Corporate Governance is now one of the hottest topics in the business world. It is both a regulatory requirement and a business enabler. But do you know whether your Corporate Governance activities are extracting maximum value? If not, this is probably because your Internal Audit team has not assessed this key topic. This audit approach is crucial as the Board and the Audit Committee need comprehensive assurance about this strategic business process.
This Auditing Corporate Governance training seminar will provide all the tools and techniques essential to audit the complex and wide-ranging field of Corporate Governance. It will help you ensure that you are applying the very best practices and meeting all regulatory requirements.
Assess the effectiveness of business continuity planning
Assist the Audit Committee in their Corporate Governance (CG) role
Assess sustainability and environmental governance
Audit joint ventures and partnerships
Lead Auditors
Senior Auditors
Audit Managers and those about to be appointed to that role
Assurance providers that need a greater understanding of Corporate Governance
Managers need a broader understanding of how to review Governance maturity
The Key Aspects of Corporate Governance:
What is Corporate Governance?
6 Core Principles of Governance
The Governance Warning Signs
New Corporate Governance Insights Paper will be Shared
Auditing Corporate Governance – new guidance
Meeting Stakeholder Requirements
How the organization is managed on behalf of the stakeholders?
The Key Parties within Governance
Audit Committee
The Board
Regulators
Customers
Suppliers
A New Governance and Accountability Tool will be Shared
Developing a Terms of Reference for the Assignment
A New Audit Programme will be Shared
New Guide on IA Standard 2120
Corporate Governance Statements
Governance Assessment Techniques:
COSO Advisory Paper – improving organizational performance and Governance
Governance and Strategy
Governance Models
Codes of Governance Requirements
Financial Reporting Implications
International vs. National Governance Criteria
The 3 Lines of Defence
Who should cover what?
The Business Environment:
The Standards, Processes, and Structures
The Tone at the Top Regarding the Importance of Internal Control
Expected Standards of Conduct
Management Reinforcement of Expectations across the Organization
The Integrity and Ethical Values of the Organization
The Governance Oversight Responsibilities
The Assignment of Authority and Responsibility
The Process for Attracting, Developing, and Retaining Staff
Establishment of Performance Measures, Incentives, and Rewards
Analyzing and Assessing the Effectiveness of Governance Controls:
Business Process Analysis Techniques
Process Objectives and Risk
The Need to Understand the Business Objectives
Developing a Programme to Reflect these Objectives
Defining and Measuring Strategic Objectives
Determining Process Components
The Link between Objectives and Risk
The Link between Risks and Controls
Process and Business System Controls
The Link between Inputs and Outputs
Trigger Events
Scoping a Governance Audit:
Governance Structure
Reporting Lines
Strategy and Risk Appetite
Leadership and Culture
3 Lines of Defence Process
Communication with Regulators
Escalation
Delegated Authorities
Whistleblowing
Accountabilities
Data Integrity
Commitment to Governance
Policies
The Need for Governance Audit of the Board:
The Key Role of the Board in Governance
The Need to Assess the Risks at this Level
Determining the Key Risks and Causes
The Audit Approach in this Sensitive Area
How to gather the evidence?
The 15 Key Governance Board Risks being Reviewed:
The actions of the Board are taken without due consideration of the impact on the organization and the stakeholders
Independent members of the Board are unable to give a robust challenge to the executive/senior management
The Board does not have sufficient, complete, or timely information on which to base its decisions
The Board is not monitoring or taking action on the most significant risks to the organization
Evidence of the decisions made by the Board, including the challenge process, is not transparent
Actions agreed by the Board are not implemented on a timely basis
Committees set up by the Board may not fulfill their obligations or there are too many committees such that the oversight is fragmented
The Board is not effective in covering the risks relating to remote sites or does not have responsibility/oversight for all parts of the organization
Policies, procedures, and projects are not aligned to the organization’s objectives
The culture of the organization is not sufficiently defined or does not support the organization in achieving its objectives
Risks are accepted or taken which are outside of the organization’s risk appetite
The organization’s risk appetite may conflict with the objectives and values of the organization
In the event of a significant incident here is an adverse effect on the wider economy or society
The governance requirements of any regulatory or legislative requirements are not met leading to increased regulatory sanction, censure or closure of a business
Communications from the Board are not effective such that parts of the organization may not be operating in line with board expectations and may not support the organization in achieving its objectives
Auditing the Overall Risk Management Process:
Establishing the Position Regarding RM in the Business
Establish Corporate Targets and Monitor Overall Progress
Risk Management using ISO 31000 Paper from IIA
Keeping the Board Apprised of the Most Significant Risks
Assessment of RM Capabilities
Strategic Risk Assessment
Review of Risk Evaluations in each Function
Ensuring Actions to Treat Exposures Implemented
Ensuring All Functions Evaluate their Risks Consistently
Evaluating the Results and Challenging where Necessary
Identification of Exposures
Reviewing Risk Registers
Imperatives for Change – RBA Planning
Basing Audit Programme on Most Significant Risks
Comparing Perceived vs. Actual Controls
A Risk Management Evaluation Tool will be provided
Evaluating Risk Appetite:
Evaluating the Risk Appetite Statement
Defining Risk Limits
Risk Profiling
Ensuring the Risk Appetite is defined for each type of risk
Ensuring Target Risk for Each Event
Auditing the Audit Committee Process:
The Audit Committee Role
Structure and Independence
Does the Committee Approve (but not direct) internal audit strategy, plan, and performance?
Do the Committee review summary IA reports and the main issues arising and seek assurance that action has been taken?
How does the Committee consider the reports of external audits and other external agencies?
How is the effectiveness of relationships between IA and EA and other bodies reviewed?
How is the effectiveness of the risk management environment and anti-fraud arrangements assessed?
The Audit Committee / IA Relationship
New Paper on How the Audit Committee should Assess IA
Case Study and Audit Programme will be provided
How does the Committee satisfy itself that assurance statements and the annual statement of accounts properly reflect the risk?
An Audit Committee Checklist will be shared
Audit Committee Report Example
Auditing Reputation:
The Rise of Reputation as a Key Risk
The Increasing Importance of a Positive Image – the need to be admired
Where does reputation come from?
How do you measure it?
The Magnifying Effect on Reputation of Business Failures
Global Brands
How to judge reputation?
The Explosion of Regulation and External Assurance
Identifying Reputational Risks
A Checklist for Reviewing Reputational Risk will be provided to all delegates
Corporate Social Responsibility:
The Increasing Importance of Corporate Social Responsibility (CSR)
New IIA Standard 2110 Re-auditing of Ethics
What constitutes CSR?
The Wider Aspects of CSR and the Implications for IA
Doing Responsible Things Responsibly
A Paper on Auditing Ethics will be provided
Redefining IA Role with CSR in Mind
An Audit Framework
How to audit CSR? – Key Steps
Is communication with the main stakeholders taken seriously?
Are the expectations of these stakeholders accurately understood, and what are the risks that these will not be met?
Are opportunities taken to develop the ethical reputation of the business?
Has the business assessed its reputation for social responsibility and its impact on our business prosperity?
Is the Board, and in particular the Chief Executive, sensitive and responsive to the concerns of customers?
Sustainability and Environment Audit:
The Need for Environmental Auditing
The Key Requirements for Sustainability of Resources
Why Environmental Audit is valuable even if you do need to comply with ISO 14001
Carrying-out an Environmental Site Review
Reviewing the Audit Trails
Meeting Regulatory Requirements
Ensuring Consistency
Auditing IT Governance:
Global Technology Audit Guides (GTAG’s)
The Need to Determine the Boundaries
Defining the IT Audit Universe
Focus on High-Risk Areas
Assess IT Vulnerabilities
Target Areas Where You are Focusing on Process rather than Technical Aspects
Use of Audit Frameworks such as CoBIT and ISO 27000
IIA New Standard on IT Governance
Risk-Based Audit of General Controls (GAIT)
IIA Guidance re GAIT
An ISO 27000 Audit Checklist will be shared
Auditing Joint Ventures and Partnerships:
Ensuring that there is a Risk Strategy for JV’s
What protocol is in place?
What is the review mechanism?
Is it effective?
What frequency is there for review by management?
What mechanism is there to guide management in attending JV meetings?
Does anyone know the number of JV’s and partnerships you are involved in and how much money and other resources are invested in them?
Has each JV been risk reviewed?
Reviewing a Current JV or Partnership:
Rationale
Added Valu
Decision-making
Performance
Finance
Problems
Termination
Auditing Business Continuity Planning:
The Importance of BCP
The Need to Recognize BCP is not just about IT Recovery
Reviewing the Different Types of Disaster – have all been considered?
Does the organization’s leadership understand the current business continuity risk level and the potential impacts of likely degrees of loss?
Can the organization prove the business continuity risks are mitigated to an approved acceptable?
Are they tested effectively?
Is the Board well set up to respond swiftly and capably in a crisis?
The Transition from an Emergency to a Disaster and the Questions to Ask at Each Stage
Is there an appropriate contingency plan ready to be used to manage a crisis?
Communication Testing
Alternative Site Testing
A Paper on BCP Resilience will be shared
Reviewing Key Controls Over Technology:
Risk and Control Matrices to Document Technology Dependencies
Evaluating End-User Computing
Implementing or Monitoring Control Activities when Outsourcing IT Functions
Configuring the IT Infrastructure to Support Restricted Access and Segregation of Duties
Configuring IT to Support the Complete and Accurate Processing of Transactions and Data
Administering Security and Access
Applying a System Development Life Cycle over Packaged Software
Assessing Management Information Governance:
Inventory of Information Requirements
Validating Information from External Sources
Information from Non-Finance Management
Creating and Maintaining Information Repositories
Enhancing Information Quality Though a Data Governance Program
Identifying, Protecting, and Retaining Financial Data and Information
Adoption of ISO 27000
Communication Internally and Externally:
External Financial Reporting Disciplines
Responsibilities and Guidelines for Communication to the Board of Directors
Communicating a Whistle-Blower Program to Company Personnel
Communicating through Alternative Reporting Channels
Establishing Cross-Functional and Multi-directional Internal Control Communication
Surveys for External Parties
Ongoing Evaluations to Ascertain Whether the Components of Internal Control are Present and Functioning:
Develop a Baseline for Effective Internal Control Processes
A case Study will be provided
Have a Mix of Evaluations from Different Sources
Use the Most Knowledgeable Personnel
Adjust Scope and Frequency
Change the Monitoring Processes as the Business Activities and Risk Profile Changes
The program opens by exploring the key leadership skills and how to apply them in the organization. Using this initial analysis, the program explores managing yourself as a leader, leading a team, creating breakthroughs through innovative leadership, communicating effectively with others, and imparting leadership values to your team members. All attendees will return to their organizations better equipped to meet the challenges and demands of leadership.
This is a fast-paced, dynamic, and highly informative advanced leadership program. It seeks to develop and enhance your personal, team, and organizational leadership skills.
This seminar is designed to provide practicing or potential leaders with the knowledge and skills required by the role. This leadership programme enables your leaders to critically explore the key idea that the most important function of a leader is to help their people move through the stages of team development.
Alliances in business are a natural route for development – but not all contracting relationships can truly be seen as alliances. A good, trusting and open relationship is essential for a long-term and successful alliance – and this needs to be practiced by the negotiators involved. Negotiation is inevitably at the heart of every process to achieve what you want, whether in an agreement, bargaining for an item, or closing a deal. At the end of each negotiation, the goal is to seek a win/win outcome – an essential characteristic of long-lasting alliances. This course provides an essential framework for effective negotiation — which will be vital for building and exploiting an alliance - from building the relationship, critical thinking to prioritize goals
Health, Safety, and Environmental Management Systems are based on a proactive process for incidents prevention as well as reactive monitoring of performance. Risk assessment is required to be applied to all activities that impact on health & safety, production, asset, environment, and the Company reputation.
All businesses in the current environment need a competitive edge. This can be gained through innovative and exciting products and services, or effective and efficient world-class employees. Top performing organizations are passionate about their most valuable resource - their staff. To maintain their high standards a large proportion of their time and energy is spent on continuous professional development, not only of their employees but of their business. This course investigates the tried and trusted management processes, procedures, and methodology used by many blue-chip companies. They use the tools to develop high levels of performance from their staff. This in turn ensures the future and reputation of their companies through innovative development, service, and evaluation. This course offers participants practical solutions to work-related issues.
Enterprise Risk Management known as (ERM) has evolved considerably since the seventies. From simply 'buying' insurance, it has now grown in importance to become a prime function in many organizations as part of a bigger system known as Governance, Risk, and Compliance (GRC) which starts with corporate governance and ends with compliance. ERM is the function of studying the risks that may hinder a corporation's ability to achieve its goals and then deciding how to overcome those risks. Studies regarding risk management were done by different organizations, including ISO which issued ISO 31000 on risk management. However, the most accepted ERM system is the one designed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). This system, which is the one covered in this course, teaches the steps needed to control risk. It starts with the evaluation of the internal environment and the setting of objectives which are, mainly, a result of the tone at the top of the organization, the directives from corporate governance as well as the vision, mission, and corporate strategies. Then, the course goes through the steps management needs to consider in order to identify and assess risk and decide on proper risk responses and controls. The course ends with how to monitor, communicate, and report risk. In addition, the course looks at risk in different organizational areas such as strategy, reporting, compliance, operations, financial and physical risk as well as risk in different industries.