FierceFinanceFierceFinanceITFierceComplianceIT   FierceCIO

Four keen IA observations

Compliance Week had some interesting observations--all of which are conversation starters--about internal auditing, and where it's headed.

First of all, most practitioners draw a division between what they do and risk management. Do not assume they are synonymous. Better to think of the internal auditors as people who can help risk managers do their job.

Second, boards and audit committees have gotten religious when it comes to risk management--which is great news.

Third, internal auditors aren't clear on what to do about certain risks. It can be very hard to "translate that risk into an auditable event."

And fourth, there are those who feel that internal auditors may be facing a conflict of interest if they were to help management and the board shape a risk management policy and then conduct the audit. It would be too easy to get the auditors "invested" in the success of the program by working with powerful directors, for example. Better to maintain some distinction.  

For more:
- here's the article

Related Articles:
Internal auditors vs. info security: Still an issue?
Big battle: Security managers vs. auditors?
The downside of auditor independence

SHARE WITH:
Email Twitter Facebook LinkedIn StumbleUpon
Get Your FREE FierceComplianceIT Email Newsletter:
Be the first to comment

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.