News & Blogs

IIA's New ERM Paper: A Critical Look at Internal Audit's Role and the Flaws in Current ERM Frameworks

Global · · riskacademy.blog

This article critically examines the IIA's latest Statement of Position on internal audit's role in Enterprise Risk Management (ERM), arguing that while it addresses independence, it sidesteps fundamental questions about ERM's effectiveness. For internal audit and assurance professionals, this piece highlights the crucial need to scrutinize the underlying methodologies of ERM, rather than merely auditing its governance, to ensure that risk management genuinely contributes to organizational decision-making and value creation.


The IIA's ERM Guidance: A Focus on Governance, Not Efficacy

The IIA's new Statement of Position on internal audit's role in Enterprise Risk Management (ERM) primarily focuses on governance, particularly the independence of internal auditors when involved in ERM processes. While the paper meticulously outlines safeguards like board approval and cooling-off periods, the author argues that this emphasis misses a more critical point: whether current ERM practices actually work. The document assumes ERM's effectiveness without challenging its methodologies, leading to a situation where internal audit might be providing assurance over a fundamentally flawed framework. This raises a significant concern for assurance professionals: are we auditing the right things, or merely validating processes that don't genuinely enhance organizational objectives?

The Broken Foundation of Traditional ERM

The article contends that the dominant forms of ERM, characterized by risk registers, heat maps, and likelihood-impact matrices, are inherently flawed. These tools, often used to integrate risk into strategy and decision-making, are criticized for mathematical errors, such as compressing continuous data into arbitrary categories and misrepresenting tail risks. The IIA's paper, by not addressing these methodological weaknesses, implicitly endorses a broken framework. For internal auditors, this means that even with perfect independence, auditing such a framework may yield little value, as a clean opinion on a useless artifact does not improve decision quality or organizational resilience. The independence problem, therefore, is presented as a symptom of a deeper structural confusion regarding the purpose and efficacy of ERM itself.

Beyond Compliance: The Need for Decision-Centric Risk Management

The IIA's emphasis on "assurance over risk-related information" is seen as a compliance-first approach, focusing on whether processes were followed rather than if better decisions were made. This perspective suggests that internal audit's role, as currently framed, is to check for the existence and proper updating of risk documents, not to evaluate the impact of risk analysis on strategic choices. True risk management, the author argues, should occur before decisions are made, actively improving their quality. The paper's nuanced acknowledgments of practicalities, while seemingly balanced, are deemed dangerous because they might lead organizations to believe they are addressing risk effectively by merely complying with governance guidelines, without fundamentally improving their decision-making capabilities. Internal audit professionals should push for a shift from process-centric assurance to outcome-focused evaluation, questioning whether ERM genuinely enhances organizational survival and success.


Read more
Comments

No comments yet. Be the first.


Sign in to join the discussion.

Sign in or Create account
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →