Risk structures, policies, and procedures Flashcards
The board needs to ensure that the appropriate structures are in place at the proper levels within the organisation to manage risk.
In deciding what these structures should be, what 3 things should boards consider?
- Whether risk and internal controls should be considered by the whole board or be delegated to a committee of the board.
- If delegating to a committee, whether risk and internal controls should fall under one committee, the AC, or into two separate committees, AC for internal controls and the RC (risk committee) for risk.
- The division of responsibility between itself and management for risk management.
Which organisations usually have a separate risk committee and why?
What are 4 benefits of having a separate risk committee?
Banks and other large financial institutions normally have separate risk committees due to the complexity of their risk exposure
- The benefits are:
1. It can focus solely on reviewing the organisation’s risk management
- It can give the board advice on risk appetite, the organisation’s risk tolerance, and strategies to manage risk
- It can provide input into strategy formulation by helping the board to understand the key risks
- The composition of the committee is not restricted by the requirements of UK CG Code
What are 4 risks of setting up a separate risk committee?
- Conflict between the audit and risk committees
- Danger of overlooking some risks = Each committee may think the other is considering a particular risk when in fact neither are
- Message sent to senior management that risk is no longer their responsibility
- Having sufficient directors with the required skills to constitute a separate risk committee
What does the ICSA ‘Terms of reference for a risk committee’ suggest in relation to the composition of a separate risk committee? (3)
- RC should consist of at least 3 members all INEDs
- Members should have appropriate knowledge, skills, and expertise to fully understand risk appetite
- The finance director/CFO and the chief risk officer/CRO should attend committee meetings regularly.
What does the ICSA ‘Terms of reference for a risk committee’ suggest the role of a risk committee may include? (4)
- Providing assurance to the board that processes for risk management are effective
- Considering risk opportunities and making recommendations to the board
- Reviewing and approving statements to be included in the annual report concerning risk management
- Overseeing the CRO’s role and responsibilities
What is internal audit?
= an independent objective assurance and consulting activity designed to add value and improve an organisation’s operations
What are 5 possible roles of the internal audit function?
- Value for Money (VFM) audits = determine if operation/activity is economical, efficient, and effective
- Reviewing compliance with laws or regulations
- Reviewing the internal control system = not the function of internal auditors to manage risks, only to monitor and report them, and to check that risk controls are efficient and cost-effective
- Risk assessment = investigate the adequacy of the mechanisms for identifying, assessing and controlling significant risks to the organisation
- Reports – To Audit Committee/Risk Committee and Board / Special investigations
What are the 4 benefits of an in-house internal audit function?
What is the benefit of a co-sourced or outsourced internal audit function?
- Understands the organisation, its culture, operations and risk profile = should be able to add value to internal control and risk management processes
- can build networks and become integrated into the company’s business = become the ‘eyes and ears’ of the board regarding those activities
- provide assurance to stakeholders on the integrity of internal control and risk management systems
- could be a lower-cost option, depending on the make-up of the team
The organisation can leverage external resources, technology, skills and experience which may not be available to it with an in-house team
Why might the independence and objectivity of internal auditors be compromised?
What does the FRC Guidance on Audit Committees suggest to protect their independence? (2)
How often should the board or AC review the internal audit function?
Independence and objectivity may be compromised because they are also employees within the organisation = if internal auditors report to the CEO, they will be reluctant to criticise the CEO
- FRC Guidance on Audit Committees: to protect the independence of the internal audit function:
1. AC should be responsible for appointment or removal of the head of internal audit
2. AC should have a reporting line which enables it to be independent of the executives
Annually
What does the UK CG Code say on whistleblowing?
- Principle E = the workforce should be able to raise any matters of concern
- Provision 6 = There should be a means for the workforce to raise concerns in confidence and – if they wish – anonymously = a whistleblowing procedure
What should an effective whistleblowing procedure allow an employee to do?
Should allow for an employee to raise concerns about illicit behaviour usually:
1. Fraud
2. serious violations of laws or regulations
3. a miscarriage of justice
4. bribery etc.
5. price-fixing
What areas should a whistleblowing policy cover? (6)
- purpose, scope and coverage
- procedures for reporting a matter
- what happens when communication is received from a whistleblower
- anonymity of the whistleblower
- Communication with the whistleblower
- Protection of the whistleblower
What are the 3 parts of a cyber security policy?
What are the 2 sets of regulations that require disclosure for a breach of cybersecurity?
- Physical security of the technology = explains the importance of keeping the physical asset secure – locking doors, surveillance, alarms etc.
- Personnel management. = explain how to conduct day-to-day activities – password management, the use of memory sticks etc.
- Hardware and software = explains what type of technology and software to use and how networks should be configured to ensure they are secure.
Market Abuse Regulation and General Data Protection Regulations
What are the Network and Information System (NIS) Regulations aimed at?
What are operates of essential services (OES)?
What are relevant digital service providers (RDSP)?
What do NIS regulations require organisations to do?
= aimed at improving the security of network and information systems of operators of essential services (OES) and relevant digital service providers (RDSP).
- OES = entities in the energy, transport, health, drinking water and digital infrastructure sectors
- RDSP = entities who provide their services to entities within the essential services sectors
Organisations required to take appropriate and proportionate measures to manage the risks posed to their NIS and to minimise impact.
What 5 things should an information disclosure policy include?
- Objectives and principles of the disclosure
a. Main objective of disclosure = keep stakeholders informed about the company to enable them to make informed decisions when dealing with the company
b. Principles = accurate, timely, complete, balanced between the positive and the negative etc. - Authorised persons = Usually the CEO, CFO, and cosec will be authorised to make disclosures
- Public information = The policy will usually set out what information about the company is in the public domain
- Confidential information = The policy should also set out what information should be kept confidential e.g. trade secrets
- Insider information = information that would, if disclosed, move the company’s share price = policy should set out how it is to be handled