Friday, April 21, 2023

The future of the auditor - The Gardener of Governance


 We have been talking a lot about the future of internal auditing, but in reality we should talk about the future of the auditor, because in essence auditing in its concepts will not need significant changes for its existence. 

On the other hand, the auditor must change his "mindset" if he wants to continue being an auditor. The metaphor about "Gardener of Governance", brought by Dr. Rainer Lenz, is a good start for us to understand how to prepare for this change, which, those who haven't started yet, are already late.

“We need to be more like farmers” and sees the auditor as respectful of nature, concerned with creating the right environment for plants to grow, due to climate and soil conditions. Internal auditors must sow, fertilize, water and nourish the plants, continuously check the weather forecast and adapt the fertilization of the plants accordingly.   Occasionally weeding, all done patiently and humbly, but also results oriented and focused. Internal auditors work indirectly and therefore their impact is through others."

In a process of corporate change as we are experiencing, speed, proactivity and protagonism are essential attributes for all professionals who want to maintain their employability, and for the internal auditor, as well as for the specialist in internal controls, it is no different. 

In my last position as CAE, the metaphor they used for auditing was "Keeper of the keys to Hell's Gate", but that, as we know, is in the past. Jack Welch always said that "Change before it's necessary, then it's too late" 

Be Happy! 

#future #mindset #employability #internalaudit #internalcontrols #inspiringpeopleforinnovation

Saturday, February 18, 2023

Corporate governance and integrity programs, are they a fiction?

 


With each case of corporate rupture that is published in the media, there is always questioning about the effectiveness of the governance structure and its compliance programs, including the integrity program.

The main question concerns how the violation of the corporation's moral values materializes in a company that demonstrates that its structure has governance policies and programs, required by law and regulations.

How its happen in companies that report having state-of-the-art structured compliance policies and integrity programs, some with certificates from important institutions, where, in some cases, specialist employees participate in industry events lecturing on the quality of their programs of combating corruption, bribery and other wrongdoing. How do these violations occur?

Not to mention, for sure, how come the risk management system and the internal control system, as well as the internal and external audit, if applicable, did not detect this violation of moral values?

Of course, the answer is not simple, because, each case is a different case. The root cause of the violation can have several components.

However, one of the causes that is present in almost cases is the lack of commitment and true attitude, on the part of management, in relation to all these governance requirements, and their moral values.

It is as if, all of this were mere “bureaucracy”, in the negative sense of the word, and that this whole structure and policies only serves to show the market, society and regulatory bodies that the company is in “compliance”.

It is important to point out that one of the causes is centered on the condition that companies and specialist professionals focus a lot on the form, but forget the essence. They forget that it is not possible to only have compliance policies and integrity programs, if there is no attitude, awareness and organizational culture for this to be true.

As much as we live in a digital age, where automation is increasingly part of organizations, it is necessary to understand that companies are still driven by people, who do not act by algorithms, but by their emotions, creeds, knowledge, goals , vision of life and logically, for its ethics.

Greed, winning for the sake of winning, selfishness, are also part of people's attitudes, and logically, organizations need to take all these attitudes into account in their governance process.

The effectiveness of governance, compliance and integrity depends on having ethical people who are truly in line with the company's moral values.

Management, including HR management, must prioritize that the people who are part of company's staff present, at least, the following attributes:

Willing
It refers to the individual choice to always do the right thing. It focuses on the certainty that, among the existing options for action and decision, in the process of achieving objectives, the choice will always be the one that best suits the moral values of the corporation.

Responsibility
It is based on the responsibility to always choose and/or keep what is right. It is to recognize the responsibility it has to continuously promote, through behavior that actions and decisions must always be aligned with the values of integrity of the company.

Commitment
It is the individual engagement and involvement in always doing what is right, regardless of the obstacles, and the contrary forces involved, without exception. Commitment is demonstrated by daily attitude and behavior.

Accountability
The individual must always transparently assume the consequences of his acts and/or omissions in relation to what is right. He must act with diligence and timely report any act of violation of the moral values of the corporation that comes to his knowledge.

In my opinion, governance structures, compliance and integrity programs will only be true and effective when corporations recognize the importance of applying good management practices in conducting their business, by people who are truly willing, responsible, committed and diligent in carrying out its activities within what is right.

As long as companies do not excel in having people with ethics aligned with corporate moral values, everything that is said about governance, compliance and integrity will continue to be a great fiction.

Finally, I always like to remember that in the chaotic world we live in, simplicity within corporate activities is a competitive advantage, even when dealing with a complex topic like this one, however remember that simplicity is not superficiality!

Be happy!

Wednesday, December 21, 2022

O Futuro da Auditoria Interna - Gardener of Governance


O futuro da auditoria interna neste novo contexto corporativo é um tema recorrente nos encontros e grupos de auditores.

Em minhas pesquisas para consolidar minha visão sobre o tema, me deparei com um artigo, onde os autores utilizam o jardineiro como uma metáfora para tratar dos atributos que a auditoria interna deverá perseguir para se manter relevante nesta nova dinâmica de negócios.

Em um encontro com os autores, para compreender um pouco melhor o ponto de vista deles, resolvemos traduzir o artigo para compartilhar com os profissionais dos países de língua portuguesa. Vocês podem baixar o artigo pelo link abaixo.

Boa leitura e ótima reflexões.

Thursday, July 28, 2022

Let's make enterprise risk management simple!

 


Today I want to bring to our reflection a fundamental theme for the consolidation of corporate governance.

Let's talk about enterprise risk management.

I was preparing the course, and I came across a slide that I use to explain, the structure applied to risk management, and I felt motivated to bring this topic to our discussion.

Anyone who follows me on social media knows that I always try to bring a simple view to important topics related to management and governance, facilitating understanding and their application in corporate activities.

Simplicity is currently a competitive advantage for the organization, but understand that being simple does not mean being superficial.

Well, let's get back to our topic, which is risk management.

In a simple way, I can say that:

“Managing risks is a proactive activity, looking to the future, understanding the events, external and/or internal, that may materialize and adversely impact the company's or process's ability to achieve its objectives; evaluates them for their magnitude, and treats them based on the acceptable levels of risk defined by the corporation.”

The primary objective of risk management is to allow the corporation, in the pursuit of fulfilling its mission, to conduct, direct and maintain its activities, actions and decisions, within its acceptable level of risk, defined by risk appetite.

The starting point for risk management is the correct understanding of objectives, whether strategic, corporate and/or operational. If we do not know the objectives clearly, it is difficult to know the risks in a comprehensive way.

Not using objectives as a basis for identifying risks is the most common mistake I find in corporations, causing time and resources to be spent in a wrong and ineffective way.

Remember that the risk event directly impacts the ability to achieve the objectives.

Regarding the operational objectives, those that relate to the various existing processes for the operationalization of the organization's activities, I recommend the definition of the objectives inherent to each of the processes, as well as the objectives related to legal compliance, objectives related to moral values of the organization, and objectives related to the consistency, integrity, confidentiality and recoverability of the processed data.

The better the definition of objectives, the more effective the identification of risks tends to be.

Well, since we have already determined the objectives, we now begin the process of identifying the events, external and/or internal, that may impact the corporation.

Then, in a simple way, we begin to identify the risks that, if materialized, will adversely impact the organization's ability to achieve its objectives. We can see risk as the negative view of the objective, for example: If one of the inherent objectives of a purchase process is to buy only products and/or services necessary for the operation of the corporation, the risk may be the purchase of products and/or or services not necessary for the operation.

Based on the understanding of the objectives, try to identify all risk events that relate to it. This is a brainstorming activity. There is no Cartesian way of doing this.

Once all the perceived risks are related, the next step is to know their causes, that is, the events that could materialize the risk.

It is the risk factors (causes) that we assess the magnitude of and that we treat, so it is important to be judicious in identifying them.

To illustrate, let's go back to the example of the purchasing process, why can the corporation buy products and/or services not necessary for the operation? The answers to this question will allow us to identify the risk factors. Example: a. A wrong purchase requisition, b. Lack of inventory planning, c. A fraud.

This procedure must be performed for all identified risks, without exception.

Very well, at this point, our risk matrix already has three basic columns: Column of objectives, column of risks related to each of the objectives and column of risk factors related to each of the identified risks.

The next step is the analysis and assessment of risk factors through the matrix reading of probability (frequency) and impact (in several dimensions, such as financial, image, market-share and others).

At this point, it is important that the corporation has metrics, approved by senior management, to assess the magnitude (probability and impact) of risk factors.

It is also important that the company already has a risk appetite defined by top management. As a suggestion, to facilitate the risk management process, guide senior management to define the risk appetite based on the heat map resulting from the metrics, indicating the quadrant that should be considered as the accepted level risk.

I like to use metrics with five levels of probability and five levels of impact, so that the heat map has quadrants from 01 to 25. In this case, risk appetite can be defined as being one of the existing quadrants, for example the high management can direct your risk appetite to quadrant six, so anything above will need to be addressed.

One of the problems that I come across, in this evaluation stage, is in relation to the use of complex metrics, with the inclusion of weights, weighted average and other calculations that only bring complexity and delay to the process.

Note that, more important than the accuracy of the risk factor measurement, is the action that management takes to address it. It doesn't matter if the risk is 15,234 or 15, what really matters is the action that management takes to mitigate the risk factor.

The calculation is simple: probability x impact = gross risk

Another important point at this stage of the evaluation is the definition of impact, that is, if the event materializes, what impact will it bring to the organization. Some corporations seek to assess impact through a weighted average across the various dimensions. The suggestion is to work with the dimension that receives the primary impact, and not with a weighted average of the impact in the different dimensions, because, note that this is not how it happens in reality. Example: if the event materializes and impacts the image, it will not necessarily impact, simultaneously, the other dimensions measured, so it is best to focus on treating the effect on the image, ensuring that it does not affect secondarily the other dimensions.

Okay, now that we know the magnitude (gross risk) for all risk factors, whether inherent, compliance, fraud, or IT, the next step is to compare the magnitude obtained with the risk appetite, and based on in this, determine the best treatment to align the raw risk with the risk appetite determined by the organization.

Keep in mind that the primary objective of risk management is to enable the corporation to act within its acceptable level of risk, formalized through the definition of risk appetite.

Risk factor treatment can be: Accept, Share, Avoid and Mitigate.

We can accept the risk, when the gross risk is already aligned or below the risk appetite, however accepting the risk does not mean doing nothing, but monitoring the risk factors, because today it is low, tomorrow it may change and with this change our treatment.

Another important point is in relation to who can accept the risk, and my suggestion is that it need to be accepted by the statutory managers, since legally they are the ones who take the risk for the company, including their private assets.

Sharing risk is a process where another corporation, be it a financial institution or an insurance company, accepts to take part of the risk for the company. Example: Insurance policies, or foreign exchange hedge. Note that this is an answer on impact and not probability.

Another form of treatment for risk factors is risk avoidance. It is one of the most difficult answers to work with, because in order to avoid risks, the organization can no longer be exposed to risk, which means, in most cases, strategic decision-making, such as the company's exit from a market, or closing a unit, or not carrying out an operation, etc.

Finally, we have the possibility of mitigating the risk factor, which operationally speaking, requires the implementation of an internal control to mitigate the probability of the risk event materializing.

Just remembering that internal controls are:

“Actions, formalized in policies and procedures, aimed at mitigating the probability of materialization of the risk event. These are actions of review, checking, certification, validation, authorization, approval, etc.”

Depending on the materiality and nature of the risk, in addition to the probability response, it will be necessary to prepare a contingency plan, which aims to minimize the effect of the impact, when the risk event materializes.

Once the responses have been determined and implemented, the next step is to calculate the residual risk, which is the effect remaining after the treatment action, and make sure it aligns with the risk appetite defined by the corporation.

Remember that simplicity is currently a competitive advantage! Bring simplicity to operation, not superficiality!

Be happy!