Page 75 - IRMSA Risk Report 2020
P. 75
RISK ASSUR ANCE AND GOVERNANCE
1. Risk reporting can be improved to support risk-based decision-making by moving away from the scheduled type
reporting to a more relevant and timeous reporting method. This will only be possible with innovative real-time
data analytics, scenario and predictive capabilities and intelligent survey/tracking solutions.
2. Better understand the concept of combined assurance and the impact it may have on the level of confidence
boards, executive- and oversight committees can place on the information reported to them.
3. Implementing performance and consequence management.
IS Y OUR OR GANISATION ’ S O WN RISK REPORT EFFEC TIVELY UTILISED
IN THE OR GANISATION ’ S RISK-B ASED DECISIONS ?
Functional Management
Operational Management
Company Secretary
Other Assurance Roles (e.g. Audit, Compliance, Ethics)
Risk Consultant/Professional
Risk Practitioner
Risk Manager
Chief Risk Officer/Head of Risk
Chief Operations Officer
Chief Financial Officer
Chief Executive Officer
Non-Executive Director or Committee Member
0% 10% 20% 30% 40% 50% 60% 70% 80% 90% 100%
Yes - we find that risk reporting is an integral part of the decisions making process
Somewhat - the risk report is used by some parts of the organisation to make risk-based decisions
No - risk reports are not utilised to drive appropriate risk-based decisions
IS C OMBINED ASSUR ANCE OPTIM ALLY USED AS P ART OF AN
INTEGR ATED RISK M ANA GEMENT PR OCESS ?
Functional Management
Operational Management
Company Secretary
Other Assurance Roles (e.g. Audit, Compliance, Ethics)
Risk Consultant/Professional
Risk Practitioner
Risk Manager
Chief Risk Officer/Head of Risk
Chief Operations Officer
Chief Financial Officer
Chief Executive Officer
Non-Executive Director or Committee Member
0% 10% 20% 30% 40% 50% 60% 70% 80% 90% 100%
Yes - we use it to provide additional assurance and benefit from assessing and managing over / under
assurance
Somewhat - we do have a combined assurance report but do not use it optimally due to poor quality or lack or
understanding
No - We have a combined assurance report to comply but do not use it
No - We do not have a combined assurance report
G R A P H S 7 : R I S K A S S U R A N C E A N D G O V E R N A N C E .
7 4