INTERNAL AUDIT • ENTERPRISE RISK MANAGEMENT & GOVERNANCE The Chartered Accountant • October 2022 • Vol. 71 • pp. 22–25 (Journal pp. 370–373)

Looking at Risk Management in the context of Internal Audit

NK
CA. Nikhil Kenjale
Author is member of the Institute • Reach at: nukenjale@gmail.com & eboard@icai.in

Core Thesis: Managing Volatility in an Era of Disruption

Largely people seek stability, growth and security. Forces beyond their control bring change to their expectations about the future. In common parlance, we call these forces as “Risk”. In pursuit of maximization of wealth, individuals / organizations invest their hard-earned money into the entities. Therefore, those entities assume a larger role in ensuring that the investors get desired return and value over a period.

Risks which are applicable to individuals take a multifold, wider, and deeper form when it comes to dealing with them at an entity level. Therefore, these are to be managed. This is nothing but what we call – Risk Management. It is not at all a new topic for discussion, but it is worth having a fresh look and embedding the risk concepts into an internal audit using modern tools.

1. The Context: Imperfect Sciences & Three Foundational Anchors

Risk Management falls within the ambit of behavioural sciences i.e. imperfect sciences. Hence, unlike perfect science (say concept of gravitational force is universal in terms of its application), risk management applies differently to each organization. Therefore, it is essential to put a context to the discussion. Our context is based on three foundational anchors:

1. Corporate Governance

A mechanism that directs and controls the entities. A Committee on Corporate Governance emphasized on enhancement of shareholder’s value keeping in view the interests of other stakeholders.1

2. Ethics and Values

It is nothing but a set of Do’s and Don’ts adopted by an entity considering applicable rules and regulations. E.g. an engineering product manufacturing company decides not to participate in tendering process floated by an entity which belongs to a country with the very high level of corruption. So, it is essentially making a choice considering established principles and regulations.

Entities assign a particular value to particular objectives – say undertaking research in medicine that can change your DNA. They feel that it will give them a competitive advantage. Accordingly, they set objectives and try to achieve those. Whether changing DNA is ethical or not could be a point of discussion. But for that entity undertaking that research is valuable. (There are multiple theories around ethics like “Axiology” which deals with what elements can contribute to the intrinsic value of state of affairs).

3. Definition of Internal Audit

As per Framework Governing Internal Audits, Internal Audit is defined as follows: “Internal audit provides independent assurance on the effectiveness of internal controls and risk management processes to enhance governance and achieve organisational objectives.” It helps an organization to accomplish its objectives by bringing a systematic, disciplined approach to evaluating and improving the effectiveness of risk management, control and governance processes.

Summary Principle: So, when we think about “Risk” with respect to any entity, at minimum, we need to consider how Corporate Governance, Ethics and Internal Audit function are positioned and how they are practiced.

2. Risk Management: Evolution, Scoping & Governance Boundaries

Before we jump to the management level it is important to spend some time in comprehending what is risk? Essential problem is, it means different areas, severity, and significance for every individual. Somebody may be easily jumping from a high cliff into the waters and another one may choose to keep himself always away from waters. That means everybody’s definition of risk is different. Therefore, our discussion is focused on how entities deal with risks and not on how individuals perceive and manage risks.

COSO ERM Definition
“Risk is defined by COSO as ‘the possibility that events will occur and affect the achievement of strategy and business objectives.’ Risks considered in this definition include those relating to all business objectives, including compliance.”2
Shift to Conscious Risk Taking

Usually, the term risk has a negative connotation. However, if we see risk management evolution, more emphasis is now being put on the upside of risks, i.e. risk of losing an opportunity. In a way, conscious risk taking is gaining importance in contrast to interpreting Risk Management as almost equal to Risk Avoidance.

So anything that brings volatility to the decided business strategy can be called as a risk event. Do refer to Standard on Internal Audit (SIA) 130 Risk Management for definition of Risk Management.

⚠️ A Word of Caution for Internal Auditors – Boundaries of Ownership

Risk Management is to be owned by the senior management and the Board. Internal Auditors are supposed to be an independent agency in the evaluation and enabling the Risk Management.

For a big, complex entity operating in multiple geographies, it would be ideal to have “Top down” approach to Risk Assessment compared to the “Bottom Up” approach where there is a chance that too many trivial nature risks might get identified.

3. Capturing “Relevant” Risks vs. Common “Cough and Cold” Disruptions

If Risk is “what may go wrong”, then many things may be going wrong in an organization or getting practiced as the way they should be – e.g. employees coming late, one TDS payment being delayed by one day, customer deliverable deadline not met, one provision pertaining to branch office expenses was missed out in quarter 2 and so on. But an entity would be interested in capturing “Relevant” risks and not the ones which can be called as common “cough and cold” type risks.

Conceptual Framework for Financial Reporting under Ind AS
“Relevance – Relevant financial information is capable of making a difference in the decisions made by users. Information may be capable of making a difference in a decision even if some users choose not to take advantage of it or are already aware of it from other sources.”3

It is interesting to note that IFRS/Ind AS Frameworks on financial reporting use word “Relevance” and not “Accuracy”. Relevance is defined to include “nature” and “materiality”.

The relevance can be better understood if the objectives of Risk Management are well understood. Broadly any entity is interested in ensuring:

01 Safeguarding Assets

Preservation and protection of organizational resources and assets from unauthorized use or loss.

02 Reliable Reporting

Integrity, timeliness, and reliability of financial and operational management reporting.

03 Operational Effectiveness

Effectiveness and operational efficiency across core business processes and resources.

04 Statutory & Policy Compliance

Adherence to applicable statutory laws, industry regulations, and internal corporate policies.

Statutory Anchor: These principles/objectives are laid down by the COSO internal control framework and are also embedded in the definition of “internal financial controls” as given in Section 134 of The Companies Act, 2013. So, with these broader objectives, one can reasonably assess the risks which are applicable to an entity.

4. Actual Process of Risk Identification: Entity Level vs. Process Level

The lifespan of entities has drastically come down in the last few years. This contrasts with good old days entities where one could see that they are being in existence for decades. Except the few global giants, companies have seen/experienced transformations through sales, mergers, acquisitions, diversifications and so on. Since continuous disruption is inevitable, context of Risk Management keeps ever changing.

Risk Identification ideally should happen at two levels – Entity and Business Processes:

Dimension Entity Level Risks Process Level Risks
Strategic Nexus Close nexus with overall business strategy, sustainable growth, and long-term going concern viability. Directly tied to the non-achievement of specific operational unit and process objectives.
Scope & Impact Broad, pervasive, and enterprise-wide; affects whether the entity will remain in business or suffer severe impairment. Localized, departmental, and transactional; affects daily workflows, controls, and outputs.
Illustrative Examples Succession planning inadequacy, foreign currency exchange rate fluctuations, cyber-attacks, customer concentration, non-compliance with regulations, employee attrition, litigation risks, pandemic disruptions (COVID-19 in MD&A), inability to innovate. Inappropriate financial reporting, procedural non-compliances, operational delays, scrap/rework, machine breakdowns, deviation from approved purchase policy, delayed expense recording.
Data Gathering & Complexity Requires aggregative data, cross-functional correlation, high-level inferences, exception spotting, and environmental scanning. Relatively easy to identify, see, gather, and analyze directly from source documents (cut-off records, invoices, logs).
Nature of Conclusion Professional Judgment / “View”: Deciding if risk is higher, if fraud risk exists, or if Audit Committee oversight is warranted. More of a seasoned “view” than an absolute certainty. “Black and White” Conclusion: Binary evaluation of whether transaction-level control rules were followed or violated.
Mandatory Professional Standard – ICAI SIA 220
ICAI Standard on Internal Audit (SIA) 220 – Conducting overall internal audit planning: “A risk based planning exercise shall form the basis of the overall internal audit plan. The Internal Auditor shall undertake an independent risk assessment exercise to prioritise and focus the audit work on high-risk areas, with due attention to matters of importance, complexity and sensitivity.”

5. Modern Evolution: The Paradigm Shift to “Fact-Based Risk Assessment”

Risk Management being an evolutionary subject, is witnessing a paradigm shift in terms of scoping, rolling out and monitoring. The earlier approach was more towards seeing risk management as compliance, it was person dependent and handled by very few people in the organization. Now with technology enablement, many aspects can be based on actual data and statistical models. Internal auditors are therefore required to learn how to do risk assessment using various data inputs i.e. facts. A concept which is widely gaining importance is “Fact Based Risk Assessment”.

Case Example Assessing “High Employee Attrition” Risk Through Fact-Based Modeling

Suppose “high employee attrition” is a risk and an internal auditor is assessing the risk as a part of his scope. By traditional means the person will recollect his own understanding of the risk, previous high-level issues reported to the board/audit committee, etc. There are logical steps that are relevant in current times as well. Additional refinement can be achieved by looking at multiple data sets, patterns like:

  • Past 5 years of attrition data: Classified using parameters like employee level wise attrition, root causes/reasons, periods, peer company’s information, and the industry average.
  • Company countermeasures: Specific retention and engagement measures taken by the company and their quantifiable benefits.
  • Bench capacity: Level and competency of people maintained on the bench to absorb sudden turnover.
  • Work culture metrics: Employee morale, exit interview trends, and organizational climate.
  • Salary structures: Market compensation parity, band-wise salary competitiveness, and variable incentives... and so on.

Various tools can be used to analyze, comprehend, correlate, and infer the above data. It is a common experience that data speaks differently than our understanding of the related process or area. Detailed data analysis is possible using simple Excel spreadsheets and it can pinpoint the exact root cause which is causing the change in the risk levels. Once analyzed, data can be effectively presented using dashboarding tools (e.g. PowerBI).

One should finally link the “Relevance” to the identified data inferences: See if the likelihood is really high, underlying account balances are really material, if the market would react negatively to the risk if materialized, and what is the level of attrition envisaged by the business while putting the strategy in place, etc.

Litmus Test for Internal Audit Scoping

Internal auditors should ask a question to themselves: Are all audit scopes supported by the fact-based risk assessment? If the answer is “No” or if there is a struggle to gather the data, then possibly it is time to revisit the audit scope – i.e. whether the audit is required on an annual basis, level of efforts to be put in, etc.

6. A Wise Man’s Job & The Four Elements of Indian Classical Tabla

One needs to keep in mind that doing risk assessment is a wise man’s job. The person doing risk assessment should have knowledge of the entity, human behavior, micro-macro economic factors relevant to the entity. Applying these things to a given risk context requires experience and good level of professional judgment. Philosophers say that complete scepticism is an impossible attitude in life. Therefore, an internal auditor should be reasonably sceptical in doing risk assessment. This is beneficial to the internal auditors as well as the entity which is served by them.

The Classical Analogy: Synthesizing Shastra, Tantra, Vidya, and Kala

A very senior Indian Classical Tabla player has said that while learning anything there are four elements – Shastra (Science which explains “Why?”), Tantra (Technique, i.e. “How?”), Vidya (Syllabus, i.e. “What?”), and Kala (an art element to pull the other three things together in a given context). This profound matrix maps directly onto enterprise risk management:

1. Shastra (Science)
Explains “Why?”

Corporate Governance, Ethics, and the Internal Audit charter telling us why an entity must have Risk Management.

2. Tantra (Technique)
Explains “How?”

Fact-finding data measures, statistical modeling, Excel correlation, and interactive PowerBI dashboard analytics.

3. Vidya (Syllabus)
Explains “What?”

Established global frameworks (COSO), Companies Act 2013 provisions, and Standards on Internal Audit (SIA 130, SIA 220).

4. Kala (The Art)
Harmonizing Synthesis

The art element to pull the other three together in a given corporate context through seasoned professional judgment and skepticism.

Now it is up to the internal auditors as to how they learn the “Art” of Risk Assessment and enhance the value of their internal audits.