Friday, February 19, 2021

Internal controls, the responsibility of everyone!


Questioning who is responsible for internal controls is a common and recurring situation in the corporate world. When the company has an area of ​​internal controls, it is attempted to wrongly attribute this responsibility to it.

Why does this happen?

In my opinion, this behavior is a consequence of the lack of maturity in the management process in relation to good practices, in line with the fragility of a university that does not properly teach managers.

This weakness is evident when, managers and other professionals, relate internal controls to bureaucracy and / or “plastering” the business process. They fail to see and associate that internal control is a response to the action of mitigating a risk factor, which results in increasing the company's ability to achieve its strategic objectives.

The maturity of governance involves the improvement of the internal environment through the strengthening of the culture in the use of good management practices and the consolidation of awareness of risks and controls.

An essential point for this to happen is the correct addressing of the responsibility of each person within the organization in relation to the internal control system.

The model of the three management lines helps us to demonstrate these responsibilities, and was the basis for the construction of the diagram that I prepared to facilitate this understanding.

Let's see:

1. Governance Structure - I include here the Board and statutory committees, which are responsible for promoting the appropriate environment for the culture development and awareness of risks and controls. In addition, they must be committed to good management practices, supervising and monitoring the application of these concepts by the executive and operational management, following up on the implementation and improvement of internal controls.

2. Executive and Operational Management - In this case, executive management is the president and his directs, while operational management is the managers below the executive management line. The responsibility lies in exemplifying the commitment to internal controls, and in defining, implementing, executing and supervising the internal control system in order to keep operational risks within acceptable limits, as defined by the corporate risk appetite. This first line of management are the “owners” of risks and control, with no exception.

3. Specialists - Responsible for supporting the executive and operational management, first line, to apply the best management practices for the modeling, implementation, maintenance and improvement of the process and its internal control system integrated with the corporate risk management structure. This group includes specialists in internal controls, specialists in risk management, compliance and governance. They are the second line of management.

4. Internal audit - It is an independent and objective activity, usually reporting to the governance structure, with the objective of adding value, through the application and execution of an independent and objective evaluation on the internal control, risk management and corporate governance systems.

As you may see, every single person within an organization, without exception, has explicit responsibilities regarding internal controls, either in their design, implementation, execution or in their quality.

However, the greatest responsibility is left to the executive management (president and its directs) which must promote the properly environment, based in the ethics and best practices, in order to create the culture where all managers and employees recognize their responsibility for the existence of high quality internal control system.


I would like conclude this article with this quote:

“The great enemy of truth is often not the lie - deliberate, contrived and dishonest - but the myth - persistent, persuasive and unrealistic” J.F.Kennedy

 

Always, be happy!

Thursday, January 14, 2021

Approach 4.0 for Internal Controls Specialist


 


The internal controls specialist, especially those with CICS - Certified Internal Control Specialist certification, cannot be supporting actors, they need to be protagonists, leading the dissemination and application of the best management practice structures in their organization, supporting management in this process structural changes, allowing the company to maintain its competitive advantage.

For this, internal control professionals must innovate their approach in the activities of modeling, implementation or evaluation of operational processes, risk management and internal control system.

Having a more holistic view of the company, aligning the market, strategy and operation, is a fundamental requirement for the specialist. He needs to see and understand the meaning of the "parts" in the "whole" business, making sense throughout the operation's ecosystem.

In addition to all the technical and managerial training that this professional must have, he needs to include, in his activities, new structured models, breaking paradigms and expanding his coverage and vision beyond the controls

Thinking about encouraging some reflections and also contributing to these changes, I describe in the diagram, some attributes, which I consider essential, and which should be part of this approach which I called, for lack of creativity, as 4.0, alluding to the fourth industrial revolution that focuses on increased efficiency and productivity using physical cyber systems, automation, IOT, cloud and others.

Let's take a look in these attributes:

1. Evaluation of the organizational structure based on a business vision, so that it can promote the alignment of the capital applied in the operational organization with the planned strategic return,

2. Application of structured and disciplined methodology to evaluate processes and activities, considering the inclusion of agile principles and values,

3. Add a review of the performance of the governance, compliance and integrity program as a requirement in the processes, tasks and environment assessment and validation programs,

4. Use of data science techniques and tools in its processes for surveying and testing the efficiency and effectiveness of the internal control system, such as for database validation and information security,

5. Strengthen the vision of strategic and operational risks inherent to the corporation, paying special attention to the emerging risks, whether in the management of data processing technology applied to operational processes, in innovation, in the market, or in other dimensions that may impact the organization's ability not to achieve its mission,

6. Identify the best management practices that can be considered as paradigms for improving performance and innovation, promoting them in the structure, strengthening the control environment and perfecting the fundamentals of corporate governance, risk management, internal control systems, compliance and / or other related activities.

As you may see, the adoption of these attributes, in the activity of internal controls, requires a change of “mindset”, not only of the professionals of internal controls, but also of the management, at all levels.

Every change generates reaction and resistance, so that in order to be successful they must be planned, including in this plan a robust process of sensitizing the structure for the promotion and justification of awareness and culture of efficiency, risks and controls, mitigating the risk of not being successful in this change.

I end this article with a phrase that always helps me when I'm making some excuse for not changing, which is:

"Change is the law of life, those who look only to the past, or to the present will be forgotten in the future" J.F Kennedy

 Be Happy!


Friday, October 30, 2020

The entrepreneurial internal auditor, a new generation, a new posture, a new vision!

 


In some meetings with members of audit committees, from different sectors, a common point that caught my attention was the dissatisfaction of the committee with the results of the audit assessment work.

In a nutshell, the most significant complaints revolved around the reactive attitude of the audit, very concerned with finding mistakes made in the past, often without understanding the root cause, generating innocuous recommendations and with little or no impact on the organization's performance, and also the low cost and benefit ratio of the audit, since it is not clear whether the results delivered bring something positive, savings or process improvement.

I understand the frustration of these directors, but I also understand that the internal audit, often, does not receive the support or necessary guidance for the improvement of their activities.

The audit committee has a share of blame in this process, since, being responsible for the audit activities, it has the obligation to give full support to the audit, in its structure and proficiency, as well as in the approval of the annual plan, including the definition of what will be audited object, the approach of the review and the emphasis that should be given on its scope.

The committee is a supervisory body, but also an advisor and guardian of good practices and quality that must be pursued by the audit team. I will not go into this in more depth, I will leave this topic for reflection in another article.

Let's go back to our central point, what I called “the entrepreneurial auditor”.

You may find this denomination strange, but it was the way found to try to convey the idea of this new posture and new vision that the auditor must conceive and apply in his activities. In order to understand where I want to arrive, I first need to let you know my vision of what is be an entrepreneur means:

“Be an entrepreneur is to do something new, realizing the opportunities, recognizing the risks and adversities. It is the ability to transform, go beyond what is expected, in a creative and resilient way.”

Now we will review the internal audit mission according to the IIA - Institute of Internal Auditors, which says that the internal audit mission is:

To enhance and protect organizational value by providing risk-based and objective assurance, advice, and insight.

 

Once these concepts are understood, we can idealize that the entrepreneurial auditor is the mixture of these two concepts.

Now we need to take into account that the corporate world has undergone profound changes, by significant paradigm disruptions.

Doing business or managing a process is very different than five years ago. Today the market is more globalized, more technological, more innovative, more disruptive and with a strong convergence to the digital, virtual world.

Technology allows borders to be gradually eliminated, opening up a vast market of operation, as well as allowing new players to enter the market only in a virtual way.

This disruptive innovation process is challenging for any corporation, making it significantly essential that the company has a strengthened governance structure, and that governance awareness is the basis for an internal environment that provides greater flexibility and adaptation of management to new market requirements. and competitiveness, without the operation losing its essence.

It is precisely in this boiling environment that the internal auditor, like the other managers, is inserted.

The internal auditor has an important role in promoting ethics and values ​​of conduct so that this culture is not lost during innovation processes. The auditor has the responsibility to contribute to the organization by making intelligent appointments that direct the necessary changes which will make either the processes or the organizational structure more innovative, more effective and more economical.

For this, the internal auditor must have an entrepreneurial vision, knowing and weaving a clear vision of the dynamics of corporate business, understanding the strategic objectives and their relationship with the organization's mission. He also needs to have a clear view of the operating cash flow cycle of the operation so that the strengthening of this cycle is always part of your assessments.

In addition, the entrepreneurial auditor must comprehensively understand the corporate risks present in the organizational and business structure, knowing their exposure, their vulnerabilities, going far beyond just looking at the risks of non-compliance.

The entrepreneurial auditor must perceive the opportunities for improvement, improvement and innovation that exist in business cycles, in operational processes, in aligning the use of resources with an effort to achieve the strategy.

Also, must be proficient in the application of audit standards, in the evaluation methodology, in the audit techniques and procedures and in the use of best management practices.

It must go beyond the trivial, helping management to see the actions that must be taken today so that the corporation remains competitive tomorrow.

Finally, I remembered a conversation with a C-Level of a business unit located in Ireland, some 25 years ago, where, in his view, the audit only served “to count the dead on the battlefield”, and what he needed was to have an audit that would support him in strengthening his actions so that he could win the war, with the fewest casualties possible.

This conversation reflected me a lot, because he was not wrong, we made reviews always looking at the past, and very little, or almost nothing, looking at the future. This conversation made us started to change our scope of work, in a timid but consistent way.

In my walks in the internal audit world, I still see that many auditors continue to “count the dead”, looking for errors and non-conformities in the transactions carried out. Not that it is not relevant to perform compliance assessments, but the auditor must be much more proactive than reactive in order to assist the organization in achieving its objectives.

Being part of a modern, proactive internal audit, with an entrepreneurial, innovative, participatory, collaborative, creative and resilient vision should be a goal for any internal audit professional who wants to have a place in this globalized world, which is increasingly volatile, complex, ambiguous and uncertain.

The decision of where you want to be is yours and nobody else. Only you can decide if you want to keep counting dead, or if you want to be an entrepreneurial auditor.  

So, as Jack Welch said:

Change before you need to do it

 

But Always Be happy!

 

 

 

Tuesday, July 21, 2020

The three lines of "defense", a new vision!

Yesterday the Institute of Internal Auditors released the new vision of the three lines, and the title caught my attention, as it does not mention the word “defense”, which can be either a mistake or deliberate, demonstrating that the members of each line are not there to defend, but to manage, add value, including the third line,  which makes much more sense to me.

The original model emerged with the publication on September 21, 2010 by FERMA and ECIIA in the Guidance on the 8th EU Company law as a recommendation for implementing the law's requirements for monitoring the effectiveness of the internal control system, internal audit and risk management.

This update model solved an anomaly of the previous model, which demonstrated a duality in the internal audit reporting line, an arrow for senior management, and another for the level of supervision and governance, creating some “noise” about the independence of the internal audit activity, with no much sense

In this new format, it is very clear that the reporting line should only be for the level of supervision and governance (Board and Committee), and the relationship with senior management (President, their directs) is a process of alignment, communication, coordination and collaboration. This point reinforces the importance of independence for the existence of an effective and integrated internal audit to the businesses.

This subject regarding independence is also addressed by principle 5, which objectively describes the independence of the audit in relation to management responsibility, as you may see below:

Principle 5: Third Line Independence

Internal audit´s independence from the responsibilities of management is critical to its objective, authority, and credibility. It is established through: accountability to the governing body; unfettered access to people, resources, and data needed to complete its work; and freedom from bias or interference in the planning and delivery of audit services.

Another relevant subject, in my vision, that this model brings to our understanding to the role of the audit as a consultancy. It was a great confusion created when the definition of the audit was disclosed which includes in its statement that the audit adds value to the organization through assurance and consulting, which unfortunately, here in Brazil, allowed misunderstandings and great debates on this topic.

This new version accommodates this theme when it describes the roles of each of the lines, as we may see below, the role of the audit:

                             Internal Audit

  •          Maintains primary accountability to the governing body and independence from the responsibilities of management.
  •          Communicates independent and objectives assurance and advice to management and the governing body on the adequacy and effectiveness of governance and risk management (including internal control) to support the achievement of organizational objectives and to promote and facilitate continuous improvement.
  •          Reports impairments to Independence and objectivity to the governing body and implements safeguards as required.

 

Observe that it describes “independent and objective assurance and advice”, remembering that objectivity is the auditor's independence in positioning and giving an opinion, based on his competence and proficiency.

I have had that the audit fulfills its role as a consultant, not implementing or executing management activities, but rather, making intelligent notes to management on opportunities for operational improvements to strengthen the efficiency, effectiveness and economy of the risk management process, controls internal and governance.

This model also stresses that independence does not mean isolation, as there must be an interaction between the three lines. The auditors have to be aligned with the organization's strategic and operational needs in order to became a “trusted advisor and strategic partner”.

However, for this to be true, the auditors must go back to basics.

When I say go back to basics, it is that the internal auditors must objectively understand their mission and the definition of what auditing is, essential points that are described in the International Structure of Professional Practices of the IIA. In addition, must be proficient in application of the standards of attributes and performance when carrying out the evaluation and / or consultancy work.

Finally, I believe that some discussions will arise about the model and its application, and this is my contribution to the understanding of this new version of the three-line model.

 

Be happy!