Most approaches to operational risk and internal control have been qualitative in
that the identification of operational risk has been measured in words rather than
numbers. A common approach has been to perform a review of the way a business
manages operational risk and then to perform a risk assessment based upon the
‘objective’ judgement of an experienced reviewer. Much of this type of review work
has, in the past, been performed by internal audit during the fulfillment of their
normal duties. In most banks, until recently, there were no other departments
involved in operational risk assessment except for internal audit and the businesses.
Many auditors have argued that they have been measuring operational risk for as
long as audit has existed (centuries). Their approach to operational risk can be
summarized by referring to various standards and guidelines on auditing.
In America, in September 1992, the Committee of Sponsoring Organizations of the
Treadway Commission produced ‘Internal Control – Integrated Framework’ for all
firms, not only financial institutions. All the key concepts of this document have
been incorporated into American Statements of Auditing Standards. SAS 55 states
that internal control is a process – effected by an entity’s board of directors, management,
and other personnel – designed to provide reasonable assurance regarding the
achievement of objectives in the following categories:
Ω reliability of financial reporting
Ω effectiveness and efficiency of operations and
Ω compliance with applicable laws and regulations.
COSO pointed out that internal control is a process and that it is ‘a series of actions
which permeate an entity’s activities’.
COSO contained the following five components of the internal control framework:
1 Control Environment
2 Risk Assessment
3 Control Activities
4 Information and Communication
5 Monitoring
Ω Control Environment – this provides the foundation on which people conduct
their activities and carry out their control activities. It includes the integrity and
ethical values of the firm.
Ω Risk Assessment – the firm must be aware of the risks it faces, including
operational risks. It must set business objectives, integrated with the sales,
production and marketing, financial and other activities so that the organization
is operating with consistency across the different business units. The firm must
establish mechanisms to identify, analyze and manage the related risks.
Ω Control Activities – control policies and procedures must be established and
executed to help ensure that the actions identified by management as necessary
to address risks to the achievement of the entity’s objectives are effectively
carried out.
Ω Information and Communication – Surrounding these activities are information
and communication systems. These enable the entity’s people to capture and
exchange the information needed to conduct, manage and control its operations.
Ω Monitoring – the entire process must be monitored, and modifications made as
necessary. In this way, the system can react dynamically, changing as conditions
warrant.
COSO identified a methodology of operational risk management before the current
trend. The five components support the three objectives mentioned above of:
Ω Financial reporting
Ω Compliance
Ω Operations.
It is with operations that we will deal with to illustrate how qualitative operational
risk measurement can be achieved using the COSO framework. We will do this by
considering the way in which COSO recommends that the ‘Effectiveness’ of the
internal control system is measured. In relation to operations the five components
must be working effectively. The test is whether the board of directors are able to
form a view about the extent to which the entity’s operations objectives are being
met. COSO believes that the effectiveness test is a subjective assessment of whether
the five components are present and operating.
The method employed by most firms to address internal control is to employ
Control Self-assessment, normally through interactive workshops with the business
to set the framework followed up by a checklist of key controls based around the five
components highlighted above. The risks (or internal control weaknesses) can be
ranked in order of priority and resources allocated to address them. The ranking is
meant to take account of the magnitude and likelihood of loss. However, this is
extremely subjective and relies on the experience of the auditor, business manager
or operational risk manager. A better approach is to quantify the operational risk.
Hiç yorum yok:
Yorum Gönder