Paterson James C.

Lean Auditing


Скачать книгу

the wider organization.

      Many of these principles link to attributes and standards that have been developed by the Institute of Internal Auditors (IIA), the global professional body for the internal audit profession.

      Particular IIA standards and attributes of note include statements that:

      • The CAE should manage the internal audit activity to ensure it adds value to the organization;

      • The CAE should share information and co-ordinate the work of other compliance and assurance providers with the work of internal audit;

      • Internal audit should operate with an understanding that the “Three lines of defence” framework (with management, compliance functions and audit each in separate “lines of defence”) is likely to be the most effective way to manage risks;

      • Internal audit should act as an independent and objective function to assess, amongst other things, the effectiveness and efficiency of the organization’s operations.

      At face value, therefore, lean ways of working can appear to be a helpful “bolt on” to the current IIA standards, since they can support the delivery of a value adding and efficient audit service. However, as we will see later in this book, lean ways of working can question a number of commonly held perceptions about the role of internal audit, for example:

      • That the role of audit should primarily be to deliver internal audits;

      • That the audit plan should cover known risk areas of concern;

      • That auditors should strictly adhere to predetermined assignment and test plans;

      • That auditors should look for fraud in each and every assignment;

      • That audit should proactively follow up the progress of management in remediating all open points;

      • That audit should mostly be comprised of qualified finance and audit staff.

      As we will see in later chapters of this book, I am not arguing that audit should ignore its role to look out for fraud, to follow up on open actions, or to have trained audit professionals, but unless care is taken there is a risk that:

      • Internal audit ceases to be a key player in visibly improving Governance, Risk, Compliance and Assurance activities and processes;

      • Internal audit is not seen to be a vital source of value add in organizations;

      • Internal audit starts to become a substitute for processes and activities that should be carried out by management, or other functions.

      The Mindset of a Lean, Progressive, Auditing Approach

      Underpinning a lean auditing approach is a mindset that some more traditionally minded internal auditors may find rather challenging, namely:

      • A view that stakeholders should be regularly engaged in relation to what they value from audit;

      • A view that stakeholders should also be challenged when necessary in relation to the role of audit, and the tasks it should perform;

      • A view that audit should take a proactive interest in the Risk Assurance picture for the whole organization, and work to influence the roles of key functions if there are gaps or overlaps of concern;

      • A view that audit should regard all risk areas equally in terms of their potential coverage and be careful not to favour traditional areas, such as financial controls or compliance;

      • A view that the recruitment of staff into audit should be influenced by the value needs of the wider organization as much as the need for qualified audit staff;

      • A view that audit should be just as interested in cultural and behavioural issues across the organization as straightforward audit findings;

      • A view that management risk appetite judgments should be challenged when necessary.

      Конец ознакомительного фрагмента.

      Текст предоставлен ООО «ЛитРес».

      Прочитайте эту книгу целиком, купив полную легальную версию на ЛитРес.

      Безопасно оплатить книгу можно банковской картой Visa, MasterCard, Maestro, со счета мобильного телефона, с платежного терминала, в салоне МТС или Связной, через PayPal, WebMoney, Яндекс.Деньги, QIWI Кошелек, бонусными картами или другим удобным Вам способом.

/9j/4AAQSkZJRgABAQEAYABgAAD/2wBDAAQCAwMDAgQDAwMEBAQEBQkGBQUFBQsICAYJDQsNDQ0LDAwOEBQRDg8TDwwMEhgSExUWFxcXDhEZGxkWGhQWFxb/2wBDAQQEBAUFBQoGBgoWDwwPFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhb/wAARCAAhAJkDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3e