Wednesday, February 20, 2013

Is IA success influenced by Board & Management desire?‎


The traditional perception indicates that “Internal Audit will be what senior management wants it to be “. I was reminded of this while reading the Framework for Excellence Article in the Ia magazine's February issue. In particular, this statement caught my attention:

“Ultimately, an audit department can only be as advanced as the board and senior management want it to be”


Do you agree with this statement?
More importantly, do you accept this as being the normal way of doing business?
Do you feel that Internal Auditors can influence how the Board & Management perceive their work?

Can you share your experience and share your success story?











picture credit:http://gearingforsuccess.ca/gearing-for-success/

Tuesday, February 19, 2013

Do you have what it takes to be a mentor?

Being a mentor provides a great deal of job satisfaction and makes jobs more enjoyable and productive! However, not everyone has got what it takes to be a mentor.
To be a mentor, one should be:
- a good listener
- a leader
- patient
- willing to share knowledge
- experienced
- committed
- and above all, has the right mindset

Why Become a mentor?

An article published by the ExecutiveBrief lists the following argument :

"A great number of mentors claim that by being a mentor, one earns the respect and recognition of peers. Mentoring enhances authority, thus firming up one’s position within the organizational structure. The mentor likewise is given the opportunity or the chance to learn from the mentee."
While I agree with the above statement, I do not support the notion that mentoring should be used for enhancing the mentor's position. This should not be an objective by itself but can be a byproduct of the mentoring process.

I have come across a useful publication by Human Resources and  Skills Development Canada ( HRSDC), which provides good guidance about mentoring. I would like to share it with you. It can be accessed here.

Have you thought about mentoring?
If you already have, was it rewarding as promised?

These are my thoughts, please share yours!



picture credit:http://www.trudeaufoundation.ca

Thursday, February 7, 2013

Differences and Similarities Between Fraud and Corruption


Fraud and corruption are two words that we hear too often. Both are on the rise worldwide, and their methods are evolving to adapt to the development of technology. Who among us did not receive at least one fraudulent email during the last month?

Is corruption a form of fraud? Or are these two different things? A review of the definition of the terms may offer an answer :

A handbook published by the World Bank Group (Fraud and Corruption Awareness Handbook Defines fraud and corruption as follows:

A fraudulent practice is any act or omission, including a misrepresentation, that knowingly or
Recklessly misleads, or attempts to mislead, a party to obtain a financial or other benefit or to avoid
an obligation.”

“A corrupt practice is the offering, giving, receiving or soliciting, directly or indirectly, of anything of
value to influence improperly the actions of another party.”

An IIA Chicago Chapter presentation (Auditing for Corruption in Emerging Markets) provides the following explanation of the two terms:

Fraud:
Deriving undue benefit by bypassing some controls or bending some rules. Fraud Schemes are used to commit corrupt activities:

• Asset Misappropriation
• Financial statement irregularities
• Corruption

Corruption:
Takes place in the form of providing illicit benefits; harder to find; narrower scope than fraud.

• Bribery
• Embezzlement
• Extortion
• Influence Peddling
• Unlawful gratuity favor or commission
• Nepotism
• Illegal Political contribution

 The Business dictionary differentiates between these two terms as follows:
 Fraud is misrepresenting yourself or something as something you or it is not. For example, if you use a fake ID, you’re committing fraud by misrepresenting yourself as someone else.
Corruption is a broad term that can be applied to fraud, as well as other dishonest acts such as bribery, extortion, or embezzlement.
The two can be used in a wide array of instances but can apply specifically to business. Corporate leaders are often prosecuted for various fraudulent and corrupt acts, as well as political leaders.

Have you reached a conclusion yet? One thing we can, for sure, agree on: Fraud and Corruption are very bad practices and should be prevented and detected at an early stage.




Photo credit:Shutterstock










Tuesday, January 22, 2013

How to tarnish your company's reputation in 30 seconds?‎


Yes it’s possible; it only takes an inappropriate tweet or a status update on a social media web-page such as Facebook , LinkedIn  or a short video on  You Tube to cause a major damage to a company’s hard earned reputation or brand .This could happen intentionally or as a result of ignorance or oversight.  While the company may not have control over the intentional acts, it can do something to eliminate, or at least minimize, the actions caused by ignorance or oversight. Here is what I think can be done:
  • It starts with recognizing the power & risks of social media .If management does not believe in it, then such management is part of the problem, not part of the solution.
  • Raise awareness at all levels in the company about the benefits and risks associated with social media.
  • Conduct training to educate all employees on how to deal with social media at work or in their private life.
  • Set a clear and concise social media policy and ensure that it is distributed to and understood by all employees.
  • Include social media risks in the company’s risk management plan.
  • Include social media behavior in the company’s Code of Ethics.
  • Perform Social Media audits on continues basis.
Can you suggest more actions or discuss your company's experience with this issue ?

Tuesday, January 8, 2013

‎ Shall we promote the CAE to CAO?‎


The Head of the Internal Audit department is usually referred to as the Chief Audit Executives (CAE). It seems this is a generally accepted title and is being used worldwide. But, do you think that it undermines the position compared to the other “C” suite positions? For example, we don’t call the top financial person Chief Financial Executive ( CFE), we call him/her Chief Financial Officer ( CFO). The same applies to other executive positions  such as CEO, CIO , CRO...
If we really want a seat at the table, shall we start by having the right title!! Why not start by changing CAE to CAO (Chief Audit Officer).
I am interested in your views and I hope that it goes beyond “ this is a formality “ and “ substance over form” cliche!




Sunday, December 30, 2012

New Year Resolution suggestions for Internal Auditors!‎


As we are about to start a New Year in our professional life, I thought of putting together an example of suggested New Year resolutions for internal auditors:

- Improve your IT skills & knowledge (this is a must-have).
- Keep current with the latest business, corporate governance, and internal audit issues.
- Have the courage to report things as they are.
- Keep a close eye on current and developing risks.
- Be a strong advocate and promoter of internal audit and corporate governance.
- Listen more, speak less ( you need to speak up when you have to).
- Make sure you fully understand your company's strategic objectives.
- Educate Audit Committee (and others) on current trends in business, internal audit & other issues.  
- Set a goal of learning something new every day.
- Add value in everything you do.
- Always be proactive,
- Look at the big picture,
- Don't wait until December to earn your CPE!

     
Wishing you all a successful and prosperous new year.

Monday, December 17, 2012

Risk - based vs. Objectives - based Audits !

In complying with the IIA CPE requirements , I have re- read some of the articles in the Ia magazine .This has given me the opportunity to think about one particular article in the April 2012 issue " Step up to the Plate ".

The authors of the article say that internal auditors are shifting away from the traditional risk-based approach toward one where the company's goals and objectives become the focus.They define the new objectives - based approach as the approach where the company's objectives and goals become the central focus of the audit.The authors explain that " After all, risks are only relevant when seen in the context of the company's objectives".
The authors explain the advantsges of the new approach as follows :
"The chief advantage of the objective-based approach is that it enables a more targeted audit by focusing audit resources only on those risks that truly matter to the organization’s strategies and goals. It also accounts for low-priority risks and enhances the capacity of internal audit to achieve its objectives. Implementing an objective-based approach involves:
  • Relying on people for risk input. Managers across the organization deal with risks every day. Because they understand their objectives, they tend to know instinctively which risks may impact those objectives, making them best positioned to help auditors understand the relationship between the company’s objectives and its risks.
  • Mapping risks to objectives. Internal auditors can use managers’ responses to quantify the relationships between risks and objectives. Applying this method enables practitioners to discover risks they had not considered.
  • Identifying risk patterns. Risks interact with each other and with objectives in complex ways. Auditors need to understand these interactions instead of looking at each risk in isolation. The whole is often more dangerous than the sum of its parts—much like reading a book while crossing a road is more dangerous than doing each activity independently.
  • Focusing risk management on the most critical objectives. By putting objectives before risk, auditors can mitigate those risks that impair the achievement of objectives and exploit risks that enable value creation. This helps internal auditors use audit resources efficiently, facilitate transparency, and align risk management with business strategy."
 
 Do you agree with the above ? Are you shifting your focus to the objectives - based approach?
 Do you recognize the difference between the two approaches ,or do you think they are the same ? Aren't both of them , at the end of the day, focus on risks to the achievement of objectives?

Whatever you think about this subject ,I strongly recommend that you read the entire article .

Humans: The Real Risk Factor in AI

  Artificial Intelligence is often seen as the looming risk to society. However, the greatest risk lies not in the algorithms themselves, bu...