Download as pdf or txt
Download as pdf or txt
You are on page 1of 12

AUDITING RISK CULTURE:

THE CHANGING ROLE OF IA

NORMAN GABRIEL
INTERNAL AUDIT DIRECTOR, Goodyear
October 20, 2016
AGENDA
• Our Current Environment
• What is Culture
• What is Risk Culture
• What Can We Do As IA
Our Current Environment
Corporate misdeeds and misconduct rocked
financial markets resulting to significant
financial losses – impacting innocent
employees & stakeholders.

Regulators continuously increasing efforts to


address this.
Source: Google
What is Culture?
Simple definition – “the way we do things
around here”

It is the values and conduct of a group of


people.

It is a unique component of every


organization’s personality.
Organization’s Culture
Much can be learned about an organization’s
culture by examining…

• Its attitude toward governance


• Its relationships with customers
• What is important to the organization (values)
• How it treats employees
• How it reacts to negative events
• How it behaves toward its competitors and
within its community
What is Risk Culture
Put simply, it is “the way we do things around
here”….. With the focus on those behaviors
that influence the company’s risk profile.
Auditing Risk Culture
Is both an Art and a Science.

Source: Google
Considerations for IA
• Is your organization ready?
• Are the main internal stakeholders on
board?
• Do you have the skills you need?
• How are you going to conduct the audit?
3 Key Challenges
• Building a methodology and tools that are
as robust as other internal audit approaches

• Training internal auditors on how to apply


(remember the “Art” component)

• Managing relationships with senior


management at audited entities
4 Critical Success Factors
• Piloting and iterating new approaches

• Getting senior IA executives strongly


involved

• Communicating clearly and continually

• Having patience
Final Thoughts
Auditing culture supports the delivery of
stakeholder value by enabling organizations
to
– Proactively manage risk and
– Reactively correctly internal control failings
before things get out of control

It will not be easy but we have a responsibility.

You might also like