Utfordringer med de tre forsvarslinjer

Like dokumenter
Intern revisjon Intern kontroll

En praktisk anvendelse av ITIL rammeverket

Asset Management. Compliance og Operasjonell Risiko. Asle Bistrup Eide. Presentasjon i VFF den 28. november 2012

ISO 41001:2018 «Den nye læreboka for FM» Pro-FM. Norsk tittel: Fasilitetsstyring (FM) - Ledelsessystemer - Krav og brukerveiledning

ISO-standarderfor informasjonssikkerhet

Erfaringer fra en Prosjektleder som fikk «overflow»

Helhetlig risikostyring og informasjonssikkerhet. Knut Håkon T. Mørch PricewaterhouseCoopers Tlf.

FM kompetanseutvikling i Statoil

RS402 Revisjon i foretak som benytter serviceorganisasjon

Hvordan vurdere/revidere overordnet styring og kontroll

REVISJON AV COMPLIANCE-PROGRAMMER

av Trygve Sørlie - Revisjonsdirektør i Gjensidige

Bedriftscase 1 Positive konsekvenser av tøffe krav

PAS 55 kvalitetsstandard for anleggsforvaltning i infrastrukturselskaper. Elsikkerhetskonferansen 2013 NEK

Nytt fra INTOSAI. CAS Oslo October

FM kompetanseutvikling i Statoil

Public roadmap for information management, governance and exchange SINTEF

Rapporterer norske selskaper integrert?

Styring og ledelse av informasjonssikkerhet

CSR i Norden hvor er vi, og hvor går vi?

Independent audit av kvalitetssystemet, teknisk seminar november 2014

INSTRUKS FOR VALGKOMITEEN I AKASTOR ASA (Fastsatt på generalforsamling i Akastor ASA (tidligere Aker Solutions ASA) 6. mai 2011)

FM strategi: Bruk av standarder for sourcing, effektivisering og dialog

Lovlig bruk av Cloud Computing. Helge Veum, avdelingsdirektør Cloud Inspiration Day, UBC

Nye krav i ISO 9001, hvilke er de og hvordan implementere disse i TQM? Ragna Karoline Aasen

Lovlig bruk av Cloud Computing. Helge Veum, avdelingsdirektør Difi, Oslo

IEA PVPS. Trond Moengen. Global co-operation towards sustainable deployment of photovoltaic power systems

The Union shall contribute to the development of quality education by encouraging cooperation between Member States and, if necessary, by supporting

Capturing the value of new technology How technology Qualification supports innovation

Risikokultur grunnmuren i risikostyring

NIRF Finansnettverk. Trond Erik Bergersen

Luftfartstilsynets funn under virksomhetstilsyn.

Grunnlag: 11 år med erfaring og tilbakemeldinger

Den europeiske byggenæringen blir digital. hva skjer i Europa? Steen Sunesen Oslo,

Arbeidet i en working group. Charlotte Grøntved

Strategi med kunden i fokus

Baltic Sea Region CCS Forum. Nordic energy cooperation perspectives

Compliance i praksis:

Når beste praksis rammeverk bidrar til bedre governance. Ingar Brauti, RC Fornebu Consulting AS

Standarder for Asset management ISO 55000/55001/55002

Procedure / Procedure 00 Håndbok for Kvalitet, Miljø og HMS / Manual for Quality, Environment and Safety

Jeanette Wheeler, C-TAGME University of Missouri-Kansas City Saint Luke s Mid America Heart Institute

Oppdatert NORSOK N-005

Microsoft Dynamics C5 Version 2008 Oversigt over Microsoft Reporting Services rapporter

Tor Solbjørg (diplom. IR, statsautorisert revisor) Revisjonssjef Helse Nord RHF

Revisjonsutvalg i Norge

RAPPORT RAPPORT OM EKSTERN EVALUERING AV INTERNREVISJONEN VED UNIVERSITETET I OSLO - IHHT. IIA STANDARD 1312

CITY OF OCEANSIDE JUNE 30, 2018 SINGLE AUDIT REPORT

«Nett for enhver pris»

EBL kvinnenettverkskonferanse 25. april 2007

Trust in the Personal Data Economy. Nina Chung Mathiesen Digital Consulting

From Policy to personal Quality

VARSLING. Finn Berg Jacobsen Compliance Officefr

Requirements regarding Safety, Health and the Working Environment (SHWE), and pay and working conditions

Kontinuitetsplanlegging teori og praksis. Arve Sandve Scandpower AS ESRA,

Virginia Tech. John C. Duke, Jr. Engineering Science & Mechanics. John C. Duke, Jr.

Ny personvernlovgivning er på vei

Neil Blacklock Development Director

Hvilken standard angår oss i arkivdanningen?

Organizational Project Management Maturity Model (OPM3)

Norges Interne Revisorers Forening

Q2 Results July 17, Hans Stråberg President and CEO. Fredrik Rystedt CFO

Risikofokus - også på de områdene du er ekspert

ISO 9001:2015 Endringer i ledelsesstandarder

KIS - Ekspertseminar om BankID

Offshore Wind Turbine Support Structures. Erfaringer med å søke EU finansiering

Kanskje en slide som presenterer grunderen?

Opplæring i Miljøbevissthet

Itled 4021 IT Governance Governance, COBIT og ITIL

2A September 23, 2005 SPECIAL SECTION TO IN BUSINESS LAS VEGAS

Vurdering av risiko og sikkerhet i skytjenester. Håvard Reknes

Integrating Evidence into Nursing Practice Using a Standard Nursing Terminology

Internationalization in Praxis INTERPRAX

E-navigasjon Juni 2014

Gjenopprettingsplan DNBs erfaringer. Roar Hoff Leder av Konsern-ICAAP og Gjenopprettingsplan Oslo, 7. desember 2017

THE NOMINATION COMMITTEE S RECOMMENDATIONS TO THE ANNUAL GENERAL MEETING 2018

Green Corridors - EUs arbeid for bærekraftig godstransport

Sikkerhet, risikoanalyse og testing: Begrepsmessig avklaring

Er evnen like stor som viljen i Norge?

Feiltre, hendelsestre og RIF-modell

Oversikt over standarder for. Kvalitetsstyring

Hybrid Cloud and Datacenter Monitoring with Operations Management Suite (OMS)

6 December 2011 DG CLIMA. Stakeholder meeting on LDV CO 2 emissions - Scene setter

Internasjonalt samarbeid og nye kunnskapsmuligheter

- En essensiell katalysator i næringsklyngene? Forskningsrådets miniseminar 12. april Mer bioteknologi i næringslivet hvordan?

Lamorinda CERT - Unit 6 12/29/2015

Erfaringer med smidige metoder på store prosjekter i Telenor. Kristoffer Kvam, Strategic Project Manager, Portfolio & Projects, Telenor Norway

Itled 4021 IT Governance Introduksjon

Er norske virksomheter digitale sinker? Hva betyr det? Og hvorfor er de det?

EQUASS ASSURANCE FORBEREDELSE AV REVISJONSBESØKET HOS TJENESTELEVERANDØREN.

Internrevisjon i en digital verden

Hvordan komme i gang med ArchiMate? Det første modelleringsspråket som gjør TOGAF Praktisk

Innovasjonsvennlig anskaffelse

Status for IMOs e-navigasjon prosess. John Erik Hagen, Regiondirektør Kystverket

IT-lederkonferansen (Hvorfor) er norske virksomheter digitale sinker? Invitasjon til diskusjon basert på en pågående undersøkelse

Never Waste a good crisis Compliance i en krisesituasjon

Oslo, 9. juni 2011 Eirik Bunæs

European Crime Prevention Network (EUCPN)

Oversikt over standarder for. Kvalitetsstyring

Endringer i revidert ISO 50001

Transkript:

Utfordringer med de tre forsvarslinjer Norges Interne Revisorers Forening 31. mai 2016 Prof. Flemming Ruud, PhD, Statsautorisert revisor Handelshøyskolen BI, Oslo University St. Gallen, Sveits flemming.ruud@bi.no

Slide 2 The Three Lines of Defense Model - tre Governing Body / Board / Audit Committee Senior Management 1 st Line of Defense 2 nd Line of Defense 3 rd Line of Defense Financial Control Security External Audit Regulator Management Controls Internal Control Measures Risk Management Quality Internal Audit Compliance (IIA Position Paper: The Three Lines of Defense in Effective Risk Management and Control, 2013, p. 2)

Slide 3 Innhold Modell forenkling av virkeligheten Presentiøs fremstilling? Risiko management - reduksjon Terminologi - forsvar vs. beskyttelse Skille vs. samarbeid Valg av variabler i modellen «Continuous auditing» - eller monitoring, eller 1. linje? Videre utvikling nye elementer eller variabler? Oppsummering

Slide 4 Leveraging COSO across the Three Lines of Defense Thought Paper of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) 2015 SUPPORT Governance Structures How the organisation assigns specific tasks and responsibilities in internal control (COSO, Leveraging COSO Across the Three Lines of Defense, 2015)

Slide 5 Leveraging COSO across the Three Lines of Defense Thought Paper of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) 2015 SUPPORT Governance Structures How the organisation assigns specific tasks and responsibilities in internal control (COSO, Leveraging COSO Across the Three Lines of Defense, 2015, S. 4)

Slide 6 Leveraging COSO across the Three Lines of Defense (COSO, Leveraging COSO Across the Three Lines of Defense, 2015, S. 5)

Slide 7 Leveraging COSO across the Three Lines of Defense (COSO, Leveraging COSO Across the Three Lines of Defense, 2015, S. 7)

Slide 8 Flere 2. linjefunksjoner Risk Management Information Security Financial Control Physical Security Quality Health and Safety Inspection Compliance Legal Environmental Supply chain Other (depending upon industry-specific or company-specific needs) (COSO, Leveraging COSO Across the Three Lines of Defense, 2015, S. 6)

Slide 9 Og som Assisting management in design and development of processes and controls to manage risks Defining activities to monitor and how to measure success as compared to management expectations Monitoring the adequacy and effectiveness of internal control activities Escalating critical issues, emerging risks and outliers Providing risk management frameworks Identifying and monitoring known and emerging issues affecting the organization s risks and controls Identifying shifts in the organization s implicit risk appetite and risk tolerance Providing guidance and training related to risk management and control processes (COSO, Leveraging COSO Across the Three Lines of Defense, 2015, S. 6)

Slide 10 Leveraging COSO across the Three Lines of Defense (COSO, Leveraging COSO Across the Three Lines of Defense, 2015, S. 8)

Slide 11 Forsvar vs. risikoreduksjon vs. in control Den iboende risikoen i verdikjeden blir redusert gjennom de tre forsvarslinjene Iboende risiko 1 st Line of Defense Management Control Interne Steuerung und Kontrolle 2 nd Line of Defense Risikomanagement Compliance Qualitätssicherung 3 rd Line of Defense Internes Audit Restrisiko

Slide 12 In Control Attention Radar

Slide 13 Internal Control Directive Controls: Support the achievement of objectives Preventive Controls Design Prevent non-beneficial behavior or events Organizational measures: Control effected by the company itself in terms of separation of functions, design of work processes Organizational tools: Plan of the organization, plan of processes, plan of functions, guidance, time stamp, signatory power Technical tools: Securities, IT controls Checking Detective Controls: designed to detect misstatements or omissions as soon as possible Corrective Controls: designed to re-align the actual state with the target state

Slide 14 «Defense» - Forsvar Betydning av forsvar : Fransk; Defense som stammer fra latin; Defensa «Protection» 1. Beskytte seg mot angrep; Angrep fra noen / forhindre noe 2. Argumentere for en person, sak - som er utsatt for kritikk 3. I en rettssak - anklaget i en straffesak forsvare seg i en rettssak 4. Sport Forsvare hvem - seg mot hvem?? Ledelsen? Styret? Eiere Kreditorer? Ansatte (Bibliografisches Institut, 2013)

Slide 15 Forsvar vs. verdiskapning Forsvar vs. Defense Lingvistiske aspekter Verdiskapende merverdiskapning i intern revisjon (3 rd linje) og risk management funksjoner (2 nd linje) Lines of Control? Lines of Responsibility? 3 rd Line-Assurance? Tradisjonelt tankemønster Intern revisjonen som politi for ledelse og styre? Gammeldags bilde av intern revisjonen? Fra «compliance revisjoner til strategic assurance» (Austbø, Statoil) Alternativ til tilbakeskuende «offense»? Se mer «upstream» og mindre «downstream» (May Ibsen)

Slide 16 Adskilte vs samarbeidende funksjoner - Objektivitet vs uavhengighet Governing Body / Board / Audit Committee Senior Management 1 st Line of Defence 2 nd Line of Defence 3 rd Line of Defence Financial Control Security External Audit Regulator Management Controls Internal Control Measures Risk Management Quality Internal Audit Compliance (Adapted from IIA Position Paper: The Three Lines of Defence in Effective Risk Management and Control, 2013, p. 2)

Slide 17 Integrated Assessment and Assurance Zurich Financial Services (Zurich Financial Services, Annual Report 2014, p. 56)

Slide 18 Utviklingen av The Three Lines of Defense-Model Senior Management Board of Directors / Audit Committee 1 st line : Value generation Controls embedded in operational processes 2 nd line : Strategy & Policies Definition and organization of systems 3 rd line : Assessment of control environment Risk management : protection, prevention & transfer actions Internal controls : Key controls Risk management : Definition of ERM system Definition of risk policies, risk appetite Reporting to governance bodies Internal control : Definition of IC system Choice of critical processes & key controls Reporting to governance bodies Internal audit Assessment of processes Testing Ethics & Compliance : Implementation of whistle blowing External certifications : Operational controls linked to : QSE, Basel 2, Ethics & Compliance: Definition of E&C system Reporting to governance bodies External controls Definition of certification policy Reporting to governance bodies External audit Assessment of processes Testing

Slide 19 Utviklingen av The Three Lines of Defense-Model

Slide 20 Utviklingen av Three Lines of Defense-Model Senior Management Board of Directors / Audit Committee 1 st Line of Defense 2 nd Line of Defense 3 rd Line of Defense Operational And Supporting Functions Risk Management and Internal Control procedures, built into business processes Compliance Risk Management Others Internal Audit External Audit Supervisory Authority

Slide 21 The Three Lines of Defense Model - hva med dataanalyser og kontinuerlig revisjon? Governing Body / Board / Audit Committee Senior Management 1 st Line of Defense 2 nd Line of Defense 3 rd Line of Defense Financial Control Security External Audit Regulator Management Controls Internal Control Measures Risk Management Quality Internal Audit Compliance Big data Analytics Continuous auditing???

Slide 22 Nature of work governance, risk management, and control processes The IAA should assess and make appropriate recommendations for improving the governance process in its accomplishment of the following objectives: Promoting appropriate ethics and values within the organization. Ensuring effective organizational performance management and accountability. Effectively communicating risk and control information to appropriate areas of the organization. Effectively coordinating the activities of and communicating information among the board, external and internal auditors and management. Risk Management Processes (2120) Governance Processes (2110) Control Processes (2130) The internal audit activity should evaluate risk exposures relating to the organization s governance, operations, and information systems;...and based on the risk assessment... Evaluate the adequacy and effectiveness of controls... Achievement of the organization s strategic objectives Reliability and integrity of financial and operational information; Effectiveness and efficiency of operations; Safeguarding of assets; and Compliance with laws, regulations, and contracts.

Slide 23 Vekst Re-Performance Intern revisjon - utvikling NYSE Listing Rules: Section 303A.07(d): "Each listed company must have an internal audit function. (2003) Ongoing Compliance Introduction SOX Compliance (2002) Basel Committee: Internal audit in banks and the supervisor's relationship with audit (2001) COSO Internal Control (1992) Control COSO ERM (2004) Risk Operations Update COSO Internal Control (2013) Basel Committee: The internal audit function in banks (2012) Governance Financial Reporting Compliance Internal Control over Financial Reporting Update NUES / Swiss Code (2014) Risiko management prosesser Standard 2120 Quo vadis Standard 2110 Governance prosesser Interne styringsog kontrollprosesser Standard 2130? 1990 2000 2010 2020

Slide 24 Tre forsvarslinje modell Prosessorientert Overordnet uttalelse - «Helhetlige bekreftelser» Legislation Shareholders Investors Other Stakeholders Government Direction Suppliers 1 st Line Indicators Controlling Risk Management BoD CEO Vision Objectives Strategies Employers Nomination Remuneration Audit Committee Compliance Value Adding Process 2 nd Line Quality Management 3 rd Line- Assurance Signals Risk Management and Internal Control External Audit Customers Accountability

Slide 25 Development and Current State of Internal Auditing Internal auditing has got to be the coolest profession in the world. (Tom Peters, The Institute of Internal Auditors International Conference, Orlando, 2013) Tom Peters (*November 7, 1942) American management guru and writer on business management practices; Co-author (with Robert H. Waterman, Jr.) of best-seller In Search of Excellence, 1982