470 likes | 614 Views
LACCD RISK ASSESSMENT Presented by Arnold Jenner Blanshard, CPA/MBA Director, Internal Audit Department. AGENDA. Welcome Risk Management A . Risk Terminology B. Risk Management Purpose
E N D
LACCD RISK ASSESSMENT Presented by Arnold Jenner Blanshard, CPA/MBA Director, Internal Audit Department
AGENDA • Welcome • Risk Management A. Risk Terminology B.Risk Management Purpose • Risk Frame Work A. Risk Category Definitions B. Risk Framework C. Risk Assessment Tool
AGENDA Cont. 1 • Risk Identification ProcessA. Identifying and Assessing Risk B. Identifying and Assessing Controls • EXAMPLES • Questions
Course Objective This course will prepare you to • identify and assess Risk in your auditees environment • Evaluate controls that are currently in place (if any) • Recommend strong controls to mitigate risks identified.
Course objectives Cont. By the end of this course, you will be able to: • Describe the purpose of risk management. • Explain the five risk categories • Describe the risk identification process • Identify and assess risks and controls in your auditee's department. • Make Recommendation that would set strong controls to mitigates risks identified.
WHAT IS INTERNAL CONTROL ? In basic term, internal control are the daily operating guidelines used by a company.
WHAT IS INTERNAL CONTROL ? Cont 1 These controls are processes, effected by people at every level (I. E.) board of directors, management, and other personnel,
WHAT IS INTERNAL CONTROL ? Cont. 2 designed to provide reasonable assurance regarding the achievement of objectives in the following categories:
WHAT IS INTERNAL CONTROL ? Cont 3 (1)Operations run Effectively and efficiently to achieve performance target and increase competitive advantage
WHAT IS INTERNAL CONTROL? Cont 4 (2) Financial reporting is accurate and timely with sufficient information to support decision
WHAT IS INTERNAL CONTROL? Cont 5 (3) Policies and procedures comply with all applicable laws and regulations.
WHAT IS INTERNAL AUDITING ? Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations.
WHAT IS INTERNAL AUDITING ? CONT It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate, monitor and improve the effectiveness of risk management, control, and governance processes.
WHAT IS THE FUNCTION OF THE INTERNAL AUDITOR ? TheInternal auditor’s work encompasses the examination and evaluation of the adequacy and effectiveness of the organization's system of internal control and the quality of the organization's performance.
WHO DOES THE INTERNAL AUDIT DEPARTMENT REPORT TO ? internal audit DEPARTMENT Reports DIRECTLY TO cfo/treasurer WITH DOTTED LINE TO THE BUDGET & finance committee
WHO IS THE AUDIT COMMITTEE ? THE AUDIT COMMITTEE IS MADE OF MEMBERS OF THE BOARD OF trustees. THE COMMITTEE IS RESPONSIBLE FOR MONITORING MANAGEMENT AND STAFF; COMPLIANCE WITH the BOARD OF Directors POLICIES AND APPLICABLE LAWS AND Regulations. THIS IS Ascertained THROUGH THE FUNCTIONS OF THE INTERNAL AUDIT DEPARTMENT.
Risk Terminology RISK:the chance of something adverse and unexpected happening that will affect corporate business (policies & procedures) objective and /or financial performance.
Risk Terminology Examples OF RISK: • CAR: Low Oil, No water, won't start, and Flat tire • Shopping: Not finding what you want: Spending a lot of money for something that’s not worth that amount • Relationship; you or your partner would cheat, someone will take your partner away from you • Work; the risk that I will not meet that deadline: the risk that I Could be late for work.
Risk Terminology cont. Control: the ACTION PLAN (TASKS OR PROCESSES) FORMULATED AND IMPLEMENTED TO REDUCE THE PROBABILITY OF CRITICAL RISKS OCURRING AND POTENTIAL DAMAGE TO THE BUSINESS.
Risk Terminology cont. Examples of Control: • Car: check oil & water weekly; regular service check up, monthly SERVICE check up of tire. • Using the internet to locate items you want to buy; shop more than three stores before making a purchase
Risk Terminology cont. Examples of Control: • Set rules that will diminish any remote idea of cheating; evaluate the type of person before becoming partners. • Set your deadline a week ahead of the actual deadline; give yourself 15 minutes earlier as your start time
Risk Categories: Credit Cont.1 Credit Risk includes: • Default ( or failure to perform) by an economic or legal entity with which the company does business. • Loss or opportunity cost as a result of the failure of a counterparty or customer to honor its obligations in a timely manner.
Risk Categories: Operational. Operational: Arises from the potential that THE COMPANY Has • inadequate information systems, • operational problems, • breaches in internal controls, • fraud • An Unforeseen catastrophe could result in unexpected financial loss
Risk Categories: Cont. MARKET: THE RISK THAT ADVERSE MOVEMENTS IN MARKET RATES OR PRICES, SUCH AS INTEREST RATE AND COMPETITORS PRICE COULD NEGATIVELY AFFECT THE MARKET VALUE OF LACCD (DISTRICTWIDE) (ASSETS AND/OR LIABILITIES).
Risk Categories: Cont. REPUTATION: IS the potential that negative publicity or public opinion regarding an institution’s business practices whether true or not, will trigger a decline in the customer base, costly litigation or revenue reductions.
Risk Categories: Cont. REPUTATION: The risk that poorly designed business strategy and /or inadequate controls surrounding credit, operational and market risks will result in significantly undermining the Company’s reputation.
Risk Categories: Reputation.cont.1 Reputation Risk cover such stakeholders as: • Members AND POTENTIAL MEMBERS • Regulatory community (Federal and state agencies) • Vendors • Providers • Other entities
IDENTIFYING AND ASSESING RISKS • Use your Policies and Procedures to identify each process and then identify the risk associated with that process. • Use the sample questions sample Risk Question.xlsand risk category definitions to help you brainstorm all risks in your department processes, activities and products.
IDENTIFYING AND ASSESING CONTROL • Identify all controls for each risk you identify in your business processes, activities and products. • Use the tip for evaluating control to assess the quality of total control currently in place. Tips For Evaluating control summaries.doc • Determine Who is responsible for each control ( management- level position)