Embedding risk management: structures and approaches
Ian Fraser and
William Henry
Managerial Auditing Journal, 2007, vol. 22, issue 4, 392-409
Abstract:
Purpose - The paper aims to report research into ways by which companies identify risks and embed risk management and control procedures and also to report on interactions between internal audit and audit committees and their contributions to risk management. Design/methodology/approach - The first section of the paper comprises a review of the literature on risk management and the roles played by internal audit and audit committees. The paper then reports the results of a series of interviews with officers in UK plcs and external auditors on the issues identified from the literature. Findings - There was agreement that, while parent boards have ultimate responsibility, the ownership of risks must reside with management at lower levels. Companies tended to adopt a multi‐procedural approach to developing consistent risk management procedures. Internal auditors were believed to have a role to play but concerns were expressed about expertise and independence. The paper recommends a split of the internal audit and risk management functions to preserve internal audit independence and clarify internal audit roles. Audit committees are increasingly involved in risk management but there are doubts as to whether they have the time and expertise to undertake more than high level risk reviews. The paper, therefore, recommends that separate risk committees should be established to direct risk management, with audit committees adopting a watching brief over the process. Originality/value - The Turnbull Report emerged against a background of growing demand for assurance on risk management and control effectiveness and the approach adopted has been endorsed by the Turnbull Review Group. This paper is a timely evaluation of the work being done by UK plcs in this area and indicates that there are issues to be resolved before risk management is fully embedded in company operations.
Keywords: Risk management; Internal auditing; Audit committees (search for similar items in EconPapers)
Date: 2007
References: Add references at CitEc
Citations: View citations in EconPapers (1)
Downloads: (external link)
https://www.emerald.com/insight/content/doi/10.110 ... d&utm_campaign=repec (text/html)
https://www.emerald.com/insight/content/doi/10.110 ... d&utm_campaign=repec (application/pdf)
Access to full text is restricted to subscribers
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eme:majpps:02686900710741955
DOI: 10.1108/02686900710741955
Access Statistics for this article
Managerial Auditing Journal is currently edited by Professor Jie Zhou
More articles in Managerial Auditing Journal from Emerald Group Publishing Limited
Bibliographic data for series maintained by Emerald Support ().