Risk audit is a systematic way of understanding the risks that an organisation faces.
Some organisations employ internal specialists to carry out risk auditing, others utilise external consultants to perform the work.
Risk audit is a systematic way of understanding the risks that an organisation faces.
Unlike financial auditing, risk audit is not a mandatory requirement for all organisations but, in some highly regulated industries, a form of ongoing risk assessment and audit is compulsory in most governance jurisdictions.
Some organisations employ internal specialists to carry out risk auditing, others utilise external consultants to perform the work.
Purpose of risk auditing:
– Risk auditing assists the overall risk monitoring activity (last step in the risk management process) by providing an independent view of risks and controls in an organisation.
– As with any audit situation, a fresh pair of eyes may identify errors or omissions in the original risk monitoring process.
– In many situations, audit work is obligatory (e.g. SOX requirements).
– Following review, internal and external audit can make recommendations to amend the risk management system or controls as necessary.
Process of a risk audit:
The process of internal, and external audit, in monitoring risks will include:
(1) Identifying the risks that exist within an organisation.
(2) Assessing those risks in terms of likelihood of occurrence and impact on the organisation should the risk actually occur.
(3) Reviewing the controls that are in place to prevent and/or detect the risk and assessing if they are appropriate.
(4) Informing the board (or risk management committee where one exists) about risks which are outside acceptable levels or where controls over specific risks are ineffective.
This lesson is waiting for its secure Vimeo video.