Purpose/Overview There will be a committee of the Board of Directors (the Board ) of Discovery Communications, Inc. (the
Utica College. Information Security Plan
Utica College Information Security Plan Author: James Farr (Information Security Officer) Version: 1.0 November 1 2012 Contents Introduction... 3 Scope... 3 Information Security Organization... 4 Roles
S24 - Governance, Risk, and Compliance (GRC) Automation Siamak Razmazma
S24 - Governance, Risk, and Compliance (GRC) Automation Siamak Razmazma Governance, Risk, Compliance (GRC) Automation Siamak Razmazma [email protected] September 2009 Agenda Introduction to
Supporting Effective Compliance Programs
October 2015 Supporting Effective Compliance Programs The Oversight Roles of the Board Audit and Risk Committees in Regulatory Compliance By Paul Osborne, CPA, CAMS, AMLP, and Peggy Sepp, CIA To be effective,
Department of Audit and Compliance. Quality Self-Assessment
Department of Audit and Compliance Quality Self-Assessment November 2014 CONTENTS EXECUTIVE SUMMARY... 2 PURPOSE OF SELF-ASSESSMENT... 4 SELF-ASSESSMENT SCOPE OF WORK... 4 RESULTS OF SELF-ASSESSMENT WORK...
Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014
Official Audit Report Issued March 6, 2015 Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014 State House Room 230 Boston, MA 02133 [email protected] www.mass.gov/auditor
452 S. Saginaw, 2 nd Floor Flint, MI 48502 810.257.3088
452 S. Saginaw, 2 nd Floor Flint, MI 48502 810.257.3088 September 2, 2015 The Genesee County Land Bank is soliciting proposals from qualified firms of Certified Public Accountants to audit its financial
Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.
Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance
ADMINISTRATIVE MANUAL Subject: CORPORATE RESPONSIBILITY 21.49. Directive #: 21.49 Present Date: January 2011
Page: 1 of 18 Directive #: 21.49 Present Date: January 2011 Original Date: September 2004 Review Date: January 2013 Applicable To: SVHC & Affiliated Companies SVMC SCLM SLH FCPC POLICY In furtherance of
Enterprise Risk Management: Taking the First Steps
Enterprise Risk Management: Taking the First Steps TN PRIMA, 2012 DOROTHY GJERDRUM, ARM, CIRM NOVEMBER 15, 2012 Agenda Goal: To understand how to begin to implement a broader approach to risk management
From Information Management to Information Governance: The New Paradigm
From Information Management to Information Governance: The New Paradigm By: Laurie Fischer Overview The explosive growth of information presents management challenges to every organization today. Retaining
Table of Contents The Revenue Division s Cash Controls Report Number 2007-01
i Table of Contents The Revenue Division s Cash Controls Report Number 2007-01 EXECUTIVE SUMMARY iii PRELIMINARY Introduction 1 Objective 1 Audit Scope 1 Citywide Ramification 2 CONCLUSIONS 1. REVENUE
RSA ARCHER OPERATIONAL RISK MANAGEMENT
RSA ARCHER OPERATIONAL RISK MANAGEMENT 87% of organizations surveyed have seen the volume and complexity of risks increase over the past five years. Another 20% of these organizations have seen the volume
INTERNAL AUDITING S ROLE IN SECTIONS 302 AND 404
INTERNAL AUDITING S ROLE IN SECTIONS 302 AND 404 OF THE U.S. SARBANES-OXLEY ACT OF 2002 May 26, 2004 Copyright 2004 by, 247 Maitland Avenue, Altamonte Springs, Florida, 32701-4201, USA Internal Auditing
ERM Program. Enterprise Risk Management Guideline
ERM Program Enterprise Management Guideline Table of Contents PREAMBLE... 2 When should I refer to this Guideline?... 3 Why do we need a Guideline?... 4 How do I use this Guideline?... 4 Who is responsible
Cyber security: Are consumer companies up to the challenge?
Cyber security: Are consumer companies up to the challenge? 1 Cyber security: Are consumer companies up to the challenge? A survey of webcast participants kpmg.com 1 Cyber security: Are consumer companies
DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING. A CaseWare IDEA Research Report
DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING A CaseWare IDEA Research Report CaseWare IDEA Inc. is a privately held software development and marketing company, with offices in Toronto
FY 2015 Annual Audit Report
FY 2015 Annual Audit Report Table of Contents I. Compliance with House Bill 16 (Texas Government Code, Section 2102.015): Posting the Internal Audit Plan, Internal Audit Annual Report, and Other Audit
How To Maintain An Effective System Of Internal Control Over Financial Reporting
Internal control over financial reporting Statement, assessment summary and action plan For the fiscal year ending March 31, 2012 Summary of the assessment of effectiveness of the system of internal control
How quality assurance reviews can strengthen the strategic value of internal auditing*
How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,
FFIEC Cybersecurity Assessment Tool
Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,
Status Report of the Auditor General of Canada to the House of Commons
2011 Status Report of the Auditor General of Canada to the House of Commons Chapter 1 Financial Management and Control and Risk Management Office of the Auditor General of Canada The 2011 Status Report
Office of Inspector General Department of Defense FY 2012 FY 2017 Strategic Plan
Office of Inspector General Department of Defense FY 2012 FY 2017 Strategic Plan May 22, 2015 Revision The Department of Defense Office of Inspector General is an independent agency established by the
V1.0 - Eurojuris ISO 9001:2008 Certified
Risk Management Manual V1.0 - Eurojuris ISO 9001:2008 Certified Section Page No 1 An Introduction to Risk Management 1-2 2 The Framework of Risk Management 3-6 3 Identification of Risks 7-8 4 Evaluation
1.1 Terms of Reference Y P N Comments/Areas for Improvement
1 Scope of Internal Audit 1.1 Terms of Reference Y P N Comments/Areas for Improvement 1.1.1 Do Terms of Reference: a) Establish the responsibilities and objectives of IA? b) Establish the organisational
The Cybersecurity Journey How to Begin an Integrated Cybersecurity Program. Version 1.0 March 2005
The Cybersecurity Journey How to Begin an Integrated Cybersecurity Program March 2005 Legal and Copyright Notice The Chemical Industry Data Exchange (CIDX) is a nonprofit corporation, incorporated in the
Montgomery County, Maryland
Montgomery County, Maryland Montgomery County County-Wide Assessment and Multi-Year Audit Plan for the Executive Branch Departments May 12, 2010 MCIA-10-5 COUNTY-WIDE RISK ASSESSMENT AND MULTI-YEAR AUDIT
Oceaneering International, Inc. Audit Committee Charter
Oceaneering International, Inc. Audit Committee Charter Purpose The Audit Committee of the Board of Directors (the Committee ) is appointed by the Board of Directors (the Board ) to assist the Board in
Model Risk, A company perspective Peter K. Reilly, FSA Valuation Actuary & Head of Actuarial Strategic Initiatives Aetna, Inc
Model Risk, A company perspective Peter K. Reilly, FSA Valuation Actuary & Head of Actuarial Strategic Initiatives Aetna, Inc 1 Agenda Thoughts/Observations on Model Risk Practical Considerations Aetna
The auditors responsibility to consider fraud in an audit of financial statements
The auditors responsibility to consider fraud in an audit of financial statements Audit in a nutshell Reality Picture (= financial statements) Balance sheet Assets Liabilities Equity Process Detection
Fraud Risk Management
Fraud Risk Management Overview Discussion Questions 1) Does your organization follow a specific risk management model? If so, which one? Do you think this model adequately addresses the risks your organization
MASSACHUSETTS GAMING COMMISSION: CHIEF INFORMATION OFFICER JOB DESCRIPTION
MASSACHUSETTS GAMING COMMISSION: CHIEF INFORMATION OFFICER JOB DESCRIPTION The Massachusetts Gaming Commission invites applications for the position of Chief Information Officer. The Commission is a new
