Showing posts with label Controls. Show all posts
Showing posts with label Controls. Show all posts

29 May 2023

The Evidence is the Control

The most comprehensively documented system of internal control does not provide any assurance that the enterprise is effectively, or even adequately, controlled. From a Risk Management perspective, controls are irrelevant; only the evidence of the functioning of the control is the control.

Let's consider the role of Risk Management in providing real assurance, and how to make this real.

I've posted the article on LinkedIn here

And below:

The most comprehensively documented system of internal control does not provide any assurance that the enterprise is effectively, or even adequately, controlled. We are so used to the SOX-generated idea that the system of internal controls needs to be documented, and where there are perceived to be inadequate controls, more controls need to be introduced and documented. This is limited, of course, to “controls over financial reporting”, as required by SArbanes-Oxley (SOX).  

This has resulted in probably hundreds of millions of dollars, probably billions, being spent to document controls over financial reporting, and then Internal Audit (and External Audit) testing of those control. A windfall for the Internal Audit profession and for External Audit firms. After all, well-documented controls, especially when the critical controls are tested, are the backbone of a sound system of internal controls. Or is it? 

We need to move from the paradigm that a documented system of internal controls equates to an effectively controlled entity. Nothing could be further from the truth, and this is why we have both Internal and External Audit. Internal Audit tests the controls, recommends improvements to controls and provides “assurance” to senior management and the board that the controls are functioning. External Audit places limited reliance (anything more and they couldn’t demand the level of fees they do) on the work of Internal Audit and on the controls. 

I’ve missed the “risk” word above. Of course, Internal Audit should determine the controls to test on a risk-assessed basis. Yet too frequently, Internal Audit focuses on the highest-risk areas (that is appropriate) while year after year, the non-high-risk areas effectively get a pass. There simply are not and never will be enough Internal Audit resources to test all areas.  

After all, a fire will destroy the kitchen and house, while the ants will slowly denude the pantry. So we audit the fire alarms, and make sure there is a fire extinguisher (have you checked the date on it recently), but we don’t hunt for ants unless they are right in front of our faces.  

To paraphrase Hemmingway, internal control failures happen slowly, and then all at once.  

So the classic three-year rolling Internal Audit programme never seems to get to the bottom two-thirds of the potential auditable areas. What does this mean? Fundamentally, too much of the entity will never be audited, and there will never the evidence that the controls are or are not functioning.  

And here is our problem. It will be one of those areas, probably not directly related to ‘financial reporting’ that will ‘go bad’, resulting in significant problems and costs. 

The evidence IS the control.  

Who cares if there is a full set of documented controls if operational management knows perfectly well that Internal Audit will never reach two-thirds of the entity? I.E., their function, system, or process? This means more resources that said operational manager could spend on resources, people, supplies, laptops, etc, because they know that the cost of the control can be deferred, because the chances of their every being audited are minimal. 

In some enterprises, the “Second Line” in the form of Risk Management contributes to the identification of appropriate controls, and should be monitoring the control environment. This augments and does not detract from the role of Internal Audit, whose role is to perform detailed reviews of processes, systems, or functions, confirming through testing that the stated controls are functioning.  

So what is the role of Risk Management, as 'second line', in providing assurance over the system of internal controls? Risk Management can provide the framework to ensure that controls are functioning, by providing the repository and process to enforce confirmation of the functioning of controls. So what can Risk Management do?

  1. Risk Management assists management in the identification, description (including quantification) of risks, and 
  2. Assists management in determining and quantifying the level of risk that is acceptable, and in gaining senior management and board endorsement of the level of acceptable risk (the Risk Appetite applicable to the risk), and 
  3. Works with management to identify what ‘controls’ would provide confidence that the risk is being mitigated or otherwise managed within appetite, and 
  4. Provides a framework for the regular assessment and reporting on the functioning of the identified controls, and 
  5. Provides an independent repository for the collection and retention of the evidence that each control is functioning, and finally 
  6. Reporting to senior management and the board on management’s reported assessment of the effectiveness of controls, to confirm that the entity is functioning within Risk Appetite, or 
  7. Provide reporting and recommendations to senior management and the board on additional steps that may be required to bring the entity into appetite (which may include the explicit modification, ‘upward’ or ‘downward’ of the actual Risk Appetite. 

In this way, it is not the fact of the existence of a documented control that matters, it is the provision of evidence by management that the control is functioning This evidence is the control. Without the evidence, it must be assumed that the control may not be functioning, and, therefore must be tested by Internal Audit, something that probably will never happen for the vast majority of non-high-risk areas. 

Quite some time ago, you probably started saying, “But this isn’t the job of Risk Management”, and in a purist sense, I agree. But I also know that someone needs to do this, and that someone needs to have access to the board and to management. Relationship management across the first line is critical, as is the ability to synthesise the information provided in the evidence of functioning controls.  

Most importantly, there cannot be an adversarial relationship such as too often exists between Internal Audit and the business, and between External Audit and everyone. Note I’m saying ‘too often’, not that this should be the natural state of things. 

Risk Management has many responsibilities, and this one fits nicely. 

Where there is an ongoing demonstration of performance of the system of internal control, identification of new or evolving risks, and a risk appetite that is both detailed and macro, Risk Management should be there. As risk specialists (both ‘downside’ and ‘upside/opportunity’) with the ability to communicate potential impacts as well as provide  

So consider a framework that includes a quarterly provision of the evidence of each control, coupled with management’s assessment of the effectiveness of that control. Consider also a regular relationship meeting between Risk Management and operational managers to confirm that the range of risks is current, the rating of the risks continues to be in line with management’s understanding of the risk, and the mitigation in place, as evidenced by the provided evidence of the functioning on the controls, ensures that the entity, or at least this risk, continues to be managed within appetite.  

Finally, the evidence provided by management and monitored by Risk Management also enables Risk Management to provide greater confidence in their reporting of the current risk status of the entity, improving the quality of assurance provided.

After all, documented controls by themselves are worthless. The Evidence of the functioning of the control is the Control. 

#Risk #InternalAudit #SOX


10 April 2015

Lets talk Risk Registers - dead boring?

There seem to be two trains of thought on Risk Registers; they are terrible and should be banned, or they are a critical part of a risk management programme and environment. I can see both perspectives, though I come down on the side favorable to Risk Registers. I also have some sympathy for those that say "Risk Registers are dead boring".

A good friend is very happy to tell me that Risk Registers are the bane of the risk management profession, and that they do significantly more damage than any benefit the provide. Risk Registers, with their attempt (or not) to create a defined universe of risks only serve to distract management and the Board from the wider range of risks, and thus provide a completely false sense of security. Use a Risk Register, he says, and you will absolutely be blind-sided by the actualisation of a risk that will kill the business.

Risk Registers also do not facilitate the quantification of all risks, or even necessarily the quantification of the value at risk for any particular risk. And without a quantification of the risk, it is impossible to have confidence in the application of resources to manage the risk.

He is right, of course, while also being completely wrong.

Any methodology or framework applied without adequate thought will court disaster. Anyone who actually thinks that their Risk Register actually contains either all the risks, or even all the important risks, is deluding themselves. Equally, anyone who thinks that they can quantify all risks either has a bloated risk function, is a major engineering conglomerate, or is delusional. Quantification can only go so far, and over-reliance on models can be just as dangerous as no assessment of potential consequences.

However, Risk Registers are an important part of risk management's ongoing processes of assisting management in the identification and management of risk. Note "a part of" and "assisting". These are critical. A Risk Register is so much more than simply an enumeration of risks, even if each has an associated description and a likelihood / impact scoring.

But a Risk Register can contain and drive so much more.

So what then is the purpose of a Risk Register. I would suggest Risk Registers can provide the following:

1. A common framework for the understanding of risk and the language for describing and managing risk within the organisation.

2. An agreed view of risks (but not all risks, as this simply is impossible, and counterproductive to attempt).
3. A linkage between organisational objectives and the risks to achievement of those objectives (as per COSO '92).
4. A central repository of the key controls associated with the risks, at a high level. In this way a control could be considered the inverse representation of a risk, or a subset of category of a risk.
5. The ability to identify control gaps, and to identify controls that need to be put in place.
6. A single source for reporting to determine the current, past and future level of risk (subjective) against the organisation's Risk Appetite.

A Risk Register does not prove that risks are being managed, nor does it record all risks. It also does not, by itself, ensure that control are effective.

Finally, reiterating the "does not record all risks"  point - there are risks that should not be put on a Risk Register. I have this discussion frequently, sometimes with a look of incredulity and a statement that "of course all risks should be on the register". There are some risks that do not belong on the register. These range from exit strategy risk to some specific regulatory risk to name two types. We can have a discussion about other risks, and I'd be happy to hear views on what risks belong on, and which should not be on the risk register.

Why should some risks not be recorded? Ah, that is NOT what I am saying. I am saying that some risks should not be on the Risk Register. These risks should of course be recorded and considered, but a Risk Register frequently is a document, system, spreadsheet, SharePoint directory(ies) or other repository of risks that will be visible by a number of individuals in the business. The Risk Register is also a living entity, with risks changing, being added, upgraded and downgraded.

I think the best summary comes from another friend, who said after attempting to build his Risk Register, "This is dead boring, but the process has actually made me think about the risks in my business, and is showing me that we have a lot more to do before I'll be comfortable that we are managing our risks".