We have worked with a number of leading clients on Risk assurance mapping. We help heads of internal audit to refocus their efforts in relation to risk assurance mapping, since it is very easy to spend a lot of time an effort in this arena with limited benefit.
Warning signs in relation to risk assurance mapping efforts include:
- Mapping out many processes
- No clear connection between the assurance map and key objectives and key risks
- A sense that the risk assurance map is going to become “another risk governance initiative”
- An unclear sense that there will be benefit, beyond a presentation to the board
- Lukewarm interest by other compliance functions
- No clear understanding of how the assurance map is going to operate on an ongoing basis
Key ingredients of a successful assurance mapping effort include:
- Creating a robust accountability framework for compliance matters, leveraging proven frameworks for compliance processes and governance
- Creating a robust accountability for the management of key risks
- Being clear about the benefits that are being sought
- Piloting the assurance approach in key areas to demonstrate its power
- Avoiding the temptation to either “boil the ocean” or to “prove its all OK”
We work with our clients in a step-by-step manner to make the assurance mapping process a positive one with clear benefits arising at each stage. This sometimes requires the need to educate key stakeholders about a realistic approach to the assurance mapping process. In addition stakeholders we have worked with gain a deeper understanding of the meaning of “reasonable assurance” and the need to tailor assurance work to fit in with the risk appetite and key concerns of the client organisation.
- Developing an assurance map for a client incorporating 11 key assurance functions, bringing the function heads on board and developing a standardised approach to understanding the assurance each is providing
- Organising an assurance co-ordination forum to maximise the information sharing from different assurance providers
- Developing a toolkit to clarify risk and assurance accountabilities in a joined up way (see knowledge exchange)
- Developing a toolkit to aid understanding of reporting and approval requirements (see knowledge exchange)
- Developing a robust audit universe
- Up-dating and streamlining audit planning and also the presentation of audit plans to gain greater clarity
- Developing a business toolkit for key risks and key controls
Sample Projects
Jan 2019 – Apr 2019
| Programme and project assurance map | Helping to resolve roles and accountabilities between an internal audit team and a programme management office. |
March 2018 – June 2018
| Risk Assurance | Working with a CAE and quality standards manager to validate and up-grade work done on risk assurance mapping to create a more practical and sustainable solution and to overcome the risk of assurance “black holes”. |
Mar 2014 – Oct 2016
| Controls project | Support for a leading multi-national to implement a new controls framework, using lean and agile techniques as well as best practices, to create a fit for purpose but robust toolkit for managers. |
Aug 2012 – Sep 2014
| Internal Audit transformation | Support to a new FTSE CAE – up-dating the planning process, implementing an assurance framework, creating a new lean audit methodology, developing root cause analysis techniques, coaching the audit team to be high performing. |
Jan 2020-October 2020 | Internal audit transformation and re-organisation | Supporting an audit committee and executive in priority areas for focus to up-grade an international internal audit function. |
Jun 2013 – Present
| Audit committee training on GRC and internal audit (numerous clients) | Numerous examples of board and audit committee level training on risk management and the importance of getting risk embedded in business as usual activities and some of the common blindspots you can see in even the most sophisticated risk management processes. |