Improving Risk Assessments and Audit Operations [Compliance Week]
| Copyright: | (c) 2011 Haymarket Media, Inc. |
| Source: | Proquest LLC |
| Wordcount: | 1194 |
At companies where internal audit and risk processes are maturing, they are now honing their operations to become more efficient and effective.
It all starts with strong, open, trusting relationships that enable internal auditors to act less like cops and more like business advisers,
Barresi said Tiffany's internal audit function spends little time on the internal controls over financial reporting that the Sarbanes-Oxley Act brought to the fore in the 2000s; now the company's focus is on tailoring the internal audit function to address the specific risks of each business unit.
Tiffany has achieved that focus in part by leveraging data analytics, Barresi said. The company uses various IT tools to monitor transactions most suggestive of control issues, he explained; those are monitored on a regular basis to look for signs of trouble. "That has really reduced the amount of time we need to spend doing full-blown store audits," he said. The
Finding the right formula for staffing is also important, Barresi said. The average age of internal auditors entering the profession is falling, which means chief audit executives must retain their best people and give them good training to assure they can meet the demands for a more expert focus on risky issues. Tiffany's internal audit staffhas become "top heavy" in terms of experience and expertise, according to Barresi. "As you move further down that risk pendulum, that level of experience is critical," he said.
At
The company's ERM process already produces regular input from a crossfunctional steering committee, an executive committee, and various subjectmatter experts, who identify risks from every conceivable angle. The risk analysis produced via the ERM process provides an ideal planning platform for internal audit, Brewer said. In addition, the company's loss prevention process reports through Brewer's office, providing more centralization of risk information that's useful to the internal audit function.
Brewer also is pinning some hopes on co-sourcing much of the internal audit function at locations outside
By hiring outside help in those locations, the company can also look for more diverse subject-matter experts at the same time, Brewer said. That adds expertise in niche areas where the company may not have such talent in-house, he said. Although efficiency is one objective in pursuing such an approach, Brewer can't make any big claims about success just yet. "It's too new," he said.
Hansen did, however, caution his fellow compliance officers to be specific about engagements when hiring expertise from outside the company to help with internal audit. "Be careful of consultant-speak," he said. "When I pay the bill, you work for me, and you're going to audit." Companies should beware that they're not being given services they didn't ask for, but they should also seek to learn as much from outside subjectmatter experts as possible during the time they are engaged.
Hansen has another tactic for building efficiency into the internal audit process: He recruits "guest auditors" from throughout the Disney organization to assist with internal audit work, providing some cross-pollination of talent inside the company. "It's good for the guest auditor, it's good for our team, and it's good for the group being audited," Hansen said. The guest auditor assignments tend to be coveted opportunities within Disney, he added.
Risk Assessments
To improve the assessment and monitoring of risk, the
Rather, Klumper said, internal audit's role at GAVI is to challenge management's identification of and management of risks. That includes helping define the risk appetite, which can be a fine line to walk, Klumper said.
Misuse of funds, for example, is an intolerable risk for GAVI, but one that is hard to define. Reducing a risk to zero is unrealistic, Klumper admitted, but putting a percentage figure on some acceptable risk level presents a separate risk of its own. "Any percentage risk of misuse of funds is a dollar figure," he said. Such a figure could be misconstrued as some tolerated level of management mishandling the money, he said.
Timken strives to give employees plenty of training to guard against the most significant risks coming to pass, to keep the key messages fresh and top of mind. The company also produces a risk control summary that succinctly documents the nature of the risk and the actions taken to mitigate it. That's a step the board of directors appreciates, Abraham said.
"We've gotten some positive feedback from the board," she said. "They say it's easy to understand what we're doing. And it's valuable for the business because it provides a clear template to talk to the leadership team about how we're going to prevent risks from materializing."
"We don't penalize the business when we find issues. An audit finding is not a 'gotcha' event. We're trying to find improvements to processes."
-


Hospitals scrambling to buy nursing homes [Indianapolis Business Journal (IN)]
Who’s Coming and Going in Governance [Compliance Week]
Advisor News
- Global economic growth will moderate as the labor force shrinks
- Estate planning during the great wealth transfer
- Main Street families need trusted financial guidance to navigate the new Trump Accounts
- Are the holidays a good time to have a long-term care conversation?
- Gen X unsure whether they can catch up with retirement saving
More Advisor NewsAnnuity News
- Pension buy-in sales up, PRT sales down in mixed Q3, LIMRA reports
- Life insurance and annuities: Reassuring ‘tired’ clients in 2026
- Insurance Compact warns NAIC some annuity designs ‘quite complicated’
- MONTGOMERY COUNTY MAN SENTENCED TO FEDERAL PRISON FOR DEFRAUDING ELDERLY VICTIMS OF HUNDREDS OF THOUSANDS OF DOLLARS
- New York Life continues to close in on Athene; annuity sales up 50%
More Annuity NewsHealth/Employee Benefits News
Life Insurance News
- Legals for December, 12 2025
- AM Best Affirms Credit Ratings of Manulife Financial Corporation and Its Subsidiaries
- AM Best Upgrades Credit Ratings of Starr International Insurance (Thailand) Public Company Limited
- PROMOTING INNOVATION WHILE GUARDING AGAINST FINANCIAL STABILITY RISKS SPEECH BY RANDY KROSZNER
- Life insurance and annuities: Reassuring ‘tired’ clients in 2026
More Life Insurance News