News & Blogs

IIA's New ERM Position Paper: A Critical Review for Internal Audit Professionals

Global · · normanmarks.wordpress.com

The IIA has released a new "Statement of Position" on internal audit's role in Enterprise Risk Management (ERM), replacing a long-standing guidance document. This article critically examines the new paper, highlighting its strengths, weaknesses, and implications for internal auditors navigating their responsibilities in ERM. It's crucial for audit professionals to understand these evolving guidelines to ensure their ERM assurance and advisory services remain independent, objective, and effective.


Evolving Guidance on Internal Audit's Role in ERM

The Institute of Internal Auditors (IIA) has published a new "Statement of Position" titled "The Role of the Internal Audit Function in Enterprise Risk Management." This document, while not mandatory guidance, is significant as Chief Audit Executives (CAEs) are increasingly expected to lead risk management initiatives. It replaces the influential 2004 paper from the IIA's UK and Ireland affiliate, which introduced the widely recognized "fan" model for internal audit activities in ERM. The new paper aims to provide updated perspectives on how internal audit can contribute to ERM, emphasizing both assurance and advisory services.

Defining ERM: A Modern Perspective

One notable aspect of the new paper is its attempt to define ERM. While an initial definition focuses on identifying, assessing, managing, monitoring, and reporting threats and opportunities, the author points out a later, more dynamic and integrated definition within the same document. This improved definition views ERM as a continuous process embedded in decision-making and performance, connecting strategy, operations, finance, compliance, and culture. It acknowledges that risk encompasses both threats and opportunities, directly linking ERM to value creation and preservation. This modern perspective is crucial for internal auditors to adopt when evaluating an organization's ERM framework.

Assurance vs. Advisory: Clarifying Internal Audit's Contributions

The new paper clearly delineates internal audit's contributions to ERM into assurance and advisory services. Assurance involves assessing the design and effectiveness of ERM processes, including alignment with risk appetite, strategy, and governance. Advisory services focus on providing insights, challenging assumptions, facilitating risk discussions, and sharing best practices without assuming management responsibility. However, the author raises a critical point about the paper's distinction between assurance and advisory, arguing that in practice, these often overlap. For instance, recommendations made during an assurance engagement can be considered advisory, and advisory work often contributes to overall assurance. This nuanced understanding is vital for internal auditors to effectively integrate both aspects into their ERM engagements.

Safeguards and Independence: A Continuing Challenge

The paper addresses situations where CAEs might assume responsibility for ERM activities, outlining necessary safeguards to maintain independence and objectivity. These include clearly defined responsibilities, separation of assurance and advisory roles, transparency of potential impairments, and obtaining independent assurance when internal audit has operational involvement. While these safeguards are generally sound, the author suggests the new paper is less clear than its predecessor in defining activities that require safeguards. The article emphasizes that internal audit should not manage risks on behalf of management and that any work beyond core assurance should be recognized as a consulting engagement. Internal auditors must meticulously adhere to these principles to avoid conflicts of interest and ensure the credibility of their ERM oversight.

Recommendations for Internal Audit Professionals

Given the nuances and potential ambiguities in the new IIA Statement of Position, the author strongly recommends that internal audit professionals read both the new document and the older 2004 paper. Combining insights from both will provide a more comprehensive understanding of internal audit's appropriate and inappropriate roles in ERM. This dual perspective will enable CAEs and their teams to navigate the complexities of ERM, ensuring they provide valuable, independent, and objective assurance and advisory services while upholding the highest standards of the profession.


Read more
Comments

No comments yet. Be the first.


Sign in to join the discussion.

Sign in or Create account
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →