Showing posts with label #eppardini. Show all posts
Showing posts with label #eppardini. Show all posts

Tuesday, March 10, 2026

The Illusion of Security: Why Your Internal Control Might Be a House of Cards

 

Once, during a consulting project, a manager told me something that sounded reassuring: "We have control for outgoing goods; it’s done every single day." However, as I dove into the process, I discovered the harsh reality behind those words. That "control" was merely an employee jotting down what left the warehouse in a notebook, no verification, no signature, and no oversight. In the manager's mind, the risk was covered; in practice, he had a hollow procedure, but not an effective control.

Many people confuse control with bureaucracy, and I often hear that "bureaucracy kills business." But that isn't true. 

Bureaucracy, in its essence, is not a bad thing. If we look at Max Weber’s theory, we understand that it was conceived as a form of human organization based on rationality, ensuring impersonality, a clear hierarchy, and meritocracy. It ensures that the process depends on the rule, rather than the mood of whoever is executing it. 

I always say that bureaucracy is simply the formalization of what is already working.

The real problem isn't bureaucracy itself, but "bureaucratic excess", when the ritual becomes more important than the result. 

An internal control system based on best practices, right sized to keep risk factors within acceptable levels, is essential for operational efficiency. It creates order and prevents the "rigidity" that often blinds an operation.

We know that internal control is an action designed to mitigate the cause of a risk before it materializes. It manifests in the "doing": in the review, the verification, the recalculation, and the careful approval. If there is no confrontation between "what should be" and "what is," the risk continues to walk freely through your company’s hallways.

For a control action to be more than just figurative, it requires four non-negotiable attributes:

  • First, the Objective, which is the very reason for its existence and must target the risk factor. For example, if the risk is the use of incorrect labor hours, the objective is to ensure that the hours in the payroll system are consistent with the time-tracking system.

  • Second, Practical Action, such as a data verification. It is vital to formalize how this action is performed so that a "prudent person" could re-perform it.
  • Third, the Evidence, because a control without a trail is invisible. It could be a sign-off, a system log, or an email. To an auditor or an internal controls specialist, a lack of evidence implies the control does not exist. Finally, the Frequency, which must match the speed of the risk, whether it be daily, monthly, or per event.

 

When we talk about Control Modeling, the starting point is knowing the risk factor and the magnitude of what we are mitigating, allowing us to define the necessary attributes to keep the operation within the organization's risk appetite. 

These same attributes allow us to evaluate Design Efficiency, concluding whether the control has the theoretical capacity to mitigate the risk.

 Once we move to Effectiveness Evaluation—the actual control testing—the focus shifts to two crucial points: discipline, observing if the evidence exists within the defined frequency; and quality, re-performing the action to ensure it wasn't just a formality. 

This is why these attributes must be formalized, at the very least, in an Internal Control Matrix.

 It is also fundamental to understand that control is neither absolute nor infallible, as it is designed and executed by people. And where there are humans, there is vulnerability—whether through errors in judgment or, in grave cases, omission, fraud, and collusion. Therefore, the effectiveness of a control does not reside solely on paper, but in the discipline and ethical stance of its execution.

Recently, the market witnessed a testimony that serves as a stark warning. A former bank director admitted to signing documents without reading them. More than a momentary lapse, his confession revealed a void: despite heading the department, he did not perform monitoring or prevention duties.
Here we have the perfect "Window Dressing Control"—the evidence and frequency exist, but the execution of the action is null.

Unfortunately, this is not an isolated case; it is present in many corporations where management still mistakenly views control as mere bureaucracy.

To conclude, I leave you with a thought for reflection:

"The effectiveness of a control depends on action, evidence, and frequency, but it only stops being a house of cards when the integrity of the person executing it is greater than the convenience of simply signing."

Be happy!

Wednesday, February 5, 2025

Courage: The Foundation of Objectivity in Auditing – Are You Prepared?


 Auditing is an essential pillar of corporate governance, requiring professionals to commit fully to objectivity. Objectivity represents the auditor's independence in expressing their opinion without being influenced by external forces or personal conflicts. However, this objectivity cannot be sustained without a fundamental component: courage. When conducting their work, auditors must be prepared to face challenges, resist external pressures, and communicate their conclusions with unwavering ethics and transparency.

Courage and Independence: Inseparable in Auditing

An auditor’s independence goes beyond rules and regulations. It manifests in a resolute stance against attempts at influence and manipulation. In many instances, auditors encounter conflicting interests that seek to mitigate or even conceal critical information. In this scenario, courage becomes the anchor that ensures a rigorous and impartial assessment, protecting stakeholders and safeguarding the integrity of financial reports.

According to Domain II of the Global Auditing Standards, objectivity and courage are fundamental ethical principles for auditors. This domain establishes that auditors must maintain independent thinking and demonstrate resilience in the face of challenges that could compromise their professional integrity. Thus, courage becomes an essential element in ensuring that professional judgment is exercised freely and impartially.

Facing Pressures and Ethical Dilemmas

Internal and external pressures can arise from various directions, from managers attempting to downplay irregularities to clients seeking to influence opinions. Without the necessary courage to resist these pressures, audit objectivity is undermined. Therefore, auditors must align their ethical stance with emotional resilience, ensuring that their work remains uncompromised by adverse circumstances.

Transparent Communication: A Reflection of Courage

Courage is not limited to resisting pressures; it also manifests in the clarity and firmness with which auditors communicate their findings. Audit reports often contain sensitive information that may be uncomfortable for those involved. However, truth and transparency must always prevail, regardless of potential retaliation or dissatisfaction from the audited parties.

Building a Culture of Courage in Auditing

To strengthen objectivity in auditing, organizations must foster a culture of courage. Continuous training, institutional support, and guidelines that protect auditors from retaliation are fundamental elements of this process. Furthermore, audit leadership must set an example, demonstrating that ethics and truth are non-negotiable values.

Final Reflection

Complete objectivity in auditing can only exist when accompanied by courage. The auditor who stands firm in their ethical and professional principles significantly contributes to the reliability and transparency of governance processes, even if this stance may cost them adversaries or even their job.

Therefore, it is important for you to reflect: How is your objectivity? How do you escalate your findings or opinions? Are you prepared to face the challenges that auditing imposes and maintain your unwavering integrity?

Remember: ethics and truth are non-negotiable values.

Be happy!

 

Monday, January 20, 2025

Professional Diligence and Integrity: Lessons from the Wells Fargo Case for Risk Managers and Internal Auditors

 

The recent decision by the Office of the Comptroller of the Currency (OCC) against former Wells Fargo executives underscores the importance of professional diligence and integrity in risk management and internal auditing. This case highlights how failures in monitoring improper practices can lead to severe penalties, impacting both the company and its executives.

The OCC investigation revealed that Claudia Anderson, who served as the Community Bank Group Risk Officer, failed to adequately challenge the bank’s incentive program, neglected to implement effective controls to mitigate the risks of improper sales practices, and did not escalate known risks. Additionally, she was found to have provided false or misleading information to regulators during 2015 examinations. Former internal auditors David Julian, Chief Auditor, and Paul McLinko, Executive Audit Director, also failed to design effective audits to detect and document irregularities and did not properly escalate issues. In McLinko’s case, there was an additional concern regarding his compromised professional independence due to his close relationship with the bank’s retail division.

To prevent such scenarios, risk managers and internal auditors must operate with technical rigor, independence, and integrity, ensuring that internal controls are effective, and that risk oversight and escalation mechanisms function appropriately. Professionals in these areas need the courage to challenge policies and practices that could compromise governance and expose the organization to financial, regulatory, and reputational risks. Furthermore, it is crucial that they are embedded in a corporate culture that prioritizes transparency and compliance, thereby reducing their own exposure to potential penalties.

The Wells Fargo case serves as a critical warning: governance failures and oversight negligence can lead to severe legal and reputational consequences. For professionals in risk management and internal auditing, the lesson is clear— 
complacency and negligence are not options. A proactive and vigilant stance, grounded in best governance practices, is essential to ensuring that business decisions are made with ethics and responsibility.

Questions for Reflection:

  1. How can corporate governance strengthen the independence and effectiveness of risk managers and internal auditors?
  2. In what ways can companies foster a culture of transparency and compliance to mitigate fraud and irregularities?
  3. What challenges do audit and risk professionals face when attempting to escalate critical issues within an organization?
  4. How can companies ensure that incentive programs do not pose risks to organizational integrity?
  5. What steps can professionals take to develop a more critical and proactive approach to risk identification and mitigation?

In future articles, I will explore these questions in greater depth. For now, I leave you with this thought:

Are you comfortable with how you are currently managing risks or conducting audits? Do you feel supported in questioning company practices that could pose governance, integrity, or reputational risks?

Be Happy!

Thursday, July 28, 2022

Let's make enterprise risk management simple!

 


Today I want to bring to our reflection a fundamental theme for the consolidation of corporate governance.

Let's talk about enterprise risk management.

I was preparing the course, and I came across a slide that I use to explain, the structure applied to risk management, and I felt motivated to bring this topic to our discussion.

Anyone who follows me on social media knows that I always try to bring a simple view to important topics related to management and governance, facilitating understanding and their application in corporate activities.

Simplicity is currently a competitive advantage for the organization, but understand that being simple does not mean being superficial.

Well, let's get back to our topic, which is risk management.

In a simple way, I can say that:

“Managing risks is a proactive activity, looking to the future, understanding the events, external and/or internal, that may materialize and adversely impact the company's or process's ability to achieve its objectives; evaluates them for their magnitude, and treats them based on the acceptable levels of risk defined by the corporation.”

The primary objective of risk management is to allow the corporation, in the pursuit of fulfilling its mission, to conduct, direct and maintain its activities, actions and decisions, within its acceptable level of risk, defined by risk appetite.

The starting point for risk management is the correct understanding of objectives, whether strategic, corporate and/or operational. If we do not know the objectives clearly, it is difficult to know the risks in a comprehensive way.

Not using objectives as a basis for identifying risks is the most common mistake I find in corporations, causing time and resources to be spent in a wrong and ineffective way.

Remember that the risk event directly impacts the ability to achieve the objectives.

Regarding the operational objectives, those that relate to the various existing processes for the operationalization of the organization's activities, I recommend the definition of the objectives inherent to each of the processes, as well as the objectives related to legal compliance, objectives related to moral values of the organization, and objectives related to the consistency, integrity, confidentiality and recoverability of the processed data.

The better the definition of objectives, the more effective the identification of risks tends to be.

Well, since we have already determined the objectives, we now begin the process of identifying the events, external and/or internal, that may impact the corporation.

Then, in a simple way, we begin to identify the risks that, if materialized, will adversely impact the organization's ability to achieve its objectives. We can see risk as the negative view of the objective, for example: If one of the inherent objectives of a purchase process is to buy only products and/or services necessary for the operation of the corporation, the risk may be the purchase of products and/or or services not necessary for the operation.

Based on the understanding of the objectives, try to identify all risk events that relate to it. This is a brainstorming activity. There is no Cartesian way of doing this.

Once all the perceived risks are related, the next step is to know their causes, that is, the events that could materialize the risk.

It is the risk factors (causes) that we assess the magnitude of and that we treat, so it is important to be judicious in identifying them.

To illustrate, let's go back to the example of the purchasing process, why can the corporation buy products and/or services not necessary for the operation? The answers to this question will allow us to identify the risk factors. Example: a. A wrong purchase requisition, b. Lack of inventory planning, c. A fraud.

This procedure must be performed for all identified risks, without exception.

Very well, at this point, our risk matrix already has three basic columns: Column of objectives, column of risks related to each of the objectives and column of risk factors related to each of the identified risks.

The next step is the analysis and assessment of risk factors through the matrix reading of probability (frequency) and impact (in several dimensions, such as financial, image, market-share and others).

At this point, it is important that the corporation has metrics, approved by senior management, to assess the magnitude (probability and impact) of risk factors.

It is also important that the company already has a risk appetite defined by top management. As a suggestion, to facilitate the risk management process, guide senior management to define the risk appetite based on the heat map resulting from the metrics, indicating the quadrant that should be considered as the accepted level risk.

I like to use metrics with five levels of probability and five levels of impact, so that the heat map has quadrants from 01 to 25. In this case, risk appetite can be defined as being one of the existing quadrants, for example the high management can direct your risk appetite to quadrant six, so anything above will need to be addressed.

One of the problems that I come across, in this evaluation stage, is in relation to the use of complex metrics, with the inclusion of weights, weighted average and other calculations that only bring complexity and delay to the process.

Note that, more important than the accuracy of the risk factor measurement, is the action that management takes to address it. It doesn't matter if the risk is 15,234 or 15, what really matters is the action that management takes to mitigate the risk factor.

The calculation is simple: probability x impact = gross risk

Another important point at this stage of the evaluation is the definition of impact, that is, if the event materializes, what impact will it bring to the organization. Some corporations seek to assess impact through a weighted average across the various dimensions. The suggestion is to work with the dimension that receives the primary impact, and not with a weighted average of the impact in the different dimensions, because, note that this is not how it happens in reality. Example: if the event materializes and impacts the image, it will not necessarily impact, simultaneously, the other dimensions measured, so it is best to focus on treating the effect on the image, ensuring that it does not affect secondarily the other dimensions.

Okay, now that we know the magnitude (gross risk) for all risk factors, whether inherent, compliance, fraud, or IT, the next step is to compare the magnitude obtained with the risk appetite, and based on in this, determine the best treatment to align the raw risk with the risk appetite determined by the organization.

Keep in mind that the primary objective of risk management is to enable the corporation to act within its acceptable level of risk, formalized through the definition of risk appetite.

Risk factor treatment can be: Accept, Share, Avoid and Mitigate.

We can accept the risk, when the gross risk is already aligned or below the risk appetite, however accepting the risk does not mean doing nothing, but monitoring the risk factors, because today it is low, tomorrow it may change and with this change our treatment.

Another important point is in relation to who can accept the risk, and my suggestion is that it need to be accepted by the statutory managers, since legally they are the ones who take the risk for the company, including their private assets.

Sharing risk is a process where another corporation, be it a financial institution or an insurance company, accepts to take part of the risk for the company. Example: Insurance policies, or foreign exchange hedge. Note that this is an answer on impact and not probability.

Another form of treatment for risk factors is risk avoidance. It is one of the most difficult answers to work with, because in order to avoid risks, the organization can no longer be exposed to risk, which means, in most cases, strategic decision-making, such as the company's exit from a market, or closing a unit, or not carrying out an operation, etc.

Finally, we have the possibility of mitigating the risk factor, which operationally speaking, requires the implementation of an internal control to mitigate the probability of the risk event materializing.

Just remembering that internal controls are:

“Actions, formalized in policies and procedures, aimed at mitigating the probability of materialization of the risk event. These are actions of review, checking, certification, validation, authorization, approval, etc.”

Depending on the materiality and nature of the risk, in addition to the probability response, it will be necessary to prepare a contingency plan, which aims to minimize the effect of the impact, when the risk event materializes.

Once the responses have been determined and implemented, the next step is to calculate the residual risk, which is the effect remaining after the treatment action, and make sure it aligns with the risk appetite defined by the corporation.

Remember that simplicity is currently a competitive advantage! Bring simplicity to operation, not superficiality!

Be happy!

Tuesday, October 5, 2021

A life, a story, a journey...



Today I would like to ask permission to leave the technical issues of management and governance for a moment, to report a brief extract from my diary.

My goal is to take some of my professional experience from these past 41 years. These are things I didn't learn from books or at university.

We are currently undergoing a change of era. 

Deep changes, some disruptive, both in the corporate world and in society. New paradigms, new knowledge, new work models, all of this directly impacts our professional life.

This entire process of change demands a lot from the professional, generates unemployment, losses, paradigm shifts, adaptation, but in the end, everything somehow stabilizes, as it is part of the maturation process.

The answers to past problems will not necessarily be the answers to current problems.

Observing people, their attitudes and knowing the experience they lived, always helped me a lot to understand the moment, allowing me to manage daily challenges.

I hope this brief report can, in some way, help you.


"Diary, August 31, 2021

Today I turn 61 years old.

This has been a different time, as on the 29th I lost my dad, and I am still processing this event.

It's interesting how our minds work, because despite everything, I feel calm and I'm here reviewing some classes that need to be taught this week.

I was, as usual, with the television tuned to the Bloomberg news agency, I think it's an addiction I bring from my corporate life as C-Level, but it allows me to keep up with what's happening in the business world, however, today I was looking for another channel, in order to start to relax, as it is already 22:30, when I go through the NetGeoWild channel, I see the program that my daughter is one of the protagonists, Dr. K Clinic of exotic animals. (My daughter is a veterinarian specializing in wild and exotic animals and works with Dr. K in Broward County, Florida.)

I always watch the program, but today it was different, seeing her in an emergency room, being broadcasting in over 160 countries, being considered as a reference, here in Brazil as in the United States, triggered, like a movie, my last 40 years of professional life experiences, starting, around 1979, when I joined Coopers & Lybrand team as a trainee.

It was a journey, full of challenges, many things lived and experienced, that not even a university can teach.

For sure many mistakes and some successes...

Various positions: external auditor, internal auditor, controller, financial director, CFO, general manager, in various sectors of the economy: services, food, animal feed, chemical, metallurgy, rubber, tanning, auto parts, textile, automotive, agricultural, most with responsibility for managing operations throughout Latin America, and sometimes including responsible for businesses in other continents.

During all this time I experienced several different economic moments, very challenging, hyperinflation, several devaluations, many economic plans, currency changes, and others.

In the corporate world, it was no different, many challenges, that sometimes, at the time it was happening, it seemed like it would never end. Many reorganizations, operation downsizing, construction and implementation of manufacturing plants, sale of operations, purchase of companies, due diligence, merger, split, dismissal, admission, hiring, project implementation, electronic systems, and much more.

Oh my god, how many things I went through!

Much of my time was spent on a business trip in Brazil and abroad, of course, this implies being absent from family life for a long time, especially in my time where everything, exactly everything, needed to be in person. There were many long journeys. I remember my record was 48 international trips in one year.

Sometimes a lot of stress, but also a lot of good times.

Interesting that even those moments that seemed to me to be a wrong decision, over time, proved to be the best option.

I met and worked with many brilliant professionals, but also with some horrible people, in this case, luckily, a minority, however living with these toxic people, helped me to mature a lot as a manager, and also as a person, and now I understand that it was part of learning process, which allows me to be what I am today.

Thirteen years ago, a little tired of corporate life, and also doing my risk management, I moved into my own business, starting Crossover Company. It wasn't easy, sometimes I wondered if I had made the right decision. I had some invitations to go back to the corporate world, but somehow, I don't know how.

However, at these moments it was very clear that I had to continue with Crossover.

It was a very complex few years, one thing is for you to work for a corporation and another thing is for you to start a company from scratch, betting everything on this company. On twenty-four hours, working at least fifteen hours a day, seven days a week.

Not that it's very different today, but I think I've gotten used to it, moreover, I've learned that when we do what we like, when we see a purpose in our efforts, such as bringing knowledge and support for the strengthening of corporations and the development of professionals, nothing it's boring, on the contrary, it ends up being very pleasurable.

It is interesting that when we are experiencing all of this, there in the middle of the hurricane, it seems that time takes a long time to pass, it seems that there will be no solution, but in the end everything, somehow, passes.

Looking at the past from today's perspective, it's as if this all happened a second ago.

What have I learned from all this?

  • The first learning is that patience is an important virtue, as everything happens in its own time, and that everything, somehow, passes,
  • That every experience, whether good or bad, is an input for our maturation as a professional and as a person,
  • That even the decisions taken, which at first seem to us to be wrong, may, in the medium and long time, prove to be correct,
  • Despite all the knowledge obtained in the academy as well as in daily life, this is never enough, we need to continually seek knowledge and learning, this is called lifelong learning,
  • I learned a lot more from mistakes than from hits, but for that, I needed to learn to recognize that I made a mistake, which was not very easy, as we are not trained to make mistakes. With time and maturity comes the humility to recognize that it was not infallible and could make mistakes,
  • Another learning is that we are nothing alone. To win, we need a committed team with excellent professionals, and I certainly had and have the best people and professionals in all my teams that a manager could have. I am immensely grateful for having the opportunity to live with each one of them,
  • I also learned that it's not the money that moves me, but the challenge, that money is a consequence,
  • That being ethical, in order to have the expected conduct, within society's moral values, is the greatest asset that a professional can have, there is no money to pay for a clear conscience.
  • There is no leader, no followers, and your hierarchical position does not make you a leader. The leader, at the very least, needs to be aggregator, inspiring and trustworthy,
  • Also that instead of worrying about keeping a job, the most important thing was to keep employability.

If I would do it all over again?

Yes definitely. Everything I am today is due to all of this. Of course, I would live all this again, but always with the support of Marcia (my wife), who has always been supporting and participating as a guide in the most difficult times, because without her it would be very difficult.

If there is something that would change?

Yes, I wouldn't have missed my daughter's 15th birthday party, being out of the country discussing corporate annual planning. But this is past and I have to leave this in the past as life goes on.

But seeing her on television, as a high-performance professional recognized for her excellence, all this achieved by her own effort and dedication, in addition to being an incredible daughter, makes me understand that all this effort of mine was not in vain.

Well, it's already two o'clock in the morning, I better go rest, because in a little while, another professional training program will begin.

Wow, if I could share a little of this experience with the students, it would be all good, maybe one day I'll write a book....

Apparently this journey is not near the end.... is it?

Good night diary."

I'm sorry if this account was too long, but I hope that somehow it can help you through the challenges of professional and personal life.

Be sure that any and all experiences, even those that hurt us, will make you more resistant, stronger, and much more aware.

Everything we go through in our life, make sure it matters!

May we leave this world better person than when we arrived!

Reflect, Innovate and Be Happy!

Wednesday, September 22, 2021

Assessment Test - Control, Compliance & Substantive


 



Hi!

As you may know, one of my goals as a professional is to inspire people to innovate, thus helping to develop their knowledge, improving their skills.

For this, one of the ways I use is the creation of specialist figures, like the one above.

• When we are carrying out an evaluation of the process and the internal control system, whether by the internal controls area, or by the internal audit, it is very important that the definition of the procedures and techniques used are aligned with the nature of the evaluation, whether it is an evaluation performance, compliance, and/or accounting.

• The choice of which test to apply in gathering the evidence needed to issue an opinion must also take into account the scope and object of what is being evaluated.

• In this figure, the three types of existing tests and the attributes for their applicability are described, according to my understanding.

• You will usually find substantive and compliance tests in the existing bibliography, considering compliance to be the test that applies in the validation of control or else in the assessment of legal compliance.

• I segregate this test into two: control test, which is used to test the effectiveness of the control and compliance test, which is used to assess whether the activity and/or product of the process was performed in accordance with legal requirements.

I hope that this understanding and this figure is useful for your professional activities, and I am available for any doubts that may exist. Enjoy and follow us on Instagram, Linkedin, Facebook, and the TV Crossover Brazil channel on Youtube.

Be happy,

Eduardo Person Pardini


Friday, February 19, 2021

Internal controls, the responsibility of everyone!


Questioning who is responsible for internal controls is a common and recurring situation in the corporate world. When the company has an area of ​​internal controls, it is attempted to wrongly attribute this responsibility to it.

Why does this happen?

In my opinion, this behavior is a consequence of the lack of maturity in the management process in relation to good practices, in line with the fragility of a university that does not properly teach managers.

This weakness is evident when, managers and other professionals, relate internal controls to bureaucracy and / or “plastering” the business process. They fail to see and associate that internal control is a response to the action of mitigating a risk factor, which results in increasing the company's ability to achieve its strategic objectives.

The maturity of governance involves the improvement of the internal environment through the strengthening of the culture in the use of good management practices and the consolidation of awareness of risks and controls.

An essential point for this to happen is the correct addressing of the responsibility of each person within the organization in relation to the internal control system.

The model of the three management lines helps us to demonstrate these responsibilities, and was the basis for the construction of the diagram that I prepared to facilitate this understanding.

Let's see:

1. Governance Structure - I include here the Board and statutory committees, which are responsible for promoting the appropriate environment for the culture development and awareness of risks and controls. In addition, they must be committed to good management practices, supervising and monitoring the application of these concepts by the executive and operational management, following up on the implementation and improvement of internal controls.

2. Executive and Operational Management - In this case, executive management is the president and his directs, while operational management is the managers below the executive management line. The responsibility lies in exemplifying the commitment to internal controls, and in defining, implementing, executing and supervising the internal control system in order to keep operational risks within acceptable limits, as defined by the corporate risk appetite. This first line of management are the “owners” of risks and control, with no exception.

3. Specialists - Responsible for supporting the executive and operational management, first line, to apply the best management practices for the modeling, implementation, maintenance and improvement of the process and its internal control system integrated with the corporate risk management structure. This group includes specialists in internal controls, specialists in risk management, compliance and governance. They are the second line of management.

4. Internal audit - It is an independent and objective activity, usually reporting to the governance structure, with the objective of adding value, through the application and execution of an independent and objective evaluation on the internal control, risk management and corporate governance systems.

As you may see, every single person within an organization, without exception, has explicit responsibilities regarding internal controls, either in their design, implementation, execution or in their quality.

However, the greatest responsibility is left to the executive management (president and its directs) which must promote the properly environment, based in the ethics and best practices, in order to create the culture where all managers and employees recognize their responsibility for the existence of high quality internal control system.


I would like conclude this article with this quote:

“The great enemy of truth is often not the lie - deliberate, contrived and dishonest - but the myth - persistent, persuasive and unrealistic” J.F.Kennedy

 

Always, be happy!

Thursday, January 14, 2021

Approach 4.0 for Internal Controls Specialist


 


The internal controls specialist, especially those with CICS - Certified Internal Control Specialist certification, cannot be supporting actors, they need to be protagonists, leading the dissemination and application of the best management practice structures in their organization, supporting management in this process structural changes, allowing the company to maintain its competitive advantage.

For this, internal control professionals must innovate their approach in the activities of modeling, implementation or evaluation of operational processes, risk management and internal control system.

Having a more holistic view of the company, aligning the market, strategy and operation, is a fundamental requirement for the specialist. He needs to see and understand the meaning of the "parts" in the "whole" business, making sense throughout the operation's ecosystem.

In addition to all the technical and managerial training that this professional must have, he needs to include, in his activities, new structured models, breaking paradigms and expanding his coverage and vision beyond the controls

Thinking about encouraging some reflections and also contributing to these changes, I describe in the diagram, some attributes, which I consider essential, and which should be part of this approach which I called, for lack of creativity, as 4.0, alluding to the fourth industrial revolution that focuses on increased efficiency and productivity using physical cyber systems, automation, IOT, cloud and others.

Let's take a look in these attributes:

1. Evaluation of the organizational structure based on a business vision, so that it can promote the alignment of the capital applied in the operational organization with the planned strategic return,

2. Application of structured and disciplined methodology to evaluate processes and activities, considering the inclusion of agile principles and values,

3. Add a review of the performance of the governance, compliance and integrity program as a requirement in the processes, tasks and environment assessment and validation programs,

4. Use of data science techniques and tools in its processes for surveying and testing the efficiency and effectiveness of the internal control system, such as for database validation and information security,

5. Strengthen the vision of strategic and operational risks inherent to the corporation, paying special attention to the emerging risks, whether in the management of data processing technology applied to operational processes, in innovation, in the market, or in other dimensions that may impact the organization's ability not to achieve its mission,

6. Identify the best management practices that can be considered as paradigms for improving performance and innovation, promoting them in the structure, strengthening the control environment and perfecting the fundamentals of corporate governance, risk management, internal control systems, compliance and / or other related activities.

As you may see, the adoption of these attributes, in the activity of internal controls, requires a change of “mindset”, not only of the professionals of internal controls, but also of the management, at all levels.

Every change generates reaction and resistance, so that in order to be successful they must be planned, including in this plan a robust process of sensitizing the structure for the promotion and justification of awareness and culture of efficiency, risks and controls, mitigating the risk of not being successful in this change.

I end this article with a phrase that always helps me when I'm making some excuse for not changing, which is:

"Change is the law of life, those who look only to the past, or to the present will be forgotten in the future" J.F Kennedy

 Be Happy!


Friday, October 30, 2020

The entrepreneurial internal auditor, a new generation, a new posture, a new vision!

 


In some meetings with members of audit committees, from different sectors, a common point that caught my attention was the dissatisfaction of the committee with the results of the audit assessment work.

In a nutshell, the most significant complaints revolved around the reactive attitude of the audit, very concerned with finding mistakes made in the past, often without understanding the root cause, generating innocuous recommendations and with little or no impact on the organization's performance, and also the low cost and benefit ratio of the audit, since it is not clear whether the results delivered bring something positive, savings or process improvement.

I understand the frustration of these directors, but I also understand that the internal audit, often, does not receive the support or necessary guidance for the improvement of their activities.

The audit committee has a share of blame in this process, since, being responsible for the audit activities, it has the obligation to give full support to the audit, in its structure and proficiency, as well as in the approval of the annual plan, including the definition of what will be audited object, the approach of the review and the emphasis that should be given on its scope.

The committee is a supervisory body, but also an advisor and guardian of good practices and quality that must be pursued by the audit team. I will not go into this in more depth, I will leave this topic for reflection in another article.

Let's go back to our central point, what I called “the entrepreneurial auditor”.

You may find this denomination strange, but it was the way found to try to convey the idea of this new posture and new vision that the auditor must conceive and apply in his activities. In order to understand where I want to arrive, I first need to let you know my vision of what is be an entrepreneur means:

“Be an entrepreneur is to do something new, realizing the opportunities, recognizing the risks and adversities. It is the ability to transform, go beyond what is expected, in a creative and resilient way.”

Now we will review the internal audit mission according to the IIA - Institute of Internal Auditors, which says that the internal audit mission is:

To enhance and protect organizational value by providing risk-based and objective assurance, advice, and insight.

 

Once these concepts are understood, we can idealize that the entrepreneurial auditor is the mixture of these two concepts.

Now we need to take into account that the corporate world has undergone profound changes, by significant paradigm disruptions.

Doing business or managing a process is very different than five years ago. Today the market is more globalized, more technological, more innovative, more disruptive and with a strong convergence to the digital, virtual world.

Technology allows borders to be gradually eliminated, opening up a vast market of operation, as well as allowing new players to enter the market only in a virtual way.

This disruptive innovation process is challenging for any corporation, making it significantly essential that the company has a strengthened governance structure, and that governance awareness is the basis for an internal environment that provides greater flexibility and adaptation of management to new market requirements. and competitiveness, without the operation losing its essence.

It is precisely in this boiling environment that the internal auditor, like the other managers, is inserted.

The internal auditor has an important role in promoting ethics and values ​​of conduct so that this culture is not lost during innovation processes. The auditor has the responsibility to contribute to the organization by making intelligent appointments that direct the necessary changes which will make either the processes or the organizational structure more innovative, more effective and more economical.

For this, the internal auditor must have an entrepreneurial vision, knowing and weaving a clear vision of the dynamics of corporate business, understanding the strategic objectives and their relationship with the organization's mission. He also needs to have a clear view of the operating cash flow cycle of the operation so that the strengthening of this cycle is always part of your assessments.

In addition, the entrepreneurial auditor must comprehensively understand the corporate risks present in the organizational and business structure, knowing their exposure, their vulnerabilities, going far beyond just looking at the risks of non-compliance.

The entrepreneurial auditor must perceive the opportunities for improvement, improvement and innovation that exist in business cycles, in operational processes, in aligning the use of resources with an effort to achieve the strategy.

Also, must be proficient in the application of audit standards, in the evaluation methodology, in the audit techniques and procedures and in the use of best management practices.

It must go beyond the trivial, helping management to see the actions that must be taken today so that the corporation remains competitive tomorrow.

Finally, I remembered a conversation with a C-Level of a business unit located in Ireland, some 25 years ago, where, in his view, the audit only served “to count the dead on the battlefield”, and what he needed was to have an audit that would support him in strengthening his actions so that he could win the war, with the fewest casualties possible.

This conversation reflected me a lot, because he was not wrong, we made reviews always looking at the past, and very little, or almost nothing, looking at the future. This conversation made us started to change our scope of work, in a timid but consistent way.

In my walks in the internal audit world, I still see that many auditors continue to “count the dead”, looking for errors and non-conformities in the transactions carried out. Not that it is not relevant to perform compliance assessments, but the auditor must be much more proactive than reactive in order to assist the organization in achieving its objectives.

Being part of a modern, proactive internal audit, with an entrepreneurial, innovative, participatory, collaborative, creative and resilient vision should be a goal for any internal audit professional who wants to have a place in this globalized world, which is increasingly volatile, complex, ambiguous and uncertain.

The decision of where you want to be is yours and nobody else. Only you can decide if you want to keep counting dead, or if you want to be an entrepreneurial auditor.  

So, as Jack Welch said:

Change before you need to do it

 

But Always Be happy!