An effective system of risk management and internal control?

An effective system of risk management and internal control?

AN EFFECTIVE SYSTEM OF RISK MANAGEMENT AND INTERNAL CONTROL.

The 2020 year-end reporting season was unlike any that have gone before. Uncertainty prevailed as the world changed. Accountants and financial controllers were focussed on the assumptions and judgements that underpinned the numbers in the financial statements, but for auditors and internal assurance providers the focus turned to ensuring that the same focus extended also to the narrative provided.

One, often overlooked, element of that narrative is the statement the directors make on the effectiveness of the system of risk management and internal control. A requirement of the Combined Code through the FRC’s Guidance for Audit Committees, it requires that directors stop and think about whether they really have confidence that risks are appropriate identified, managed, mitigated within their risk appetite, assured and reported. There should be a clear link to other elements of the annual report, in particular information on business objectives and performance, the principal risk disclosures and the assessment of viability. Each of these disclosures is the subject of discussion at present with a greater focus on business resilience and perhaps the best way to signpost that the organisation has an appropriate focus on the future, is through the discussion of the system of risk management and internal control.

Remote working, changes in the corporate strategy, reprioritising investment, reallocating people to meet immediate needs (particularly those who usually work in the second and third line) and new technologies fundamentally shifted the way in which risks manifest and the requirements of sound controls. Directors and management willingly took on greater risk in certain areas, whilst reducing their tolerance to risk in others. The evolving macro-economic environment required reforecasting, often on a rolling and real-time basis.

So how have the systems of risk management and internal control really stood up to these waves of change? As internal auditors and risk managers we should be applying hindsight to create valuable insights for our organisations. As the foundations of the organisation shifted where did we discover strength and where did the gaps soon appear? Where did we discover resources and data that enabled us to get a clear picture and feel confident despite these shifts? What does this tell us about how we can become more efficient, more strategic, more insightful? And where did the gaps appear and simply widen over time such that sticky plasters were necessary, or we continue to feel a sense of unease and the need for further investment?

We must help our organisations evaluate transparently where the strengths and weaknesses are. Without taking and accepting risk organisations do not succeed. As professionals in this field, we must create a narrative that responds to our principal risk assessments with insight. The strength of a robust system of internal control and risk management is its ability to bring to light quickly risks that are falling outside of appetite and controls that are not working as intended. Through an integrated assurance approach, involving both the second line functions and internal audit, emerging weaknesses should become apparent on a timely basis, with pragmatic and proportionate responses identified.

I urge directors and management, as well as risk and assurance professionals, to use the requirement for disclosure as the lever to assess and evaluate the effectiveness of your systems of risk management and internal control at each reporting period, to be authentic and to have the courage to really explore the current environment and the opportunities it creates.

AUTHOR.

CAROLYN CLARKE.

Share on
Related Posts